XueTr --- Computer Examination Report
Examination Date: 2012-02-06 14:39
OS Information: Microsoft Windows 7 Home Premium Edition Service Pack 1 (build 7601), 32-bit
Internet Explorer: 9.0.8112.16421

Examination Items:
      Process
      Process Modules
      Process Threads
      Kernel Module
      Notify Routine
      Filter
      DPC Timer
      Worker Thread
      Object Hijack
      Direct IO
      GDT
      SSDT
      Shadow SSDT
      FSD
      Keyboard
      Mouclass
      Classpnp
      Atapi
      Acpi
      Scsi
      Kernel Hook
      Object Type
      IDT
      Message Hook
      Process Hook
      KernelCallbackTable
      Port
      Tcpip
      Nsiproxy
      IE Plugin
      IE Shell
      Spi
      Hosts File
      Startup
      Service
      File Association
      IFEO
      IME
      Firewall Rule
      Scan MBR Rootkit

==========================================================================================

Process

       System - System - 
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       explorer.exe - C:\Windows\explorer.exe - Microsoft Corporation
       AvastSvc.exe - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - AVAST Software
       smss.exe - C:\Windows\System32\smss.exe - Microsoft Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
       Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       csrss.exe - C:\Windows\System32\csrss.exe - Microsoft Corporation
       chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
       chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
       daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation
       csrss.exe - C:\Windows\System32\csrss.exe - Microsoft Corporation
       wininit.exe - C:\Windows\System32\wininit.exe - Microsoft Corporation
       winlogon.exe - C:\Windows\System32\winlogon.exe - Microsoft Corporation
       nvxdsync.exe - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe - NVIDIA Corporation
       services.exe - C:\Windows\System32\services.exe - Microsoft Corporation
       lsass.exe - C:\Windows\System32\lsass.exe - Microsoft Corporation
       lsm.exe - C:\Windows\System32\lsm.exe - Microsoft Corporation
       WmiPrvSE.exe - C:\Windows\System32\wbem\WmiPrvSE.exe - Microsoft Corporation
       iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
       nvvsvc.exe - C:\Windows\System32\nvvsvc.exe - NVIDIA Corporation
       vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
       chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
       PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
       nvvsvc.exe - C:\Windows\System32\nvvsvc.exe - NVIDIA Corporation
       nvSCPAPISvr.exe - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - NVIDIA Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       wmpnetwk.exe - C:\Program Files\Windows Media Player\wmpnetwk.exe - Microsoft Corporation
       taskhost.exe - C:\Windows\System32\taskhost.exe - Microsoft Corporation
       chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       nvtray.exe - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe - NVIDIA Corporation
       PDAgentS1.exe - C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe - Raxco Software, Inc.
       taskmgr.exe - C:\Windows\System32\taskmgr.exe - Microsoft Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       SearchIndexer.exe - C:\Windows\System32\SearchIndexer.exe - Microsoft Corporation
       soffice.bin - C:\Program Files\OpenOffice.org 3\program\soffice.bin - OpenOffice.org
       dwm.exe - C:\Windows\System32\dwm.exe - Microsoft Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       sqlservr.exe - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe - Microsoft Corporation
       XueTr.exe - C:\Nov sloka\XueTr.exe - Email: linxer@163.com
       chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
       AppleMobileDeviceService.exe - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - Apple Inc.
       VM305_STI.EXE - C:\Windows\VM305_STI.EXE - Vimicro
       soffice.exe - C:\Program Files\OpenOffice.org 3\program\soffice.exe - OpenOffice.org
       mDNSResponder.exe - C:\Program Files\Bonjour\mDNSResponder.exe - Apple Inc.
       vmnetdhcp.exe - C:\Windows\System32\vmnetdhcp.exe - VMware, Inc.
       spoolsv.exe - C:\Windows\System32\spoolsv.exe - Microsoft Corporation
       CepstralLicSrv.exe - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe - Cepstral, LLC
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe - TeamViewer GmbH
       launcherd.exe - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe - 
       PnkBstrA.exe - C:\Windows\System32\PnkBstrA.exe - 
       PnkBstrB.exe - C:\Windows\System32\PnkBstrB.exe - 
       sqlwriter.exe - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe - Microsoft Corporation
       svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
       TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe - TeamViewer GmbH
       vmnat.exe - C:\Windows\System32\vmnat.exe - VMware, Inc.
       chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
       WLIDSVC.EXE - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE - Microsoft Corp.
       vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.
       WLIDSVCM.EXE - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE - Microsoft Corp.
       vmware-hostd.exe - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe - 
       PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
       audiodg.exe - C:\Windows\System32\audiodg.exe - Microsoft Corporation
       Idle - Idle - 

==========================================================================================

Process Modules

      Image File Name[System]Modules
             ntdll.dll - C:\Windows\System32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             gpsvc.dll - c:\windows\system32\gpsvc.dll - Microsoft Corporation
             GPAPI.dll - c:\windows\system32\GPAPI.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             Secur32.dll - c:\windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             SYSNTFY.dll - c:\windows\system32\SYSNTFY.dll - Microsoft Corporation
             nlaapi.dll - c:\windows\system32\nlaapi.dll - Microsoft Corporation
             themeservice.dll - c:\windows\system32\themeservice.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             profsvc.dll - c:\windows\system32\profsvc.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             USERENV.dll - c:\windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - c:\windows\system32\profapi.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             ATL.DLL - c:\windows\system32\ATL.DLL - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             dsrole.dll - C:\Windows\system32\dsrole.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             SAMLIB.dll - C:\Windows\system32\SAMLIB.dll - Microsoft Corporation
             shsvcs.dll - c:\windows\system32\shsvcs.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             FVEAPI.dll - C:\Windows\system32\FVEAPI.dll - Microsoft Corporation
             tbs.dll - C:\Windows\system32\tbs.dll - Microsoft Corporation
             FVECERTS.dll - C:\Windows\system32\FVECERTS.dll - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             LOGONCLI.DLL - C:\Windows\system32\LOGONCLI.DLL - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             wiarpc.dll - C:\Windows\system32\wiarpc.dll - Microsoft Corporation
             shell32.dll - C:\Windows\system32\shell32.dll - Microsoft Corporation
             schedsvc.dll - c:\windows\system32\schedsvc.dll - Microsoft Corporation
             pcwum.dll - c:\windows\system32\pcwum.dll - Microsoft Corporation
             wevtapi.dll - c:\windows\system32\wevtapi.dll - Microsoft Corporation
             AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             UBPM.dll - c:\windows\system32\UBPM.dll - Microsoft Corporation
             ktmw32.dll - c:\windows\system32\ktmw32.dll - Microsoft Corporation
             XmlLite.dll - c:\windows\system32\XmlLite.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             taskcomp.dll - C:\Windows\system32\taskcomp.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             netjoin.dll - C:\Windows\system32\netjoin.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             ikeext.dll - c:\windows\system32\ikeext.dll - Microsoft Corporation
             fwpuclnt.dll - c:\windows\system32\fwpuclnt.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             wmisvc.dll - c:\windows\system32\wbem\wmisvc.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             iphlpsvc.dll - c:\windows\system32\iphlpsvc.dll - Microsoft Corporation
             FirewallAPI.dll - c:\windows\system32\FirewallAPI.dll - Microsoft Corporation
             rtutils.dll - c:\windows\system32\rtutils.dll - Microsoft Corporation
             sqmapi.dll - c:\windows\system32\sqmapi.dll - Microsoft Corporation
             WDSCORE.dll - c:\windows\system32\WDSCORE.dll - Microsoft Corporation
             VSSAPI.DLL - C:\Windows\system32\VSSAPI.DLL - Microsoft Corporation
             VssTrace.DLL - C:\Windows\system32\VssTrace.DLL - Microsoft Corporation
             samcli.dll - C:\Windows\system32\samcli.dll - Microsoft Corporation
             wbemcore.dll - C:\Windows\system32\wbem\wbemcore.dll - Microsoft Corporation
             esscli.dll - C:\Windows\system32\wbem\esscli.dll - Microsoft Corporation
             FastProx.dll - C:\Windows\system32\wbem\FastProx.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             devrtl.DLL - C:\Windows\system32\devrtl.DLL - Microsoft Corporation
             netprofm.dll - C:\Windows\System32\netprofm.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             wmiutils.dll - C:\Windows\system32\wbem\wmiutils.dll - Microsoft Corporation
             NCI.dll - C:\Windows\system32\NCI.dll - Microsoft Corporation
             repdrvfs.dll - C:\Windows\system32\wbem\repdrvfs.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             wmiprvsd.dll - C:\Windows\system32\wbem\wmiprvsd.dll - Microsoft Corporation
             NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             wbemess.dll - C:\Windows\system32\wbem\wbemess.dll - Microsoft Corporation
             ncprov.dll - C:\Windows\system32\wbem\ncprov.dll - Microsoft Corporation
             srvsvc.dll - c:\windows\system32\srvsvc.dll - Microsoft Corporation
             browser.dll - c:\windows\system32\browser.dll - Microsoft Corporation
             SSCORE.DLL - C:\Windows\system32\SSCORE.DLL - Microsoft Corporation
             CLUSAPI.DLL - C:\Windows\system32\CLUSAPI.DLL - Microsoft Corporation
             cryptdll.dll - C:\Windows\system32\cryptdll.dll - Microsoft Corporation
             RESUTILS.DLL - C:\Windows\system32\RESUTILS.DLL - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             SPINF.dll - C:\Windows\system32\SPINF.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             wuaueng.dll - c:\windows\system32\wuaueng.dll - Microsoft Corporation
             ESENT.dll - c:\windows\system32\ESENT.dll - Microsoft Corporation
             WINSPOOL.DRV - c:\windows\system32\WINSPOOL.DRV - Microsoft Corporation
             WINHTTP.dll - c:\windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - c:\windows\system32\webio.dll - Microsoft Corporation
             Cabinet.dll - c:\windows\system32\Cabinet.dll - Microsoft Corporation
             mspatcha.dll - c:\windows\system32\mspatcha.dll - Microsoft Corporation
             WMsgAPI.dll - C:\Windows\system32\WMsgAPI.dll - Microsoft Corporation
             appinfo.dll - c:\windows\system32\appinfo.dll - Microsoft Corporation
             msxml3.dll - C:\Windows\System32\msxml3.dll - Microsoft Corporation
             wer.dll - C:\Windows\system32\wer.dll - Microsoft Corporation
             schannel.DLL - C:\Windows\system32\schannel.DLL - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation
             tschannel.dll - C:\Windows\system32\tschannel.dll - Microsoft Corporation
             actxprxy.dll - C:\Windows\system32\actxprxy.dll - Microsoft Corporation
             hnetcfg.dll - C:\Windows\system32\hnetcfg.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             mmcss.dll - c:\windows\system32\mmcss.dll - Microsoft Corporation
             AVRT.dll - c:\windows\system32\AVRT.dll - Microsoft Corporation
             aelupsvc.dll - c:\windows\system32\aelupsvc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[explorer.exe]Modules
             Explorer.EXE - C:\Windows\Explorer.EXE - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             EXPLORERFRAME.dll - C:\Windows\system32\EXPLORERFRAME.dll - Microsoft Corporation
             DUser.dll - C:\Windows\system32\DUser.dll - Microsoft Corporation
             DUI70.dll - C:\Windows\system32\DUI70.dll - Microsoft Corporation
             IMM32.dll - C:\Windows\system32\IMM32.dll - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             WindowsCodecs.dll - C:\Windows\system32\WindowsCodecs.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             ashShell.dll - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software
             msi.dll - C:\Windows\system32\msi.dll - Microsoft Corporation
             EhStorShell.dll - C:\Windows\system32\EhStorShell.dll - Microsoft Corporation
             ntshrui.dll - C:\Windows\system32\ntshrui.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             IconCodecService.dll - C:\Windows\system32\IconCodecService.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             SndVolSSO.DLL - C:\Windows\system32\SndVolSSO.DLL - Microsoft Corporation
             HID.DLL - C:\Windows\system32\HID.DLL - Microsoft Corporation
             MMDevApi.dll - C:\Windows\System32\MMDevApi.dll - Microsoft Corporation
             timedate.cpl - C:\Windows\system32\timedate.cpl - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             actxprxy.dll - C:\Windows\system32\actxprxy.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             shdocvw.dll - C:\Windows\System32\shdocvw.dll - Microsoft Corporation
             LINKINFO.dll - C:\Windows\system32\LINKINFO.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             SAMLIB.dll - C:\Windows\system32\SAMLIB.dll - Microsoft Corporation
             samcli.dll - C:\Windows\system32\samcli.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             gameux.dll - C:\Windows\System32\gameux.dll - Microsoft Corporation
             XmlLite.dll - C:\Windows\System32\XmlLite.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             wer.dll - C:\Windows\System32\wer.dll - Microsoft Corporation
             msls31.dll - C:\Windows\system32\msls31.dll - Microsoft Corporation
             tiptsf.dll - C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll - Microsoft Corporation
             authui.dll - C:\Windows\system32\authui.dll - Microsoft Corporation
             CRYPTUI.dll - C:\Windows\system32\CRYPTUI.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             ieframe.dll - C:\Windows\System32\ieframe.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\System32\OLEACC.dll - Microsoft Corporation
             stobject.dll - C:\Windows\system32\stobject.dll - Microsoft Corporation
             BatMeter.dll - C:\Windows\system32\BatMeter.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             es.dll - C:\Windows\system32\es.dll - Microsoft Corporation
             msiltcfg.dll - C:\Windows\system32\msiltcfg.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             prnfldr.dll - C:\Windows\system32\prnfldr.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             MLANG.dll - C:\Windows\system32\MLANG.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             wdmaud.drv - C:\Windows\system32\wdmaud.drv - Microsoft Corporation
             ksuser.dll - C:\Windows\system32\ksuser.dll - Microsoft Corporation
             AVRT.dll - C:\Windows\system32\AVRT.dll - Microsoft Corporation
             AUDIOSES.DLL - C:\Windows\system32\AUDIOSES.DLL - Microsoft Corporation
             msacm32.drv - C:\Windows\system32\msacm32.drv - Microsoft Corporation
             MSACM32.dll - C:\Windows\system32\MSACM32.dll - Microsoft Corporation
             midimap.dll - C:\Windows\system32\midimap.dll - Microsoft Corporation
             SFC.DLL - C:\Windows\system32\SFC.DLL - Microsoft Corporation
             sfc_os.DLL - C:\Windows\system32\sfc_os.DLL - Microsoft Corporation
             DEVRTL.dll - C:\Windows\system32\DEVRTL.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             UIAnimation.dll - C:\Windows\System32\UIAnimation.dll - Microsoft Corporation
             msutb.dll - C:\Windows\system32\msutb.dll - Microsoft Corporation
             dxp.dll - C:\Windows\system32\dxp.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             Syncreg.dll - C:\Windows\system32\Syncreg.dll - Microsoft Corporation
             ehSSO.dll - C:\Windows\ehome\ehSSO.dll - Microsoft Corporation
             netshell.dll - C:\Windows\System32\netshell.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\System32\IPHLPAPI.DLL - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\System32\WINNSI.DLL - Microsoft Corporation
             nlaapi.dll - C:\Windows\System32\nlaapi.dll - Microsoft Corporation
             AltTab.dll - C:\Windows\System32\AltTab.dll - Microsoft Corporation
             wpdshserviceobj.dll - C:\Windows\system32\wpdshserviceobj.dll - Microsoft Corporation
             PortableDeviceTypes.dll - C:\Windows\system32\PortableDeviceTypes.dll - Microsoft Corporation
             PortableDeviceApi.dll - C:\Windows\system32\PortableDeviceApi.dll - Microsoft Corporation
             pnidui.dll - C:\Windows\System32\pnidui.dll - Microsoft Corporation
             QUtil.dll - C:\Windows\System32\QUtil.dll - Microsoft Corporation
             wevtapi.dll - C:\Windows\System32\wevtapi.dll - Microsoft Corporation
             srchadmin.dll - C:\Windows\System32\srchadmin.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             Actioncenter.dll - C:\Windows\System32\Actioncenter.dll - Microsoft Corporation
             fxsst.dll - C:\Windows\system32\fxsst.dll - Microsoft Corporation
             FXSAPI.dll - C:\Windows\system32\FXSAPI.dll - Microsoft Corporation
             FXSRESM.DLL - C:\Windows\system32\FXSRESM.DLL - Microsoft Corporation
             MsftEdit.dll - C:\Windows\system32\MsftEdit.dll - Microsoft Corporation
             mssprxy.dll - C:\Windows\system32\mssprxy.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             Wlanapi.dll - C:\Windows\system32\Wlanapi.dll - Microsoft Corporation
             wlanutil.dll - C:\Windows\system32\wlanutil.dll - Microsoft Corporation
             wwanapi.dll - C:\Windows\system32\wwanapi.dll - Microsoft Corporation
             wwapi.dll - C:\Windows\system32\wwapi.dll - Microsoft Corporation
             QAgent.dll - C:\Windows\System32\QAgent.dll - Microsoft Corporation
             bthprops.cpl - C:\Windows\System32\bthprops.cpl - Microsoft Corporation
             provsvc.dll - C:\Windows\System32\provsvc.dll - Microsoft Corporation
             SyncCenter.dll - C:\Windows\System32\SyncCenter.dll - Microsoft Corporation
             imapi2.dll - C:\Windows\system32\imapi2.dll - Microsoft Corporation
             hgcpl.dll - C:\Windows\System32\hgcpl.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             wscinterop.dll - C:\Windows\System32\wscinterop.dll - Microsoft Corporation
             WSCAPI.dll - C:\Windows\System32\WSCAPI.dll - Microsoft Corporation
             wscui.cpl - C:\Windows\System32\wscui.cpl - Microsoft Corporation
             werconcpl.dll - C:\Windows\System32\werconcpl.dll - Microsoft Corporation
             framedynos.dll - C:\Windows\System32\framedynos.dll - Microsoft Corporation
             wercplsupport.dll - C:\Windows\System32\wercplsupport.dll - Microsoft Corporation
             msxml6.dll - C:\Windows\System32\msxml6.dll - Microsoft Corporation
             hcproviders.dll - C:\Windows\System32\hcproviders.dll - Microsoft Corporation
             ieproxy.dll - C:\Program Files\Internet Explorer\ieproxy.dll - Microsoft Corporation
             NetworkExplorer.dll - C:\Windows\system32\NetworkExplorer.dll - Microsoft Corporation
             StructuredQuery.dll - C:\Windows\System32\StructuredQuery.dll - Microsoft Corporation
             fzshellext.dll - C:\Program Files\FileZilla FTP Client\fzshellext.dll - 
             PhotoBase.dll - C:\Program Files\Windows Photo Viewer\PhotoBase.dll - Microsoft Corporation
             windowscodecsext.dll - C:\Windows\system32\windowscodecsext.dll - Microsoft Corporation
             imagehlp.dll - C:\Windows\system32\imagehlp.dll - Microsoft Corporation
             thumbcache.dll - C:\Windows\system32\thumbcache.dll - Microsoft Corporation
             nvshext.dll - C:\Windows\system32\nvshext.dll - NVIDIA Corporation
             sbdrop.dll - C:\Program Files\Windows Sidebar\sbdrop.dll - Microsoft Corporation
             zipfldr.dll - C:\Windows\system32\zipfldr.dll - Microsoft Corporation
             rarext.dll - C:\Program Files\WinRAR\rarext.dll - 

------------------------------------------------------------------------------------------

      Image File Name[AvastSvc.exe]Modules
             AvastSvc.exe - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - AVAST Software
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             aswCmnBS.dll - C:\Program Files\AVAST Software\Avast\aswCmnBS.dll - AVAST Software
             aswCmnOS.dll - C:\Program Files\AVAST Software\Avast\aswCmnOS.dll - AVAST Software
             aswCmnIS.dll - C:\Program Files\AVAST Software\Avast\aswCmnIS.dll - AVAST Software
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             MSVCP90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll - Microsoft Corporation
             ashBase.dll - C:\Program Files\AVAST Software\Avast\ashBase.dll - AVAST Software
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             aswEngLdr.dll - C:\Program Files\AVAST Software\Avast\aswEngLdr.dll - AVAST Software
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             dbghelp.dll - C:\Windows\system32\dbghelp.dll - Microsoft Corporation
             Base.dll - C:\Program Files\AVAST Software\Avast\1051\Base.dll - AVAST Software
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             aswAux.dll - C:\Program Files\AVAST Software\Avast\aswAux.dll - AVAST Software
             ashTask.dll - C:\Program Files\AVAST Software\Avast\ashTask.dll - AVAST Software
             ashTaskEx.dll - C:\Program Files\AVAST Software\Avast\ashTaskEx.dll - AVAST Software
             aswLog.dll - C:\Program Files\AVAST Software\Avast\aswLog.dll - AVAST Software
             aswSqLt.dll - C:\Program Files\AVAST Software\Avast\aswSqLt.dll - AVAST Software
             aswProperty.dll - C:\Program Files\AVAST Software\Avast\aswProperty.dll - AVAST Software
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             AavmRpch.dll - C:\Program Files\AVAST Software\Avast\AavmRpch.dll - AVAST Software
             aswIdle.dll - C:\Program Files\AVAST Software\Avast\aswIdle.dll - AVAST Software
             aswStrm.dll - C:\Program Files\AVAST Software\Avast\aswStrm.dll - AVAST Software
             aswDld.dll - C:\Program Files\AVAST Software\Avast\aswDld.dll - AVAST Software
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             wscisvif.dll - C:\Windows\system32\wscisvif.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             WSCAPI.dll - C:\Windows\system32\WSCAPI.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             FltLib.dll - C:\Windows\system32\FltLib.dll - Microsoft Corporation
             Wtsapi32.dll - C:\Windows\system32\Wtsapi32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             NetApi32.dll - C:\Windows\system32\NetApi32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             AhResBhv.dll - C:\Program Files\AVAST Software\Avast\AhResBhv.dll - AVAST Software
             AhResJs.dll - C:\Program Files\AVAST Software\Avast\AhResJs.dll - AVAST Software
             AhResMai.dll - C:\Program Files\AVAST Software\Avast\AhResMai.dll - AVAST Software
             AhResMes.dll - C:\Program Files\AVAST Software\Avast\AhResMes.dll - AVAST Software
             AhResNS.dll - C:\Program Files\AVAST Software\Avast\AhResNS.dll - AVAST Software
             AhResP2P.dll - C:\Program Files\AVAST Software\Avast\AhResP2P.dll - AVAST Software
             AhResStd.dll - C:\Program Files\AVAST Software\Avast\AhResStd.dll - AVAST Software
             AhResWS.dll - C:\Program Files\AVAST Software\Avast\AhResWS.dll - AVAST Software
             ashMaiSv.dll - C:\Program Files\AVAST Software\Avast\ashMaiSv.dll - AVAST Software
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             ashWebSv.dll - C:\Program Files\AVAST Software\Avast\ashWebSv.dll - AVAST Software
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             Iphlpapi.DLL - C:\Windows\system32\Iphlpapi.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             security.dll - C:\Windows\system32\security.dll - Microsoft Corporation
             ashWsFtr.dll - C:\Program Files\AVAST Software\Avast\ashWsFtr.dll - AVAST Software
             wininet.dll - C:\Windows\system32\wininet.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             aswEngin.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswEngin.dll - AVAST Software
             aswCmnOS.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswCmnOS.dll - AVAST Software
             aswCmnIS.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswCmnIS.dll - AVAST Software
             aswCmnBS.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswCmnBS.dll - AVAST Software
             aswScan.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswScan.dll - AVAST Software
             aswRep.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswRep.dll - AVAST Software
             aswFiDb.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswFiDb.dll - AVAST Software
             algo.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\algo.dll - 
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             arPot.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\arPot.dll - AVAST Software

------------------------------------------------------------------------------------------

      Image File Name[smss.exe]Modules
             smss.exe - C:\Windows\System32\smss.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             umpnpmgr.dll - c:\windows\system32\umpnpmgr.dll - Microsoft Corporation
             SPINF.dll - c:\windows\system32\SPINF.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             DEVRTL.dll - c:\windows\system32\DEVRTL.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             umpo.dll - c:\windows\system32\umpo.dll - Microsoft Corporation
             WINSTA.dll - c:\windows\system32\WINSTA.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             pcwum.DLL - c:\windows\system32\pcwum.DLL - Microsoft Corporation
             rpcss.dll - c:\windows\system32\rpcss.dll - Microsoft Corporation
             SspiCli.dll - c:\windows\system32\SspiCli.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             wmidcprv.dll - C:\Windows\system32\wbem\wmidcprv.dll - Microsoft Corporation
             FastProx.dll - C:\Windows\system32\wbem\FastProx.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             wmiutils.dll - C:\Windows\system32\wbem\wmiutils.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[AvastUI.exe]Modules
             AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             aswUtil.dll - C:\Program Files\AVAST Software\Avast\aswUtil.dll - AVAST Software
             ashBase.dll - C:\Program Files\AVAST Software\Avast\ashBase.dll - AVAST Software
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             aswEngLdr.dll - C:\Program Files\AVAST Software\Avast\aswEngLdr.dll - AVAST Software
             aswCmnOS.dll - C:\Program Files\AVAST Software\Avast\aswCmnOS.dll - AVAST Software
             aswCmnIS.dll - C:\Program Files\AVAST Software\Avast\aswCmnIS.dll - AVAST Software
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             MSVCP90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll - Microsoft Corporation
             aswCmnBS.dll - C:\Program Files\AVAST Software\Avast\aswCmnBS.dll - AVAST Software
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             ashTask.dll - C:\Program Files\AVAST Software\Avast\ashTask.dll - AVAST Software
             aswAux.dll - C:\Program Files\AVAST Software\Avast\aswAux.dll - AVAST Software
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             aswLog.dll - C:\Program Files\AVAST Software\Avast\aswLog.dll - AVAST Software
             aswSqLt.dll - C:\Program Files\AVAST Software\Avast\aswSqLt.dll - AVAST Software
             aswProperty.dll - C:\Program Files\AVAST Software\Avast\aswProperty.dll - AVAST Software
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             mfc90u.dll - C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             COMDLG32.dll - C:\Windows\system32\COMDLG32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             dbghelp.dll - C:\Windows\system32\dbghelp.dll - Microsoft Corporation
             Base.dll - C:\Program Files\AVAST Software\Avast\1051\Base.dll - AVAST Software
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             aswData.dll - C:\Program Files\AVAST Software\Avast\aswData.dll - AVAST Software
             ashTaskEx.dll - C:\Program Files\AVAST Software\Avast\ashTaskEx.dll - AVAST Software
             Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             AavmRpch.dll - C:\Program Files\AVAST Software\Avast\AavmRpch.dll - AVAST Software
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             UILangRes.dll - C:\Program Files\AVAST Software\Avast\1051\UILangRes.dll - AVAST Software
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             CommonRes.dll - C:\Program Files\AVAST Software\Avast\CommonRes.dll - AVAST Software
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\System32\mswsock.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             Iphlpapi.DLL - C:\Windows\system32\Iphlpapi.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             uiExt.dll - C:\Program Files\AVAST Software\Avast\defs\12020503\uiExt.dll - AVAST Software
             comctl32.DLL - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[Skype.exe]Modules
             Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             oleaut32.dll - C:\Windows\system32\oleaut32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             advapi32.dll - C:\Windows\system32\advapi32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             wintrust.dll - C:\Windows\system32\wintrust.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             msimg32.dll - C:\Windows\system32\msimg32.dll - Microsoft Corporation
             version.dll - C:\Windows\system32\version.dll - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             winspool.drv - C:\Windows\system32\winspool.drv - Microsoft Corporation
             URLMON.DLL - C:\Windows\system32\URLMON.DLL - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             shell32.dll - C:\Windows\system32\shell32.dll - Microsoft Corporation
             comdlg32.dll - C:\Windows\system32\comdlg32.dll - Microsoft Corporation
             oleacc.dll - C:\Windows\system32\oleacc.dll - Microsoft Corporation
             d3d9.dll - C:\Windows\system32\d3d9.dll - Microsoft Corporation
             d3d8thk.dll - C:\Windows\system32\d3d8thk.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             SHFolder.dll - C:\Windows\system32\SHFolder.dll - Microsoft Corporation
             winmm.dll - C:\Windows\system32\winmm.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             MSACM32.dll - C:\Windows\system32\MSACM32.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             Iphlpapi.dll - C:\Windows\system32\Iphlpapi.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             cryptui.dll - C:\Windows\system32\cryptui.dll - Microsoft Corporation
             olepro32.dll - C:\Windows\system32\olepro32.dll - Microsoft Corporation
             mapi32.dll - C:\Windows\system32\mapi32.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             wtsapi32.dll - C:\Windows\system32\wtsapi32.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             propsys.dll - C:\Windows\system32\propsys.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             wlanapi.dll - C:\Windows\system32\wlanapi.dll - Microsoft Corporation
             wlanutil.dll - C:\Windows\system32\wlanutil.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             explorerframe.dll - C:\Windows\system32\explorerframe.dll - Microsoft Corporation
             DUser.dll - C:\Windows\system32\DUser.dll - Microsoft Corporation
             DUI70.dll - C:\Windows\system32\DUI70.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             gameux.dll - C:\Windows\System32\gameux.dll - Microsoft Corporation
             XmlLite.dll - C:\Windows\System32\XmlLite.dll - Microsoft Corporation
             wer.dll - C:\Windows\System32\wer.dll - Microsoft Corporation
             shdocvw.dll - C:\Windows\System32\shdocvw.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             LINKINFO.dll - C:\Windows\system32\LINKINFO.dll - Microsoft Corporation
             ntshrui.dll - C:\Windows\system32\ntshrui.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             nvd3dum.dll - C:\Windows\system32\nvd3dum.dll - NVIDIA Corporation
             WindowsCodecs.dll - C:\Windows\system32\WindowsCodecs.dll - Microsoft Corporation
             ashShell.dll - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software
             msi.dll - C:\Windows\system32\msi.dll - Microsoft Corporation
             EhStorShell.dll - C:\Windows\system32\EhStorShell.dll - Microsoft Corporation
             mshtml.dll - C:\Windows\System32\mshtml.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             ieframe.dll - C:\Windows\System32\ieframe.dll - Microsoft Corporation
             RASAPI32.dll - C:\Windows\system32\RASAPI32.dll - Microsoft Corporation
             rasman.dll - C:\Windows\system32\rasman.dll - Microsoft Corporation
             rtutils.dll - C:\Windows\system32\rtutils.dll - Microsoft Corporation
             mlang.dll - C:\Windows\system32\mlang.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             msimtf.dll - C:\Windows\system32\msimtf.dll - Microsoft Corporation
             jscript9.dll - C:\Windows\System32\jscript9.dll - Microsoft Corporation
             aswJsFlt.dll - C:\Program Files\AVAST Software\Avast\aswJsFlt.dll - AVAST Software
             d2d1.dll - C:\Windows\system32\d2d1.dll - Microsoft Corporation
             DWrite.dll - C:\Windows\system32\DWrite.dll - Microsoft Corporation
             dxgi.dll - C:\Windows\system32\dxgi.dll - Microsoft Corporation
             d3d10_1.dll - C:\Windows\system32\d3d10_1.dll - Microsoft Corporation
             d3d10_1core.dll - C:\Windows\system32\d3d10_1core.dll - Microsoft Corporation
             msxml3.dll - C:\Windows\System32\msxml3.dll - Microsoft Corporation
             d3d10.dll - C:\Windows\system32\d3d10.dll - Microsoft Corporation
             d3d10core.dll - C:\Windows\system32\d3d10core.dll - Microsoft Corporation
             msls31.dll - C:\Windows\system32\msls31.dll - Microsoft Corporation
             Dxtrans.dll - C:\Windows\System32\Dxtrans.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\System32\ATL.DLL - Microsoft Corporation
             ddrawex.dll - C:\Windows\system32\ddrawex.dll - Microsoft Corporation
             DDRAW.dll - C:\Windows\system32\DDRAW.dll - Microsoft Corporation
             DCIMAN32.dll - C:\Windows\system32\DCIMAN32.dll - Microsoft Corporation
             Dxtmsft.dll - C:\Windows\System32\Dxtmsft.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             devenum.dll - C:\Windows\system32\devenum.dll - Microsoft Corporation
             msdmo.dll - C:\Windows\system32\msdmo.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             ksproxy.ax - C:\Windows\system32\ksproxy.ax - Microsoft Corporation
             ksuser.dll - C:\Windows\system32\ksuser.dll - Microsoft Corporation
             MMDevApi.dll - C:\Windows\System32\MMDevApi.dll - Microsoft Corporation
             kswdmcap.ax - C:\Windows\system32\kswdmcap.ax - Microsoft Corporation
             MFC42.dll - C:\Windows\system32\MFC42.dll - Microsoft Corporation
             ODBC32.dll - C:\Windows\system32\ODBC32.dll - Microsoft Corporation
             odbcint.dll - C:\Windows\system32\odbcint.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             VM305Prp.Ax - C:\Windows\system32\VM305Prp.Ax - Vimicro
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             AUDIOSES.DLL - C:\Windows\system32\AUDIOSES.DLL - Microsoft Corporation
             D3D10Warp.dll - C:\Windows\system32\D3D10Warp.dll - Microsoft Corporation
             windowscodecsext.dll - C:\Windows\system32\windowscodecsext.dll - Microsoft Corporation
             mscms.dll - C:\Windows\system32\mscms.dll - Microsoft Corporation
             icm32.dll - C:\Windows\system32\icm32.dll - Microsoft Corporation
             schannel.DLL - C:\Windows\system32\schannel.DLL - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             cryptnet.dll - C:\Windows\system32\cryptnet.dll - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation
             Cabinet.dll - C:\Windows\system32\Cabinet.dll - Microsoft Corporation
             DEVRTL.dll - C:\Windows\system32\DEVRTL.dll - Microsoft Corporation
             Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             DSOUND.dll - C:\Windows\system32\DSOUND.dll - Microsoft Corporation
             wdmaud.drv - C:\Windows\system32\wdmaud.drv - Microsoft Corporation
             AVRT.dll - C:\Windows\system32\AVRT.dll - Microsoft Corporation
             msacm32.drv - C:\Windows\system32\msacm32.drv - Microsoft Corporation
             midimap.dll - C:\Windows\system32\midimap.dll - Microsoft Corporation
             RICHED20.DLL - C:\Windows\system32\RICHED20.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             dnsrslvr.dll - c:\windows\system32\dnsrslvr.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             DNSAPI.dll - c:\windows\system32\DNSAPI.dll - Microsoft Corporation
             WINNSI.DLL - c:\windows\system32\WINNSI.DLL - Microsoft Corporation
             Fwpuclnt.dll - C:\Windows\system32\Fwpuclnt.dll - Microsoft Corporation
             dnsext.dll - C:\Windows\System32\dnsext.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             iphlpapi.dll - C:\Windows\system32\iphlpapi.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wkssvc.dll - c:\windows\system32\wkssvc.dll - Microsoft Corporation
             netutils.dll - c:\windows\system32\netutils.dll - Microsoft Corporation
             netjoin.dll - c:\windows\system32\netjoin.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             cryptsvc.dll - c:\windows\system32\cryptsvc.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             VSSAPI.DLL - C:\Windows\system32\VSSAPI.DLL - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             VssTrace.DLL - C:\Windows\system32\VssTrace.DLL - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             samcli.dll - C:\Windows\system32\samcli.dll - Microsoft Corporation
             SAMLIB.dll - C:\Windows\system32\SAMLIB.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             es.dll - C:\Windows\system32\es.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             nlasvc.dll - c:\windows\system32\nlasvc.dll - Microsoft Corporation
             wevtapi.dll - c:\windows\system32\wevtapi.dll - Microsoft Corporation
             ncsi.dll - c:\windows\system32\ncsi.dll - Microsoft Corporation
             WINHTTP.dll - c:\windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - c:\windows\system32\webio.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             ssdpapi.dll - C:\Windows\system32\ssdpapi.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             ESENT.dll - C:\Windows\system32\ESENT.dll - Microsoft Corporation
             psapi.dll - C:\Windows\system32\psapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             CRYPTNET.dll - C:\Windows\system32\CRYPTNET.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[csrss.exe]Modules
             csrss.exe - C:\Windows\system32\csrss.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             basesrv.DLL - C:\Windows\system32\basesrv.DLL - Microsoft Corporation
             winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\SYSTEM32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sxssrv.DLL - C:\Windows\system32\sxssrv.DLL - Microsoft Corporation
             sxs.dll - C:\Windows\system32\sxs.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Modules
             chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             icudt.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\icudt.dll - The ICU Project
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             mscms.dll - C:\Windows\system32\mscms.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             shdocvw.dll - C:\Windows\System32\shdocvw.dll - Microsoft Corporation
             LINKINFO.dll - C:\Windows\system32\LINKINFO.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             fzshellext.dll - C:\Program Files\FileZilla FTP Client\fzshellext.dll - 
             ntshrui.dll - C:\Windows\system32\ntshrui.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             mssprxy.dll - C:\Windows\system32\mssprxy.dll - Microsoft Corporation
             WINHTTP.dll - C:\Windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             cryptnet.dll - C:\Windows\system32\cryptnet.dll - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation
             Cabinet.dll - C:\Windows\system32\Cabinet.dll - Microsoft Corporation
             DEVRTL.dll - C:\Windows\system32\DEVRTL.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             WindowsCodecs.dll - C:\Windows\system32\WindowsCodecs.dll - Microsoft Corporation
             ashShell.dll - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software
             msi.dll - C:\Windows\system32\msi.dll - Microsoft Corporation
             EhStorShell.dll - C:\Windows\system32\EhStorShell.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Modules
             chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             icudt.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\icudt.dll - The ICU Project
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             pdf.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll - 
             ppGoogleNaClPluginChrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll - 
             crypt32.dll - C:\Windows\system32\crypt32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             avcodec-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avcodec-53.dll - 
             avutil-51.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avutil-51.dll - 
             avformat-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avformat-53.dll - 
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[daemonu.exe]Modules
             daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             WINHTTP.dll - C:\Windows\system32\WINHTTP.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             Iphlpapi.DLL - C:\Windows\system32\Iphlpapi.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[csrss.exe]Modules
             csrss.exe - C:\Windows\system32\csrss.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             basesrv.DLL - C:\Windows\system32\basesrv.DLL - Microsoft Corporation
             winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\SYSTEM32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sxssrv.DLL - C:\Windows\system32\sxssrv.DLL - Microsoft Corporation
             sxs.dll - C:\Windows\system32\sxs.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[wininit.exe]Modules
             wininit.exe - C:\Windows\system32\wininit.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[winlogon.exe]Modules
             winlogon.exe - C:\Windows\system32\winlogon.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             UXINIT.dll - C:\Windows\system32\UXINIT.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             WindowsCodecs.dll - C:\Windows\system32\WindowsCodecs.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             netjoin.dll - C:\Windows\system32\netjoin.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvxdsync.exe]Modules
             nvxdsync.exe - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe - NVIDIA Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             nvxdapix.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll - NVIDIA Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             NvUI.dll - C:\Program Files\NVIDIA Corporation\Display\NvUI.dll - NVIDIA Corporation
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             COMDLG32.dll - C:\Windows\system32\COMDLG32.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             oledlg.dll - C:\Windows\system32\oledlg.dll - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             nvapi.dll - C:\Windows\system32\nvapi.dll - NVIDIA Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             nvxdbat.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll - NVIDIA Corporation
             nvStereoApiI.dll - C:\Program Files\NVIDIA Corporation\3D Vision\nvStereoApiI.dll - NVIDIA Corporation
             nvSCPAPI.dll - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPI.dll - NVIDIA Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[services.exe]Modules
             services.exe - C:\Windows\system32\services.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             scext.dll - C:\Windows\system32\scext.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SCESRV.dll - C:\Windows\system32\SCESRV.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             AUTHZ.dll - C:\Windows\system32\AUTHZ.dll - Microsoft Corporation
             UBPM.dll - C:\Windows\system32\UBPM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[lsass.exe]Modules
             lsass.exe - C:\Windows\system32\lsass.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             SspiSrv.dll - C:\Windows\system32\SspiSrv.dll - Microsoft Corporation
             lsasrv.dll - C:\Windows\system32\lsasrv.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             SAMSRV.dll - C:\Windows\system32\SAMSRV.dll - Microsoft Corporation
             cryptdll.dll - C:\Windows\system32\cryptdll.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             wevtapi.dll - C:\Windows\system32\wevtapi.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             cngaudit.dll - C:\Windows\system32\cngaudit.dll - Microsoft Corporation
             AUTHZ.dll - C:\Windows\system32\AUTHZ.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             msprivs.DLL - C:\Windows\system32\msprivs.DLL - Microsoft Corporation
             netjoin.dll - C:\Windows\system32\netjoin.dll - Microsoft Corporation
             negoexts.DLL - C:\Windows\system32\negoexts.DLL - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             kerberos.DLL - C:\Windows\system32\kerberos.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             msv1_0.DLL - C:\Windows\system32\msv1_0.DLL - Microsoft Corporation
             netlogon.DLL - C:\Windows\system32\netlogon.DLL - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             logoncli.dll - C:\Windows\system32\logoncli.dll - Microsoft Corporation
             schannel.DLL - C:\Windows\system32\schannel.DLL - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             wdigest.DLL - C:\Windows\system32\wdigest.DLL - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             tspkg.DLL - C:\Windows\system32\tspkg.DLL - Microsoft Corporation
             pku2u.DLL - C:\Windows\system32\pku2u.DLL - Microsoft Corporation
             livessp.DLL - C:\Windows\system32\livessp.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             efslsaext.dll - C:\Windows\system32\efslsaext.dll - Microsoft Corporation
             scecli.DLL - C:\Windows\system32\scecli.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             dssenh.dll - C:\Windows\system32\dssenh.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             cryptnet.dll - C:\Windows\system32\cryptnet.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             certpoleng.dll - C:\Windows\system32\certpoleng.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             Cabinet.dll - C:\Windows\system32\Cabinet.dll - Microsoft Corporation
             DEVRTL.dll - C:\Windows\system32\DEVRTL.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[lsm.exe]Modules
             lsm.exe - C:\Windows\system32\lsm.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             SYSNTFY.dll - C:\Windows\system32\SYSNTFY.dll - Microsoft Corporation
             WMsgAPI.dll - C:\Windows\system32\WMsgAPI.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             pcwum.dll - C:\Windows\system32\pcwum.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[WmiPrvSE.exe]Modules
             wmiprvse.exe - C:\Windows\system32\wbem\wmiprvse.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             FastProx.dll - C:\Windows\system32\wbem\FastProx.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             wmiutils.dll - C:\Windows\system32\wbem\wmiutils.dll - Microsoft Corporation
             cimwin32.dll - C:\Windows\system32\wbem\cimwin32.dll - Microsoft Corporation
             framedynos.dll - C:\Windows\system32\framedynos.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             perfos.dll - C:\Windows\System32\perfos.dll - Microsoft Corporation
             WINBRAND.dll - C:\Windows\system32\WINBRAND.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             schannel.DLL - C:\Windows\system32\schannel.DLL - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[iPodService.exe]Modules
             iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             iPodServiceLocalized.DLL - C:\Program Files\iPod\bin\iPodService.Resources\cs.lproj\iPodServiceLocalized.DLL - Apple Inc.
             iPodService.DLL - C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL - Apple Inc.
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             Wtsapi32.dll - C:\Windows\system32\Wtsapi32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvvsvc.exe]Modules
             nvvsvc.exe - C:\Windows\system32\nvvsvc.exe - NVIDIA Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             NVSVC.DLL - C:\Windows\system32\NVSVC.DLL - NVIDIA Corporation
             mscms.dll - C:\Windows\system32\mscms.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             COMDLG32.dll - C:\Windows\system32\COMDLG32.dll - Microsoft Corporation
             nvapi.dll - C:\Windows\system32\nvapi.dll - NVIDIA Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             NVSVCR.DLL - C:\Windows\system32\NVSVCR.DLL - NVIDIA Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             nvxdbat.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll - NVIDIA Corporation
             nvxdplcy.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll - NVIDIA Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmware-usbarbitrator.exe]Modules
             vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             bthprops.cpl - C:\Windows\system32\bthprops.cpl - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Modules
             chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             icudt.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\icudt.dll - The ICU Project
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             pdf.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll - 
             ppGoogleNaClPluginChrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll - 
             crypt32.dll - C:\Windows\system32\crypt32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             avcodec-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avcodec-53.dll - 
             avutil-51.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avutil-51.dll - 
             avformat-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avformat-53.dll - 
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PDAgent.exe]Modules
             PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             MSVCP100.dll - C:\Windows\system32\MSVCP100.dll - Microsoft Corporation
             MSVCR100.dll - C:\Windows\system32\MSVCR100.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             msado15.dll - C:\Program Files\Common Files\System\ado\msado15.dll - Microsoft Corporation
             MSDART.DLL - C:\Windows\system32\MSDART.DLL - Microsoft Corporation
             oledb32.dll - C:\Program Files\Common Files\System\Ole DB\oledb32.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             Comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32.dll - Microsoft Corporation
             OLEDB32R.DLL - C:\Program Files\Common Files\System\Ole DB\OLEDB32R.DLL - Microsoft Corporation
             comsvcs.dll - C:\Windows\system32\comsvcs.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             sqlceoledb35.dll - C:\Program Files\Raxco\PerfectDisk\sqlceoledb35.dll - Microsoft Corporation
             MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             msadrh15.dll - C:\Program Files\Common Files\System\ado\msadrh15.dll - Microsoft Corporation
             PDEnginePS.dll - C:\Program Files\Common Files\Raxco\Shared\PDEnginePS.dll - Raxco Software, Inc.
             PDutils.dll - C:\Program Files\Common Files\Raxco\Shared\PDutils.dll - Raxco Software, Inc
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             BROWCLI.DLL - C:\Windows\system32\BROWCLI.DLL - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvvsvc.exe]Modules
             nvvsvc.exe - C:\Windows\system32\nvvsvc.exe - NVIDIA Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             nvxdbat.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll - NVIDIA Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvSCPAPISvr.exe]Modules
             nvSCPAPISvr.exe - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - NVIDIA Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             DEVRTL.dll - C:\Windows\system32\DEVRTL.dll - Microsoft Corporation
             SPINF.dll - C:\Windows\system32\SPINF.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             rpcepmap.dll - c:\windows\system32\rpcepmap.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             rpcss.dll - c:\windows\system32\rpcss.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             user32.dll - C:\Windows\system32\user32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             FirewallAPI.dll - C:\Windows\system32\FirewallAPI.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\system32\fwpuclnt.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\System32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             wevtsvc.dll - c:\windows\system32\wevtsvc.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\System32\RpcRtRemote.dll - Microsoft Corporation
             secur32.dll - C:\Windows\System32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\System32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\System32\credssp.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\System32\GPAPI.dll - Microsoft Corporation
             audiosrv.dll - c:\windows\system32\audiosrv.dll - Microsoft Corporation
             POWRPROF.dll - c:\windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             MMDevAPI.DLL - c:\windows\system32\MMDevAPI.DLL - Microsoft Corporation
             PROPSYS.dll - c:\windows\system32\PROPSYS.dll - Microsoft Corporation
             AVRT.dll - c:\windows\system32\AVRT.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             WINSTA.dll - C:\Windows\System32\WINSTA.dll - Microsoft Corporation
             lmhsvc.dll - c:\windows\system32\lmhsvc.dll - Microsoft Corporation
             IPHLPAPI.DLL - c:\windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - c:\windows\system32\WINNSI.DLL - Microsoft Corporation
             nrpsrv.DLL - c:\windows\system32\nrpsrv.DLL - Microsoft Corporation
             dhcpcore.dll - c:\windows\system32\dhcpcore.dll - Microsoft Corporation
             DNSAPI.dll - c:\windows\system32\DNSAPI.dll - Microsoft Corporation
             firewallapi.dll - C:\Windows\System32\firewallapi.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\System32\VERSION.dll - Microsoft Corporation
             dhcpcore6.dll - C:\Windows\System32\dhcpcore6.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\System32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\System32\dhcpcsvc.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\System32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             audioses.dll - C:\Windows\System32\audioses.dll - Microsoft Corporation
             provsvc.dll - c:\windows\system32\provsvc.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             actxprxy.dll - C:\Windows\system32\actxprxy.dll - Microsoft Corporation
             FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             msxml6.dll - C:\Windows\System32\msxml6.dll - Microsoft Corporation
             fdproxy.dll - C:\Windows\system32\fdproxy.dll - Microsoft Corporation
             ieproxy.dll - C:\Program Files\Internet Explorer\ieproxy.dll - Microsoft Corporation
             XmlLite.dll - C:\Windows\System32\XmlLite.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             wscsvc.dll - c:\windows\system32\wscsvc.dll - Microsoft Corporation
             dbghelp.dll - c:\windows\system32\dbghelp.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             fastprox.dll - C:\Windows\system32\wbem\fastprox.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             WINTRUST.DLL - C:\Windows\system32\WINTRUST.DLL - Microsoft Corporation
             imagehlp.dll - C:\Windows\system32\imagehlp.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\System32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\System32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             wuapi.dll - C:\Windows\system32\wuapi.dll - Microsoft Corporation
             Cabinet.dll - C:\Windows\system32\Cabinet.dll - Microsoft Corporation
             profapi.dll - C:\Windows\System32\profapi.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\System32\USERENV.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\System32\wkscli.dll - Microsoft Corporation
             netutils.dll - C:\Windows\System32\netutils.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             rasadhlp.dll - C:\Windows\System32\rasadhlp.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             RtkAPO.dll - C:\Windows\system32\RtkAPO.dll - Realtek Semiconductor Corp.
             audioeng.dll - C:\Windows\system32\audioeng.dll - Microsoft Corporation
             services.exe - C:\Windows\System32\services.exe - Microsoft Corporation
             winlogon.exe - C:\Windows\System32\winlogon.exe - Microsoft Corporation
             tquery.dll - C:\Windows\System32\tquery.dll - Microsoft Corporation
             WinMgmtR.dll - C:\Windows\System32\wbem\WinMgmtR.dll - Microsoft Corporation
             wevtapi.dll - C:\Windows\System32\wevtapi.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\System32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             audiosrv.dll - c:\windows\system32\audiosrv.dll - Microsoft Corporation
             POWRPROF.dll - c:\windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             MMDevAPI.DLL - c:\windows\system32\MMDevAPI.DLL - Microsoft Corporation
             PROPSYS.dll - c:\windows\system32\PROPSYS.dll - Microsoft Corporation
             AVRT.dll - c:\windows\system32\AVRT.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             uxsms.dll - c:\windows\system32\uxsms.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\System32\WTSAPI32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\System32\WINSTA.dll - Microsoft Corporation
             wudfsvc.dll - c:\windows\system32\wudfsvc.dll - Microsoft Corporation
             WUDFPlatform.dll - c:\windows\system32\WUDFPlatform.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             VERSION.dll - c:\windows\system32\VERSION.dll - Microsoft Corporation
             wevtapi.dll - c:\windows\system32\wevtapi.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\System32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\System32\profapi.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\System32\SspiCli.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             sysmain.dll - c:\windows\system32\sysmain.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\System32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             trkwks.dll - c:\windows\system32\trkwks.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\System32\RpcRtRemote.dll - Microsoft Corporation
             netman.dll - c:\windows\system32\netman.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WINNSI.DLL - c:\windows\system32\WINNSI.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\System32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             netshell.dll - C:\Windows\System32\netshell.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\System32\IPHLPAPI.DLL - Microsoft Corporation
             nlaapi.dll - C:\Windows\System32\nlaapi.dll - Microsoft Corporation
             RASDLG.dll - C:\Windows\System32\RASDLG.dll - Microsoft Corporation
             MPRAPI.dll - C:\Windows\System32\MPRAPI.dll - Microsoft Corporation
             RASAPI32.dll - C:\Windows\System32\RASAPI32.dll - Microsoft Corporation
             rasman.dll - C:\Windows\System32\rasman.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             rtutils.dll - C:\Windows\System32\rtutils.dll - Microsoft Corporation
             dsrole.dll - C:\Windows\System32\dsrole.dll - Microsoft Corporation
             netcfgx.dll - C:\Windows\system32\netcfgx.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             devrtl.DLL - C:\Windows\System32\devrtl.DLL - Microsoft Corporation
             hnetcfg.dll - C:\Windows\system32\hnetcfg.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             fastprox.dll - C:\Windows\system32\wbem\fastprox.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             secur32.dll - C:\Windows\System32\secur32.dll - Microsoft Corporation
             credssp.dll - C:\Windows\System32\credssp.dll - Microsoft Corporation
             pcasvc.dll - c:\windows\system32\pcasvc.dll - Microsoft Corporation
             AEPIC.dll - c:\windows\system32\AEPIC.dll - Microsoft Corporation
             sfc.dll - c:\windows\system32\sfc.dll - Microsoft Corporation
             sfc_os.DLL - c:\windows\system32\sfc_os.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[wmpnetwk.exe]Modules
             wmpnetwk.exe - C:\Program Files\Windows Media Player\wmpnetwk.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             wmdrmdev.dll - C:\Windows\system32\wmdrmdev.dll - Microsoft Corporation
             drmv2clt.dll - C:\Windows\system32\drmv2clt.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             MFPlat.DLL - C:\Windows\system32\MFPlat.DLL - Microsoft Corporation
             AVRT.dll - C:\Windows\system32\AVRT.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             upnp.dll - C:\Windows\system32\upnp.dll - Microsoft Corporation
             WINHTTP.dll - C:\Windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             wmp.dll - C:\Windows\system32\wmp.dll - Microsoft Corporation
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             wmploc.dll - C:\Windows\system32\wmploc.dll - Microsoft Corporation
             ieproxy.dll - C:\Program Files\Internet Explorer\ieproxy.dll - Microsoft Corporation
             windowscodecs.dll - C:\Windows\system32\windowscodecs.dll - Microsoft Corporation
             wmpps.dll - C:\Windows\System32\wmpps.dll - Microsoft Corporation
             netprofm.dll - C:\Windows\System32\netprofm.dll - Microsoft Corporation
             nlaapi.dll - C:\Windows\System32\nlaapi.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             FirewallAPI.dll - C:\Windows\system32\FirewallAPI.dll - Microsoft Corporation
             devenum.dll - C:\Windows\system32\devenum.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             msdmo.dll - C:\Windows\system32\msdmo.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             fastprox.dll - C:\Windows\system32\wbem\fastprox.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             provsvc.dll - C:\Windows\System32\provsvc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[taskhost.exe]Modules
             taskhost.exe - C:\Windows\system32\taskhost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             PlaySndSrv.dll - C:\Windows\System32\PlaySndSrv.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             HotStartUserAgent.dll - C:\Windows\System32\HotStartUserAgent.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             MsCtfMonitor.dll - C:\Windows\system32\MsCtfMonitor.dll - Microsoft Corporation
             MSUTB.dll - C:\Windows\system32\MSUTB.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             dimsjob.dll - C:\Windows\system32\dimsjob.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             taskschd.dll - C:\Windows\system32\taskschd.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             netprofm.dll - C:\Windows\System32\netprofm.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             nlaapi.dll - C:\Windows\System32\nlaapi.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             dsrole.dll - C:\Windows\system32\dsrole.dll - Microsoft Corporation
             MMDevAPI.DLL - C:\Windows\system32\MMDevAPI.DLL - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             wdmaud.drv - C:\Windows\system32\wdmaud.drv - Microsoft Corporation
             ksuser.dll - C:\Windows\system32\ksuser.dll - Microsoft Corporation
             AVRT.dll - C:\Windows\system32\AVRT.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             AUDIOSES.DLL - C:\Windows\system32\AUDIOSES.DLL - Microsoft Corporation
             msacm32.drv - C:\Windows\system32\msacm32.drv - Microsoft Corporation
             MSACM32.dll - C:\Windows\system32\MSACM32.dll - Microsoft Corporation
             midimap.dll - C:\Windows\system32\midimap.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Modules
             chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             icudt.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\icudt.dll - The ICU Project
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             pdf.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll - 
             ppGoogleNaClPluginChrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll - 
             crypt32.dll - C:\Windows\system32\crypt32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             avcodec-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avcodec-53.dll - 
             avutil-51.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avutil-51.dll - 
             avformat-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avformat-53.dll - 
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             nsisvc.dll - c:\windows\system32\nsisvc.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             es.dll - c:\windows\system32\es.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             winhttp.dll - C:\Windows\system32\winhttp.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\System32\mswsock.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             Iphlpapi.DLL - C:\Windows\system32\Iphlpapi.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             wdi.dll - c:\windows\system32\wdi.dll - Microsoft Corporation
             netprofm.dll - c:\windows\system32\netprofm.dll - Microsoft Corporation
             perftrack.dll - C:\Windows\system32\perftrack.dll - Microsoft Corporation
             wer.dll - C:\Windows\system32\wer.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             AEPIC.dll - C:\Windows\system32\AEPIC.dll - Microsoft Corporation
             sfc.dll - C:\Windows\system32\sfc.dll - Microsoft Corporation
             sfc_os.DLL - C:\Windows\system32\sfc_os.DLL - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             fdphost.dll - c:\windows\system32\fdphost.dll - Microsoft Corporation
             fdwsd.dll - C:\Windows\system32\fdwsd.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             MLANG.dll - C:\Windows\system32\MLANG.dll - Microsoft Corporation
             wsdapi.dll - C:\Windows\system32\wsdapi.dll - Microsoft Corporation
             webservices.dll - C:\Windows\system32\webservices.dll - Microsoft Corporation
             FirewallAPI.dll - C:\Windows\system32\FirewallAPI.dll - Microsoft Corporation
             fdssdp.dll - C:\Windows\system32\fdssdp.dll - Microsoft Corporation
             SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             fdproxy.dll - C:\Windows\system32\fdproxy.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             XmlLite.dll - C:\Windows\system32\XmlLite.dll - Microsoft Corporation
             FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             msxml6.dll - C:\Windows\System32\msxml6.dll - Microsoft Corporation
             propsys.dll - C:\Windows\system32\propsys.dll - Microsoft Corporation
             ieproxy.dll - C:\Program Files\Internet Explorer\ieproxy.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvtray.exe]Modules
             nvtray.exe - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe - NVIDIA Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             NvUI.dll - C:\Program Files\NVIDIA Corporation\Display\NvUI.dll - NVIDIA Corporation
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             COMDLG32.dll - C:\Windows\system32\COMDLG32.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             oledlg.dll - C:\Windows\system32\oledlg.dll - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             IMM32.dll - C:\Windows\system32\IMM32.dll - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             NvUpdt.dll - C:\Program Files\NVIDIA Corporation\NvUpdate\NvUpdt.dll - NVIDIA Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             NVUPDTR.DLL - C:\Program Files\NVIDIA Corporation\NvUpdate\NVUPDTR.DLL - NVIDIA Corporation
             easyUpdatusAPIU.dll - C:\Windows\system32\easyUpdatusAPIU.dll - NVIDIA Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             Iphlpapi.DLL - C:\Windows\system32\Iphlpapi.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PDAgentS1.exe]Modules
             PDAgentS1.exe - C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe - Raxco Software, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             MSVCP100.dll - C:\Windows\system32\MSVCP100.dll - Microsoft Corporation
             MSVCR100.dll - C:\Windows\system32\MSVCR100.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[taskmgr.exe]Modules
             taskmgr.exe - C:\Windows\system32\taskmgr.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             pcwum.dll - C:\Windows\system32\pcwum.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             wevtapi.dll - C:\Windows\system32\wevtapi.dll - Microsoft Corporation
             credui.dll - C:\Windows\system32\credui.dll - Microsoft Corporation
             VDMDBG.dll - C:\Windows\system32\VDMDBG.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             UTILDLL.dll - C:\Windows\system32\UTILDLL.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             LOGONCLI.DLL - C:\Windows\system32\LOGONCLI.DLL - Microsoft Corporation
             BROWCLI.DLL - C:\Windows\system32\BROWCLI.DLL - Microsoft Corporation
             SAMCLI.DLL - C:\Windows\system32\SAMCLI.DLL - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             DUser.dll - C:\Windows\system32\DUser.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             bfe.dll - c:\windows\system32\bfe.dll - Microsoft Corporation
             AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             slc.dll - c:\windows\system32\slc.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             pcwum.dll - C:\Windows\system32\pcwum.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             FirewallAPI.dll - c:\windows\system32\FirewallAPI.dll - Microsoft Corporation
             VERSION.dll - c:\windows\system32\VERSION.dll - Microsoft Corporation
             fwpuclnt.dll - c:\windows\system32\fwpuclnt.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshqos.dll - C:\Windows\System32\wshqos.dll - Microsoft Corporation
             wshtcpip.DLL - C:\Windows\system32\wshtcpip.DLL - Microsoft Corporation
             wship6.dll - C:\Windows\system32\wship6.dll - Microsoft Corporation
             wfapigp.dll - C:\Windows\system32\wfapigp.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             dps.dll - c:\windows\system32\dps.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             taskschd.dll - C:\Windows\system32\taskschd.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             wdi.dll - C:\Windows\system32\wdi.dll - Microsoft Corporation
             netprofm.dll - C:\Windows\System32\netprofm.dll - Microsoft Corporation
             nlaapi.dll - C:\Windows\System32\nlaapi.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             npmproxy.dll - C:\Windows\System32\npmproxy.dll - Microsoft Corporation
             radardt.dll - C:\Windows\system32\radardt.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             wdiasqmmodule.dll - C:\Windows\system32\wdiasqmmodule.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             diagperf.dll - C:\Windows\system32\diagperf.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[SearchIndexer.exe]Modules
             SearchIndexer.exe - C:\Windows\system32\SearchIndexer.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             TQUERY.DLL - C:\Windows\system32\TQUERY.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             MSSRCH.DLL - C:\Windows\system32\MSSRCH.DLL - Microsoft Corporation
             ESENT.dll - C:\Windows\system32\ESENT.dll - Microsoft Corporation
             IMM32.dll - C:\Windows\system32\IMM32.dll - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             psapi.dll - C:\Windows\system32\psapi.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             Msidle.dll - C:\Windows\system32\Msidle.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             mssprxy.dll - C:\Windows\system32\mssprxy.dll - Microsoft Corporation
             propsys.dll - C:\Windows\system32\propsys.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             VSSAPI.DLL - C:\Windows\system32\VSSAPI.DLL - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             VssTrace.DLL - C:\Windows\system32\VssTrace.DLL - Microsoft Corporation
             samcli.dll - C:\Windows\system32\samcli.dll - Microsoft Corporation
             SAMLIB.dll - C:\Windows\system32\SAMLIB.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             es.dll - C:\Windows\system32\es.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             NaturalLanguage6.dll - C:\Windows\System32\NaturalLanguage6.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             elscore.dll - C:\Windows\system32\elscore.dll - Microsoft Corporation
             ElsLad.dll - C:\Windows\system32\ElsLad.dll - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             NLSData001b.dll - C:\Windows\System32\NLSData001b.dll - Microsoft Corporation
             NLSLexicons001b.dll - C:\Windows\System32\NLSLexicons001b.dll - Microsoft Corporation
             NLSData0000.dll - C:\Windows\System32\NLSData0000.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[soffice.bin]Modules
             soffice.bin - C:\Program Files\OpenOffice.org 3\program\soffice.bin - OpenOffice.org
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             sal3.dll - C:\Program Files\OpenOffice.org 3\URE\bin\sal3.dll - OpenOffice.org
             uwinapi.dll - C:\Program Files\OpenOffice.org 3\URE\bin\uwinapi.dll - OpenOffice.org
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             sofficeapp.dll - C:\Program Files\OpenOffice.org 3\program\sofficeapp.dll - OpenOffice.org
             comphelp4MSC.dll - C:\Program Files\OpenOffice.org 3\program\comphelp4MSC.dll - OpenOffice.org
             cppuhelper3MSC.dll - C:\Program Files\OpenOffice.org 3\URE\bin\cppuhelper3MSC.dll - OpenOffice.org
             salhelper3MSC.dll - C:\Program Files\OpenOffice.org 3\URE\bin\salhelper3MSC.dll - OpenOffice.org
             cppu3.dll - C:\Program Files\OpenOffice.org 3\URE\bin\cppu3.dll - OpenOffice.org
             stlport_vc7145.dll - C:\Program Files\OpenOffice.org 3\URE\bin\stlport_vc7145.dll - STLport Consulting, Inc.
             ucbhelper4MSC.dll - C:\Program Files\OpenOffice.org 3\program\ucbhelper4MSC.dll - OpenOffice.org
             vos3MSC.dll - C:\Program Files\OpenOffice.org 3\program\vos3MSC.dll - OpenOffice.org
             i18nisolang1MSC.dll - C:\Program Files\OpenOffice.org 3\program\i18nisolang1MSC.dll - OpenOffice.org
             sfxmi.dll - C:\Program Files\OpenOffice.org 3\program\sfxmi.dll - OpenOffice.org
             fwemi.dll - C:\Program Files\OpenOffice.org 3\program\fwemi.dll - OpenOffice.org
             fwimi.dll - C:\Program Files\OpenOffice.org 3\program\fwimi.dll - OpenOffice.org
             utlmi.dll - C:\Program Files\OpenOffice.org 3\program\utlmi.dll - OpenOffice.org
             tlmi.dll - C:\Program Files\OpenOffice.org 3\program\tlmi.dll - OpenOffice.org
             basegfxmi.dll - C:\Program Files\OpenOffice.org 3\program\basegfxmi.dll - OpenOffice.org
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             vclmi.dll - C:\Program Files\OpenOffice.org 3\program\vclmi.dll - OpenOffice.org
             sotmi.dll - C:\Program Files\OpenOffice.org 3\program\sotmi.dll - OpenOffice.org
             i18npapermi.dll - C:\Program Files\OpenOffice.org 3\program\i18npapermi.dll - OpenOffice.org
             i18nutilMSC.dll - C:\Program Files\OpenOffice.org 3\program\i18nutilMSC.dll - OpenOffice.org
             icuuc40.dll - C:\Program Files\OpenOffice.org 3\program\icuuc40.dll - IBM Corporation and others
             icudt40.dll - C:\Program Files\OpenOffice.org 3\program\icudt40.dll - IBM Corporation and others
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             IMM32.dll - C:\Windows\system32\IMM32.dll - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             tkmi.dll - C:\Program Files\OpenOffice.org 3\program\tkmi.dll - OpenOffice.org
             svlmi.dll - C:\Program Files\OpenOffice.org 3\program\svlmi.dll - OpenOffice.org
             svtmi.dll - C:\Program Files\OpenOffice.org 3\program\svtmi.dll - OpenOffice.org
             jvmfwk3.dll - C:\Program Files\OpenOffice.org 3\URE\bin\jvmfwk3.dll - OpenOffice.org
             libxml2.dll - C:\Program Files\OpenOffice.org 3\program\libxml2.dll - 
             sbmi.dll - C:\Program Files\OpenOffice.org 3\program\sbmi.dll - OpenOffice.org
             xcrmi.dll - C:\Program Files\OpenOffice.org 3\program\xcrmi.dll - OpenOffice.org
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             saxmi.dll - C:\Program Files\OpenOffice.org 3\program\saxmi.dll - OpenOffice.org
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             msci_uno.dll - C:\Program Files\OpenOffice.org 3\URE\bin\msci_uno.dll - OpenOffice.org
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             bootstrap.uno.dll - C:\Program Files\OpenOffice.org 3\URE\bin\bootstrap.uno.dll - OpenOffice.org
             reg3.dll - C:\Program Files\OpenOffice.org 3\URE\bin\reg3.dll - OpenOffice.org
             store3.dll - C:\Program Files\OpenOffice.org 3\URE\bin\store3.dll - OpenOffice.org
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             configmgr2.uno.dll - C:\Program Files\OpenOffice.org 3\program\configmgr2.uno.dll - OpenOffice.org
             stocservices.uno.dll - C:\Program Files\OpenOffice.org 3\URE\bin\stocservices.uno.dll - OpenOffice.org
             sysmgr1.uno.dll - C:\Program Files\OpenOffice.org 3\program\sysmgr1.uno.dll - OpenOffice.org
             sax.uno.dll - C:\Program Files\OpenOffice.org 3\program\sax.uno.dll - OpenOffice.org
             localebe1.uno.dll - C:\Program Files\OpenOffice.org 3\program\localebe1.uno.dll - OpenOffice.org
             behelper.uno.dll - C:\Program Files\OpenOffice.org 3\program\behelper.uno.dll - OpenOffice.org
             wer.dll - C:\Windows\system32\wer.dll - Microsoft Corporation
             ucb1.dll - C:\Program Files\OpenOffice.org 3\program\ucb1.dll - OpenOffice.org
             fwkmi.dll - C:\Program Files\OpenOffice.org 3\program\fwkmi.dll - OpenOffice.org
             ucpfile1.dll - C:\Program Files\OpenOffice.org 3\program\ucpfile1.dll - OpenOffice.org
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             oleautobridge.uno.dll - C:\Program Files\OpenOffice.org 3\program\oleautobridge.uno.dll - OpenOffice.org
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             emsermi.dll - C:\Program Files\OpenOffice.org 3\program\emsermi.dll - OpenOffice.org
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             propsys.dll - C:\Windows\system32\propsys.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[dwm.exe]Modules
             Dwm.exe - C:\Windows\system32\Dwm.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             IMM32.dll - C:\Windows\system32\IMM32.dll - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             dwmredir.dll - C:\Windows\system32\dwmredir.dll - Microsoft Corporation
             dwmcore.dll - C:\Windows\system32\dwmcore.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WindowsCodecs.dll - C:\Windows\system32\WindowsCodecs.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             d3d10_1.dll - C:\Windows\system32\d3d10_1.dll - Microsoft Corporation
             d3d10_1core.dll - C:\Windows\system32\d3d10_1core.dll - Microsoft Corporation
             dxgi.dll - C:\Windows\system32\dxgi.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             nvwgf2um.dll - C:\Windows\system32\nvwgf2um.dll - NVIDIA Corporation
             uDWM.dll - C:\Windows\system32\uDWM.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             fdrespub.dll - c:\windows\system32\fdrespub.dll - Microsoft Corporation
             wsdapi.dll - c:\windows\system32\wsdapi.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IPHLPAPI.DLL - c:\windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - c:\windows\system32\WINNSI.DLL - Microsoft Corporation
             webservices.dll - c:\windows\system32\webservices.dll - Microsoft Corporation
             FirewallAPI.dll - c:\windows\system32\FirewallAPI.dll - Microsoft Corporation
             VERSION.dll - c:\windows\system32\VERSION.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             wshqos.dll - C:\Windows\System32\wshqos.dll - Microsoft Corporation
             wshtcpip.DLL - C:\Windows\system32\wshtcpip.DLL - Microsoft Corporation
             WINHTTP.dll - C:\Windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             HTTPAPI.dll - C:\Windows\system32\HTTPAPI.dll - Microsoft Corporation
             pcwum.dll - C:\Windows\system32\pcwum.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             msxml6.dll - C:\Windows\System32\msxml6.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             XmlLite.dll - C:\Windows\system32\XmlLite.dll - Microsoft Corporation
             fntcache.dll - c:\windows\system32\fntcache.dll - Microsoft Corporation
             ktmw32.dll - c:\windows\system32\ktmw32.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             ssdpsrv.dll - c:\windows\system32\ssdpsrv.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             wcncsvc.dll - c:\windows\system32\wcncsvc.dll - Microsoft Corporation
             Wlanapi.dll - c:\windows\system32\Wlanapi.dll - Microsoft Corporation
             wlanutil.dll - c:\windows\system32\wlanutil.dll - Microsoft Corporation
             wlanhlp.dll - c:\windows\system32\wlanhlp.dll - Microsoft Corporation
             OneX.DLL - c:\windows\system32\OneX.DLL - Microsoft Corporation
             eappprxy.dll - c:\windows\system32\eappprxy.dll - Microsoft Corporation
             eappcfg.dll - c:\windows\system32\eappcfg.dll - Microsoft Corporation
             bcrypt.dll - c:\windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             upnp.dll - C:\Windows\system32\upnp.dll - Microsoft Corporation
             SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[sqlservr.exe]Modules
             sqlservr.exe - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             MSVCP80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCP80.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             sqlos.dll - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlos.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             opends60.dll - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\opends60.dll - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             LOGONCLI.DLL - C:\Windows\system32\LOGONCLI.DLL - Microsoft Corporation
             SAMCLI.DLL - C:\Windows\system32\SAMCLI.DLL - Microsoft Corporation
             BatchParser.dll - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\BatchParser.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             psapi.dll - C:\Windows\system32\psapi.dll - Microsoft Corporation
             instapi10.dll - C:\Program Files\Microsoft SQL Server\100\Shared\instapi10.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             sqlevn70.rll - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\Resources\1033\sqlevn70.rll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             BROWCLI.DLL - C:\Windows\system32\BROWCLI.DLL - Microsoft Corporation
             AUTHZ.DLL - C:\Windows\system32\AUTHZ.DLL - Microsoft Corporation
             MSCOREE.DLL - C:\Windows\system32\MSCOREE.DLL - Microsoft Corporation
             mscoreei.dll - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             msv1_0.DLL - C:\Windows\system32\msv1_0.DLL - Microsoft Corporation
             cryptdll.dll - C:\Windows\system32\cryptdll.dll - Microsoft Corporation
             kerberos.DLL - C:\Windows\system32\kerberos.DLL - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             schannel.DLL - C:\Windows\system32\schannel.DLL - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             security.dll - C:\Windows\system32\security.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             ntdsapi.dll - C:\Windows\system32\ntdsapi.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[XueTr.exe]Modules
             XueTr.exe - C:\Nov sloka\XueTr.exe - Email: linxer@163.com
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MFC42u.DLL - C:\Windows\system32\MFC42u.DLL - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ODBC32.dll - C:\Windows\system32\ODBC32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll - Microsoft Corporation
             MSVCP60.dll - C:\Windows\system32\MSVCP60.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             odbcint.dll - C:\Windows\system32\odbcint.dll - Microsoft Corporation
             RICHED32.DLL - C:\Windows\system32\RICHED32.DLL - Microsoft Corporation
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             wintrust.dll - C:\Windows\system32\wintrust.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             WindowsCodecs.dll - C:\Windows\system32\WindowsCodecs.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             ashShell.dll - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software
             msi.dll - C:\Windows\system32\msi.dll - Microsoft Corporation
             EhStorShell.dll - C:\Windows\system32\EhStorShell.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             ntshrui.dll - C:\Windows\system32\ntshrui.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             slc.dll - C:\Windows\system32\slc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Modules
             chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             icudt.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\icudt.dll - The ICU Project
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             pdf.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll - 
             ppGoogleNaClPluginChrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll - 
             crypt32.dll - C:\Windows\system32\crypt32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             avcodec-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avcodec-53.dll - 
             avutil-51.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avutil-51.dll - 
             avformat-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avformat-53.dll - 
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[AppleMobileDeviceService.exe]Modules
             AppleMobileDeviceService.exe - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - Apple Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             MSVCP80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCP80.dll - Microsoft Corporation
             MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             AppleVersions.dll - C:\Program Files\Common Files\Apple\Apple Application Support\AppleVersions.dll - Apple Inc.
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             YSCrashDump.DLL - C:\Program Files\Common Files\Apple\Apple Application Support\YSCrashDump.DLL - Apple Inc.
             CoreFoundation.dll - C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll - Apple Inc.
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             pthreadVC2.dll - C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll - Open Source Software community project
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             objc.dll - C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll - Apple Inc.
             libdispatch.dll - C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll - Apple Inc.
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             libicuin.dll - C:\Program Files\Common Files\Apple\Apple Application Support\libicuin.dll - The ICU Project
             libicuuc.dll - C:\Program Files\Common Files\Apple\Apple Application Support\libicuuc.dll - The ICU Project
             icudt46.dll - C:\Program Files\Common Files\Apple\Apple Application Support\icudt46.dll - The ICU Project
             ASL.dll - C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll - Apple Inc.
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             AppleMobileDeviceService_main.dll - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll - Apple Inc.
             iphlpapi.dll - C:\Windows\system32\iphlpapi.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             dnssd.dll - C:\Windows\system32\dnssd.dll - Apple Inc.
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             MobileDevice.dll - C:\Program Files\Common Files\Apple\Mobile Device Support\MobileDevice.dll - Apple Inc.
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             zlib1.dll - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll - 
             CFNetwork.dll - C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll - Apple, Inc.
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             SQLite3.dll - C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll - Apple Inc.
             libxml2.dll - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll - 
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[VM305_STI.EXE]Modules
             VM305_STI.EXE - C:\Windows\VM305_STI.EXE - Vimicro
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ksproxy.ax - C:\Windows\system32\ksproxy.ax - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             ksuser.dll - C:\Windows\system32\ksuser.dll - Microsoft Corporation
             d3d9.dll - C:\Windows\system32\d3d9.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             d3d8thk.dll - C:\Windows\system32\d3d8thk.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             msdmo.dll - C:\Windows\system32\msdmo.dll - Microsoft Corporation
             devenum.dll - C:\Windows\system32\devenum.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             kswdmcap.ax - C:\Windows\system32\kswdmcap.ax - Microsoft Corporation
             MFC42.dll - C:\Windows\system32\MFC42.dll - Microsoft Corporation
             ODBC32.dll - C:\Windows\system32\ODBC32.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll - Microsoft Corporation
             odbcint.dll - C:\Windows\system32\odbcint.dll - Microsoft Corporation
             VM305Prp.Ax - C:\Windows\system32\VM305Prp.Ax - Vimicro
             comdlg32.dll - C:\Windows\system32\comdlg32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[soffice.exe]Modules
             soffice.exe - C:\Program Files\OpenOffice.org 3\program\soffice.exe - OpenOffice.org
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[mDNSResponder.exe]Modules
             mDNSResponder.exe - C:\Program Files\Bonjour\mDNSResponder.exe - Apple Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmnetdhcp.exe]Modules
             vmnetdhcp.exe - C:\Windows\system32\vmnetdhcp.exe - VMware, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[spoolsv.exe]Modules
             spoolsv.exe - C:\Windows\System32\spoolsv.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\System32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\System32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\System32\CRYPTBASE.dll - Microsoft Corporation
             slc.dll - C:\Windows\System32\slc.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\System32\RpcRtRemote.dll - Microsoft Corporation
             secur32.dll - C:\Windows\System32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\System32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\System32\credssp.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\System32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\System32\WINNSI.DLL - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             rasadhlp.dll - C:\Windows\System32\rasadhlp.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             umb.dll - C:\Windows\system32\umb.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             localspl.dll - C:\Windows\System32\localspl.dll - Microsoft Corporation
             SPOOLSS.DLL - C:\Windows\System32\SPOOLSS.DLL - Microsoft Corporation
             srvcli.dll - C:\Windows\System32\srvcli.dll - Microsoft Corporation
             winspool.drv - C:\Windows\system32\winspool.drv - Microsoft Corporation
             PrintIsolationProxy.dll - C:\Windows\System32\PrintIsolationProxy.dll - Microsoft Corporation
             hpzllw71.dll - C:\Windows\System32\hpzllw71.dll - Hewlett-Packard Corporation
             FXSMON.DLL - C:\Windows\System32\FXSMON.DLL - Microsoft Corporation
             tcpmon.dll - C:\Windows\System32\tcpmon.dll - Microsoft Corporation
             snmpapi.dll - C:\Windows\System32\snmpapi.dll - Microsoft Corporation
             wsnmp32.dll - C:\Windows\System32\wsnmp32.dll - Microsoft Corporation
             msxml6.dll - C:\Windows\System32\msxml6.dll - Microsoft Corporation
             usbmon.dll - C:\Windows\System32\usbmon.dll - Microsoft Corporation
             wls0wndh.dll - C:\Windows\system32\wls0wndh.dll - Microsoft Corporation
             WSDMon.dll - C:\Windows\System32\WSDMon.dll - Microsoft Corporation
             wsdapi.dll - C:\Windows\System32\wsdapi.dll - Microsoft Corporation
             webservices.dll - C:\Windows\System32\webservices.dll - Microsoft Corporation
             FirewallAPI.dll - C:\Windows\System32\FirewallAPI.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\System32\VERSION.dll - Microsoft Corporation
             FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             fdPnp.dll - C:\Windows\system32\fdPnp.dll - Microsoft Corporation
             winprint.dll - C:\Windows\system32\spool\PRTPROCS\W32X86\winprint.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\System32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\System32\profapi.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\System32\GPAPI.dll - Microsoft Corporation
             hpzppw71.dll - C:\Windows\system32\spool\PRTPROCS\W32X86\hpzppw71.dll - Hewlett-Packard Corporation
             dsrole.dll - C:\Windows\System32\dsrole.dll - Microsoft Corporation
             win32spl.dll - C:\Windows\System32\win32spl.dll - Microsoft Corporation
             DEVRTL.dll - C:\Windows\System32\DEVRTL.dll - Microsoft Corporation
             SPINF.dll - C:\Windows\System32\SPINF.dll - Microsoft Corporation
             inetpp.dll - C:\Windows\System32\inetpp.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\System32\CRYPTSP.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\System32\WINSTA.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             cscapi.dll - C:\Windows\System32\cscapi.dll - Microsoft Corporation
             netutils.dll - C:\Windows\System32\netutils.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[CepstralLicSrv.exe]Modules
             CepstralLicSrv.exe - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe - Cepstral, LLC
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             swift.dll - C:\Program Files\Cepstral\bin\swift.dll - Cepstral, LLC
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\System32\mswsock.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             Iphlpapi.DLL - C:\Windows\system32\Iphlpapi.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ipsecsvc.dll - c:\windows\system32\ipsecsvc.dll - Microsoft Corporation
             AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             fwpuclnt.dll - c:\windows\system32\fwpuclnt.dll - Microsoft Corporation
             FirewallAPI.dll - c:\windows\system32\FirewallAPI.dll - Microsoft Corporation
             VERSION.dll - c:\windows\system32\VERSION.dll - Microsoft Corporation
             FwRemoteSvr.DLL - c:\windows\system32\FwRemoteSvr.DLL - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[TeamViewer_Service.exe]Modules
             TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe - TeamViewer GmbH
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             iphlpapi.dll - C:\Windows\system32\iphlpapi.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             imagehlp.dll - C:\Windows\system32\imagehlp.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             wtsapi32.dll - C:\Windows\system32\wtsapi32.dll - Microsoft Corporation
             msimg32.dll - C:\Windows\system32\msimg32.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             userenv.dll - C:\Windows\system32\userenv.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             Netapi32.dll - C:\Windows\system32\Netapi32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             Wintrust.dll - C:\Windows\system32\Wintrust.dll - Microsoft Corporation
             Psapi.dll - C:\Windows\system32\Psapi.dll - Microsoft Corporation
             winsta.dll - C:\Windows\system32\winsta.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             SHFolder.dll - C:\Windows\system32\SHFolder.dll - Microsoft Corporation
             jsproxy.dll - C:\Windows\system32\jsproxy.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             SAMCLI.DLL - C:\Windows\system32\SAMCLI.DLL - Microsoft Corporation
             BROWCLI.DLL - C:\Windows\system32\BROWCLI.DLL - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             propsys.dll - C:\Windows\system32\propsys.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\System32\mswsock.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[launcherd.exe]Modules
             launcherd.exe - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe - 
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             AcLayers.DLL - C:\Windows\AppPatch\AcLayers.DLL - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PnkBstrA.exe]Modules
             PnkBstrA.exe - C:\Windows\system32\PnkBstrA.exe - 
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PnkBstrB.exe]Modules
             PnkBstrB.exe - C:\Windows\system32\PnkBstrB.exe - 
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             psapi.dll - C:\Windows\system32\psapi.dll - Microsoft Corporation
             Iphlpapi.dll - C:\Windows\system32\Iphlpapi.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[sqlwriter.exe]Modules
             sqlwriter.exe - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             psapi.dll - C:\Windows\system32\psapi.dll - Microsoft Corporation
             sqlwvss.dll - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwvss.dll - Microsoft Corporation
             MSVCP80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCP80.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             VSSAPI.DLL - C:\Windows\system32\VSSAPI.DLL - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             VssTrace.DLL - C:\Windows\system32\VssTrace.DLL - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             samcli.dll - C:\Windows\system32\samcli.dll - Microsoft Corporation
             SAMLIB.dll - C:\Windows\system32\SAMLIB.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             es.dll - C:\Windows\system32\es.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Modules
             svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             wiaservc.dll - c:\windows\system32\wiaservc.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             VERSION.dll - c:\windows\system32\VERSION.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             wiatrace.dll - C:\Windows\system32\wiatrace.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             msv1_0.DLL - C:\Windows\system32\msv1_0.DLL - Microsoft Corporation
             cryptdll.dll - C:\Windows\system32\cryptdll.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[TeamViewer_Service.exe]Modules
             TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe - TeamViewer GmbH
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             iphlpapi.dll - C:\Windows\system32\iphlpapi.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             imagehlp.dll - C:\Windows\system32\imagehlp.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             MSWSOCK.dll - C:\Windows\system32\MSWSOCK.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             wtsapi32.dll - C:\Windows\system32\wtsapi32.dll - Microsoft Corporation
             msimg32.dll - C:\Windows\system32\msimg32.dll - Microsoft Corporation
             dwmapi.dll - C:\Windows\system32\dwmapi.dll - Microsoft Corporation
             userenv.dll - C:\Windows\system32\userenv.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             Netapi32.dll - C:\Windows\system32\Netapi32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             Wintrust.dll - C:\Windows\system32\Wintrust.dll - Microsoft Corporation
             Psapi.dll - C:\Windows\system32\Psapi.dll - Microsoft Corporation
             winsta.dll - C:\Windows\system32\winsta.dll - Microsoft Corporation
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             SHFolder.dll - C:\Windows\system32\SHFolder.dll - Microsoft Corporation
             jsproxy.dll - C:\Windows\system32\jsproxy.dll - Microsoft Corporation
             gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             Magnification.dll - C:\Windows\system32\Magnification.dll - Microsoft Corporation
             d3d9.dll - C:\Windows\system32\d3d9.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             d3d8thk.dll - C:\Windows\system32\d3d8thk.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             SAMCLI.DLL - C:\Windows\system32\SAMCLI.DLL - Microsoft Corporation
             BROWCLI.DLL - C:\Windows\system32\BROWCLI.DLL - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             propsys.dll - C:\Windows\system32\propsys.dll - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmnat.exe]Modules
             vmnat.exe - C:\Windows\system32\vmnat.exe - VMware, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             SHFOLDER.dll - C:\Windows\system32\SHFOLDER.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Modules
             chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             RICHED20.dll - C:\Windows\system32\RICHED20.dll - Microsoft Corporation
             MSIMG32.dll - C:\Windows\system32\MSIMG32.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             OLEACC.dll - C:\Windows\system32\OLEACC.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             COMCTL32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             icudt.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\icudt.dll - The ICU Project
             uxtheme.dll - C:\Windows\system32\uxtheme.dll - Microsoft Corporation
             cryptbase.dll - C:\Windows\system32\cryptbase.dll - Microsoft Corporation
             pdf.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll - 
             ppGoogleNaClPluginChrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll - 
             crypt32.dll - C:\Windows\system32\crypt32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             avcodec-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avcodec-53.dll - 
             avutil-51.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avutil-51.dll - 
             avformat-53.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\avformat-53.dll - 
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[WLIDSVC.EXE]Modules
             WLIDSVC.EXE - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE - Microsoft Corp.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             SensApi.dll - C:\Windows\system32\SensApi.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             sqmapi.dll - C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             SAMCLI.DLL - C:\Windows\system32\SAMCLI.DLL - Microsoft Corporation
             WINHTTP.dll - C:\Windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             wer.dll - C:\Windows\system32\wer.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\system32\WINTRUST.dll - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             WinSCard.dll - C:\Windows\system32\WinSCard.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             msxml3.dll - C:\Windows\System32\msxml3.dll - Microsoft Corporation
             WINSTA.dll - C:\Windows\system32\WINSTA.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             apphelp.dll - C:\Windows\system32\apphelp.dll - Microsoft Corporation
             dssenh.dll - C:\Windows\system32\dssenh.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             credssp.dll - C:\Windows\system32\credssp.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshqos.dll - C:\Windows\System32\wshqos.dll - Microsoft Corporation
             wshtcpip.DLL - C:\Windows\system32\wshtcpip.DLL - Microsoft Corporation
             wship6.dll - C:\Windows\system32\wship6.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             fastprox.dll - C:\Windows\system32\wbem\fastprox.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             schannel.DLL - C:\Windows\system32\schannel.DLL - Microsoft Corporation
             secur32.dll - C:\Windows\system32\secur32.dll - Microsoft Corporation
             ncrypt.dll - C:\Windows\system32\ncrypt.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             cryptnet.dll - C:\Windows\system32\cryptnet.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             Cabinet.dll - C:\Windows\system32\Cabinet.dll - Microsoft Corporation
             DEVRTL.dll - C:\Windows\system32\DEVRTL.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmware-authd.exe]Modules
             vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             vmwarebase.DLL - C:\Program Files\VMware\VMware Workstation\vmwarebase.DLL - VMware, Inc.
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             Normaliz.dll - C:\Windows\system32\Normaliz.dll - Microsoft Corporation
             iertutil.dll - C:\Windows\system32\iertutil.dll - Microsoft Corporation
             urlmon.dll - C:\Windows\system32\urlmon.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             VERSION.dll - C:\Windows\system32\VERSION.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             WINHTTP.dll - C:\Windows\system32\WINHTTP.dll - Microsoft Corporation
             webio.dll - C:\Windows\system32\webio.dll - Microsoft Corporation
             CRYPTUI.dll - C:\Windows\system32\CRYPTUI.dll - Microsoft Corporation
             WinSCard.dll - C:\Windows\system32\WinSCard.dll - Microsoft Corporation
             libxml2.dll - C:\Program Files\VMware\VMware Workstation\libxml2.dll - 
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             iconv.dll - C:\Program Files\VMware\VMware Workstation\iconv.dll - Free Software Foundation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             libeay32.dll - C:\Program Files\VMware\VMware Workstation\libeay32.dll - The OpenSSL Project, http://www.openssl.org/
             ssleay32.dll - C:\Program Files\VMware\VMware Workstation\ssleay32.dll - The OpenSSL Project, http://www.openssl.org/
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             SspiCli.dll - C:\Windows\system32\SspiCli.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             perfos.dll - C:\Windows\System32\perfos.dll - Microsoft Corporation
             perfproc.dll - C:\Windows\System32\perfproc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[WLIDSVCM.EXE]Modules
             WLIDSvcM.exe - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe - Microsoft Corp.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmware-hostd.exe]Modules
             vmware-hostd.exe - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe - 
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             types.dll - C:\Program Files\VMware\VMware Workstation\types.dll - VMware, Inc.
             MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             MSVCP90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll - Microsoft Corporation
             vmacore.dll - C:\Program Files\VMware\VMware Workstation\vmacore.dll - VMware, Inc.
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\system32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\system32\MSASN1.dll - Microsoft Corporation
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             SAMCLI.DLL - C:\Windows\system32\SAMCLI.DLL - Microsoft Corporation
             WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             MSWSOCK.dll - C:\Windows\system32\MSWSOCK.dll - Microsoft Corporation
             vmomi.dll - C:\Program Files\VMware\VMware Workstation\vmomi.dll - VMware, Inc.
             libxml2.dll - C:\Program Files\VMware\VMware Workstation\libxml2.dll - 
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             iconv.dll - C:\Program Files\VMware\VMware Workstation\iconv.dll - Free Software Foundation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             WINSPOOL.DRV - C:\Windows\system32\WINSPOOL.DRV - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             IPHLPAPI.DLL - C:\Windows\system32\IPHLPAPI.DLL - Microsoft Corporation
             WINNSI.DLL - C:\Windows\system32\WINNSI.DLL - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             DNSAPI.dll - C:\Windows\system32\DNSAPI.dll - Microsoft Corporation
             VNETLIB.dll - C:\Program Files\VMware\VMware Workstation\VNETLIB.dll - VMware, Inc.
             MPRAPI.dll - C:\Windows\system32\MPRAPI.dll - Microsoft Corporation
             newdev.dll - C:\Windows\system32\newdev.dll - Microsoft Corporation
             UxTheme.dll - C:\Windows\system32\UxTheme.dll - Microsoft Corporation
             devrtl.DLL - C:\Windows\system32\devrtl.DLL - Microsoft Corporation
             Secur32.dll - C:\Windows\system32\Secur32.dll - Microsoft Corporation
             SSPICLI.DLL - C:\Windows\system32\SSPICLI.DLL - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             dhcpcsvc.DLL - C:\Windows\system32\dhcpcsvc.DLL - Microsoft Corporation
             wship6.dll - C:\Windows\System32\wship6.dll - Microsoft Corporation
             dhcpcsvc6.DLL - C:\Windows\system32\dhcpcsvc6.DLL - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             SAMLIB.dll - C:\Windows\system32\SAMLIB.dll - Microsoft Corporation
             libeay32.dll - C:\Program Files\VMware\VMware Workstation\libeay32.dll - The OpenSSL Project, http://www.openssl.org/
             ssleay32.dll - C:\Program Files\VMware\VMware Workstation\ssleay32.dll - The OpenSSL Project, http://www.openssl.org/
             MMDevAPI.DLL - C:\Windows\system32\MMDevAPI.DLL - Microsoft Corporation
             PROPSYS.dll - C:\Windows\system32\PROPSYS.dll - Microsoft Corporation
             wdmaud.drv - C:\Windows\system32\wdmaud.drv - Microsoft Corporation
             ksuser.dll - C:\Windows\system32\ksuser.dll - Microsoft Corporation
             AVRT.dll - C:\Windows\system32\AVRT.dll - Microsoft Corporation
             AUDIOSES.DLL - C:\Windows\system32\AUDIOSES.DLL - Microsoft Corporation
             msacm32.drv - C:\Windows\system32\msacm32.drv - Microsoft Corporation
             MSACM32.dll - C:\Windows\system32\MSACM32.dll - Microsoft Corporation
             midimap.dll - C:\Windows\system32\midimap.dll - Microsoft Corporation
             ActiveDS.dll - C:\Windows\system32\ActiveDS.dll - Microsoft Corporation
             adsldpc.dll - C:\Windows\system32\adsldpc.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             LOGONCLI.DLL - C:\Windows\system32\LOGONCLI.DLL - Microsoft Corporation
             NLAapi.dll - C:\Windows\system32\NLAapi.dll - Microsoft Corporation
             napinsp.dll - C:\Windows\system32\napinsp.dll - Microsoft Corporation
             pnrpnsp.dll - C:\Windows\system32\pnrpnsp.dll - Microsoft Corporation
             winrnr.dll - C:\Windows\System32\winrnr.dll - Microsoft Corporation
             WLIDNSP.DLL - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             mdnsNSP.dll - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.
             SXS.DLL - C:\Windows\system32\SXS.DLL - Microsoft Corporation
             cscapi.dll - C:\Windows\system32\cscapi.dll - Microsoft Corporation
             wshtcpip.dll - C:\Windows\System32\wshtcpip.dll - Microsoft Corporation
             rasadhlp.dll - C:\Windows\system32\rasadhlp.dll - Microsoft Corporation
             fwpuclnt.dll - C:\Windows\System32\fwpuclnt.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             fastprox.dll - C:\Windows\system32\wbem\fastprox.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             wmiutils.dll - C:\Windows\system32\wbem\wmiutils.dll - Microsoft Corporation
             WmiPerfInst.dll - C:\Windows\system32\wbem\WmiPerfInst.dll - Microsoft Corporation
             pdh.dll - C:\Windows\system32\pdh.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             Perfctrs.dll - C:\Windows\System32\Perfctrs.dll - Microsoft Corporation
             perfos.dll - C:\Windows\System32\perfos.dll - Microsoft Corporation
             perfdisk.dll - C:\Windows\System32\perfdisk.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PDEngine.exe]Modules
             PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\system32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\system32\KERNELBASE.dll - Microsoft Corporation
             snxhk.dll - C:\Program Files\AVAST Software\Avast\snxhk.dll - AVAST Software
             SHFOLDER.dll - C:\Windows\system32\SHFOLDER.dll - Microsoft Corporation
             SHELL32.dll - C:\Windows\system32\SHELL32.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\system32\GDI32.dll - Microsoft Corporation
             USER32.dll - C:\Windows\system32\USER32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\system32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\system32\USP10.dll - Microsoft Corporation
             WTSAPI32.dll - C:\Windows\system32\WTSAPI32.dll - Microsoft Corporation
             USERENV.dll - C:\Windows\system32\USERENV.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\system32\RPCRT4.dll - Microsoft Corporation
             profapi.dll - C:\Windows\system32\profapi.dll - Microsoft Corporation
             PSAPI.DLL - C:\Windows\system32\PSAPI.DLL - Microsoft Corporation
             WSOCK32.dll - C:\Windows\system32\WSOCK32.dll - Microsoft Corporation
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             FLTLIB.DLL - C:\Windows\system32\FLTLIB.DLL - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\system32\OLEAUT32.dll - Microsoft Corporation
             MSVCP100.dll - C:\Windows\system32\MSVCP100.dll - Microsoft Corporation
             MSVCR100.dll - C:\Windows\system32\MSVCR100.dll - Microsoft Corporation
             POWRPROF.dll - C:\Windows\system32\POWRPROF.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             PDEnginePS.dll - C:\Program Files\Common Files\Raxco\Shared\PDEnginePS.dll - Raxco Software, Inc.
             PDVmGuestPS.dll - C:\Program Files\Raxco\PerfectDisk\PDVmGuestPS.dll - 
             wbemcomn.dll - C:\Windows\system32\wbemcomn.dll - Microsoft Corporation
             wbemprox.dll - C:\Windows\system32\wbem\wbemprox.dll - Microsoft Corporation
             wbemsvc.dll - C:\Windows\system32\wbem\wbemsvc.dll - Microsoft Corporation
             fastprox.dll - C:\Windows\system32\wbem\fastprox.dll - Microsoft Corporation
             NTDSAPI.dll - C:\Windows\system32\NTDSAPI.dll - Microsoft Corporation
             msado15.dll - C:\Program Files\Common Files\System\ado\msado15.dll - Microsoft Corporation
             MSDART.DLL - C:\Windows\system32\MSDART.DLL - Microsoft Corporation
             oledb32.dll - C:\Program Files\Common Files\System\Ole DB\oledb32.dll - Microsoft Corporation
             bcrypt.dll - C:\Windows\system32\bcrypt.dll - Microsoft Corporation
             Comctl32.dll - C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32.dll - Microsoft Corporation
             OLEDB32R.DLL - C:\Program Files\Common Files\System\Ole DB\OLEDB32R.DLL - Microsoft Corporation
             comsvcs.dll - C:\Windows\system32\comsvcs.dll - Microsoft Corporation
             ATL.DLL - C:\Windows\system32\ATL.DLL - Microsoft Corporation
             bcryptprimitives.dll - C:\Windows\system32\bcryptprimitives.dll - Microsoft Corporation
             sqlceoledb35.dll - C:\Program Files\Common Files\Raxco\Shared\sqlceoledb35.dll - Microsoft Corporation
             MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             msadrh15.dll - C:\Program Files\Common Files\System\ado\msadrh15.dll - Microsoft Corporation
             PDutils.dll - C:\Program Files\Common Files\Raxco\Shared\PDutils.dll - Raxco Software, Inc
             NETAPI32.dll - C:\Windows\system32\NETAPI32.dll - Microsoft Corporation
             netutils.dll - C:\Windows\system32\netutils.dll - Microsoft Corporation
             srvcli.dll - C:\Windows\system32\srvcli.dll - Microsoft Corporation
             wkscli.dll - C:\Windows\system32\wkscli.dll - Microsoft Corporation
             BROWCLI.DLL - C:\Windows\system32\BROWCLI.DLL - Microsoft Corporation
             MPR.dll - C:\Windows\system32\MPR.dll - Microsoft Corporation
             GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             sqlceer35EN.DLL - C:\Program Files\Microsoft SQL Server Compact Edition\v3.5\sqlceer35EN.DLL - Microsoft Corporation
             sqlcese35.dll - C:\Program Files\Common Files\Raxco\Shared\sqlcese35.dll - Microsoft Corporation
             sqlceqp35.dll - C:\Program Files\Common Files\Raxco\Shared\sqlceqp35.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[audiodg.exe]Modules
             AUDIODG.EXE - C:\Windows\system32\AUDIODG.EXE - Microsoft Corporation
             ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             kernel32.dll - C:\Windows\System32\kernel32.dll - Microsoft Corporation
             KERNELBASE.dll - C:\Windows\System32\KERNELBASE.dll - Microsoft Corporation
             msvcrt.dll - C:\Windows\System32\msvcrt.dll - Microsoft Corporation
             RPCRT4.dll - C:\Windows\System32\RPCRT4.dll - Microsoft Corporation
             MMDevAPI.DLL - C:\Windows\System32\MMDevAPI.DLL - Microsoft Corporation
             sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             USER32.dll - C:\Windows\System32\USER32.dll - Microsoft Corporation
             GDI32.dll - C:\Windows\System32\GDI32.dll - Microsoft Corporation
             LPK.dll - C:\Windows\System32\LPK.dll - Microsoft Corporation
             USP10.dll - C:\Windows\System32\USP10.dll - Microsoft Corporation
             PROPSYS.dll - C:\Windows\System32\PROPSYS.dll - Microsoft Corporation
             ole32.dll - C:\Windows\System32\ole32.dll - Microsoft Corporation
             OLEAUT32.dll - C:\Windows\System32\OLEAUT32.dll - Microsoft Corporation
             IMM32.DLL - C:\Windows\system32\IMM32.DLL - Microsoft Corporation
             MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             CRYPTBASE.dll - C:\Windows\system32\CRYPTBASE.dll - Microsoft Corporation
             RpcRtRemote.dll - C:\Windows\system32\RpcRtRemote.dll - Microsoft Corporation
             ntmarta.dll - C:\Windows\system32\ntmarta.dll - Microsoft Corporation
             WLDAP32.dll - C:\Windows\system32\WLDAP32.dll - Microsoft Corporation
             CLBCatQ.DLL - C:\Windows\system32\CLBCatQ.DLL - Microsoft Corporation
             CRYPTSP.dll - C:\Windows\system32\CRYPTSP.dll - Microsoft Corporation
             rsaenh.dll - C:\Windows\system32\rsaenh.dll - Microsoft Corporation
             audioses.dll - C:\Windows\System32\audioses.dll - Microsoft Corporation
             audioeng.dll - C:\Windows\System32\audioeng.dll - Microsoft Corporation
             AVRT.dll - C:\Windows\System32\AVRT.dll - Microsoft Corporation
             SETUPAPI.dll - C:\Windows\system32\SETUPAPI.dll - Microsoft Corporation
             CFGMGR32.dll - C:\Windows\system32\CFGMGR32.dll - Microsoft Corporation
             DEVOBJ.dll - C:\Windows\system32\DEVOBJ.dll - Microsoft Corporation
             audiokse.dll - C:\Windows\System32\audiokse.dll - Microsoft Corporation
             CRYPT32.dll - C:\Windows\System32\CRYPT32.dll - Microsoft Corporation
             MSASN1.dll - C:\Windows\System32\MSASN1.dll - Microsoft Corporation
             WINTRUST.dll - C:\Windows\System32\WINTRUST.dll - Microsoft Corporation
             ksuser.dll - C:\Windows\System32\ksuser.dll - Microsoft Corporation
             SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             RtkAPO.dll - C:\Windows\system32\RtkAPO.dll - Realtek Semiconductor Corp.
             WS2_32.dll - C:\Windows\system32\WS2_32.dll - Microsoft Corporation
             NSI.dll - C:\Windows\system32\NSI.dll - Microsoft Corporation
             WMALFXGFXDSP.dll - C:\Windows\system32\WMALFXGFXDSP.dll - Microsoft Corporation
             mfplat.DLL - C:\Windows\system32\mfplat.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[Idle]Modules

==========================================================================================

Process Threads

      Image File Name[System]Threads
             8 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             12 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             16 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             20 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             24 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             28 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             32 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             36 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             40 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             44 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             48 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             52 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             56 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             60 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             64 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             68 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             72 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             76 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             80 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             84 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             88 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             92 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             96 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             100 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             104 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             116 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             120 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             124 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             128 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             132 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             136 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             140 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             144 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             152 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             156 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             160 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             164 - Wait - ACPI.sys - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
             168 - Wait - ACPI.sys - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
             176 - Wait - vmci.sys - C:\Windows\system32\DRIVERS\vmci.sys - VMware, Inc.
             180 - Wait - vmci.sys - C:\Windows\system32\DRIVERS\vmci.sys - VMware, Inc.
             184 - Wait - ndis.sys - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
             188 - Wait - ndis.sys - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
             192 - Wait - ndis.sys - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
             208 - Wait - aswSnx.SYS - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
             212 - Wait - aswSnx.SYS - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
             216 - Wait - aswSnx.SYS - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
             220 - Wait - aswSnx.SYS - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
             224 - Wait - aswSnx.SYS - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
             228 - Wait - watchdog.sys - C:\Windows\System32\drivers\watchdog.sys - Microsoft Corporation
             232 - Wait - aswTdi.SYS - C:\Windows\System32\Drivers\aswTdi.SYS - AVAST Software
             236 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             240 - Wait - blbdrive.sys - C:\Windows\system32\DRIVERS\blbdrive.sys - Microsoft Corporation
             244 - Terminate - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             248 - Wait - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             252 - Wait - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             256 - Wait - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             260 - Wait - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             264 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             280 - Wait - dxgkrnl.sys - C:\Windows\System32\drivers\dxgkrnl.sys - Microsoft Corporation
             284 - Wait - dxgkrnl.sys - C:\Windows\System32\drivers\dxgkrnl.sys - Microsoft Corporation
             288 - Wait - VBoxNetAdp.sys - C:\Windows\system32\DRIVERS\VBoxNetAdp.sys - Oracle Corporation
             292 - Wait - VBoxNetFlt.sys - C:\Windows\system32\DRIVERS\VBoxNetFlt.sys - Oracle Corporation
             296 - Wait - dtsoftbus01.sys - C:\Windows\system32\DRIVERS\dtsoftbus01.sys - DT Soft Ltd
             300 - Wait - parport.sys - C:\Windows\system32\DRIVERS\parport.sys - Microsoft Corporation
             308 - Wait - raspptp.sys - C:\Windows\system32\DRIVERS\raspptp.sys - Microsoft Corporation
             312 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             316 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             320 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             324 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             328 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             332 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             336 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             340 - Wait - RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
             388 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             424 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             432 - Wait - nvlddmkm.sys - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
             436 - Wait - nvlddmkm.sys - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
             440 - Wait - dxgmms1.sys - C:\Windows\System32\drivers\dxgmms1.sys - Microsoft Corporation
             496 - Wait - msrpc.sys - C:\Windows\System32\Drivers\msrpc.sys - Microsoft Corporation
             676 - Wait - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             752 - Wait - luafv.sys - C:\Windows\system32\drivers\luafv.sys - Microsoft Corporation
             756 - Wait - aswMonFlt.sys - C:\Windows\system32\drivers\aswMonFlt.sys - AVAST Software
             760 - Terminate - aswMonFlt.sys - C:\Windows\system32\drivers\aswMonFlt.sys - AVAST Software
             764 - Terminate - aswMonFlt.sys - C:\Windows\system32\drivers\aswMonFlt.sys - AVAST Software
             768 - Terminate - aswMonFlt.sys - C:\Windows\system32\drivers\aswMonFlt.sys - AVAST Software
             772 - Wait - PDFsFilter.sys - C:\Windows\system32\DRIVERS\PDFsFilter.sys - Raxco Software, Inc.
             776 - Wait - PDFsFilter.sys - C:\Windows\system32\DRIVERS\PDFsFilter.sys - Raxco Software, Inc.
             1072 - Wait - aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
             1160 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             2168 - Wait - HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
             2172 - Wait - HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
             2176 - Wait - HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
             2268 - Wait - mpsdrv.sys - C:\Windows\System32\drivers\mpsdrv.sys - Microsoft Corporation
             2344 - Wait - hcmon.sys - C:\Windows\system32\drivers\hcmon.sys - VMware, Inc.
             2348 - Wait - vmx86.sys - C:\Windows\system32\Drivers\vmx86.sys - VMware, Inc.
             2512 - Terminate -  -  - 
             2660 - Wait - HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
             3056 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             3068 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             3624 - Wait - srv2.sys - C:\Windows\System32\DRIVERS\srv2.sys - Microsoft Corporation
             3628 - Wait - srv2.sys - C:\Windows\System32\DRIVERS\srv2.sys - Microsoft Corporation
             3632 - Wait - srv2.sys - C:\Windows\System32\DRIVERS\srv2.sys - Microsoft Corporation
             3652 - Wait - srv2.sys - C:\Windows\System32\DRIVERS\srv2.sys - Microsoft Corporation
             3656 - Wait - srv2.sys - C:\Windows\System32\DRIVERS\srv2.sys - Microsoft Corporation
             3660 - Wait - srv.sys - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
             3664 - Wait - srv.sys - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
             3668 - Wait - srv.sys - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
             3672 - Wait - srv.sys - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
             3828 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             4432 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             4980 - Wait - rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
             5316 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             5388 - Wait - HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
             5392 - Wait - HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
             5408 - Wait - ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
             5696 - Terminate - aswMonFlt.sys - C:\Windows\system32\drivers\aswMonFlt.sys - AVAST Software

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             108 - Wait - wbemcore.dll - C:\Windows\system32\wbem\wbemcore.dll - Microsoft Corporation
             624 - Terminate - ESENT.dll - c:\windows\system32\ESENT.dll - Microsoft Corporation
             1004 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             1012 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1020 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1124 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1128 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1132 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1228 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1244 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1288 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             1352 - Terminate - gpsvc.dll - c:\windows\system32\gpsvc.dll - Microsoft Corporation
             1360 - Wait - gpsvc.dll - c:\windows\system32\gpsvc.dll - Microsoft Corporation
             1416 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1540 - Terminate - gpsvc.dll - c:\windows\system32\gpsvc.dll - Microsoft Corporation
             1544 - Wait - gpsvc.dll - c:\windows\system32\gpsvc.dll - Microsoft Corporation
             1548 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             1576 - Terminate - gpsvc.dll - c:\windows\system32\gpsvc.dll - Microsoft Corporation
             2140 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2144 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2148 - Wait - schedsvc.dll - c:\windows\system32\schedsvc.dll - Microsoft Corporation
             2152 - Wait - taskcomp.dll - C:\Windows\system32\taskcomp.dll - Microsoft Corporation
             2164 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2564 - Terminate - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2592 - Wait - AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             2596 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2776 - Terminate - wuaueng.dll - c:\windows\system32\wuaueng.dll - Microsoft Corporation
             2828 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3224 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3344 - Terminate - ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             3444 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3456 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3464 - Wait - AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             3468 - Terminate - NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             3472 - Terminate - NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             3604 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3608 - Wait - ncprov.dll - C:\Windows\system32\wbem\ncprov.dll - Microsoft Corporation
             3612 - Wait - NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             3616 - Wait - NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             3696 - Terminate - ESENT.dll - c:\windows\system32\ESENT.dll - Microsoft Corporation
             4060 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             4144 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4164 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4280 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4420 - Terminate - wuaueng.dll - c:\windows\system32\wuaueng.dll - Microsoft Corporation
             4436 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4492 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             4692 - Terminate - wuaueng.dll - c:\windows\system32\wuaueng.dll - Microsoft Corporation
             4844 - Wait - mmcss.dll - c:\windows\system32\mmcss.dll - Microsoft Corporation
             4924 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             5036 - Wait - aelupsvc.dll - c:\windows\system32\aelupsvc.dll - Microsoft Corporation
             5524 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             5576 - Terminate - ESENT.dll - c:\windows\system32\ESENT.dll - Microsoft Corporation
             5672 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             5816 - Wait - wbemcore.dll - C:\Windows\system32\wbem\wbemcore.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[explorer.exe]Threads
             112 - Wait - msiltcfg.dll - C:\Windows\system32\msiltcfg.dll - Microsoft Corporation
             536 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             1280 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1500 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1564 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1612 - Wait - Explorer.EXE - C:\Windows\Explorer.EXE - Microsoft Corporation
             1648 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1852 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             1856 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             1864 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             1884 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1896 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1916 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             1928 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             1936 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2000 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             2576 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             2584 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             2588 - Wait - MMDevApi.dll - C:\Windows\System32\MMDevApi.dll - Microsoft Corporation
             2656 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             2680 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             2688 - Wait - fxsst.dll - C:\Windows\system32\fxsst.dll - Microsoft Corporation
             2728 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             3516 - Wait - WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation
             3864 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3924 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4136 - Wait - SHLWAPI.dll - C:\Windows\system32\SHLWAPI.dll - Microsoft Corporation
             4424 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4480 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             4660 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5652 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5704 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[AvastSvc.exe]Threads
             204 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             352 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             384 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             584 - Wait - ashMaiSv.dll - C:\Program Files\AVAST Software\Avast\ashMaiSv.dll - AVAST Software
             644 - Wait - AhResMai.dll - C:\Program Files\AVAST Software\Avast\AhResMai.dll - AVAST Software
             708 - Wait - AhResMai.dll - C:\Program Files\AVAST Software\Avast\AhResMai.dll - AVAST Software
             920 - Ready - aswLog.dll - C:\Program Files\AVAST Software\Avast\aswLog.dll - AVAST Software
             924 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             928 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             996 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1044 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1052 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1120 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1144 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1152 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1156 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1196 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1232 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1236 - Wait - AhResStd.dll - C:\Program Files\AVAST Software\Avast\AhResStd.dll - AVAST Software
             1312 - Wait - AvastSvc.exe - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - AVAST Software
             1332 - Wait - ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             1344 - Wait - AhResWS.dll - C:\Program Files\AVAST Software\Avast\AhResWS.dll - AVAST Software
             1392 - Wait - ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             1396 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1400 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1412 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1452 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1456 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1464 - Wait - ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             1476 - Terminate - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1496 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1668 - Wait - ashWsFtr.dll - C:\Program Files\AVAST Software\Avast\ashWsFtr.dll - AVAST Software
             1676 - Wait - ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             1680 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1684 - Terminate - ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             1700 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1736 - Wait - ashServ.dll - C:\Program Files\AVAST Software\Avast\ashServ.dll - AVAST Software
             1768 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1772 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1776 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1780 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1784 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1788 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1792 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1796 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1800 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1804 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             1808 - Wait - AhResBhv.dll - C:\Program Files\AVAST Software\Avast\AhResBhv.dll - AVAST Software
             1812 - Wait - AhResBhv.dll - C:\Program Files\AVAST Software\Avast\AhResBhv.dll - AVAST Software
             1816 - Wait - AhResBhv.dll - C:\Program Files\AVAST Software\Avast\AhResBhv.dll - AVAST Software
             1828 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             2004 - Wait - ashWsFtr.dll - C:\Program Files\AVAST Software\Avast\ashWsFtr.dll - AVAST Software
             2008 - Wait - AhResWS.dll - C:\Program Files\AVAST Software\Avast\AhResWS.dll - AVAST Software
             2016 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             2200 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             2652 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             2916 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             3256 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3720 - Wait - mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             4172 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             4836 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5200 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             5348 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             5892 - Terminate - aswEngin.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\aswEngin.dll - AVAST Software
             5896 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             6008 - Wait - arPot.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\arPot.dll - AVAST Software
             6012 - Ready - arPot.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\arPot.dll - AVAST Software
             6016 - Wait - arPot.dll - C:\Program Files\AVAST Software\Avast\defs\12020600\arPot.dll - AVAST Software
             6024 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[smss.exe]Threads
             272 - Wait - smss.exe - C:\Windows\System32\smss.exe - Microsoft Corporation
             396 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             696 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             704 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             712 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             720 - Terminate - GPAPI.dll - C:\Windows\system32\GPAPI.dll - Microsoft Corporation
             728 - Wait - umpnpmgr.dll - c:\windows\system32\umpnpmgr.dll - Microsoft Corporation
             732 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             736 - Wait - umpo.dll - c:\windows\system32\umpo.dll - Microsoft Corporation
             740 - Wait - umpo.dll - c:\windows\system32\umpo.dll - Microsoft Corporation
             836 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             840 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3448 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5440 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[AvastUI.exe]Threads
             348 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             356 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             360 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             364 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             368 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             372 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             380 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             832 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1744 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1912 - Wait - AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software
             1992 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1996 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             2024 - Wait - aswData.dll - C:\Program Files\AVAST Software\Avast\aswData.dll - AVAST Software
             2028 - Wait - Aavm4h.dll - C:\Program Files\AVAST Software\Avast\Aavm4h.dll - AVAST Software
             2032 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[Skype.exe]Threads
             376 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             492 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             540 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1080 - Terminate - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             1276 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             1300 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             1444 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             1624 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             1836 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2100 - Terminate - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             2120 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             2272 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             3180 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             3284 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             3288 - Wait - rasman.dll - C:\Windows\system32\rasman.dll - Microsoft Corporation
             3292 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             3504 - Wait - Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             3848 - Wait - Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             3888 - Wait - Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             3968 - Terminate - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             3972 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             4104 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             4132 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             4188 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             4316 - Wait - WININET.dll - C:\Windows\system32\WININET.dll - Microsoft Corporation
             4472 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4640 - Wait - Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             4728 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             4736 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             4756 - Wait - gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             5032 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5100 - Wait - Dxtrans.dll - C:\Windows\System32\Dxtrans.dll - Microsoft Corporation
             5112 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5132 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5156 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5188 - Wait - mshtml.dll - C:\Windows\System32\mshtml.dll - Microsoft Corporation
             5196 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5204 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5424 - Wait - Dxtrans.dll - C:\Windows\System32\Dxtrans.dll - Microsoft Corporation
             5580 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5592 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5604 - Wait - Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             5640 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5708 - Wait - Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - Skype Technologies S.A.
             5736 - Wait - Dxtrans.dll - C:\Windows\System32\Dxtrans.dll - Microsoft Corporation
             5884 - Wait - Dxtrans.dll - C:\Windows\System32\Dxtrans.dll - Microsoft Corporation
             5956 - Wait - Flash11e.ocx - C:\Windows\system32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc.
             5992 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             6028 - Wait - MMDevApi.dll - C:\Windows\System32\MMDevApi.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             404 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1208 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             1212 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1220 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1252 - Wait - dnsrslvr.dll - c:\windows\system32\dnsrslvr.dll - Microsoft Corporation
             1256 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1260 - Wait - dnsrslvr.dll - c:\windows\system32\dnsrslvr.dll - Microsoft Corporation
             1264 - Wait - dnsrslvr.dll - c:\windows\system32\dnsrslvr.dll - Microsoft Corporation
             1268 - Wait - dnsrslvr.dll - c:\windows\system32\dnsrslvr.dll - Microsoft Corporation
             1620 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1712 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2332 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2492 - Terminate - cryptsvc.dll - c:\windows\system32\cryptsvc.dll - Microsoft Corporation
             2716 - Wait - nlasvc.dll - c:\windows\system32\nlasvc.dll - Microsoft Corporation
             2724 - Terminate - ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             2732 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2880 - Wait - ESENT.dll - C:\Windows\system32\ESENT.dll - Microsoft Corporation
             2900 - Wait - msvcrt.dll - C:\Windows\system32\msvcrt.dll - Microsoft Corporation
             3508 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4780 - Wait - ssdpapi.dll - C:\Windows\system32\ssdpapi.dll - Microsoft Corporation
             4796 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4948 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5164 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5220 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5512 - Wait - dnsrslvr.dll - c:\windows\system32\dnsrslvr.dll - Microsoft Corporation
             5700 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6052 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[csrss.exe]Threads
             444 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             448 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             452 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             456 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             484 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             544 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             552 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             600 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             1316 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Threads
             412 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             688 - Wait - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             1024 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             1436 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1940 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             1948 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             1960 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2636 - Wait - mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation
             2648 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2708 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3028 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3112 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3532 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3740 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4204 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4352 - Wait - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             4448 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4568 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4648 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4684 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4748 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4820 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4884 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4988 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5048 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5160 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5332 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5364 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5584 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5692 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6004 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             6020 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6080 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Threads
             420 - Wait - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             1888 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3572 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4168 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4240 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4444 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4972 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5272 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5796 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[daemonu.exe]Threads
             1408 - Wait - daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation
             2384 - Wait - daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation
             3500 - Wait - daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation
             3544 - Wait - daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation
             4000 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             4056 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4084 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5484 - Wait - daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - NVIDIA Corporation

------------------------------------------------------------------------------------------

      Image File Name[csrss.exe]Threads
             500 - Wait - cdd.dll - C:\Windows\System32\cdd.dll - Microsoft Corporation
             504 - Wait - cdd.dll - C:\Windows\System32\cdd.dll - Microsoft Corporation
             508 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             512 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             516 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             520 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             532 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             548 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             556 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation
             1388 - Wait - CSRSRV.dll - C:\Windows\system32\CSRSRV.dll - Microsoft Corporation
             5724 - Wait - winsrv.DLL - C:\Windows\system32\winsrv.DLL - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[wininit.exe]Threads
             480 - Wait - wininit.exe - C:\Windows\system32\wininit.exe - Microsoft Corporation
             488 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             564 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             568 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             620 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[winlogon.exe]Threads
             528 - Wait - winlogon.exe - C:\Windows\system32\winlogon.exe - Microsoft Corporation
             912 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5976 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvxdsync.exe]Threads
             560 - Wait - nvxdapix.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll - NVIDIA Corporation
             1368 - Wait - nvxdsync.exe - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe - NVIDIA Corporation
             1432 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1448 - Wait - nvxdsync.exe - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe - NVIDIA Corporation
             1460 - Wait - nvxdapix.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll - NVIDIA Corporation
             1568 - Wait - nvapi.dll - C:\Windows\system32\nvapi.dll - NVIDIA Corporation
             1572 - Wait - nvxdapix.dll - C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll - NVIDIA Corporation
             5476 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[services.exe]Threads
             576 - Terminate - services.exe - C:\Windows\system32\services.exe - Microsoft Corporation
             636 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             640 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             672 - Wait - UBPM.dll - C:\Windows\system32\UBPM.dll - Microsoft Corporation
             748 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2136 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2912 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2992 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3460 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3928 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5008 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5916 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6108 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[lsass.exe]Threads
             596 - Wait - lsass.exe - C:\Windows\system32\lsass.exe - Microsoft Corporation
             604 - Wait - lsasrv.dll - C:\Windows\system32\lsasrv.dll - Microsoft Corporation
             608 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             612 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             616 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             656 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2180 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2184 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3096 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[lsm.exe]Threads
             592 - Wait - lsm.exe - C:\Windows\system32\lsm.exe - Microsoft Corporation
             664 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             888 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             892 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             896 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             900 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             904 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             908 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             916 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3744 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4360 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4764 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[WmiPrvSE.exe]Threads
             628 - Wait - cimwin32.dll - C:\Windows\system32\wbem\cimwin32.dll - Microsoft Corporation
             3152 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3860 - Wait - wmiprvse.exe - C:\Windows\system32\wbem\wmiprvse.exe - Microsoft Corporation
             3932 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3956 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3960 - Wait - NCObjAPI.DLL - C:\Windows\system32\NCObjAPI.DLL - Microsoft Corporation
             3976 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             3980 - Wait - wmiprvse.exe - C:\Windows\system32\wbem\wmiprvse.exe - Microsoft Corporation
             5404 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[iPodService.exe]Threads
             632 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             988 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             1136 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             1672 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             2816 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             2864 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             2868 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             2872 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             3340 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4012 - Wait - iPodService.exe - C:\Program Files\iPod\bin\iPodService.exe - Apple Inc.
             4028 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4040 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvvsvc.exe]Threads
             648 - Wait - NVSVC.DLL - C:\Windows\system32\NVSVC.DLL - NVIDIA Corporation
             1380 - Wait - nvvsvc.exe - C:\Windows\system32\nvvsvc.exe - NVIDIA Corporation
             1480 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1488 - Wait - nvapi.dll - C:\Windows\system32\nvapi.dll - NVIDIA Corporation
             3076 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmware-usbarbitrator.exe]Threads
             652 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             668 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             1192 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             1324 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             1424 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             1760 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             2052 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             2092 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             2528 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             2600 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             2692 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3052 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3144 - Wait - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3164 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3172 - Wait - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3176 - Wait - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3244 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3312 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3388 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3416 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3420 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3424 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3428 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3432 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3436 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3524 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3852 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             3988 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4088 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4092 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4220 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4224 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4228 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4232 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4264 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4300 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4304 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4368 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4376 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4380 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4384 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4388 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4440 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4516 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4544 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4560 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4632 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             4936 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5068 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5412 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5496 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5616 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5656 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5748 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             5908 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             6048 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             6092 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.
             6128 - Terminate - vmware-usbarbitrator.exe - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe - VMware, Inc.

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Threads
             716 - Wait - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             1428 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2040 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             2248 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3916 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5432 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5588 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5596 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5792 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PDAgent.exe]Threads
             724 - Wait - PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             1584 - Terminate - PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             1764 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2740 - Wait - PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             2788 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2796 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2808 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             2812 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             3484 - Wait - PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             3732 - Wait - PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             3772 - Wait - PDAgent.exe - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe - Raxco Software, Inc.
             3936 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4584 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvvsvc.exe]Threads
             784 - Wait - nvvsvc.exe - C:\Windows\system32\nvvsvc.exe - NVIDIA Corporation
             796 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             800 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1372 - Wait - nvvsvc.exe - C:\Windows\system32\nvvsvc.exe - NVIDIA Corporation
             2892 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvSCPAPISvr.exe]Threads
             808 - Wait - nvSCPAPISvr.exe - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - NVIDIA Corporation
             812 - Wait - nvSCPAPISvr.exe - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - NVIDIA Corporation
             816 - Wait - nvSCPAPISvr.exe - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - NVIDIA Corporation
             828 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             940 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2780 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             852 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             856 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             860 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             872 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             876 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             880 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             884 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5488 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5620 - Wait - rpcss.dll - c:\windows\system32\rpcss.dll - Microsoft Corporation
             5728 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             948 - Wait - svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
             952 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             956 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             960 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             964 - Terminate - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             968 - Wait - wevtsvc.dll - c:\windows\system32\wevtsvc.dll - Microsoft Corporation
             972 - Wait - wevtsvc.dll - c:\windows\system32\wevtsvc.dll - Microsoft Corporation
             1008 - Terminate - GPAPI.dll - C:\Windows\System32\GPAPI.dll - Microsoft Corporation
             1028 - Wait - wevtsvc.dll - c:\windows\system32\wevtsvc.dll - Microsoft Corporation
             1032 - Wait - wevtsvc.dll - c:\windows\system32\wevtsvc.dll - Microsoft Corporation
             1036 - Wait - wevtsvc.dll - c:\windows\system32\wevtsvc.dll - Microsoft Corporation
             1076 - Wait - audiosrv.dll - c:\windows\system32\audiosrv.dll - Microsoft Corporation
             1096 - Wait - MMDevAPI.DLL - c:\windows\system32\MMDevAPI.DLL - Microsoft Corporation
             1172 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1200 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1240 - Wait - lmhsvc.dll - c:\windows\system32\lmhsvc.dll - Microsoft Corporation
             1248 - Wait - dhcpcore6.dll - C:\Windows\System32\dhcpcore6.dll - Microsoft Corporation
             1696 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2804 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3752 - Wait - FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             3896 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4612 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             4704 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4840 - Wait - wscsvc.dll - c:\windows\system32\wscsvc.dll - Microsoft Corporation
             4860 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4864 - Wait - wscsvc.dll - c:\windows\system32\wscsvc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             980 - Wait - svchost.exe - C:\Windows\System32\svchost.exe - Microsoft Corporation
             984 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             992 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1056 - Wait - audiosrv.dll - c:\windows\system32\audiosrv.dll - Microsoft Corporation
             1060 - Wait - MMDevAPI.DLL - c:\windows\system32\MMDevAPI.DLL - Microsoft Corporation
             1148 - Wait - uxsms.dll - c:\windows\system32\uxsms.dll - Microsoft Corporation
             1164 - Wait - WUDFPlatform.dll - c:\windows\system32\WUDFPlatform.dll - Microsoft Corporation
             1336 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1348 - Terminate - ADVAPI32.dll - C:\Windows\system32\ADVAPI32.dll - Microsoft Corporation
             3008 - Ready - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3132 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4500 - Run - sysmain.dll - c:\windows\system32\sysmain.dll - Microsoft Corporation
             5320 - Wait - sysmain.dll - c:\windows\system32\sysmain.dll - Microsoft Corporation
             5680 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5684 - Wait - pcasvc.dll - c:\windows\system32\pcasvc.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[wmpnetwk.exe]Threads
             1016 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             1732 - Terminate - SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             2080 - Terminate - SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             2612 - Wait - wmpnetwk.exe - C:\Program Files\Windows Media Player\wmpnetwk.exe - Microsoft Corporation
             3496 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4148 - Wait - wmpnetwk.exe - C:\Program Files\Windows Media Player\wmpnetwk.exe - Microsoft Corporation
             4476 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4652 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             4812 - Wait - gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             5260 - Wait - SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             5996 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[taskhost.exe]Threads
             1092 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2232 - Wait - taskhost.exe - C:\Windows\system32\taskhost.exe - Microsoft Corporation
             2336 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2340 - Wait - taskhost.exe - C:\Windows\system32\taskhost.exe - Microsoft Corporation
             2368 - Terminate - taskhost.exe - C:\Windows\system32\taskhost.exe - Microsoft Corporation
             2376 - Wait - PlaySndSrv.dll - C:\Windows\System32\PlaySndSrv.dll - Microsoft Corporation
             2436 - Terminate - taskhost.exe - C:\Windows\system32\taskhost.exe - Microsoft Corporation
             2448 - Wait - MsCtfMonitor.dll - C:\Windows\system32\MsCtfMonitor.dll - Microsoft Corporation
             2452 - Wait - MSCTF.dll - C:\Windows\system32\MSCTF.dll - Microsoft Corporation
             3716 - Wait - WINMM.dll - C:\Windows\system32\WINMM.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Threads
             1140 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             1524 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1532 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1600 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             2684 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3700 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4312 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             4520 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5020 - Wait - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             1180 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             1184 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1188 - Wait - netprofm.dll - c:\windows\system32\netprofm.dll - Microsoft Corporation
             1404 - Wait - fdwsd.dll - C:\Windows\system32\fdwsd.dll - Microsoft Corporation
             2068 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2108 - Wait - netprofm.dll - c:\windows\system32\netprofm.dll - Microsoft Corporation
             2568 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2572 - Terminate - es.dll - c:\windows\system32\es.dll - Microsoft Corporation
             3168 - Wait - netprofm.dll - c:\windows\system32\netprofm.dll - Microsoft Corporation
             3592 - Wait - netprofm.dll - c:\windows\system32\netprofm.dll - Microsoft Corporation
             3948 - Wait - fdwsd.dll - C:\Windows\system32\fdwsd.dll - Microsoft Corporation
             4044 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             4404 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4588 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4604 - Wait - fdwsd.dll - C:\Windows\system32\fdwsd.dll - Microsoft Corporation
             4708 - Terminate - fdwsd.dll - C:\Windows\system32\fdwsd.dll - Microsoft Corporation
             5120 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5460 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6032 - Wait - fdwsd.dll - C:\Windows\system32\fdwsd.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[nvtray.exe]Threads
             1328 - Wait - nvtray.exe - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe - NVIDIA Corporation
             1664 - Terminate - NvUpdt.dll - C:\Program Files\NVIDIA Corporation\NvUpdate\NvUpdt.dll - NVIDIA Corporation
             1716 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1868 - Wait - NvUI.dll - C:\Program Files\NVIDIA Corporation\Display\NvUI.dll - NVIDIA Corporation
             5300 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5516 - Wait - easyUpdatusAPIU.dll - C:\Windows\system32\easyUpdatusAPIU.dll - NVIDIA Corporation

------------------------------------------------------------------------------------------

      Image File Name[PDAgentS1.exe]Threads
             1292 - Wait - PDAgentS1.exe - C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe - Raxco Software, Inc.
             3724 - Wait - PDAgentS1.exe - C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe - Raxco Software, Inc.
             4140 - Wait - PDAgentS1.exe - C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe - Raxco Software, Inc.

------------------------------------------------------------------------------------------

      Image File Name[taskmgr.exe]Threads
             1952 - Wait - taskmgr.exe - C:\Windows\system32\taskmgr.exe - Microsoft Corporation
             2676 - Wait - taskmgr.exe - C:\Windows\system32\taskmgr.exe - Microsoft Corporation
             4992 - Wait - taskmgr.exe - C:\Windows\system32\taskmgr.exe - Microsoft Corporation
             5264 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5344 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             1472 - Wait - wdiasqmmodule.dll - C:\Windows\system32\wdiasqmmodule.dll - Microsoft Corporation
             1752 - Wait - radardt.dll - C:\Windows\system32\radardt.dll - Microsoft Corporation
             2224 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             2236 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2252 - Wait - AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             2264 - Wait - AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             2276 - Wait - AUTHZ.dll - c:\windows\system32\AUTHZ.dll - Microsoft Corporation
             2280 - Terminate - mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             2284 - Wait - mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             2288 - Terminate - mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             2296 - Wait - mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             2308 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2312 - Wait - mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             2316 - Wait - mpssvc.dll - c:\windows\system32\mpssvc.dll - Microsoft Corporation
             2472 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2488 - Wait - dps.dll - c:\windows\system32\dps.dll - Microsoft Corporation
             4048 - Wait - dps.dll - c:\windows\system32\dps.dll - Microsoft Corporation
             4156 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4788 - Wait - radardt.dll - C:\Windows\system32\radardt.dll - Microsoft Corporation
             5296 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[SearchIndexer.exe]Threads
             1492 - Wait - ESENT.dll - C:\Windows\system32\ESENT.dll - Microsoft Corporation
             1748 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3128 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3824 - Wait - SearchIndexer.exe - C:\Windows\system32\SearchIndexer.exe - Microsoft Corporation
             3984 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3996 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             4320 - Wait - TQUERY.DLL - C:\Windows\system32\TQUERY.DLL - Microsoft Corporation
             4324 - Terminate - MSSRCH.DLL - C:\Windows\system32\MSSRCH.DLL - Microsoft Corporation
             4328 - Wait - MSSRCH.DLL - C:\Windows\system32\MSSRCH.DLL - Microsoft Corporation
             4332 - Wait - MSSRCH.DLL - C:\Windows\system32\MSSRCH.DLL - Microsoft Corporation
             4336 - Wait - MSSRCH.DLL - C:\Windows\system32\MSSRCH.DLL - Microsoft Corporation
             4344 - Wait - MSSRCH.DLL - C:\Windows\system32\MSSRCH.DLL - Microsoft Corporation
             4624 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5144 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6056 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[soffice.bin]Threads
             1504 - Wait - gdiplus.dll - C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll - Microsoft Corporation
             1560 - Wait - sfxmi.dll - C:\Program Files\OpenOffice.org 3\program\sfxmi.dll - OpenOffice.org
             1824 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1880 - Wait - sal3.dll - C:\Program Files\OpenOffice.org 3\URE\bin\sal3.dll - OpenOffice.org
             1892 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1964 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             1988 - Wait - soffice.bin - C:\Program Files\OpenOffice.org 3\program\soffice.bin - OpenOffice.org
             3560 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[dwm.exe]Threads
             1592 - Wait - Dwm.exe - C:\Windows\system32\Dwm.exe - Microsoft Corporation
             1652 - Wait - Dwm.exe - C:\Windows\system32\Dwm.exe - Microsoft Corporation
             1656 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1832 - Wait - dwmcore.dll - C:\Windows\system32\dwmcore.dll - Microsoft Corporation
             1840 - Wait - uDWM.dll - C:\Windows\system32\uDWM.dll - Microsoft Corporation
             2996 - Terminate - Dwm.exe - C:\Windows\system32\Dwm.exe - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             1536 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             1640 - Wait - fntcache.dll - c:\windows\system32\fntcache.dll - Microsoft Corporation
             2056 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2112 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             2536 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             2540 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2552 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2556 - Terminate - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2604 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2616 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2620 - Wait - FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             2624 - Wait - FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             2632 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3228 - Terminate - SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             3580 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3840 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4128 - Wait - SSDPAPI.dll - C:\Windows\system32\SSDPAPI.dll - Microsoft Corporation
             4548 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4680 - Terminate - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             4772 - Wait - ssdpsrv.dll - c:\windows\system32\ssdpsrv.dll - Microsoft Corporation
             4776 - Wait - ssdpsrv.dll - c:\windows\system32\ssdpsrv.dll - Microsoft Corporation
             4868 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4912 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5000 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[sqlservr.exe]Threads
             1644 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2412 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2644 - Wait - sqlservr.exe - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe - Microsoft Corporation
             2712 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2744 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2748 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2752 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2756 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2760 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2764 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2768 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2772 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2800 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2884 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2888 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2932 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2936 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2940 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2944 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2948 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2956 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             3072 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             3084 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             3088 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3100 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             4268 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             4740 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             4984 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             5564 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             6068 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             6120 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[XueTr.exe]Threads
             1660 - Wait - XueTr.exe - C:\Nov sloka\XueTr.exe - Email: linxer@163.com
             1724 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2204 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3336 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3392 - Run - XueTr.exe - C:\Nov sloka\XueTr.exe - Email: linxer@163.com

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Threads
             1820 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             2256 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3384 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4184 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5024 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5256 - Wait - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             5328 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5352 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             6096 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[AppleMobileDeviceService.exe]Threads
             1844 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2356 - Wait - AppleMobileDeviceService.exe - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - Apple Inc.
             2372 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2380 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2388 - Terminate - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2392 - Ready - AppleMobileDeviceService_main.dll - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll - Apple Inc.
             2396 - Wait - AppleMobileDeviceService_main.dll - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll - Apple Inc.
             2400 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2580 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation
             2668 - Wait - MSVCR80.dll - C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[VM305_STI.EXE]Threads
             1924 - Wait - VM305_STI.EXE - C:\Windows\VM305_STI.EXE - Vimicro

------------------------------------------------------------------------------------------

      Image File Name[soffice.exe]Threads
             1972 - Wait - soffice.exe - C:\Program Files\OpenOffice.org 3\program\soffice.exe - OpenOffice.org

------------------------------------------------------------------------------------------

      Image File Name[mDNSResponder.exe]Threads
             1980 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2408 - Wait - mDNSResponder.exe - C:\Program Files\Bonjour\mDNSResponder.exe - Apple Inc.
             2428 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2432 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3240 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4944 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmnetdhcp.exe]Threads
             2088 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3588 - Wait - vmnetdhcp.exe - C:\Windows\system32\vmnetdhcp.exe - VMware, Inc.
             3600 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[spoolsv.exe]Threads
             2192 - Wait - spoolsv.exe - C:\Windows\System32\spoolsv.exe - Microsoft Corporation
             2208 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2212 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2216 - Wait - spoolsv.exe - C:\Windows\System32\spoolsv.exe - Microsoft Corporation
             5216 - Wait - usbmon.dll - C:\Windows\System32\usbmon.dll - Microsoft Corporation
             5224 - Wait - WSDMon.dll - C:\Windows\System32\WSDMon.dll - Microsoft Corporation
             5228 - Wait - FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             5232 - Wait - fdPnp.dll - C:\Windows\system32\fdPnp.dll - Microsoft Corporation
             5236 - Wait - FunDisc.dll - C:\Windows\system32\FunDisc.dll - Microsoft Corporation
             5244 - Wait - PrintIsolationProxy.dll - C:\Windows\System32\PrintIsolationProxy.dll - Microsoft Corporation
             5252 - Wait - localspl.dll - C:\Windows\System32\localspl.dll - Microsoft Corporation
             5888 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[CepstralLicSrv.exe]Threads
             2444 - Wait - CepstralLicSrv.exe - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe - Cepstral, LLC
             2460 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2464 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2476 - Wait - CepstralLicSrv.exe - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe - Cepstral, LLC
             2480 - Wait - CepstralLicSrv.exe - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe - Cepstral, LLC
             2484 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             2468 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2848 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2856 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4068 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             4076 - Terminate - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4080 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[TeamViewer_Service.exe]Threads
             2496 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3036 - Wait - TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe - TeamViewer GmbH
             3048 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3108 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3148 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3220 - Wait - TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe - TeamViewer GmbH

------------------------------------------------------------------------------------------

      Image File Name[launcherd.exe]Threads
             2504 - Wait - launcherd.exe - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe - 
             2508 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2516 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             2520 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2524 - Wait - launcherd.exe - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe - 

------------------------------------------------------------------------------------------

      Image File Name[PnkBstrA.exe]Threads
             2824 - Wait - PnkBstrA.exe - C:\Windows\system32\PnkBstrA.exe - 
             2836 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2840 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4252 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PnkBstrB.exe]Threads
             2908 - Wait - PnkBstrB.exe - C:\Windows\system32\PnkBstrB.exe - 
             2920 - Run - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2928 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4288 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[sqlwriter.exe]Threads
             2964 - Wait - sqlwriter.exe - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe - Microsoft Corporation
             2976 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             2980 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5928 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[svchost.exe]Threads
             2988 - Wait - svchost.exe - C:\Windows\system32\svchost.exe - Microsoft Corporation
             3004 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3012 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3020 - Wait - wiaservc.dll - c:\windows\system32\wiaservc.dll - Microsoft Corporation
             3024 - Wait - wiaservc.dll - c:\windows\system32\wiaservc.dll - Microsoft Corporation
             4488 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[TeamViewer_Service.exe]Threads
             3064 - Wait - TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe - TeamViewer GmbH
             3116 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3120 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3156 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3268 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3316 - Wait - TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe - TeamViewer GmbH

------------------------------------------------------------------------------------------

      Image File Name[vmnat.exe]Threads
             3196 - Wait - vmnat.exe - C:\Windows\system32\vmnat.exe - VMware, Inc.
             3200 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3208 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3212 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3216 - Wait - vmnat.exe - C:\Windows\system32\vmnat.exe - VMware, Inc.
             3232 - Wait - mswsock.dll - C:\Windows\system32\mswsock.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[chrome.exe]Threads
             3252 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3568 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             3768 - Ready - chrome.exe - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe - Google Inc.
             4416 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4700 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4828 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5072 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             5676 - Wait - chrome.dll - C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll - Google Inc.
             5852 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[WLIDSVC.EXE]Threads
             3264 - Wait - WLIDSVC.EXE - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE - Microsoft Corp.
             3300 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3308 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3320 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3324 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3328 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3372 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4428 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4816 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmware-authd.exe]Threads
             3356 - Wait - vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.
             3476 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3480 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3536 - Terminate - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3636 - Wait - vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.
             3640 - Wait - vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.
             3644 - Wait - vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.
             3648 - Wait - vmware-authd.exe - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe - VMware, Inc.

------------------------------------------------------------------------------------------

      Image File Name[WLIDSVCM.EXE]Threads
             3380 - Wait - WLIDSvcM.exe - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe - Microsoft Corp.
             3396 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3400 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3404 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[vmware-hostd.exe]Threads
             3680 - Wait - vmware-hostd.exe - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe - 
             3688 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             3760 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3788 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             3792 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4292 - Wait - perfdisk.dll - C:\Windows\System32\perfdisk.dll - Microsoft Corporation
             4832 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             4880 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             4896 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             4900 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             5480 - Wait - MSVCR90.dll - C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll - Microsoft Corporation
             5764 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[PDEngine.exe]Threads
             2700 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3784 - Wait - PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
             3796 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3808 - Wait - sechost.dll - C:\Windows\SYSTEM32\sechost.dll - Microsoft Corporation
             3816 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             3832 - Wait - PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
             3836 - Wait - ole32.dll - C:\Windows\system32\ole32.dll - Microsoft Corporation
             4032 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4108 - Wait - PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
             4112 - Wait - PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
             4116 - Wait - PDEngine.exe - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe - Raxco Software, Inc.
             5016 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[audiodg.exe]Threads
             3800 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             3912 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation
             4540 - Wait - AUDIODG.EXE - C:\Windows\system32\AUDIODG.EXE - Microsoft Corporation
             5284 - Wait - ole32.dll - C:\Windows\System32\ole32.dll - Microsoft Corporation
             5948 - Wait - ntdll.dll - C:\Windows\SYSTEM32\ntdll.dll - Microsoft Corporation

------------------------------------------------------------------------------------------

      Image File Name[Idle]Threads

==========================================================================================

Kernel Module

       ntkrnlpa.exe - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       halmacpi.dll - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       kdcom.dll - C:\Windows\system32\kdcom.dll - Microsoft Corporation
       mcupdate_AuthenticAMD.dll - C:\Windows\system32\mcupdate_AuthenticAMD.dll - Microsoft Corporation
       PSHED.dll - C:\Windows\system32\PSHED.dll - Microsoft Corporation
       BOOTVID.dll - C:\Windows\system32\BOOTVID.dll - Microsoft Corporation
       CLFS.SYS - C:\Windows\system32\CLFS.SYS - Microsoft Corporation
       CI.dll - C:\Windows\system32\CI.dll - Microsoft Corporation
       Wdf01000.sys - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       WDFLDR.SYS - C:\Windows\system32\drivers\WDFLDR.SYS - Microsoft Corporation
       ACPI.sys - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       WMILIB.SYS - C:\Windows\system32\drivers\WMILIB.SYS - Microsoft Corporation
       msisadrv.sys - C:\Windows\system32\drivers\msisadrv.sys - Microsoft Corporation
       pci.sys - C:\Windows\system32\drivers\pci.sys - Microsoft Corporation
       vdrvroot.sys - C:\Windows\system32\drivers\vdrvroot.sys - Microsoft Corporation
       partmgr.sys - C:\Windows\System32\drivers\partmgr.sys - Microsoft Corporation
       volmgr.sys - C:\Windows\system32\drivers\volmgr.sys - Microsoft Corporation
       volmgrx.sys - C:\Windows\System32\drivers\volmgrx.sys - Microsoft Corporation
       pciide.sys - C:\Windows\system32\drivers\pciide.sys - Microsoft Corporation
       PCIIDEX.SYS - C:\Windows\system32\drivers\PCIIDEX.SYS - Microsoft Corporation
       vmci.sys - C:\Windows\system32\DRIVERS\vmci.sys - VMware, Inc.
       mountmgr.sys - C:\Windows\System32\drivers\mountmgr.sys - Microsoft Corporation
       atapi.sys - C:\Windows\system32\drivers\atapi.sys - Microsoft Corporation
       ataport.SYS - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       nvstor.sys - C:\Windows\system32\drivers\nvstor.sys - NVIDIA Corporation
       storport.sys - C:\Windows\system32\drivers\storport.sys - Microsoft Corporation
       nvstor32.sys - C:\Windows\system32\DRIVERS\nvstor32.sys - NVIDIA Corporation
       amdxata.sys - C:\Windows\system32\drivers\amdxata.sys - Advanced Micro Devices
       fltmgr.sys - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       fileinfo.sys - C:\Windows\system32\drivers\fileinfo.sys - Microsoft Corporation
       Ntfs.sys - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       msrpc.sys - C:\Windows\System32\Drivers\msrpc.sys - Microsoft Corporation
       ksecdd.sys - C:\Windows\System32\Drivers\ksecdd.sys - Microsoft Corporation
       cng.sys - C:\Windows\System32\Drivers\cng.sys - Microsoft Corporation
       pcw.sys - C:\Windows\System32\drivers\pcw.sys - Microsoft Corporation
       Fs_Rec.sys - C:\Windows\System32\Drivers\Fs_Rec.sys - Microsoft Corporation
       ndis.sys - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       NETIO.SYS - C:\Windows\system32\drivers\NETIO.SYS - Microsoft Corporation
       ksecpkg.sys - C:\Windows\System32\Drivers\ksecpkg.sys - Microsoft Corporation
       tcpip.sys - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       fwpkclnt.sys - C:\Windows\System32\drivers\fwpkclnt.sys - Microsoft Corporation
       volsnap.sys - C:\Windows\system32\drivers\volsnap.sys - Microsoft Corporation
       spldr.sys - C:\Windows\System32\Drivers\spldr.sys - Microsoft Corporation
       rdyboost.sys - C:\Windows\System32\drivers\rdyboost.sys - Microsoft Corporation
       mup.sys - C:\Windows\System32\Drivers\mup.sys - Microsoft Corporation
       hwpolicy.sys - C:\Windows\System32\drivers\hwpolicy.sys - Microsoft Corporation
       fvevol.sys - C:\Windows\System32\DRIVERS\fvevol.sys - Microsoft Corporation
       disk.sys - C:\Windows\system32\DRIVERS\disk.sys - Microsoft Corporation
       CLASSPNP.SYS - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       dtsoftbus01.sys - C:\Windows\system32\DRIVERS\dtsoftbus01.sys - DT Soft Ltd
       cdrom.sys - C:\Windows\system32\DRIVERS\cdrom.sys - Microsoft Corporation
       aswSnx.SYS - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       Null.SYS - C:\Windows\System32\Drivers\Null.SYS - Microsoft Corporation
       Beep.SYS - C:\Windows\System32\Drivers\Beep.SYS - Microsoft Corporation
       vga.sys - C:\Windows\System32\drivers\vga.sys - Microsoft Corporation
       VIDEOPRT.SYS - C:\Windows\System32\drivers\VIDEOPRT.SYS - Microsoft Corporation
       watchdog.sys - C:\Windows\System32\drivers\watchdog.sys - Microsoft Corporation
       RDPCDD.sys - C:\Windows\System32\DRIVERS\RDPCDD.sys - Microsoft Corporation
       rdpencdd.sys - C:\Windows\system32\drivers\rdpencdd.sys - Microsoft Corporation
       rdprefmp.sys - C:\Windows\system32\drivers\rdprefmp.sys - Microsoft Corporation
       Msfs.SYS - C:\Windows\System32\Drivers\Msfs.SYS - Microsoft Corporation
       Npfs.SYS - C:\Windows\System32\Drivers\Npfs.SYS - Microsoft Corporation
       tdx.sys - C:\Windows\system32\DRIVERS\tdx.sys - Microsoft Corporation
       TDI.SYS - C:\Windows\system32\DRIVERS\TDI.SYS - Microsoft Corporation
       aswTdi.SYS - C:\Windows\System32\Drivers\aswTdi.SYS - AVAST Software
       afd.sys - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       aswRdr.SYS - C:\Windows\System32\Drivers\aswRdr.SYS - AVAST Software
       netbt.sys - C:\Windows\System32\DRIVERS\netbt.sys - Microsoft Corporation
       ws2ifsl.sys - C:\Windows\system32\drivers\ws2ifsl.sys - Microsoft Corporation
       wfplwf.sys - C:\Windows\system32\DRIVERS\wfplwf.sys - Microsoft Corporation
       pacer.sys - C:\Windows\system32\DRIVERS\pacer.sys - Microsoft Corporation
       netbios.sys - C:\Windows\system32\DRIVERS\netbios.sys - Microsoft Corporation
       serial.sys - C:\Windows\system32\DRIVERS\serial.sys - Brother Industries Ltd.
       wanarp.sys - C:\Windows\system32\DRIVERS\wanarp.sys - Microsoft Corporation
       VBoxUSBMon.sys - C:\Windows\system32\DRIVERS\VBoxUSBMon.sys - Oracle Corporation
       VBoxDrv.sys - C:\Windows\system32\DRIVERS\VBoxDrv.sys - Oracle Corporation
       termdd.sys - C:\Windows\system32\drivers\termdd.sys - Microsoft Corporation
       rdbss.sys - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
       nsiproxy.sys - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       mssmbios.sys - C:\Windows\system32\drivers\mssmbios.sys - Microsoft Corporation
       discache.sys - C:\Windows\System32\drivers\discache.sys - Microsoft Corporation
       dfsc.sys - C:\Windows\System32\Drivers\dfsc.sys - Microsoft Corporation
       blbdrive.sys - C:\Windows\system32\DRIVERS\blbdrive.sys - Microsoft Corporation
       aswSP.SYS - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       tunnel.sys - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       amdk8.sys - C:\Windows\system32\DRIVERS\amdk8.sys - Microsoft Corporation
       fdc.sys - C:\Windows\system32\DRIVERS\fdc.sys - Microsoft Corporation
       parport.sys - C:\Windows\system32\DRIVERS\parport.sys - Microsoft Corporation
       ASACPI.sys - C:\Windows\system32\DRIVERS\ASACPI.sys - 
       i8042prt.sys - C:\Windows\system32\drivers\i8042prt.sys - Microsoft Corporation
       kbdclass.sys - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       serenum.sys - C:\Windows\system32\DRIVERS\serenum.sys - Microsoft Corporation
       usbohci.sys - C:\Windows\system32\DRIVERS\usbohci.sys - Microsoft Corporation
       USBPORT.SYS - C:\Windows\system32\DRIVERS\USBPORT.SYS - Microsoft Corporation
       usbehci.sys - C:\Windows\system32\DRIVERS\usbehci.sys - Microsoft Corporation
       HDAudBus.sys - C:\Windows\system32\drivers\HDAudBus.sys - Microsoft Corporation
       GEARAspiWDM.sys - C:\Windows\system32\DRIVERS\GEARAspiWDM.sys - GEAR Software Inc.
       nvmf6232.sys - C:\Windows\system32\DRIVERS\nvmf6232.sys - NVIDIA Corporation
       nvlddmkm.sys - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       nvBridge.kmd - C:\Windows\System32\Drivers\nvBridge.kmd - NVIDIA Corporation
       dxgkrnl.sys - C:\Windows\System32\drivers\dxgkrnl.sys - Microsoft Corporation
       dxgmms1.sys - C:\Windows\System32\drivers\dxgmms1.sys - Microsoft Corporation
       CompositeBus.sys - C:\Windows\system32\drivers\CompositeBus.sys - Microsoft Corporation
       AgileVpn.sys - C:\Windows\system32\DRIVERS\AgileVpn.sys - Microsoft Corporation
       rasl2tp.sys - C:\Windows\system32\DRIVERS\rasl2tp.sys - Microsoft Corporation
       ndistapi.sys - C:\Windows\system32\DRIVERS\ndistapi.sys - Microsoft Corporation
       ndiswan.sys - C:\Windows\system32\DRIVERS\ndiswan.sys - Microsoft Corporation
       raspppoe.sys - C:\Windows\system32\DRIVERS\raspppoe.sys - Microsoft Corporation
       raspptp.sys - C:\Windows\system32\DRIVERS\raspptp.sys - Microsoft Corporation
       rassstp.sys - C:\Windows\system32\DRIVERS\rassstp.sys - Microsoft Corporation
       hamachi.sys - C:\Windows\system32\DRIVERS\hamachi.sys - LogMeIn, Inc.
       VBoxNetAdp.sys - C:\Windows\system32\DRIVERS\VBoxNetAdp.sys - Oracle Corporation
       tap0901t.sys - C:\Windows\system32\DRIVERS\tap0901t.sys - Tunngle.net
       mouclass.sys - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       VBoxNetFlt.sys - C:\Windows\system32\DRIVERS\VBoxNetFlt.sys - Oracle Corporation
       swenum.sys - C:\Windows\system32\drivers\swenum.sys - Microsoft Corporation
       ks.sys - C:\Windows\system32\drivers\ks.sys - Microsoft Corporation
       umbus.sys - C:\Windows\system32\drivers\umbus.sys - Microsoft Corporation
       vmnetadapter.sys - C:\Windows\system32\DRIVERS\vmnetadapter.sys - VMware, Inc.
       VMNET.SYS - C:\Windows\system32\DRIVERS\VMNET.SYS - VMware, Inc.
       flpydisk.sys - C:\Windows\system32\DRIVERS\flpydisk.sys - Microsoft Corporation
       usbhub.sys - C:\Windows\system32\DRIVERS\usbhub.sys - Microsoft Corporation
       NDProxy.SYS - C:\Windows\System32\Drivers\NDProxy.SYS - Microsoft Corporation
       RTKVHDA.sys - C:\Windows\system32\drivers\RTKVHDA.sys - Realtek Semiconductor Corp.
       portcls.sys - C:\Windows\system32\drivers\portcls.sys - Microsoft Corporation
       drmk.sys - C:\Windows\system32\drivers\drmk.sys - Microsoft Corporation
       hidusb.sys - C:\Windows\system32\DRIVERS\hidusb.sys - Microsoft Corporation
       HIDCLASS.SYS - C:\Windows\system32\DRIVERS\HIDCLASS.SYS - Microsoft Corporation
       HIDPARSE.SYS - C:\Windows\system32\DRIVERS\HIDPARSE.SYS - Microsoft Corporation
       USBD.SYS - C:\Windows\system32\DRIVERS\USBD.SYS - Microsoft Corporation
       udfs.sys - C:\Windows\system32\DRIVERS\udfs.sys - Microsoft Corporation
       mouhid.sys - C:\Windows\system32\DRIVERS\mouhid.sys - Microsoft Corporation
       USBSTOR.SYS - C:\Windows\system32\DRIVERS\USBSTOR.SYS - Microsoft Corporation
       crashdmp.sys - C:\Windows\System32\Drivers\crashdmp.sys - Microsoft Corporation
       dump_diskdump.sys - C:\Windows\System32\Drivers\dump_diskdump.sys - File not found
       dump_nvstor32.sys - C:\Windows\System32\Drivers\dump_nvstor32.sys - File not found
       dump_dumpfve.sys - C:\Windows\System32\Drivers\dump_dumpfve.sys - File not found
       fastfat.SYS - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       win32k.sys - C:\Windows\System32\win32k.sys - Microsoft Corporation
       Dxapi.sys - C:\Windows\System32\drivers\Dxapi.sys - Microsoft Corporation
       usbVM305.sys - C:\Windows\System32\Drivers\usbVM305.sys - Vimicro Corporation
       STREAM.SYS - C:\Windows\System32\Drivers\STREAM.SYS - Microsoft Corporation
       monitor.sys - C:\Windows\system32\DRIVERS\monitor.sys - Microsoft Corporation
       TSDDD.dll - C:\Windows\System32\TSDDD.dll - Microsoft Corporation
       cdd.dll - C:\Windows\System32\cdd.dll - Microsoft Corporation
       ATMFD.DLL - C:\Windows\System32\ATMFD.DLL - Adobe Systems Incorporated
       luafv.sys - C:\Windows\system32\drivers\luafv.sys - Microsoft Corporation
       aswMonFlt.sys - C:\Windows\system32\drivers\aswMonFlt.sys - AVAST Software
       aswFsBlk.SYS - C:\Windows\System32\Drivers\aswFsBlk.SYS - AVAST Software
       PDFsFilter.sys - C:\Windows\system32\DRIVERS\PDFsFilter.sys - Raxco Software, Inc.
       WudfPf.sys - C:\Windows\system32\drivers\WudfPf.sys - Microsoft Corporation
       DefragFS.SYS - C:\Windows\System32\Drivers\DefragFS.SYS - Raxco Software, Inc.
       vmnetbridge.sys - C:\Windows\system32\DRIVERS\vmnetbridge.sys - VMware, Inc.
       lltdio.sys - C:\Windows\system32\DRIVERS\lltdio.sys - Microsoft Corporation
       rspndr.sys - C:\Windows\system32\DRIVERS\rspndr.sys - Microsoft Corporation
       HTTP.sys - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
       bowser.sys - C:\Windows\system32\DRIVERS\bowser.sys - Microsoft Corporation
       mpsdrv.sys - C:\Windows\System32\drivers\mpsdrv.sys - Microsoft Corporation
       mrxsmb.sys - C:\Windows\system32\DRIVERS\mrxsmb.sys - Microsoft Corporation
       mrxsmb10.sys - C:\Windows\system32\DRIVERS\mrxsmb10.sys - Microsoft Corporation
       mrxsmb20.sys - C:\Windows\system32\DRIVERS\mrxsmb20.sys - Microsoft Corporation
       hcmon.sys - C:\Windows\system32\drivers\hcmon.sys - VMware, Inc.
       parvdm.sys - C:\Windows\system32\DRIVERS\parvdm.sys - Microsoft Corporation
       VMparport.sys - C:\Windows\system32\Drivers\VMparport.sys - VMware, Inc.
       vmx86.sys - C:\Windows\system32\Drivers\vmx86.sys - VMware, Inc.
       peauth.sys - C:\Windows\system32\drivers\peauth.sys - Microsoft Corporation
       secdrv.SYS - C:\Windows\System32\Drivers\secdrv.SYS - Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.
       srvnet.sys - C:\Windows\System32\DRIVERS\srvnet.sys - Microsoft Corporation
       tcpipreg.sys - C:\Windows\System32\drivers\tcpipreg.sys - Microsoft Corporation
       vmnetuserif.sys - C:\Windows\system32\drivers\vmnetuserif.sys - VMware, Inc.
       vstor2-mntapi10-shared.sys - C:\Windows\system32\drivers\vstor2-mntapi10-shared.sys - VMware, Inc.
       srv2.sys - C:\Windows\System32\DRIVERS\srv2.sys - Microsoft Corporation
       srv.sys - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
       XueTr.sys - C:\Nov sloka\XueTr.sys - File not found

==========================================================================================

Notify Routine

       CreateProcess - 0x82CFBD15 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CreateProcess - 0x88D749D8 - C:\Windows\System32\Drivers\ksecdd.sys - Microsoft Corporation
       CreateProcess - 0x88D7FD96 - C:\Windows\System32\Drivers\cng.sys - Microsoft Corporation
       CreateProcess - 0x890A0833 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       CreateProcess - 0x8328EDFC - C:\Windows\system32\CI.dll - Microsoft Corporation
       CreateProcess - 0x8DA8D756 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       CreateProcess - 0x90DC652E - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       CreateProcess - 0x91A6668E - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       CreateProcess - 0xAE35E1D9 - C:\Windows\system32\drivers\peauth.sys - Microsoft Corporation
       CreateThread - 0x8DA8A2C4 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       CreateThread - 0x90DC6224 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       CreateThread - 0x91B064B0 - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       LoadImage - 0x82E93B77 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       LoadImage - 0x8DA8D2CC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       LoadImage - 0x90DC6110 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       CmpCallback - 0x90DB1788 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       CmpCallback - 0x8DAA6973 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x88E44660 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       BugCheckCallback - 0x82C16996 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x97A2F1BE - C:\Windows\System32\Drivers\crashdmp.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x9102F50E - C:\Windows\system32\DRIVERS\mouhid.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x91021ABC - C:\Windows\system32\DRIVERS\HIDCLASS.SYS - Microsoft Corporation
       BugCheckReasonCallback - 0x9283285E - C:\Windows\system32\DRIVERS\hidusb.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x911CBA0A - C:\Windows\system32\DRIVERS\usbhub.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x911CB9B5 - C:\Windows\system32\DRIVERS\usbhub.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x913E15F5 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x91ACD8F0 - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       BugCheckReasonCallback - 0x91225AC9 - C:\Windows\System32\drivers\dxgkrnl.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x910ADE77 - C:\Windows\system32\DRIVERS\USBPORT.SYS - Microsoft Corporation
       BugCheckReasonCallback - 0x910ADF2E - C:\Windows\system32\DRIVERS\USBPORT.SYS - Microsoft Corporation
       BugCheckReasonCallback - 0x910ADED4 - C:\Windows\system32\DRIVERS\USBPORT.SYS - Microsoft Corporation
       BugCheckReasonCallback - 0x9106E861 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x9105B8D5 - C:\Windows\system32\drivers\i8042prt.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x90D64EEC - C:\Windows\system32\drivers\mssmbios.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x90D64EA4 - C:\Windows\system32\drivers\mssmbios.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x90D64E54 - C:\Windows\system32\drivers\mssmbios.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x90D64E0C - C:\Windows\system32\drivers\mssmbios.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8DAFE392 - C:\Windows\System32\drivers\VIDEOPRT.SYS - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8DA5B889 - C:\Windows\system32\DRIVERS\cdrom.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x88F974FF - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338072D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x8338022A - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       BugCheckReasonCallback - 0x88AF62A6 - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       SeFileSystem - 0xAE2C9EB9 - C:\Windows\system32\DRIVERS\mrxsmb.sys - Microsoft Corporation
       SeFileSystem - 0x97B499D9 - C:\Windows\system32\drivers\luafv.sys - Microsoft Corporation
       Shutdown - 0x8DB03107 - C:\Windows\System32\drivers\VIDEOPRT.SYS - Microsoft Corporation
       Shutdown - 0x911CB963 - C:\Windows\system32\DRIVERS\usbhub.sys - Microsoft Corporation
       Shutdown - 0x911CB963 - C:\Windows\system32\DRIVERS\usbhub.sys - Microsoft Corporation
       Shutdown - 0x8DB03107 - C:\Windows\System32\drivers\VIDEOPRT.SYS - Microsoft Corporation
       Shutdown - 0x8DB03107 - C:\Windows\System32\drivers\VIDEOPRT.SYS - Microsoft Corporation
       Shutdown - 0x8DB03107 - C:\Windows\System32\drivers\VIDEOPRT.SYS - Microsoft Corporation
       Shutdown - 0x88D74A14 - C:\Windows\System32\Drivers\ksecdd.sys - Microsoft Corporation
       Shutdown - 0x88ADE172 - C:\Windows\System32\drivers\mountmgr.sys - Microsoft Corporation
       Shutdown - 0x82F1ED63 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Shutdown - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Shutdown - 0x88A50318 - C:\Windows\system32\drivers\volmgr.sys - Microsoft Corporation
       PlugPlay - 0xAE333FEC - C:\Windows\system32\drivers\hcmon.sys - VMware, Inc.
       PlugPlay - 0x91BF1DAE - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       PlugPlay - 0x82DCABB1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PlugPlay - 0x82DCABB1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PlugPlay - 0x8267D34C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       PlugPlay - 0x9130F958 - C:\Windows\system32\drivers\CompositeBus.sys - Microsoft Corporation
       PlugPlay - 0x91BF97AE - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       PlugPlay - 0x82DCABB1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PlugPlay - 0x82DCABB1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PlugPlay - 0x9130F958 - C:\Windows\system32\drivers\CompositeBus.sys - Microsoft Corporation
       PlugPlay - 0x88A56448 - C:\Windows\system32\drivers\volmgr.sys - Microsoft Corporation
       PlugPlay - 0x912756FB - C:\Windows\System32\drivers\dxgkrnl.sys - Microsoft Corporation
       PlugPlay - 0x8267D34C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       PlugPlay - 0x8266FED8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       PlugPlay - 0x91CC19D4 - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       PlugPlay - 0xAE335CFA - C:\Windows\system32\drivers\hcmon.sys - VMware, Inc.
       PlugPlay - 0xAE341EA4 - C:\Windows\system32\Drivers\VMparport.sys - VMware, Inc.
       PlugPlay - 0x88A56448 - C:\Windows\system32\drivers\volmgr.sys - Microsoft Corporation
       PlugPlay - 0x88AE6214 - C:\Windows\System32\drivers\mountmgr.sys - Microsoft Corporation
       PlugPlay - 0x891C9F94 - C:\Windows\system32\drivers\volsnap.sys - Microsoft Corporation
       PlugPlay - 0x8267D34C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       PlugPlay - 0x82DCABB1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PlugPlay - 0x88A45F77 - C:\Windows\System32\drivers\partmgr.sys - Microsoft Corporation
       FsNotifyChange - 0x88BDEBDA - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       FsNotifyChange - 0x97BBBE48 - C:\Windows\System32\Drivers\DefragFS.SYS - Raxco Software, Inc.

==========================================================================================

Filter

       File - \FileSystem\FltMgr->\FileSystem\Ntfs - 0x85C645F0 - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       Disk - \Driver\partmgr->\Driver\Disk - 0x85C5E020 - C:\Windows\System32\drivers\partmgr.sys - Microsoft Corporation
       Volume - \Driver\fvevol->\Driver\volmgr - 0x85C65020 - C:\Windows\System32\DRIVERS\fvevol.sys - Microsoft Corporation
       Volume - \Driver\rdyboost->\Driver\fvevol - 0x85C649C8 - C:\Windows\System32\drivers\rdyboost.sys - Microsoft Corporation
       Volume - \Driver\volsnap->\Driver\rdyboost - 0x85C61020 - C:\Windows\system32\drivers\volsnap.sys - Microsoft Corporation
       I8042prt - \Driver\kbdclass->\Driver\i8042prt - 0x85E6B100 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       PnpManager - \Driver\volmgr->\Driver\PnpManager - 0x8557F030 - C:\Windows\system32\drivers\volmgr.sys - Microsoft Corporation
       PnpManager - \Driver\vmci->\Driver\PnpManager - 0x85591298 - C:\Windows\system32\DRIVERS\vmci.sys - VMware, Inc.
       PnpManager - \Driver\VMnetAdapter->\Driver\PnpManager - 0x86041028 - C:\Windows\system32\DRIVERS\vmnetadapter.sys - VMware, Inc.
       PnpManager - \Driver\VMnetAdapter->\Driver\PnpManager - 0x8603A028 - C:\Windows\system32\DRIVERS\vmnetadapter.sys - VMware, Inc.
       PnpManager - \Driver\vdrvroot->\Driver\PnpManager - 0x85575590 - C:\Windows\system32\drivers\vdrvroot.sys - Microsoft Corporation
       PnpManager - \Driver\umbus->\Driver\PnpManager - 0x86039CD8 - C:\Windows\system32\drivers\umbus.sys - Microsoft Corporation
       PnpManager - \Driver\dtsoftbus01->\Driver\PnpManager - 0x85EA99A0 - C:\Windows\system32\DRIVERS\dtsoftbus01.sys - DT Soft Ltd
       PnpManager - \Driver\swenum->\Driver\PnpManager - 0x86034558 - C:\Windows\system32\drivers\swenum.sys - Microsoft Corporation
       PnpManager - \Driver\VBoxNetFlt->\Driver\PnpManager - 0x86038028 - C:\Windows\system32\DRIVERS\VBoxNetFlt.sys - Oracle Corporation
       PnpManager - \Driver\VBoxNetFlt->\Driver\PnpManager - 0x86036028 - C:\Windows\system32\DRIVERS\VBoxNetFlt.sys - Oracle Corporation
       PnpManager - \Driver\VBoxNetFlt->\Driver\PnpManager - 0x86032028 - C:\Windows\system32\DRIVERS\VBoxNetFlt.sys - Oracle Corporation
       PnpManager - \Driver\TermDD->\Driver\PnpManager - 0x85EA8740 - C:\Windows\system32\drivers\termdd.sys - Microsoft Corporation
       PnpManager - \Driver\mouclass->\Driver\TermDD - 0x85EA8558 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       PnpManager - \Driver\TermDD->\Driver\PnpManager - 0x86023E20 - C:\Windows\system32\drivers\termdd.sys - Microsoft Corporation
       PnpManager - \Driver\kbdclass->\Driver\TermDD - 0x8602F1E8 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       PnpManager - \Driver\tap0901t->\Driver\PnpManager - 0x86030028 - C:\Windows\system32\DRIVERS\tap0901t.sys - Tunngle.net
       PnpManager - \Driver\VBoxNetAdp->\Driver\PnpManager - 0x8602E028 - C:\Windows\system32\DRIVERS\VBoxNetAdp.sys - Oracle Corporation
       PnpManager - \Driver\hamachi->\Driver\PnpManager - 0x8602C028 - C:\Windows\system32\DRIVERS\hamachi.sys - LogMeIn, Inc.
       PnpManager - \Driver\RasSstp->\Driver\PnpManager - 0x86022028 - C:\Windows\system32\DRIVERS\rassstp.sys - Microsoft Corporation
       PnpManager - \Driver\PptpMiniport->\Driver\PnpManager - 0x86020028 - C:\Windows\system32\DRIVERS\raspptp.sys - Microsoft Corporation
       PnpManager - \Driver\RasPppoe->\Driver\PnpManager - 0x8601E028 - C:\Windows\system32\DRIVERS\raspppoe.sys - Microsoft Corporation
       PnpManager - \Driver\NdisWan->\Driver\PnpManager - 0x8601C028 - C:\Windows\system32\DRIVERS\ndiswan.sys - Microsoft Corporation
       PnpManager - \Driver\NdisWan->\Driver\PnpManager - 0x8601A028 - C:\Windows\system32\DRIVERS\ndiswan.sys - Microsoft Corporation
       PnpManager - \Driver\NdisWan->\Driver\PnpManager - 0x86018028 - C:\Windows\system32\DRIVERS\ndiswan.sys - Microsoft Corporation
       PnpManager - \Driver\Rasl2tp->\Driver\PnpManager - 0x86016028 - C:\Windows\system32\DRIVERS\rasl2tp.sys - Microsoft Corporation
       PnpManager - \Driver\RasAgileVpn->\Driver\PnpManager - 0x85FE5028 - C:\Windows\system32\DRIVERS\AgileVpn.sys - Microsoft Corporation
       PnpManager - \Driver\mssmbios->\Driver\PnpManager - 0x85FE4750 - C:\Windows\system32\drivers\mssmbios.sys - Microsoft Corporation
       PnpManager - \Driver\CompositeBus->\Driver\PnpManager - 0x85E9C878 - C:\Windows\system32\drivers\CompositeBus.sys - Microsoft Corporation
       PnpManager - \Driver\blbdrive->\Driver\PnpManager - 0x85E22EB8 - C:\Windows\system32\DRIVERS\blbdrive.sys - Microsoft Corporation
       PnpManager - \Driver\ACPI_HAL->\Driver\PnpManager - 0x84CDBAA8 -  - 
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E5F028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E5D028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E5B028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E59028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E57028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E50028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E49028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       PnpManager - \Driver\tunnel->\Driver\PnpManager - 0x85E09028 - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation

==========================================================================================

DPC Timer

       0x87CFA9F0 - 0xAF89C005 - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
       0x87B4A338 - 0x8DBAF94B - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0xAF8AC878 - 0xAF89C0B6 - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
       0xC22E33D0 - 0x8DBAF94B - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0xC23BAED0 - 0x8DBAF94B - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0x82D79760 - 0x82D52BB3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x87BD8748 - 0xAF815005 - C:\Windows\System32\DRIVERS\srvnet.sys - Microsoft Corporation
       0x82D80700 - 0x82D04F15 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0xAE233900 - 0xAE20B298 - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
       0x82C23F68 - 0x82C15C8C - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       0x88DCFB90 - 0x88D80F92 - C:\Windows\System32\Drivers\cng.sys - Microsoft Corporation
       0x8606D1B8 - 0x91115EB0 - C:\Windows\system32\DRIVERS\nvmf6232.sys - NVIDIA Corporation
       0x855A9D20 - 0x88B41D31 - C:\Windows\system32\drivers\storport.sys - Microsoft Corporation
       0x85EA01B0 - 0x91ACDCB6 - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       0x8AD4BCC8 - 0x82CB9CFD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x90C15610 - 0x90C0354C - C:\Windows\system32\DRIVERS\tunnel.sys - Microsoft Corporation
       0x82DA5320 - 0x82CBF48E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x85CD6B40 - 0x91B885E4 - C:\Windows\system32\DRIVERS\nvlddmkm.sys - NVIDIA Corporation
       0x86799E38 - 0x8335596D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       0x86068200 - 0x8335596D - C:\Windows\system32\drivers\Wdf01000.sys - Microsoft Corporation
       0x8DB98290 - 0x8DB8806A - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0x82DA66A0 - 0x82CD87FB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x97B41180 - 0x97B3C240 - C:\Windows\system32\drivers\luafv.sys - Microsoft Corporation
       0x88DCFC18 - 0x88D811C8 - C:\Windows\System32\Drivers\cng.sys - Microsoft Corporation
       0x84CB2D20 - 0x88B41D31 - C:\Windows\system32\drivers\storport.sys - Microsoft Corporation
       0x84CB5288 - 0x88AFDA6C - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       0x84CB1288 - 0x88AFDA6C - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       0x85E5D150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x85E5B150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x85E59150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x85E57150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x85E50150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x85E49150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x85E09150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x84C3C728 - 0x88EC5538 - C:\Windows\system32\drivers\NETIO.SYS - Microsoft Corporation
       0x85E5F150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x82DA5CC0 - 0x82D00B89 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x85E85150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x873D40E0 - 0x8DBAF94B - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0x90D7E1E0 - 0x90D7BB0E - C:\Windows\System32\Drivers\dfsc.sys - Microsoft Corporation
       0x891194D8 - 0x88EC5538 - C:\Windows\system32\drivers\NETIO.SYS - Microsoft Corporation
       0x8911A078 - 0x88EC5538 - C:\Windows\system32\drivers\NETIO.SYS - Microsoft Corporation
       0x89118BF8 - 0x88EC5538 - C:\Windows\system32\drivers\NETIO.SYS - Microsoft Corporation
       0x89114208 - 0x88EC5538 - C:\Windows\system32\drivers\NETIO.SYS - Microsoft Corporation
       0x82D6C1A8 - 0x82C71A77 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x85418948 - 0x8DBAF94B - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0x85BFA590 - 0x890A2029 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       0x8911AB60 - 0x89097040 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       0x8601A150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86018150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86016150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x8601C150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0xAE230A38 - 0xAE20BA39 - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
       0xAE233800 - 0xAE20BACA - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
       0xAE233D20 - 0xAE20BAB3 - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
       0x82D796E0 - 0x82D52BE3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x85984E08 - 0x88B4DCD0 - C:\Windows\system32\drivers\storport.sys - Microsoft Corporation
       0x86022150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86020150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x8601E150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x90D2C180 - 0x90D19569 - C:\Windows\system32\DRIVERS\rdbss.sys - Microsoft Corporation
       0x8603A150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86041150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x8602C150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x8602E150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86032150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86036150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86038150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x82DA5170 - 0x82C6FAE1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0xC233E178 - 0x8DBAF94B - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0x82D79660 - 0x82D09E4B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x88C4E520 - 0x88C2AEE5 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       0x82DA5B40 - 0x82D0D574 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0xAE34FF80 - 0xAE347C7E - C:\Windows\system32\Drivers\vmx86.sys - VMware, Inc.
       0x85DE5DD8 - 0x8DB88360 - C:\Windows\system32\drivers\afd.sys - Microsoft Corporation
       0x85FE5150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x86742A88 - 0x88E64E1B - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x8674F940 - 0x90C27005 - C:\Windows\System32\DRIVERS\netbt.sys - Microsoft Corporation
       0x82D797E0 - 0x82D52B81 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0xAE230D80 - 0xAE20B9B0 - C:\Windows\system32\drivers\HTTP.sys - Microsoft Corporation
       0x86030150 - 0x88E63B38 - C:\Windows\system32\drivers\ndis.sys - Microsoft Corporation
       0x90D751E0 - 0x90D6FFAF - C:\Windows\System32\drivers\discache.sys - Microsoft Corporation
       0x85B99E68 - 0x88BCB6C2 - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       0x8673F7B0 - 0x90C27005 - C:\Windows\System32\DRIVERS\netbt.sys - Microsoft Corporation
       0x85E9CFA0 - 0x91228525 - C:\Windows\System32\drivers\dxgkrnl.sys - Microsoft Corporation
       0x88C4E580 - 0x88C1695B - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       0x88F43670 - 0x88F2E9E6 - C:\Windows\System32\drivers\rdyboost.sys - Microsoft Corporation
       0x82D79DE0 - 0x82CDACF1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x84ECD490 - 0x82C6F1FC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       0x87CFAC30 - 0xAF89C005 - C:\Windows\System32\DRIVERS\srv.sys - Microsoft Corporation
       0x85BFA6B8 - 0x890A2029 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       0x807C75A8 - 0x82C71A77 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation

==========================================================================================

Worker Thread

       CriticalWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CriticalWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CriticalWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CriticalWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CriticalWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       HyperCriticalWorkQueue - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DelayedWorkQueue - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation

==========================================================================================

Object Hijack

       Nothing

==========================================================================================

Direct IO

       Nothing

==========================================================================================

GDT

       Selector(0x0001) - Type(Code RE Ac)
       Selector(0x0002) - Type(Data RW Ac)
       Selector(0x0003) - Type(Code RE Ac)
       Selector(0x0004) - Type(Data RW Ac)
       Selector(0x0005) - Type(T5532 Busy)
       Selector(0x0006) - Type(Data RW Ac)
       Selector(0x0007) - Type(Data RW Ac)
       Selector(0x0008) - Type(Data RW)
       Selector(0x000A) - Type(T5532 Avl)
       Selector(0x000B) - Type(T5532 Avl)
       Selector(0x000E) - Type(Data RW)
       Selector(0x0014) - Type(T5532 Avl)
       Selector(0x001D) - Type(Data RW)
       Selector(0x001E) - Type(Code EO)
       Selector(0x001F) - Type(Data RW)

==========================================================================================

SSDT

       NtAcceptConnectPort - OK - 0x82EB7CE8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheck - OK - 0x82CFF3ED - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheckAndAuditAlarm - OK - 0x82E47BE4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheckByType - OK - 0x82C6388A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheckByTypeAndAuditAlarm - OK - 0x82EB95BF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheckByTypeResultList - OK - 0x82D3C35E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheckByTypeResultListAndAuditAlarm - OK - 0x82F29C4F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAccessCheckByTypeResultListAndAuditAlarmByHandle - OK - 0x82F29C98 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAddAtom - OK - 0x82E3C433 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAddBootEntry - ssdt hook - 0x8DA83374 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtAddDriverEntry - OK - 0x82F44713 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAdjustGroupsToken - OK - 0x82E32C0B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAdjustPrivilegesToken - OK - 0x82EC3BFD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlertResumeThread - OK - 0x82F1CA55 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlertThread - OK - 0x82E6FB00 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAllocateLocallyUniqueId - OK - 0x82E3F748 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAllocateReserveObject - OK - 0x82DD5930 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAllocateUserPhysicalPages - OK - 0x82F0E97C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAllocateUuids - OK - 0x82E261C4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAllocateVirtualMemory - ssdt hook - 0x90DA92B8 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       NtAlpcAcceptConnectPort - OK - 0x82EB4EB1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcCancelMessage - OK - 0x82E16240 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcConnectPort - OK - 0x82EB42BE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcCreatePort - OK - 0x82E33C82 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcCreatePortSection - OK - 0x82EC5684 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcCreateResourceReserve - OK - 0x82E36305 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcCreateSectionView - OK - 0x82EC5464 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcCreateSecurityContext - OK - 0x82EBDBBC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcDeletePortSection - OK - 0x82E4816C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcDeleteResourceReserve - OK - 0x82F0973F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcDeleteSectionView - OK - 0x82EBAF89 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcDeleteSecurityContext - OK - 0x82EC58B6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcDisconnectPort - OK - 0x82E9E2BA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcImpersonateClientOfPort - OK - 0x82EB8FEE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcOpenSenderProcess - OK - 0x82E4AD91 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcOpenSenderThread - OK - 0x82E3ED6F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcQueryInformation - OK - 0x82E30BE6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcQueryInformationMessage - OK - 0x82E9EB41 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcRevokeSecurityContext - OK - 0x82F09867 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcSendWaitReceivePort - OK - 0x82E90FC7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAlpcSetInformation - OK - 0x82E3E77F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtApphelpCacheControl - OK - 0x82E50297 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAreMappedFilesTheSame - OK - 0x82E0C0EB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtAssignProcessToJobObject - OK - 0x82E3DF4E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCallbackReturn - OK - 0x82CBD87C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCancelIoFile - OK - 0x82E075CB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCancelIoFileEx - OK - 0x82E3BD5D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCancelSynchronousIoFile - OK - 0x82EF6098 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCancelTimer - OK - 0x82C69D56 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtClearEvent - OK - 0x82E6AC09 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtClose - OK - 0x82E83438 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCloseObjectAuditAlarm - OK - 0x82EB94EE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCommitComplete - OK - 0x82F31542 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCommitEnlistment - OK - 0x82F31262 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCommitTransaction - OK - 0x82E129C1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCompactKeys - OK - 0x82EDB0E3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCompareTokens - OK - 0x82E39D13 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCompleteConnectPort - OK - 0x82E3ED65 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCompressKey - OK - 0x82EDB34F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtConnectPort - OK - 0x82EB6DC9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtContinue - OK - 0x82C7FD3C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateDebugObject - OK - 0x82EEBD43 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateDirectoryObject - OK - 0x82E41581 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateEnlistment - OK - 0x82DE3A5D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateEvent - ssdt hook - 0x8DA85996 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateEventPair - ssdt hook - 0x8DA859EE - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateFile - OK - 0x82E8E2A2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateIoCompletion - ssdt hook - 0x8DA85B04 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateJobObject - OK - 0x82E309ED - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateJobSet - OK - 0x82F1E7DC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateKey - OK - 0x82E3FEA6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateKeyedEvent - OK - 0x82E4ED9A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateKeyTransacted - OK - 0x82E10A3E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateMailslotFile - OK - 0x82E443AB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateMutant - ssdt hook - 0x8DA858EC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateNamedPipeFile - OK - 0x82EBF5B9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreatePagingFile - OK - 0x82DCB40E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreatePort - OK - 0x82E307D5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreatePrivateNamespace - OK - 0x82E12587 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateProcess - OK - 0x82F1AEE5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateProcessEx - inline hook - 0x90DBE9AA - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       NtCreateProfile - OK - 0x82F49C5F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateProfileEx - OK - 0x82F49C25 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateResourceManager - OK - 0x82DE6367 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateSection - ssdt hook - 0x8DA85A3E - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateSemaphore - ssdt hook - 0x8DA85940 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateSymbolicLinkObject - OK - 0x82E40871 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateThread - OK - 0x82F1ACEE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateThreadEx - OK - 0x82EAF1E4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateTimer - ssdt hook - 0x8DA85AB2 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtCreateToken - OK - 0x82E43B44 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateTransaction - OK - 0x82E0EE6A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateTransactionManager - OK - 0x82DE6173 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateUserProcess - OK - 0x82EAD116 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateWaitablePort - OK - 0x82DE313C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtCreateWorkerFactory - OK - 0x82E4EFB5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDebugActiveProcess - OK - 0x82EECC00 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDebugContinue - OK - 0x82EED2C1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDelayExecution - OK - 0x82E67A19 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeleteAtom - OK - 0x82E2B0F1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeleteBootEntry - ssdt hook - 0x8DA83398 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtDeleteDriverEntry - OK - 0x82F44747 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeleteFile - OK - 0x82DD76B5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeleteKey - OK - 0x82E2A987 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeleteObjectAuditAlarm - OK - 0x82EC9AA7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeletePrivateNamespace - OK - 0x82ED27BE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeleteValueKey - OK - 0x82E1C39E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDeviceIoControlFile - OK - 0x82EB248A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDisableLastKnownGood - OK - 0x82F065C2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDisplayString - OK - 0x82F41737 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDrawText - OK - 0x82D531BD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDuplicateObject - OK - 0x82E7059A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtDuplicateToken - OK - 0x82EAAA34 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnableLastKnownGood - OK - 0x82F066A3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnumerateBootEntries - OK - 0x82F436F1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnumerateDriverEntries - OK - 0x82F44947 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnumerateKey - OK - 0x82EA5B19 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnumerateSystemEnvironmentValuesEx - OK - 0x82F432D1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnumerateTransactionObject - OK - 0x82F32082 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtEnumerateValueKey - OK - 0x82EA7F7F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtExtendSection - OK - 0x82F0CAFB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFilterToken - OK - 0x82E23DF7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFindAtom - OK - 0x82E2F975 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushBuffersFile - OK - 0x82E47193 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushInstallUILanguage - OK - 0x82DD3917 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushInstructionCache - OK - 0x82E3E53F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushKey - OK - 0x82E1DA43 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushProcessWriteBuffers - OK - 0x82C641B1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushVirtualMemory - OK - 0x82E19168 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFlushWriteBuffer - OK - 0x82F0FA9B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFreeUserPhysicalPages - OK - 0x82F0F11D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFreeVirtualMemory - ssdt hook - 0x90DA9368 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       NtFreezeRegistry - OK - 0x82D126BC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFreezeTransactions - OK - 0x82F324D2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtFsControlFile - OK - 0x82E94760 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetContextThread - OK - 0x82ED3E89 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetCurrentProcessorNumber - OK - 0x82ED3E1E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetDevicePowerState - OK - 0x82F17F23 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetMUIRegistryInfo - OK - 0x82E4FE2B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetNextProcess - OK - 0x82F1CC4C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetNextThread - OK - 0x82ECBCD2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetNlsSectionPtr - OK - 0x82E185FE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetNotificationResourceManager - OK - 0x82F32632 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetPlugPlayEvent - OK - 0x82DFDE6F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtGetWriteWatch - OK - 0x82D2959B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtImpersonateAnonymousToken - OK - 0x82E34840 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtImpersonateClientOfPort - OK - 0x82F08889 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtImpersonateThread - OK - 0x82EB86BC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtInitializeNlsFiles - OK - 0x82E9AFCB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtInitializeRegistry - OK - 0x82DD71D2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtInitiatePowerAction - OK - 0x82ECE68B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtIsProcessInJob - OK - 0x82ECFDA5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtIsSystemResumeAutomatic - OK - 0x82F17F0A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtIsUILanguageComitted - OK - 0x82DD1DF1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtListenPort - OK - 0x82DCEC7D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLoadDriver - ssdt hook - 0x8DA83162 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtLoadKey - OK - 0x82DD042E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLoadKey2 - OK - 0x82DBDA23 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLoadKeyEx - OK - 0x82DE0E7A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLockFile - OK - 0x82E423A7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLockProductActivationKeys - OK - 0x82DB702D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLockRegistryKey - OK - 0x82DB26D5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtLockVirtualMemory - OK - 0x82C63191 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtMakePermanentObject - OK - 0x82E051B9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtMakeTemporaryObject - OK - 0x82E4A8CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtMapCMFModule - OK - 0x82E4F3D7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtMapUserPhysicalPages - OK - 0x82F0DC3D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtMapUserPhysicalPagesScatter - OK - 0x82F0E213 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtMapViewOfSection - OK - 0x82E85452 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtModifyBootEntry - ssdt hook - 0x8DA833BC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtModifyDriverEntry - OK - 0x82F44918 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtNotifyChangeDirectoryFile - OK - 0x82E34E2C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtNotifyChangeKey - ssdt hook - 0x8DA85EFC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtNotifyChangeMultipleKeys - ssdt hook - 0x8DA83E54 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtNotifyChangeSession - OK - 0x82DFED73 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenDirectoryObject - OK - 0x82E81642 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenEnlistment - OK - 0x82F30AC9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenEvent - ssdt hook - 0x8DA859C6 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenEventPair - ssdt hook - 0x8DA85A16 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenFile - OK - 0x82E70BBA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenIoCompletion - ssdt hook - 0x8DA85B2E - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenJobObject - OK - 0x82F1E153 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenKey - OK - 0x82E8A700 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenKeyEx - OK - 0x82E4EB59 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenKeyedEvent - OK - 0x82F49603 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenKeyTransacted - OK - 0x82E0E171 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenKeyTransactedEx - OK - 0x82E0E101 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenMutant - ssdt hook - 0x8DA85918 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenObjectAuditAlarm - OK - 0x82E174EA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenPrivateNamespace - OK - 0x82E18F3F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenProcess - OK - 0x82E50A58 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenProcessToken - OK - 0x82EA30BF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenProcessTokenEx - OK - 0x82E90BF4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenResourceManager - OK - 0x82DBC0CE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenSection - ssdt hook - 0x8DA85A7E - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenSemaphore - ssdt hook - 0x8DA8596E - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenSession - OK - 0x82EC5A3F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenSymbolicLinkObject - OK - 0x82E8CC2D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenThread - OK - 0x82E9CE45 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenThreadToken - OK - 0x82EB73A4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenThreadTokenEx - OK - 0x82E90D0B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenTimer - ssdt hook - 0x8DA85ADC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtOpenTransaction - OK - 0x82F31827 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtOpenTransactionManager - OK - 0x82F32AC7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPlugPlayControl - OK - 0x82E2257C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPowerInformation - OK - 0x82E7FA2E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrepareComplete - OK - 0x82F313D2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrepareEnlistment - OK - 0x82F310F0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrePrepareComplete - OK - 0x82F3148A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrePrepareEnlistment - OK - 0x82F311AA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrivilegeCheck - OK - 0x82E359B5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrivilegedServiceAuditAlarm - OK - 0x82E04F68 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPrivilegeObjectAuditAlarm - OK - 0x82E1FAC7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPropagationComplete - OK - 0x82F33222 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtPropagationFailed - OK - 0x82F332EA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtProtectVirtualMemory - ssdt hook - 0x90DA9400 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       NtPulseEvent - OK - 0x82ED266F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryAttributesFile - OK - 0x82E96A5F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryBootEntryOrder - OK - 0x82F43B92 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryBootOptions - OK - 0x82F43FD5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryDebugFilterState - OK - 0x82D02D0E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryDefaultLocale - OK - 0x82EB5C4C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryDefaultUILanguage - OK - 0x82DE1F64 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryDirectoryFile - OK - 0x82E72DBB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryDirectoryObject - OK - 0x82E97AAE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryDriverEntryOrder - OK - 0x82F444D3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryEaFile - OK - 0x82DD0B52 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryEvent - OK - 0x82E39894 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryFullAttributesFile - OK - 0x82EBF695 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationAtom - OK - 0x82E2B2C2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationEnlistment - OK - 0x82F30CD4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationFile - OK - 0x82E94793 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationJobObject - OK - 0x82ECB1C7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationPort - OK - 0x82F088BC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationProcess - OK - 0x82E756EE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationResourceManager - OK - 0x82F3273C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationThread - OK - 0x82E9BE2B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationToken - OK - 0x82E9112B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationTransaction - OK - 0x82F31A1A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationTransactionManager - OK - 0x82DBBBD6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInformationWorkerFactory - OK - 0x82D53DE5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryInstallUILanguage - OK - 0x82E1DCB5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryIntervalProfile - OK - 0x82F49FCF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryIoCompletion - OK - 0x82EF5E50 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryKey - OK - 0x82E8AD6C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryLicenseValue - OK - 0x82E40F09 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryMultipleValueKey - OK - 0x82E1FD36 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryMutant - OK - 0x82F496E2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryObject - ssdt hook - 0x8DA83D1A - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtQueryOpenSubKeys - OK - 0x82EDABD5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryOpenSubKeysEx - OK - 0x82EC8EC0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryPerformanceCounter - OK - 0x82E4F2F3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryPortInformationProcess - OK - 0x82F1B3B0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryQuotaInformationFile - OK - 0x82EF7431 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySection - OK - 0x82EB5AA6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySecurityAttributesToken - OK - 0x82E35346 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySecurityObject - OK - 0x82E38EC2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySemaphore - OK - 0x82F4254E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySymbolicLinkObject - OK - 0x82E8CCD3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySystemEnvironmentValue - OK - 0x82F42727 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySystemEnvironmentValueEx - OK - 0x82F42D1D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySystemInformation - OK - 0x82E6ED7E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySystemInformationEx - OK - 0x82EA7E9D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQuerySystemTime - OK - 0x82EB5BB7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryTimer - OK - 0x82F49032 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryTimerResolution - OK - 0x82E2B79F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryValueKey - OK - 0x82E894C3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryVirtualMemory - OK - 0x82E9A765 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueryVolumeInformationFile - OK - 0x82E95386 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueueApcThread - OK - 0x82E3AD20 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtQueueApcThreadEx - OK - 0x82E36EDD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRaiseException - OK - 0x82C7FD84 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRaiseHardError - OK - 0x82E160AB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReadFile - OK - 0x82EA0D4A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReadFileScatter - OK - 0x82DD66AF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReadOnlyEnlistment - OK - 0x82F316B2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReadRequestData - OK - 0x82F089A1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReadVirtualMemory - OK - 0x82E9E8EA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRecoverEnlistment - OK - 0x82F30C7A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRecoverResourceManager - OK - 0x82DE6894 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRecoverTransactionManager - OK - 0x82DE8130 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRegisterProtocolAddressInformation - OK - 0x82F33076 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRegisterThreadTerminatePort - OK - 0x82F1C18A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReleaseKeyedEvent - OK - 0x82E6F197 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReleaseMutant - OK - 0x82E6791D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReleaseSemaphore - OK - 0x82E51BE6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReleaseWorkerFactoryWorker - OK - 0x82CC2C28 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRemoveIoCompletion - OK - 0x82E44B0A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRemoveIoCompletionEx - OK - 0x82E3FB0A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRemoveProcessDebug - OK - 0x82EECD4B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRenameKey - OK - 0x82EDAE1B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRenameTransactionManager - OK - 0x82F32D12 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReplaceKey - OK - 0x82EDA968 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReplacePartitionUnit - OK - 0x82D1B3A7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReplyPort - OK - 0x82E2FAB3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReplyWaitReceivePort - OK - 0x82E7768C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReplyWaitReceivePortEx - OK - 0x82E7720F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtReplyWaitReplyPort - OK - 0x82F08B6D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRequestPort - OK - 0x82EBF4F5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRequestWaitReplyPort - OK - 0x82E7C983 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtResetEvent - OK - 0x82E1AEFB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtResetWriteWatch - OK - 0x82D29BEC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRestoreKey - OK - 0x82ED09CC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtResumeProcess - OK - 0x82F1C9EF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtResumeThread - OK - 0x82EAF40B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRollbackComplete - OK - 0x82F3176A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRollbackEnlistment - OK - 0x82F3131A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRollbackTransaction - OK - 0x82DE4C84 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtRollforwardTransactionManager - OK - 0x82F32E74 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSaveKey - OK - 0x82ED223E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSaveKeyEx - OK - 0x82ED19E4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSaveMergedKeys - OK - 0x82ED9C8B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSecureConnectPort - OK - 0x82E9CE7A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSerializeBoot - OK - 0x82DC9F0F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetBootEntryOrder - ssdt hook - 0x8DA833E0 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtSetBootOptions - ssdt hook - 0x8DA83404 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtSetContextThread - OK - 0x82F1BDEF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetDebugFilterState - OK - 0x82DAF9BD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetDefaultHardErrorPort - OK - 0x82DCD89D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetDefaultLocale - OK - 0x82DE1CE9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetDefaultUILanguage - OK - 0x82DE2258 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetDriverEntryOrder - OK - 0x82F44D4B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetEaFile - OK - 0x82EF6EC2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetEvent - OK - 0x82E68788 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetEventBoostPriority - OK - 0x82F4220F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetHighEventPair - OK - 0x82F49599 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetHighWaitLowEventPair - OK - 0x82F494CB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationDebugObject - OK - 0x82EED487 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationEnlistment - OK - 0x82F30F1A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationFile - OK - 0x82E9581A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationJobObject - OK - 0x82E3AD44 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationKey - OK - 0x82EDA47D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationObject - OK - 0x82E47390 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationProcess - OK - 0x82E776AD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationResourceManager - OK - 0x82F3294A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationThread - OK - 0x82EA8B6F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationToken - OK - 0x82E427FC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationTransaction - OK - 0x82F3227C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationTransactionManager - OK - 0x82F32F39 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetInformationWorkerFactory - OK - 0x82CEC345 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetIntervalProfile - OK - 0x82F49FAC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetIoCompletion - OK - 0x82E22BF8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetIoCompletionEx - OK - 0x82EF5F76 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetLdtEntries - OK - 0x82F1DE13 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetLowEventPair - OK - 0x82F49536 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetLowWaitHighEventPair - OK - 0x82F49460 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetQuotaInformationFile - OK - 0x82EF7A47 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetSecurityObject - OK - 0x82E406A2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetSystemEnvironmentValue - OK - 0x82F42A23 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetSystemEnvironmentValueEx - OK - 0x82F43035 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetSystemInformation - ssdt hook - 0x8DA831BC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtSetSystemPowerState - ssdt hook - 0x8DA832F8 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtSetSystemTime - OK - 0x82ECEF38 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetThreadExecutionState - OK - 0x82ED5C15 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetTimer - OK - 0x82CC2D52 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetTimerEx - OK - 0x82CD54A2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetTimerResolution - OK - 0x82E2FBB4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetUuidSeed - OK - 0x82DD12DF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetValueKey - OK - 0x82E494A3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSetVolumeInformationFile - OK - 0x82EF7A61 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtShutdownSystem - ssdt hook - 0x8DA832D4 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtShutdownWorkerFactory - OK - 0x82E51A33 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSignalAndWaitForSingleObject - OK - 0x82D0C6DB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSinglePhaseReject - OK - 0x82F315FA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtStartProfile - OK - 0x82F49CE8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtStopProfile - OK - 0x82F49EDF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSuspendProcess - OK - 0x82F1C98F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSuspendThread - OK - 0x82ED3EF5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtSystemDebugControl - ssdt hook - 0x8DA8331C - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtTerminateJobObject - OK - 0x82E313E5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtTerminateProcess - OK - 0x82E99A7D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtTerminateThread - OK - 0x82EB73F4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtTestAlert - OK - 0x82EAEBBA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtThawRegistry - OK - 0x82D1271F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtThawTransactions - OK - 0x82F325B2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtTraceControl - OK - 0x82E8EA79 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtTraceEvent - OK - 0x82D0567A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtTranslateFilePath - OK - 0x82F44F4F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUmsThreadYield - OK - 0x82F08833 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnloadDriver - OK - 0x82EF82B7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnloadKey - OK - 0x82EC75CB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnloadKey2 - OK - 0x82EC75E5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnloadKeyEx - OK - 0x82ED9E23 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnlockFile - OK - 0x82E44F2B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnlockVirtualMemory - OK - 0x82C5BB17 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtUnmapViewOfSection - OK - 0x82EA36FA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtVdmControl - ssdt hook - 0x8DA83428 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtWaitForDebugEvent - OK - 0x82EECFA5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitForKeyedEvent - OK - 0x82E6EEC0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitForMultipleObjects - OK - 0x82E674DF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitForMultipleObjects32 - OK - 0x82F129E8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitForSingleObject - OK - 0x82E66B91 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitForWorkViaWorkerFactory - OK - 0x82CC27B1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitHighEventPair - OK - 0x82F493F7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWaitLowEventPair - OK - 0x82F4938E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWorkerFactoryWorkerReady - OK - 0x82CFB494 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWriteFile - OK - 0x82EADFEB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWriteFileGather - OK - 0x82DDE2FF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWriteRequestData - OK - 0x82F08A0E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtWriteVirtualMemory - OK - 0x82E9E7DA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       NtYieldExecution - OK - 0x82C6A5C5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation

==========================================================================================

Shadow SSDT

       NtGdiAbortDoc - OK - 0x827F6A40 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAbortPath - OK - 0x8280E89E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAddFontResourceW - OK - 0x826671AC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAddRemoteFontToDC - OK - 0x82805977 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAddFontMemResourceEx - OK - 0x8280FFD9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRemoveMergeFont - OK - 0x827F725D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAddRemoteMMInstanceToDC - OK - 0x827F72F1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAlphaBlend - inline hook - 0x8DA871BA - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiAngleArc - OK - 0x8280F80F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAnyLinkedFonts - OK - 0x826D2BF2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFontIsLinked - OK - 0x826D2B0F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiArcInternal - OK - 0x82811B27 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBeginGdiRendering - OK - 0x8280FD00 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBeginPath - OK - 0x8280E912 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBitBlt - OK - 0x8271392B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCancelDC - OK - 0x8280FC53 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCheckBitmapBits - OK - 0x828128CB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCloseFigure - OK - 0x8280E819 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiClearBitmapAttributes - OK - 0x82745B70 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiClearBrushAttributes - OK - 0x8280FD8A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiColorCorrectPalette - OK - 0x828122BF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCombineRgn - OK - 0x826D32EC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCombineTransform - OK - 0x82779E8A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiComputeXformCoefficients - OK - 0x8279E3A0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiConfigureOPMProtectedOutput - OK - 0x828132B7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiConvertMetafileRect - OK - 0x828082DC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateBitmap - OK - 0x82734673 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateBitmapFromDxSurface - OK - 0x8280FCF0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateClientObj - OK - 0x82788FC9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateColorSpace - OK - 0x82812182 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateColorTransform - OK - 0x8281254C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateCompatibleBitmap - OK - 0x8270DF91 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateCompatibleDC - OK - 0x827343FC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateDIBBrush - OK - 0x82774441 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateDIBitmapInternal - OK - 0x826F9D83 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateDIBSection - OK - 0x8271D129 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateEllipticRgn - OK - 0x827FC4D9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateHalftonePalette - OK - 0x8269E20B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateHatchBrushInternal - OK - 0x828136AD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateMetafileDC - OK - 0x8278904E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateOPMProtectedOutputs - OK - 0x8275A4DB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreatePaletteInternal - OK - 0x826D1D0A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreatePatternBrushInternal - OK - 0x826F73F4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreatePen - OK - 0x827A4F2F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateRectRgn - OK - 0x82702173 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateRoundRectRgn - OK - 0x826CFB88 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateServerMetaFile - OK - 0x82814153 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCreateSolidBrush - OK - 0x827373EA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiD3dContextCreate - OK - 0x827F0ADB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiD3dContextDestroy - OK - 0x827F0AEE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiD3dContextDestroyAll - OK - 0x827F0B01 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiD3dValidateTextureStageState - OK - 0x827F0B14 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiD3dDrawPrimitives2 - OK - 0x827F0B27 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetDriverState - OK - 0x827F0B3A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdAddAttachedSurface - OK - 0x827F07BF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdAlphaBlt - OK - 0x827F0C3C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdAttachSurface - OK - 0x827F07D2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdBeginMoCompFrame - OK - 0x827F0BE7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdBlt - OK - 0x827F07E5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCanCreateSurface - OK - 0x827F07F8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCanCreateD3DBuffer - OK - 0x827F0AB2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdColorControl - OK - 0x827F080B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateDirectDrawObject - OK - 0x82778057 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateSurface - OK - 0x827F081E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateD3DBuffer - OK - 0x827F0A9C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateMoComp - OK - 0x827F0BBB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateSurfaceObject - OK - 0x827F0834 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDeleteDirectDrawObject - OK - 0x827F0860 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDeleteSurfaceObject - OK - 0x827F084A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDestroyMoComp - OK - 0x827F0BD1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDestroySurface - OK - 0x827F0876 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDestroyD3DBuffer - OK - 0x827F0AC5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdEndMoCompFrame - OK - 0x827F0BFA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdFlip - OK - 0x827F088C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdFlipToGDISurface - OK - 0x827F093C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetAvailDriverMemory - OK - 0x827F08A2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetBltStatus - OK - 0x827F08B8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetDC - OK - 0x827F08CE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetDriverInfo - OK - 0x827F08E4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetDxHandle - OK - 0x827F0A44 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetFlipStatus - OK - 0x827F08FA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetInternalMoCompInfo - OK - 0x827F0BA5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetMoCompBuffInfo - OK - 0x827F0B8F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetMoCompGuids - OK - 0x827F0B63 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetMoCompFormats - OK - 0x827F0B79 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdGetScanLine - OK - 0x827F0910 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdLock - OK - 0x827F0952 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdLockD3D - OK - 0x827F0A70 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdQueryDirectDrawObject - OK - 0x827F0968 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdQueryMoCompStatus - OK - 0x827F0C26 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdReenableDirectDrawObject - OK - 0x827F097E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdReleaseDC - OK - 0x827F0994 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdRenderMoComp - OK - 0x827F0C10 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdResetVisrgn - OK - 0x827F09AA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdSetColorKey - OK - 0x827F09C0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdSetExclusiveMode - OK - 0x827F0926 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdSetGammaRamp - OK - 0x827F0A5A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateSurfaceEx - OK - 0x827F0B4D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdSetOverlayPosition - OK - 0x827F09D6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdUnattachSurface - OK - 0x827F09EC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdUnlock - OK - 0x827F0A02 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdUnlockD3D - OK - 0x827F0A86 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdUpdateOverlay - OK - 0x827F0A18 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdWaitForVerticalBlank - OK - 0x827F0A2E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpCanCreateVideoPort - OK - 0x827F0C4F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpColorControl - OK - 0x827F0C65 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpCreateVideoPort - OK - 0x827F0C7B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpDestroyVideoPort - OK - 0x827F0C91 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpFlipVideoPort - OK - 0x827F0CA7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortBandwidth - OK - 0x827F0CBD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortField - OK - 0x827F0CD3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortFlipStatus - OK - 0x827F0CE9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortInputFormats - OK - 0x827F0CFF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortLine - OK - 0x827F0D15 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortOutputFormats - OK - 0x827F0D2B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoPortConnectInfo - OK - 0x827F0D41 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpGetVideoSignalStatus - OK - 0x827F0D57 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpUpdateVideoPort - OK - 0x827F0D6D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpWaitForVideoPortSync - OK - 0x827F0D83 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpAcquireNotification - OK - 0x827F0D99 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDvpReleaseNotification - OK - 0x827F0DAF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDxgGenericThunk - OK - 0x827F07AC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDeleteClientObj - OK - 0x8279634F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDeleteColorSpace - OK - 0x82812152 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDeleteColorTransform - OK - 0x828127E8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDeleteObjectApp - inline hook - 0x8DA86D54 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiDescribePixelFormat - OK - 0x82810B8D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDestroyOPMProtectedOutput - OK - 0x8275B20E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetPerBandInfo - OK - 0x827F6F29 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDoBanding - OK - 0x827F6E04 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDoPalette - OK - 0x82703AE0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDrawEscape - OK - 0x8280F859 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEllipse - OK - 0x82814BDA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEnableEudc - OK - 0x826664EB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEndDoc - OK - 0x827F6A28 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEndGdiRendering - OK - 0x8280FD10 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEndPage - OK - 0x827F6B49 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEndPath - OK - 0x8280E9C4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEnumFonts - OK - 0x826D7AE2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEnumObjects - OK - 0x82816BA7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEqualRgn - OK - 0x8279FF1E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEudcLoadUnloadLink - OK - 0x8281695C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExcludeClipRect - OK - 0x826D43D5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtCreatePen - OK - 0x82772FE4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtCreateRegion - OK - 0x826A1604 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtEscape - OK - 0x8278AEB7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtFloodFill - OK - 0x82794854 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtGetObjectW - OK - 0x82717C31 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtSelectClipRgn - OK - 0x82711CE8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiExtTextOutW - OK - 0x8271FC18 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFillPath - OK - 0x8280ECAF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFillRgn - OK - 0x8279D448 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFlattenPath - OK - 0x8280EA21 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFlush - OK - 0x82728A35 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiForceUFIMapping - OK - 0x82810B22 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFrameRgn - OK - 0x827A3CDA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFullscreenControl - OK - 0x8280142D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetAndSetDCDword - OK - 0x82791800 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetAppClipBox - OK - 0x827214B5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetBitmapBits - OK - 0x826A69A3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetBitmapDimension - OK - 0x82810A5E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetBoundsRect - OK - 0x826B80AC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCertificate - OK - 0x8275A56C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCertificateSize - OK - 0x8275A766 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCharABCWidthsW - OK - 0x826E5763 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCharacterPlacementW - OK - 0x8280F1D7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCharSet - OK - 0x827108B7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCharWidthW - OK - 0x8278657E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCharWidthInfo - OK - 0x8269D66F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetColorAdjustment - OK - 0x8280FADF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetColorSpaceforBitmap - OK - 0x828170D8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetCOPPCompatibleOPMInformation - OK - 0x82813251 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDCDword - OK - 0x82711433 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDCforBitmap - OK - 0x826D80D1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDCObject - OK - 0x82717B46 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDCPoint - OK - 0x8279ED9A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDeviceCaps - OK - 0x8271D0B6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDeviceGammaRamp - OK - 0x82812A36 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDeviceCapsAll - OK - 0x827813EC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDIBitsInternal - OK - 0x82701EB5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetETM - OK - 0x82817EB1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetEudcTimeStampEx - OK - 0x82815DDB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetFontData - OK - 0x826D275E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetFontFileData - OK - 0x828187FF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetFontFileInfo - OK - 0x82748C08 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetFontResourceInfoInternalW - OK - 0x82810284 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetGlyphIndicesW - OK - 0x826CE31E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetGlyphIndicesWInternal - OK - 0x826CE1C2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetGlyphOutline - OK - 0x8280F946 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetOPMInformation - OK - 0x8275A169 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetKerningPairs - OK - 0x82789A7D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetLinkedUFIs - OK - 0x827F6FE0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetMiterLimit - OK - 0x827743E0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetMonitorID - OK - 0x82773923 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetNearestColor - OK - 0x826CFCEB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetNearestPaletteIndex - OK - 0x82789B25 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetObjectBitmapHandle - OK - 0x82774725 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetOPMRandomNumber - OK - 0x8275BBBE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetOutlineTextMetricsInternalW - OK - 0x826D25A1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetPath - OK - 0x8280F02D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetPixel - inline hook - 0x8DA86D7E - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiGetRandomRgn - OK - 0x8271E97D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetRasterizerCaps - OK - 0x8280FA5B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetRealizationInfo - OK - 0x826CE113 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetRegionData - OK - 0x826D3040 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetRgnBox - OK - 0x826C7690 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetServerMetaFileBits - OK - 0x82814253 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       DxgStubContextCreate - OK - 0x82810B83 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetStats - OK - 0x828189E2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetStockObject - OK - 0x8273256F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetStringBitmapW - OK - 0x82816AB3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetSuggestedOPMProtectedOutputArraySize - OK - 0x827595C9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetSystemPaletteUse - OK - 0x827771F6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetTextCharsetInfo - OK - 0x826B559A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetTextExtent - OK - 0x8280FDCA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetTextExtentExW - OK - 0x826B4AA0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetTextFaceW - OK - 0x826D71E7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetTextMetricsW - OK - 0x826D716E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetTransform - OK - 0x826A2780 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetUFI - OK - 0x828104C0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetEmbUFI - OK - 0x8281059E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetUFIPathname - OK - 0x82810698 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetEmbedFonts - OK - 0x8281044B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiChangeGhostFont - OK - 0x82810455 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiAddEmbFontToDC - OK - 0x827F5ABE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetFontUnicodeRanges - OK - 0x827633CA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetWidthTable - OK - 0x826CF1CC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGradientFill - OK - 0x8279EDF0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiHfontCreate - OK - 0x826E3361 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiIcmBrushInfo - OK - 0x82812D33 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       IsIMMEnabledSystem - OK - 0x82730696 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiInitSpool - OK - 0x827FE570 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiIntersectClipRect - OK - 0x8271049C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiInvertRgn - OK - 0x8278E8AE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiLineTo - OK - 0x827980CD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiMakeFontDir - OK - 0x82810C18 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiMakeInfoDC - OK - 0x82817209 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiMaskBlt - inline hook - 0x8DA86FB2 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiModifyWorldTransform - OK - 0x826A266F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiMonoBitmap - OK - 0x827746E5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiMoveTo - OK - 0x8280FC83 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiOffsetClipRgn - OK - 0x827FC609 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiOffsetRgn - OK - 0x826BC8DD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiOpenDCW - inline hook - 0x8DA86D0A - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiPatBlt - OK - 0x826B0F95 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPolyPatBlt - OK - 0x8273FCC2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPathToRegion - OK - 0x8280ED72 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPlgBlt - inline hook - 0x8DA87070 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiPolyDraw - OK - 0x8280F719 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPolyPolyDraw - OK - 0x82798C65 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPolyTextOutW - OK - 0x8273DA85 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPtInRegion - OK - 0x8276C54D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPtVisible - OK - 0x827FC763 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiQueryFonts - OK - 0x8280FEF9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiQueryFontAssocInfo - OK - 0x8273257F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRectangle - OK - 0x827A8FAA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRectInRegion - OK - 0x8276C486 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRectVisible - OK - 0x826DAACC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRemoveFontResourceW - OK - 0x828100D7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRemoveFontMemResourceEx - OK - 0x82810268 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiResetDC - OK - 0x82790996 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiResizePalette - OK - 0x82813D37 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRestoreDC - OK - 0x826CD929 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiRoundRect - OK - 0x8279658D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSaveDC - OK - 0x826CD4D0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiScaleViewportExtEx - OK - 0x82808087 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiScaleWindowExtEx - OK - 0x828109FB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       GreSelectBitmap - OK - 0x82734547 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSelectBrush - OK - 0x8280FC63 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSelectClipPath - OK - 0x8280EBBF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSelectFont - OK - 0x827108C7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSelectPen - OK - 0x8280FC73 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetBitmapAttributes - OK - 0x82670103 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetBitmapBits - OK - 0x826A3FBE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetBitmapDimension - OK - 0x82810ABB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetBoundsRect - OK - 0x826B5E1C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetBrushAttributes - OK - 0x8280FD6A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetBrushOrg - OK - 0x82784B8B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetColorAdjustment - OK - 0x8280FB35 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetColorSpace - OK - 0x82812415 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetDeviceGammaRamp - OK - 0x82812ABD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetDIBitsToDeviceInternal - OK - 0x826F3B88 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetFontEnumeration - OK - 0x826D806F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetFontXform - OK - 0x8277DCC9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetIcmMode - OK - 0x8278992A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetLinkedUFIs - OK - 0x827F644A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetMagicColors - OK - 0x82746C44 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetMetaRgn - OK - 0x827781BA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetMiterLimit - OK - 0x8277DBE4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDeviceWidth - OK - 0x828109EB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiMirrorWindowOrg - OK - 0x828109DB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetLayout - OK - 0x8269B4DC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetOPMSigningKeyAndSequenceNumbers - OK - 0x8275BCBD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetPixel - OK - 0x827AC57C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetPixelFormat - OK - 0x8281971C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetRectRgn - OK - 0x8280FDBA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetSystemPaletteUse - OK - 0x8280FCE0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetTextJustification - OK - 0x82818E9B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetVirtualResolution - OK - 0x82779E01 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetSizeDevice - OK - 0x8277DB8E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiStartDoc - OK - 0x827F6559 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiStartPage - OK - 0x827F6A58 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiStretchBlt - inline hook - 0x8DA86EFA - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtGdiStretchDIBitsInternal - OK - 0x82703D90 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiStrokeAndFillPath - OK - 0x8280EE57 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiStrokePath - OK - 0x8280EF54 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSwapBuffers - OK - 0x828198F1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiTransformPoints - OK - 0x826A1F75 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiTransparentBlt - inline hook - 0x8DA87118 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       DxgStubEnableDirectDrawRedirection - OK - 0x82760D07 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiUnmapMemFont - OK - 0x8281A10C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiUnrealizeObject - OK - 0x8280FDAA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiUpdateColors - OK - 0x82813F9A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiWidenPath - OK - 0x8280EAAC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserActivateKeyboardLayout - OK - 0x826AA693 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserAddClipboardFormatListener - OK - 0x827C0E8E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserAlterWindowStyle - OK - 0x827BDDBA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserAssociateInputContext - OK - 0x826D3288 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserAttachThreadInput - OK - 0x827AF32E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserBeginPaint - OK - 0x8270D91B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserBitBltSysBmp - OK - 0x827933EE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserBlockInput - inline hook - 0x8DA861AE - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserBuildHimcList - OK - 0x8270ABF3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserBuildHwndList - OK - 0x826F85A3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserBuildNameList - inline hook - 0x8DA864CC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserBuildPropList - OK - 0x827BE0C1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallHwnd - OK - 0x82681126 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallHwndLock - OK - 0x82707CA2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallHwndOpt - OK - 0x826707B6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallHwndParam - OK - 0x826D8FA5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallHwndParamLock - inline hook - 0x8DA860DA - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserCallMsgFilter - OK - 0x827A42CE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallNextHookEx - OK - 0x82789F83 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallNoParam - OK - 0x82733C2A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallOneParam - OK - 0x82733BD5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCallTwoParam - OK - 0x826F9CCF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserChangeClipboardChain - OK - 0x827934B3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserChangeDisplaySettings - OK - 0x82771035 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetDisplayConfigBufferSizes - OK - 0x82690E26 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetDisplayConfig - OK - 0x827BE5D8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserQueryDisplayConfig - OK - 0x826855DF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDisplayConfigGetDeviceInfo - OK - 0x82748D83 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDisplayConfigSetDeviceInfo - OK - 0x827BE8E6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCheckAccessForIntegrityLevel - OK - 0x827C11AE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCheckDesktopByThreadId - OK - 0x826A16DF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCheckWindowThreadDesktop - OK - 0x827BDE5F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCheckMenuItem - OK - 0x82760D31 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserChildWindowFromPointEx - OK - 0x82786C75 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserClipCursor - OK - 0x8274F2F4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCloseClipboard - OK - 0x8279E266 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCloseDesktop - OK - 0x826F086E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCloseWindowStation - OK - 0x826DDE66 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserConsoleControl - OK - 0x8273D6EC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserConvertMemHandle - OK - 0x827530EE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCopyAcceleratorTable - OK - 0x82798A4A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCountClipboardFormats - OK - 0x827A675D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateAcceleratorTable - OK - 0x826A4E45 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateCaret - OK - 0x827A47CF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateDesktopEx - OK - 0x8267E25E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateInputContext - OK - 0x8277A20C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateLocalMemHandle - OK - 0x82754EF4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateWindowEx - OK - 0x8270132C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCreateWindowStation - OK - 0x82668E2D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDdeInitialize - OK - 0x826950E4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDeferWindowPos - OK - 0x826AE305 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDefSetText - OK - 0x827901D0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDeleteMenu - OK - 0x82709AEF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDestroyAcceleratorTable - OK - 0x827A0D52 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDestroyCursor - OK - 0x826B2A41 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDestroyInputContext - OK - 0x82791DAC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDestroyMenu - OK - 0x826A2F11 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDestroyWindow - inline hook - 0x8DA8614A - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserDisableThreadIme - OK - 0x826A032F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDispatchMessage - OK - 0x827104AC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDoSoundConnect - OK - 0x82666157 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDoSoundDisconnect - OK - 0x82747855 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDragDetect - OK - 0x827BE1BB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDragObject - OK - 0x827BC902 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDrawAnimatedRects - OK - 0x827BD3BC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDrawCaption - OK - 0x827BD47F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDrawCaptionTemp - OK - 0x827BEAFC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDrawIconEx - OK - 0x826DE87D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDrawMenuBarTemp - OK - 0x827BEA2B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEmptyClipboard - OK - 0x82753208 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEnableMenuItem - OK - 0x8277A25B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEnableScrollBar - OK - 0x8277DEB1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEndDeferWindowPosEx - OK - 0x826AE2A8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEndMenu - OK - 0x826AAACF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEndPaint - OK - 0x8271F824 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEnumDisplayDevices - OK - 0x8270295A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEnumDisplayMonitors - OK - 0x826F2F64 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEnumDisplaySettings - OK - 0x826E5F5A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEvent - OK - 0x827BCA64 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserExcludeUpdateRgn - OK - 0x8278EBFD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserFillWindow - OK - 0x8279ECB1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserFindExistingCursorIcon - OK - 0x826E8314 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserFindWindowEx - OK - 0x826DD35B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserFlashWindowEx - OK - 0x8278CF72 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserFrostCrashedWindow - OK - 0x827C1159 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetAltTabInfo - OK - 0x827BCF0E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetAncestor - OK - 0x826DBE92 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetAppImeLevel - OK - 0x827BFBD0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetAsyncKeyState - OK - 0x826BC69E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetAtomName - OK - 0x826F6D89 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetCaretBlinkTime - OK - 0x826E4B5C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetCaretPos - OK - 0x8279A005 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClassInfoEx - OK - 0x826EE313 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClassName - OK - 0x826D6148 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClipboardData - inline hook - 0x8DA8628E - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserGetClipboardFormatName - OK - 0x82771EC1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClipboardOwner - OK - 0x8279E2E7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClipboardSequenceNumber - OK - 0x8279E2C1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClipboardViewer - OK - 0x827BD5CC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetClipCursor - OK - 0x827BD261 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetComboBoxInfo - OK - 0x82798B99 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetControlBrush - OK - 0x827721C0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetControlColor - OK - 0x827BD528 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetCPD - OK - 0x826A96DF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetCursorFrameInfo - OK - 0x82790E40 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetCursorInfo - OK - 0x827BCDD5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetDC - OK - 0x8271CFAC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetDCEx - OK - 0x826D440C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetDoubleClickTime - OK - 0x826B0A02 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetForegroundWindow - OK - 0x826F2F25 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetGuiResources - OK - 0x827C1F56 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetGUIThreadInfo - OK - 0x826F7992 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetIconInfo - OK - 0x826DE3B1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetIconSize - OK - 0x82704C67 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetImeHotKey - OK - 0x827BFAA0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetImeInfoEx - OK - 0x826CB7AB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetInputLocaleInfo - OK - 0x827BE4DE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetInternalWindowPos - OK - 0x827BCB72 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetKeyboardLayoutList - OK - 0x826A3150 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetKeyboardLayoutName - OK - 0x827BE3F1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetKeyboardState - OK - 0x827B4D41 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetKeyNameText - OK - 0x827BE378 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetKeyState - OK - 0x826D6443 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetListBoxInfo - OK - 0x827BCD7D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetMenuBarInfo - OK - 0x827BA7E7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetMenuIndex - OK - 0x827BD2EB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetMenuItemRect - OK - 0x82750BF8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetMessage - OK - 0x8272AB07 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetMouseMovePointsEx - OK - 0x827BDA21 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetObjectInformation - OK - 0x826DD66E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetOpenClipboardWindow - OK - 0x827A74A8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetPriorityClipboardFormat - OK - 0x827BD5F8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetProcessWindowStation - OK - 0x826E7862 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetRawInputBuffer - OK - 0x827C0A0D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetRawInputData - OK - 0x827C0443 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetRawInputDeviceInfo - OK - 0x827C05CD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetRawInputDeviceList - OK - 0x827C08AD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetRegisteredRawInputDevices - OK - 0x827C09D2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetScrollBarInfo - OK - 0x8272103E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetSystemMenu - OK - 0x82709916 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetThreadDesktop - OK - 0x827372D0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetThreadState - OK - 0x8270B067 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetTitleBarInfo - OK - 0x827108D7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetTopLevelWindow - OK - 0x827BD117 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetUpdatedClipboardFormats - OK - 0x827C0FD9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetUpdateRect - OK - 0x826C7F33 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetUpdateRgn - OK - 0x82791E78 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowCompositionInfo - OK - 0x826D02D7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowCompositionAttribute - OK - 0x82709FDC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowDC - OK - 0x827131CE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowDisplayAffinity - OK - 0x827BD157 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowPlacement - OK - 0x827B284B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWOWClass - OK - 0x827BCAE9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGhostWindowFromHungWindow - OK - 0x826B7AC0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserHardErrorControl - OK - 0x827C1CA7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserHideCaret - OK - 0x826A25BF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserHiliteMenuItem - OK - 0x827BD67B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserHungWindowFromGhostWindow - OK - 0x8276533A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserImpersonateDdeClientWindow - OK - 0x827BE30B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInitialize - OK - 0x82672FAC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInitializeClientPfnArrays - OK - 0x8267B66D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInitTask - OK - 0x827BCC44 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInternalGetWindowText - OK - 0x827125FA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInternalGetWindowIcon - OK - 0x82766D62 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInvalidateRect - OK - 0x8271E8B2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInvalidateRgn - OK - 0x826AA0B8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserIsClipboardFormatAvailable - OK - 0x8279E285 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserIsTopLevelWindow - OK - 0x826C76E5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserKillTimer - OK - 0x8271FAA9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserLoadKeyboardLayoutEx - OK - 0x8266A147 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserLockWindowStation - OK - 0x8267E9E1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserLockWindowUpdate - OK - 0x82760527 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserLockWorkStation - OK - 0x82748388 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserLogicalToPhysicalPoint - OK - 0x827BA2BE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMapVirtualKeyEx - OK - 0x827B7C28 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMenuItemFromPoint - OK - 0x827BDC77 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMessageCall - OK - 0x8271C4A4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMinMaximize - OK - 0x827BD726 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMNDragLeave - OK - 0x827BD84C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMNDragOver - OK - 0x827BD7B4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserModifyUserStartupInfoFlags - OK - 0x827BDD78 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMoveWindow - OK - 0x826A10C9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserNotifyIMEStatus - OK - 0x826D2E76 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserNotifyProcessCreate - OK - 0x82737E94 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserNotifyWinEvent - OK - 0x826F2E98 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserOpenClipboard - OK - 0x8279E1D1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserOpenDesktop - inline hook - 0x8DA86326 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserOpenInputDesktop - OK - 0x82695295 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserOpenThreadDesktop - OK - 0x827BDE0A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserOpenWindowStation - OK - 0x826DDF08 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPaintDesktop - OK - 0x826919E2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPaintMonitor - OK - 0x826921CA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPeekMessage - OK - 0x8271C40F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPhysicalToLogicalPoint - OK - 0x827B1F5C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPostMessage - OK - 0x8271CCC9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPostThreadMessage - OK - 0x826EDCD0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPrintWindow - OK - 0x827C03B5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserProcessConnect - OK - 0x827376D1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserQueryInformationThread - OK - 0x82747413 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserQueryInputContext - OK - 0x826D2B6B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserQuerySendMessage - OK - 0x827BE267 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserQueryWindow - OK - 0x8271D5C6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRealChildWindowFromPoint - OK - 0x827BCED0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRealInternalGetMessage - OK - 0x8271D42F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRealWaitMessageEx - OK - 0x827BDBB7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRedrawWindow - OK - 0x826F78B6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterClassExWOW - OK - 0x826ED87E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterErrorReportingDialog - OK - 0x827C1122 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterUserApiHook - OK - 0x82670123 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterHotKey - OK - 0x826BC8ED - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterRawInputDevices - inline hook - 0x8DA865E6 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserRegisterServicesProcess - OK - 0x826613E5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterTasklist - OK - 0x827BCD49 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterWindowMessage - OK - 0x826DADAD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoveClipboardFormatListener - OK - 0x827C0F6F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoveMenu - OK - 0x826A71EF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoveProp - OK - 0x827207E8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserResolveDesktopForWOW - OK - 0x827C1E2D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSBGetParms - OK - 0x8272110D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserScrollDC - OK - 0x8273EC40 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserScrollWindowEx - OK - 0x827A1719 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSelectPalette - OK - 0x826D80A5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSendInput - inline hook - 0x8DA861E4 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserSetActiveWindow - OK - 0x826D58C2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetAppImeLevel - OK - 0x827BFB6A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetCapture - OK - 0x827B2570 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetChildWindowNoActivate - OK - 0x82666740 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetClassLong - OK - 0x8269A409 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetClassWord - OK - 0x827BD869 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetClipboardData - OK - 0x82753158 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetClipboardViewer - inline hook - 0x8DA86254 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserSetCursor - OK - 0x826D5803 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetCursorContents - OK - 0x827BDC30 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetCursorIconData - OK - 0x826FA733 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetFocus - OK - 0x826B6B4F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetImeHotKey - OK - 0x82669F9E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetImeInfoEx - OK - 0x8266FFC9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetImeOwnerWindow - OK - 0x826D2C26 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetInformationThread - OK - 0x826B4053 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetInternalWindowPos - OK - 0x827BD027 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetKeyboardState - OK - 0x827B5853 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetMenu - OK - 0x827ABA2E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetMenuContextHelpId - OK - 0x827BD34B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetMenuDefaultItem - OK - 0x826A7270 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetMenuFlagRtoL - OK - 0x827BD388 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetObjectInformation - OK - 0x827C1D6C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetParent - OK - 0x826A4F7F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetProcessWindowStation - OK - 0x826DD5E8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetProp - OK - 0x827153D5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetProp - OK - 0x8271F9ED - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetScrollInfo - OK - 0x82720CF8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetShellWindowEx - OK - 0x82670839 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetSysColors - inline hook - 0x8DA86096 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserSetSystemCursor - OK - 0x827BDBF7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetSystemMenu - OK - 0x82792FF5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetSystemTimer - OK - 0x827BE219 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetThreadDesktop - OK - 0x826DD26F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetThreadLayoutHandles - OK - 0x827BFC38 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetThreadState - OK - 0x82799104 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetTimer - OK - 0x8270C1A3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetProcessDPIAware - OK - 0x8273D4CA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowCompositionAttribute - OK - 0x826B9DC3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowDisplayAffinity - OK - 0x827BD1E8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowFNID - OK - 0x826EE4EF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowLong - OK - 0x82715372 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowPlacement - OK - 0x826A6FDB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowPos - OK - 0x826F0387 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowRgn - OK - 0x826A66E2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowRgnEx - OK - 0x826D3C9E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowRgnEx - OK - 0x82793B95 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowsHookAW - OK - 0x827BD8A5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowsHookEx - inline hook - 0x8DA85FFE - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserSetWindowStationUser - OK - 0x8266924F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWindowWord - OK - 0x8277A2D3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetWinEventHook - inline hook - 0x8DA85F32 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserShowCaret - OK - 0x826A2585 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserShowScrollBar - OK - 0x827992B6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserShowWindow - OK - 0x827038F6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserShowWindowAsync - OK - 0x827BD8D1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSoundSentry - OK - 0x82763479 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSwitchDesktop - inline hook - 0x8DA864BC - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserSystemParametersInfo - inline hook - 0x8DA86016 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       NtUserTestForInteractiveUser - OK - 0x827BDD15 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserThunkedMenuInfo - OK - 0x827A668D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserThunkedMenuItemInfo - OK - 0x82709114 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserToUnicodeEx - OK - 0x8274F4EF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserTrackMouseEvent - OK - 0x826E6AC3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserTrackPopupMenuEx - OK - 0x827A069E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCalculatePopupWindowPosition - OK - 0x827483F9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCalcMenuBar - OK - 0x82710A0A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserPaintMenuBar - OK - 0x827BB539 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserTranslateAccelerator - OK - 0x827ACD66 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserTranslateMessage - OK - 0x827B733D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnhookWindowsHookEx - OK - 0x826B20E2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnhookWinEvent - OK - 0x8270AD58 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnloadKeyboardLayout - OK - 0x827BE18D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnlockWindowStation - OK - 0x82680BB3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnregisterClass - OK - 0x826F71BF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnregisterUserApiHook - OK - 0x826700E6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnregisterHotKey - OK - 0x827B5E2F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUpdateInputContext - OK - 0x826E308E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUpdateInstance - OK - 0x827BC9DD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUpdateLayeredWindow - OK - 0x826C78B2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetLayeredWindowAttributes - OK - 0x827C02DF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetLayeredWindowAttributes - OK - 0x826AFCF2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUpdatePerUserSystemParameters - OK - 0x8266A946 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUserHandleGrantAccess - OK - 0x827BDECF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserValidateHandleSecure - OK - 0x827980A5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserValidateRect - OK - 0x8278A452 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserValidateTimerCallback - OK - 0x8272286F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserVkKeyScanEx - OK - 0x82793A1C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserWaitForInputIdle - OK - 0x8278D060 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserWaitForMsgAndEvent - OK - 0x827BC8DA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserWaitMessage - OK - 0x82721A3D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserWindowFromPhysicalPoint - OK - 0x827AE3EB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserWindowFromPoint - OK - 0x827AC522 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserYieldTask - OK - 0x827BDAED - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoteConnect - OK - 0x8267D13F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoteRedrawRectangle - OK - 0x827BC7F1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoteRedrawScreen - OK - 0x827BC848 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRemoteStopScreenUpdates - OK - 0x827BC898 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserCtxDisplayIOCtl - OK - 0x827C1BD3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserRegisterSessionPort - OK - 0x826665A7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUnregisterSessionPort - OK - 0x827C0C82 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserUpdateWindowTransform - OK - 0x827C01EC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDwmStartRedirection - OK - 0x8268206A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserDwmStopRedirection - OK - 0x8276C55D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetWindowMinimizeRect - OK - 0x826B57B5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxBindSwapChain - OK - 0x8275A80B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxOpenSwapChain - OK - 0x8275B816 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxReleaseSwapChain - OK - 0x8275AB30 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxSetSwapChainBindingStatus - OK - 0x8275ADF7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxQuerySwapChainBindingStatus - OK - 0x8275BA8A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxReportPendingBindingsToDwm - OK - 0x8268324D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxGetSwapChainStats - OK - 0x8275A2A8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDxSetSwapChainStats - OK - 0x8272A49C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmGetLogicalSurfaceBinding - OK - 0x827C0CBD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSfmDestroyLogicalSurfaceBinding - OK - 0x827C0E06 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserModifyWindowTouchCapability - OK - 0x827C12AA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserIsTouchWindow - OK - 0x827C1311 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSendTouchInput - OK - 0x827C139D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserEndTouchOperation - OK - 0x827C14E1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetTouchInputInfo - OK - 0x827C1572 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserChangeWindowMessageFilterEx - OK - 0x826F7689 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserInjectGesture - OK - 0x827C1653 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetGestureInfo - OK - 0x827C181F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetGestureExtArgs - OK - 0x827C18E4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserManageGestureHandlerWindow - OK - 0x827C19BE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetGestureConfig - OK - 0x8267E619 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserGetGestureConfig - OK - 0x827C1A40 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngAssociateSurface - OK - 0x8281A98C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCreateBitmap - OK - 0x8281AA9D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCreateDeviceSurface - OK - 0x8281A117 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCreateDeviceBitmap - OK - 0x8281A187 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCreatePalette - OK - 0x82791421 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngComputeGlyphSet - OK - 0x8281E451 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCopyBits - OK - 0x8281B4D8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngDeletePalette - OK - 0x827892D6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngDeleteSurface - OK - 0x8281AA21 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngEraseSurface - OK - 0x8281ACA4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngUnlockSurface - OK - 0x8281AC71 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngLockSurface - OK - 0x8281AC3A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngBitBlt - OK - 0x8281BDAF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngStretchBlt - OK - 0x8281B66D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngPlgBlt - OK - 0x8281BBCF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngMarkBandingSurface - OK - 0x8281AA4E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngStrokePath - OK - 0x8281C06E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngFillPath - OK - 0x8281C256 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngStrokeAndFillPath - OK - 0x8281C3B3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngPaint - OK - 0x8281C59B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngLineTo - OK - 0x8281C6AF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngAlphaBlend - OK - 0x8281C7D2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngGradientFill - OK - 0x8281C93D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngTransparentBlt - OK - 0x8281CB73 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngTextOut - OK - 0x8281CCCB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngStretchBltROP - OK - 0x8281B8DA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiXLATEOBJ_cGetPalette - OK - 0x8281E352 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiXLATEOBJ_iXlate - OK - 0x8281E406 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiXLATEOBJ_hGetColorTransform - OK - 0x8281E30B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCLIPOBJ_bEnum - OK - 0x8281CF29 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCLIPOBJ_cEnumStart - OK - 0x8281CEA2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiCLIPOBJ_ppoGetPath - OK - 0x8281ADA6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngDeletePath - OK - 0x8281ADDD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCreateClip - OK - 0x8281AE10 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngDeleteClip - OK - 0x8281AE3B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBRUSHOBJ_ulGetBrushColor - OK - 0x8281D0A1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBRUSHOBJ_pvAllocRbrush - OK - 0x8281D010 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBRUSHOBJ_pvGetRbrush - OK - 0x8281D05A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBRUSHOBJ_hGetColorTransform - OK - 0x8281D181 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiXFORMOBJ_bApplyXform - OK - 0x8281D1C8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiXFORMOBJ_iGetXform - OK - 0x8281D31E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_vGetInfo - OK - 0x8281D3C7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_pxoGetXform - OK - 0x8281AE6E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_cGetGlyphs - OK - 0x8281D4B5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_pifi - OK - 0x8281D91A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_pfdg - OK - 0x8281D72F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_pQueryGlyphAttrs - OK - 0x8281D81C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_pvTrueTypeFontFile - OK - 0x8281E23E - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiFONTOBJ_cGetAllGlyphHandles - OK - 0x8281D663 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSTROBJ_bEnum - OK - 0x8281DB3A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSTROBJ_bEnumPositionsOnly - OK - 0x8281DB58 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSTROBJ_bGetAdvanceWidths - OK - 0x8281DB76 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSTROBJ_vEnumStart - OK - 0x8281DC50 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSTROBJ_dwGetCodePage - OK - 0x8281DC8D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPATHOBJ_vGetBounds - OK - 0x8281DD70 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPATHOBJ_bEnum - OK - 0x8281DDF2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPATHOBJ_vEnumStart - OK - 0x8281DF46 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPATHOBJ_vEnumStartClipLines - OK - 0x8281DFB3 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiPATHOBJ_bEnumClipLines - OK - 0x8281E0C6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetDhpdev - OK - 0x8281AEA5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiEngCheckAbort - OK - 0x8281AEDB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiHT_Get8BPPFormatPalette - OK - 0x8281AF3D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiHT_Get8BPPMaskPalette - OK - 0x8281AFC8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiUpdateTransform - OK - 0x828082A1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSetPUMPDOBJ - OK - 0x82791BCA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiBRUSHOBJ_DeleteRbrush - OK - 0x8281DCD4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiUnmapMemFont - OK - 0x8281A10C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDrawStream - OK - 0x82711DDD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiSfmGetNotificationTokens - OK - 0x82729493 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiHLSurfGetInformation - OK - 0x826F7D69 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiHLSurfSetInformation - OK - 0x826E6870 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateAllocation - OK - 0x826F0AA7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIQueryResourceInfo - OK - 0x8270A43B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIOpenResource - OK - 0x8270A45A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroyAllocation - OK - 0x8270A8B0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetAllocationPriority - OK - 0x827718C6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIQueryAllocationResidency - OK - 0x82798868 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateDevice - OK - 0x82693513 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroyDevice - OK - 0x827713C6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateContext - OK - 0x826934F4 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroyContext - OK - 0x82771C3A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateSynchronizationObject - OK - 0x8275BB4C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIOpenSynchronizationObject - OK - 0x827F0F90 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroySynchronizationObject - OK - 0x8275B262 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIWaitForSynchronizationObject - OK - 0x827595AA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISignalSynchronizationObject - OK - 0x8275958B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetRuntimeData - OK - 0x827F0FAF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIQueryAdapterInfo - OK - 0x826934D5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDILock - OK - 0x82709DE6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIUnlock - OK - 0x82709E05 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetDisplayModeList - OK - 0x82771B50 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetDisplayMode - OK - 0x82691BDE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetMultisampleMethodList - OK - 0x827F0FCE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIPresent - OK - 0x8272AD27 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIRender - OK - 0x8272A2A8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIOpenAdapterFromDeviceName - OK - 0x82681AB1 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIOpenAdapterFromHdc - OK - 0x82693301 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICloseAdapter - OK - 0x8269327A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetSharedPrimaryHandle - OK - 0x8276C76B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIEscape - OK - 0x82693532 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIQueryStatistics - OK - 0x827F0FED - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetVidPnSourceOwner - OK - 0x82691209 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetPresentHistory - OK - 0x8272930B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetPresentQueueEvent - OK - 0x82691360 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateOverlay - OK - 0x827F100C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIUpdateOverlay - OK - 0x827F102B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIFlipOverlay - OK - 0x827F104A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroyOverlay - OK - 0x827F1069 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIWaitForVerticalBlankEvent - OK - 0x8272A2C7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetGammaRamp - OK - 0x827F1088 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetDeviceState - OK - 0x8272953F - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateDCFromMemory - OK - 0x8274C324 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroyDCFromMemory - OK - 0x8274F1CE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetContextSchedulingPriority - OK - 0x82771E68 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetContextSchedulingPriority - OK - 0x827F10A7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetProcessSchedulingPriorityClass - OK - 0x8268159C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetProcessSchedulingPriorityClass - OK - 0x827F10C6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIReleaseProcessVidPnSourceOwners - OK - 0x827F10E5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetScanLine - OK - 0x8275A1CF - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetQueuedLimit - OK - 0x827597FE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIPollDisplayChildren - OK - 0x827F111D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIInvalidateActiveVidPn - OK - 0x827F113C - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICheckOcclusion - OK - 0x827F115B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIWaitForIdle - OK - 0x827F117A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICheckMonitorPowerState - OK - 0x8272A2E6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICheckExclusiveOwnership - OK - 0x827597EB - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISetDisplayPrivateDriverFormat - OK - 0x827F1199 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISharedPrimaryLockNotification - OK - 0x827F2333 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDISharedPrimaryUnLockNotification - OK - 0x827F23A2 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICreateKeyedMutex - OK - 0x827F11B8 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIOpenKeyedMutex - OK - 0x827F11D7 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIDestroyKeyedMutex - OK - 0x827F11F6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIAcquireKeyedMutex - OK - 0x827F1215 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIReleaseKeyedMutex - OK - 0x827F1234 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIConfigureSharedResource - OK - 0x8275BD4B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDIGetOverlayState - OK - 0x827F1253 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICheckVidPnExclusiveOwnership - OK - 0x82723388 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDDICheckSharedResourceAccess - OK - 0x8275BA50 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       DxgStubEnableDirectDrawRedirection - OK - 0x82760D07 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       DxgStubDeleteDirectDrawObject - OK - 0x8277804D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetNumberOfPhysicalMonitors - OK - 0x8281E7EE - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetPhysicalMonitors - OK - 0x8281E81D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiGetPhysicalMonitorDescription - OK - 0x8281F1C6 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       DestroyPhysicalMonitor - OK - 0x8281F4DA - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDDCCIGetVCPFeature - OK - 0x8281F26B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDDCCISetVCPFeature - OK - 0x8281F2FD - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDDCCISaveCurrentSettings - OK - 0x8281F313 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDDCCIGetCapabilitiesStringLength - OK - 0x8281F67D - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDDCCIGetCapabilitiesString - OK - 0x8281F6DC - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDDCCIGetTimingReport - OK - 0x8281F329 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdCreateFullscreenSprite - OK - 0x827F1490 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdNotifyFullscreenSpriteUpdate - OK - 0x827F14A0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdDestroyFullscreenSprite - OK - 0x827F14B0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtGdiDdQueryVisRgnUniqueness - OK - 0x827F14C0 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserSetMirrorRendering - OK - 0x827BD954 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserShowSystemCursor - OK - 0x827BD9D9 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMagControl - OK - 0x82774F9B - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMagSetContextInformation - OK - 0x8277500A - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserMagGetContextInformation - OK - 0x82774793 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserHwndQueryRedirectionInfo - OK - 0x827713E5 - C:\Windows\System32\win32k.sys - Microsoft Corporation
       NtUserHwndSetRedirectionInfo - OK - 0x82763F18 - C:\Windows\System32\win32k.sys - Microsoft Corporation

==========================================================================================

FSD

       (Fastfat)IRP_MJ_CREATE - OK - 0x97A9D130 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_CLOSE - OK - 0x97A9962C - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_READ - OK - 0x97A904F0 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_WRITE - OK - 0x97A90DFA - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_QUERY_INFORMATION - OK - 0x97AA5D72 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_SET_INFORMATION - OK - 0x97AA61B6 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_QUERY_EA - OK - 0x97AA0D58 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_SET_EA - OK - 0x97AA0D58 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_FLUSH_BUFFERS - OK - 0x97AA6E2A - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x97AAFA60 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x97AAFAF6 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_DIRECTORY_CONTROL - OK - 0x97A9EF54 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x97AAA3F6 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_DEVICE_CONTROL - OK - 0x97A9D3EA - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_SHUTDOWN - OK - 0x97AACB48 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_LOCK_CONTROL - OK - 0x97AAAC1A - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_CLEANUP - OK - 0x97A98EF0 - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Fastfat)IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_QUERY_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_SET_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_POWER - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_QUERY_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_SET_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Fastfat)IRP_MJ_PNP_POWER - OK - 0x97AAB91E - C:\Windows\System32\Drivers\fastfat.SYS - Microsoft Corporation
       (Ntfs)IRP_MJ_CREATE - OK - 0x88CB8842 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Ntfs)IRP_MJ_CLOSE - OK - 0x88CB93E3 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_READ - OK - 0x88C21A7E - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_WRITE - OK - 0x88C22599 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_QUERY_INFORMATION - OK - 0x88CB37BF - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_SET_INFORMATION - OK - 0x88C1C078 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_QUERY_EA - OK - 0x88CB37BF - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_SET_EA - OK - 0x88CB37BF - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_FLUSH_BUFFERS - OK - 0x88C8DC7B - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x88CB401E - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x88CB401E - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_DIRECTORY_CONTROL - OK - 0x88CBCD38 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x88CA4244 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_DEVICE_CONTROL - OK - 0x88CADF0D - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Ntfs)IRP_MJ_SHUTDOWN - OK - 0x88CEE857 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_LOCK_CONTROL - OK - 0x88C2B4A1 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_CLEANUP - OK - 0x88CB9CAE - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Ntfs)IRP_MJ_QUERY_SECURITY - OK - 0x88CB401E - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_SET_SECURITY - OK - 0x88CB401E - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_POWER - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Ntfs)IRP_MJ_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Ntfs)IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       (Ntfs)IRP_MJ_QUERY_QUOTA - OK - 0x88CB37BF - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_SET_QUOTA - OK - 0x88CB37BF - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation
       (Ntfs)IRP_MJ_PNP_POWER - OK - 0x88C7E517 - C:\Windows\System32\Drivers\Ntfs.sys - Microsoft Corporation

==========================================================================================

Keyboard

       IRP_MJ_CREATE - OK - 0x9106D000 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x9106D294 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_READ - OK - 0x9106E0BA - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x9106CF78 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x91071C22 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x910713C2 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x9106C6C6 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x9107242A - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x91071AB2 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x9106DDA4 - C:\Windows\system32\drivers\kbdclass.sys - Microsoft Corporation

==========================================================================================

Mouclass

       IRP_MJ_CREATE - OK - 0x913DFE42 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x913E00CE - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_READ - OK - 0x913E0E54 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x913DFDBA - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x913E45E4 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x913E43C2 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x913DF6C6 - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x913E526C - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x913E4C9C - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x913E0B6C - C:\Windows\system32\DRIVERS\mouclass.sys - Microsoft Corporation

==========================================================================================

Classpnp

       IRP_MJ_CREATE - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_READ - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x88F8A39F - C:\Windows\system32\DRIVERS\CLASSPNP.SYS - Microsoft Corporation

==========================================================================================

Atapi

       IRP_MJ_CREATE - OK - 0x88B0E8CC - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x88B0E8CC - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       IRP_MJ_READ - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x88AFA47C - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x88AFA44E - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x88AFA4AA - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x88B09DB2 - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x88B09D7E - C:\Windows\system32\drivers\ataport.SYS - Microsoft Corporation
       DriverStartIo - OK - 0x00000000 - - - 

==========================================================================================

Acpi

       IRP_MJ_CREATE - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_READ - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x833B34CC - C:\Windows\system32\drivers\ACPI.sys - Microsoft Corporation

==========================================================================================

Scsi

       Nothing

==========================================================================================

Kernel Hook

       Inline - len(1) RtlPrefetchMemoryNonTemporal[ntkrnlpa.exe] - [0x82C78E88]->[-]
       Inline - len(5) ObMakeTemporaryObject[ntkrnlpa.exe] - [0x82E49BE8]->[0x90DBA3DE][C:\Windows\System32\Drivers\aswSP.SYS]
       Inline - len(1) KiFastCallEntry[ntkrnlpa.exe] - [0x82C7C369]->[-]
       Inline - len(4) NtAlpcSendWaitReceivePort[ntkrnlpa.exe] - [0x82E910E9]->[0x8DA844DA][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(7) NtCreateProcessEx[ntkrnlpa.exe] - [0x82F1AF30]->[0x90DBE9AA][C:\Windows\System32\Drivers\aswSP.SYS]
       Inline - len(22) [ntkrnlpa.exe] - [0x82CB5D52]->[-]
       Inline - len(1) [ntkrnlpa.exe] - [0x82CB5D6F]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCD80]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCDA8]->[-]
       Inline - len(16) [ntkrnlpa.exe] - [0x82CBCE5C]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCE84]->[-]
       Inline - len(8) [ntkrnlpa.exe] - [0x82CBCEAC]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCEC0]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCEEC]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCF68]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBCFC8]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD000]->[-]
       Inline - len(8) [ntkrnlpa.exe] - [0x82CBD00C]->[-]
       Inline - len(16) [ntkrnlpa.exe] - [0x82CBD020]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD048]->[-]
       Inline - len(8) [ntkrnlpa.exe] - [0x82CBD064]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD080]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD0B8]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD13C]->[-]
       Inline - len(8) [ntkrnlpa.exe] - [0x82CBD244]->[-]
       Inline - len(8) [ntkrnlpa.exe] - [0x82CBD2D4]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD2FC]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD31C]->[-]
       Inline - len(4) [ntkrnlpa.exe] - [0x82CBD364]->[-]
       Inline - len(5) [ntkrnlpa.exe] - [0x82E621D0]->[0x90DBBE9C][C:\Windows\System32\Drivers\aswSP.SYS]
       Inline - len(4) [ntkrnlpa.exe] - [0x82E77317]->[0x8DA844C4][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826801E5]->[0x8DA864BC][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826942B2]->[0x8DA865E6][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826B0B9C]->[0x8DA86D7E][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826B54EF]->[0x8DA860DA][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826B693C]->[0x8DA86FB2][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826D6385]->[0x8DA85F32][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826D9633]->[0x8DA85FFE][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826D96F1]->[0x8DA86016][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826DDD77]->[0x8DA864CC][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826E7748]->[0x8DA86326][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826EF8D8]->[0x8DA8614A][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x826F9B88]->[0x8DA86D0A][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x8271119E]->[0x8DA86D54][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x8271EB71]->[0x8DA871BA][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x82735DBB]->[0x8DA86D96][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x82746C60]->[0x8DA86096][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x82754B97]->[0x8DA8628E][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x8275BDDF]->[0x8DA87070][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x82772B8F]->[0x8DA86254][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x82793CC9]->[0x8DA87118][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x827ABCAF]->[0x8DA86EFA][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x827AC240]->[0x8DA861AE][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(5) [win32k.sys] - [0x827B2476]->[0x8DA861E4][C:\Windows\System32\Drivers\aswSnx.SYS]
       Inline - len(28) [peauth.sys] - [0xAE357C9D]->[-]
       Inline - len(28) [peauth.sys] - [0xAE357CC1]->[-]

==========================================================================================

Object Type

       CmpCloseKeyObject - CmpKeyObjectType - OK - 0x82E8A226 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpDeleteKeyObject - CmpKeyObjectType - OK - 0x82E7174B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpParseKey - CmpKeyObjectType - OK - 0x82E6BDF5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpSecurityMethod - CmpKeyObjectType - OK - 0x82E3329F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpQueryKeyName - CmpKeyObjectType - OK - 0x82E29C84 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopCloseFile - IoFileObjectType - OK - 0x82E707CB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopDeleteFile - IoFileObjectType - OK - 0x82E6F913 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopParseFile - IoFileObjectType - OK - 0x82EBF11D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopGetSetSecurityObject - IoFileObjectType - OK - 0x82EA225D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopQueryName - IoFileObjectType - OK - 0x82EAE707 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopDeleteDriver - IoDriverObjectType - OK - 0x82EF7F6F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - IoDriverObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopDeleteDevice - IoDeviceObjectType - OK - 0x82DF92BC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopParseDevice - IoDeviceObjectType - OK - 0x82E83490 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopGetSetSecurityObject - IoDeviceObjectType - OK - 0x82EA225D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopCloseIoCompletion - IoCompletionObjectType - OK - 0x82E9FA83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IopDeleteIoCompletion - IoCompletionObjectType - OK - 0x82E9FAA1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - IoCompletionObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspJobClose - PsJobType - OK - 0x82E30F81 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspJobDelete - PsJobType - OK - 0x82E30E29 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - PsJobType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspThreadOpen - PsThreadType - OK - 0x82EA520C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspThreadDelete - PsThreadType - OK - 0x82EA7854 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - PsThreadType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspProcessOpen - PsProcessType - OK - 0x82E4ED47 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspProcessClose - PsProcessType - OK - 0x82EAEDEE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PspProcessDelete - PsProcessType - OK - 0x82EB16B5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - PsProcessType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - ObpTypeObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       ObpCloseDirectoryObject - ObpDirectoryObjectType - OK - 0x82EA890F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - ObpDirectoryObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       ObpDeleteSymbolicLink - ObpSymbolicLinkObjectType - OK - 0x82E49CA7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       ObpParseSymbolicLink - ObpSymbolicLinkObjectType - OK - 0x82E657A9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - ObpSymbolicLinkObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       MiSectionDelete - MmSectionObjectType - OK - 0x82E608C1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - MmSectionObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - ExEventObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       ExpDeleteMutant - ExMutantObjectType - OK - 0x82CFEFEB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - ExMutantObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - ExSemaphoreObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SepTokenDeleteMethod - SeTokenObjectType - OK - 0x82E97FD0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - SeTokenObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       AlpcpOpenPort - AlpcPortObjectType - OK - 0x82EA854F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       AlpcpClosePort - AlpcPortObjectType - OK - 0x82E9DF53 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       AlpcpDeletePort - AlpcPortObjectType - OK - 0x82E9D75C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - AlpcPortObjectType - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - TpWorkerFactory - OK - 0x82E51A17 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - TpWorkerFactory - OK - 0x82D0076E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - TpWorkerFactory - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - FilterCommunicationPort - OK - 0x88BE251A - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       DeleteProcedure - FilterCommunicationPort - OK - 0x88BE1FC8 - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       SeDefaultObjectMethod - FilterCommunicationPort - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - TmTx - OK - 0x82E10774 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - TmTx - OK - 0x82E1093F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - TmTx - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Controller - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - EtwRegistration - OK - 0x82EAEDD4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - EtwRegistration - OK - 0x82E9E25D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - EtwRegistration - OK - 0x82E93615 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - EtwRegistration - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - Profile - OK - 0x82F49872 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Profile - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - EventPair - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - Desktop - OK - 0x82E9E35C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - Desktop - OK - 0x82EB8846 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - Desktop - OK - 0x82ECADF1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Desktop - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OkayToCloseProcedure - Desktop - OK - 0x82EB87C7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - UserApcReserve - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - EtwConsumer - OK - 0x82EAEDD4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - EtwConsumer - OK - 0x82ED43EE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - EtwConsumer - OK - 0x82ED43C3 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - EtwConsumer - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - Timer - OK - 0x82C62682 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Timer - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - WindowStation - OK - 0x82E9E35C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - WindowStation - OK - 0x82EB8846 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - WindowStation - OK - 0x82ECADF1 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       ParseProcedure - WindowStation - OK - 0x82E50217 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - WindowStation - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OkayToCloseProcedure - WindowStation - OK - 0x82EB87C7 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - PcwObject - OK - 0x88DDEC70 - C:\Windows\System32\drivers\pcw.sys - Microsoft Corporation
       CloseProcedure - PcwObject - OK - 0x88DDEC8A - C:\Windows\System32\drivers\pcw.sys - Microsoft Corporation
       DeleteProcedure - PcwObject - OK - 0x88DDECAC - C:\Windows\System32\drivers\pcw.sys - Microsoft Corporation
       SeDefaultObjectMethod - PcwObject - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - TmEn - OK - 0x82E1463A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - TmEn - OK - 0x82E14671 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - TmEn - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - WmiGuid - OK - 0x82C660E9 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - WmiGuid - OK - 0x82E302EF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - KeyedEvent - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - DebugObject - OK - 0x82EEBA55 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - DebugObject - OK - 0x82EBB93E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - DebugObject - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - TmRm - OK - 0x82DE5F9F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - TmRm - OK - 0x82EC68C5 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - TmRm - OK - 0x82EC658B - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - TmRm - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Adapter - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - PowerRequest - OK - 0x82E26406 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - PowerRequest - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - Session - OK - 0x82EC9777 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Session - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       OpenProcedure - TmTm - OK - 0x82DE50C0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - TmTm - OK - 0x82DE5041 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - TmTm - OK - 0x82EC618C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - TmTm - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - IoCompletionReserve - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       DeleteProcedure - Callback - OK - 0x82EBB93E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       SeDefaultObjectMethod - Callback - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CloseProcedure - FilterConnectionPort - OK - 0x88BE254A - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       DeleteProcedure - FilterConnectionPort - OK - 0x88BE1FE2 - C:\Windows\system32\drivers\fltmgr.sys - Microsoft Corporation
       SeDefaultObjectMethod - FilterConnectionPort - OK - 0x82EA3676 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       PostOperation - Thread - ObjectType_Callback - 0x90DB0D64 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       PreOperation - Thread - ObjectType_Callback - 0x90DB0D18 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       PostOperation - Thread - ObjectType_Callback - 0x8DA83BE6 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       PreOperation - Thread - ObjectType_Callback - 0x8DA85B56 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       PostOperation - Process - ObjectType_Callback - 0x90DB0D64 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       PreOperation - Process - ObjectType_Callback - 0x90DB0D18 - C:\Windows\System32\Drivers\aswSP.SYS - AVAST Software
       PostOperation - Process - ObjectType_Callback - 0x8DA83BE6 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       PreOperation - Process - ObjectType_Callback - 0x8DA85B56 - C:\Windows\System32\Drivers\aswSnx.SYS - AVAST Software
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       GetCellRoutine - HHIVE - OK - 0x82E88350 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpAllocate - HHIVE - OK - 0x82E49AAD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFree - HHIVE - OK - 0x82E49C87 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileSetSize - HHIVE - OK - 0x82E1F924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileWrite - HHIVE - OK - 0x82E4D990 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileRead - HHIVE - OK - 0x82E0A4CF - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       CmpFileFlush - HHIVE - OK - 0x82E4D9CD - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation

==========================================================================================

IDT

       Divide error - OK - 0x82C7CFF0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Debug - OK - 0x82C7D180 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Not used - OK - 0x00000000 - - - 
       Breakpoint - OK - 0x82C7D5F0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Overflow - OK - 0x82C7D778 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Bounds check - OK - 0x82C7D8D8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Invalid opcode - OK - 0x82C7DA4C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Device not available - OK - 0x82C7E048 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Double fault - OK - 0x00000000 - - - 
       Coprocessor segment overrun - OK - 0x82C7E4A8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Invalid TSS - OK - 0x82C7E5CC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Segment not present - OK - 0x82C7E70C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Stack segment fault - OK - 0x82C7E96C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       General protection - OK - 0x82C7EC5C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Page Fault - OK - 0x82C7F32C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Floating-point error - OK - 0x82C7F804 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Alignment check - OK - 0x82C7F944 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Machine check - OK - 0x00000000 - - - 
       SIMD floating point exception - OK - 0x82C7FAB0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved by Intel - OK - 0x82C21AF8 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       Not used - OK - 0x00000000 - - - 
       KiGetTickCount - OK - 0x82C7C66A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiCallbackReturn - OK - 0x82C7C7F0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiSetLowWaitHighThread - OK - 0x82C7C92C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiDebugService - OK - 0x82C7D4C8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiSystemService - OK - 0x82C7C01E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       Reserved for APIC - OK - 0x82C7F6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiStartUnexpectedRange - OK - 0x82C7B6E0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt1 - OK - 0x82C7B6EA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt2 - OK - 0x82C7B6F4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt3 - OK - 0x82C7B6FE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt4 - OK - 0x82C7B708 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt5 - OK - 0x82C7B712 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt6 - OK - 0x82C7B71C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt7 - OK - 0x82C21104 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt8 - OK - 0x82C7B730 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt9 - OK - 0x82C7B73A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt10 - OK - 0x82C7B744 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt11 - OK - 0x82C7B74E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt12 - OK - 0x82C7B758 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt13 - OK - 0x82C7B762 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt14 - OK - 0x82C7B76C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt15 - OK - 0x82C7B776 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt16 - OK - 0x82C7B780 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt17 - OK - 0x82C7B78A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt18 - OK - 0x82C7B794 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt19 - OK - 0x82C7B79E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt20 - OK - 0x82C7B7A8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt21 - OK - 0x82C7B7B2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt22 - OK - 0x82C7B7BC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt23 - OK - 0x82C7B7C6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt24 - OK - 0x82C7B7D0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt25 - OK - 0x82C7B7DA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt26 - OK - 0x82C7B7E4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt27 - OK - 0x82C7B7EE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt28 - OK - 0x82C7B7F8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt29 - OK - 0x82C7B802 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt30 - OK - 0x82C7B80C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt31 - OK - 0x82C7B816 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt32 - OK - 0x82C7B820 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt33 - idt hook - 0x860642D8 - unknown image - 
       KiUnexpectedInterrupt34 - idt hook - 0x85599558 - unknown image - 
       KiUnexpectedInterrupt35 - idt hook - 0x86064CD8 - unknown image - 
       KiUnexpectedInterrupt36 - OK - 0x82C7B848 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt37 - OK - 0x82C7B852 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt38 - OK - 0x82C7B85C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt39 - OK - 0x82C7B866 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt40 - OK - 0x82C7B870 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt41 - OK - 0x82C7B87A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt42 - OK - 0x82C7B884 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt43 - OK - 0x82C7B88E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt44 - OK - 0x82C7B898 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt45 - OK - 0x82C7B8A2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt46 - OK - 0x82C7B8AC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt47 - OK - 0x82C7B8B6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt48 - OK - 0x82C7B8C0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt49 - OK - 0x82C7B8CA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt50 - idt hook - 0x855997D8 - unknown image - 
       KiUnexpectedInterrupt51 - idt hook - 0x86064558 - unknown image - 
       KiUnexpectedInterrupt52 - OK - 0x82C7B8E8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt53 - OK - 0x82C7B8F2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt54 - OK - 0x82C7B8FC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt55 - OK - 0x82C7B906 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt56 - OK - 0x82C7B910 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt57 - OK - 0x82C7B91A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt58 - OK - 0x82C7B924 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt59 - OK - 0x82C7B92E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt60 - OK - 0x82C7B938 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt61 - OK - 0x82C7B942 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt62 - OK - 0x82C7B94C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt63 - OK - 0x82C7B956 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt64 - OK - 0x82C7B960 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt65 - OK - 0x82C7B96A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt66 - idt hook - 0x85599A58 - unknown image - 
       KiUnexpectedInterrupt67 - idt hook - 0x86064058 - unknown image - 
       KiUnexpectedInterrupt68 - OK - 0x82C7B988 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt69 - OK - 0x82C7B992 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt70 - OK - 0x82C7B99C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt71 - OK - 0x82C7B9A6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt72 - OK - 0x82C7B9B0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt73 - OK - 0x82C7B9BA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt74 - OK - 0x82C7B9C4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt75 - OK - 0x82C7B9CE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt76 - OK - 0x82C7B9D8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt77 - OK - 0x82C7B9E2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt78 - OK - 0x82C7B9EC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt79 - OK - 0x82C7B9F6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt80 - OK - 0x82C7BA00 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt81 - OK - 0x82C7BA0A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt82 - OK - 0x82C7BA14 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt83 - OK - 0x82C7BA1E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt84 - OK - 0x82C7BA28 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt85 - OK - 0x82C7BA32 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt86 - OK - 0x82C7BA3C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt87 - OK - 0x82C7BA46 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt88 - OK - 0x82C7BA50 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt89 - OK - 0x82C7BA5A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt90 - OK - 0x82C7BA64 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt91 - OK - 0x82C7BA6E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt92 - OK - 0x82C7BA78 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt93 - OK - 0x82C7BA82 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt94 - OK - 0x82C7BA8C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt95 - OK - 0x82C7BA96 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt96 - OK - 0x82C7BAA0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt97 - OK - 0x82C7BAAA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt98 - OK - 0x82C7BAB4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt99 - OK - 0x82C7BABE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt100 - OK - 0x82C7BAC8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt101 - OK - 0x82C7BAD2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt102 - OK - 0x82C7BADC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt103 - OK - 0x82C7BAE6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt104 - OK - 0x82C7BAF0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt105 - OK - 0x82C7BAFA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt106 - OK - 0x82C7BB04 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt107 - OK - 0x82C7BB0E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt108 - OK - 0x82C7BB18 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt109 - OK - 0x82C7BB22 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt110 - OK - 0x82C7BB2C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt111 - OK - 0x82C7BB36 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt112 - OK - 0x82C7BB40 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt113 - OK - 0x82C7BB4A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt114 - OK - 0x82C7BB54 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt115 - OK - 0x82C7BB5E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt116 - OK - 0x82C7BB68 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt117 - OK - 0x82C7BB72 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt118 - OK - 0x82C7BB7C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt119 - OK - 0x82C7BB86 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt120 - OK - 0x82C7BB90 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt121 - OK - 0x82C7BB9A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt122 - OK - 0x82C7BBA4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt123 - OK - 0x82C7BBAE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt124 - OK - 0x82C7BBB8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt125 - OK - 0x82C7BBC2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt126 - OK - 0x82C7BBCC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt127 - OK - 0x82C7BBD6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt128 - OK - 0x82C7BBE0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt129 - idt hook - 0x85599CD8 - unknown image - 
       KiUnexpectedInterrupt130 - idt hook - 0x85599058 - unknown image - 
       KiUnexpectedInterrupt131 - idt hook - 0x855992D8 - unknown image - 
       KiUnexpectedInterrupt132 - OK - 0x82C7BC08 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt133 - OK - 0x82C7BC12 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt134 - OK - 0x82C7BC1C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt135 - OK - 0x82C7BC26 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt136 - OK - 0x82C7BC30 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt137 - OK - 0x82C7BC3A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt138 - OK - 0x82C7BC44 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt139 - OK - 0x82C7BC4E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt140 - OK - 0x82C7BC58 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt141 - OK - 0x82C7BC62 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt142 - OK - 0x82C7BC6C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt143 - OK - 0x82C7BC76 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt144 - OK - 0x82C7BC80 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt145 - OK - 0x82C213F4 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt146 - OK - 0x82C7BC94 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt147 - OK - 0x82C7BC9E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt148 - OK - 0x82C7BCA8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt149 - OK - 0x82C7BCB2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt150 - OK - 0x82C7BCBC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt151 - OK - 0x82C7BCC6 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt152 - OK - 0x82C7BCD0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt153 - OK - 0x82C7BCDA - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt154 - OK - 0x82C7BCE4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt155 - OK - 0x82C7BCEE - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt156 - OK - 0x82C7BCF8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt157 - OK - 0x82C7BD02 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt158 - OK - 0x82C7BD0C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt159 - OK - 0x82C7BD16 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt160 - OK - 0x82C7BD20 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt161 - OK - 0x82C0A2D8 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt162 - OK - 0x82C09898 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt163 - OK - 0x82C7BD3E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt164 - OK - 0x82C7BD48 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt165 - OK - 0x82C7BD52 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt166 - OK - 0x82C7BD5C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt167 - OK - 0x82C7BD66 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt168 - OK - 0x82C7BD70 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt169 - OK - 0x82C7BD7A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt170 - OK - 0x82C7BD84 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt171 - OK - 0x82C7BD8E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt172 - OK - 0x82C7BD98 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt173 - OK - 0x82C7BDA2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt174 - OK - 0x82C7BDAC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt175 - OK - 0x82C211DC - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt176 - OK - 0x82C7BDC0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt177 - OK - 0x82C21958 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt178 - OK - 0x82C7BDD4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt179 - OK - 0x82C216F8 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt180 - OK - 0x82C7BDE8 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt181 - OK - 0x82C7BDF2 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt182 - OK - 0x82C7BDFC - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt183 - OK - 0x82C7BE06 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt184 - OK - 0x82C7BE10 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt185 - OK - 0x82C7BE1A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt186 - OK - 0x82C7BE24 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt187 - OK - 0x82C7BE2E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt188 - OK - 0x82C7BE38 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt189 - OK - 0x82C7BE42 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt190 - OK - 0x82C7BE49 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt191 - OK - 0x82C7BE50 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt192 - OK - 0x82C7BE57 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt193 - OK - 0x82C7BE5E - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt194 - OK - 0x82C7BE65 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt195 - OK - 0x82C7BE6C - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt196 - OK - 0x82C7BE73 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt197 - OK - 0x82C7BE7A - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt198 - OK - 0x82C7BE81 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt199 - OK - 0x82C7BE88 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt200 - OK - 0x82C7BE8F - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt201 - OK - 0x82C7BE96 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt202 - OK - 0x82C7BE9D - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt203 - OK - 0x82C7BEA4 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt204 - OK - 0x82C7BEAB - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       KiUnexpectedInterrupt205 - OK - 0x82C21F2C - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt206 - OK - 0x82C221A8 - C:\Windows\system32\halmacpi.dll - Microsoft Corporation
       KiUnexpectedInterrupt207 - OK - 0x82C7BEC0 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation

==========================================================================================

Message Hook

       AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - WH_MSGFILTER - mfc90u.dll
       nvtray.exe - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe - WH_MSGFILTER - nvtray.exe
       AvastUI.exe - C:\Program Files\AVAST Software\Avast\AvastUI.exe - WH_CBT - mfc90u.dll
       Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - WH_MOUSE - ieframe.dll
       Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - WH_KEYBOARD - ieframe.dll
       Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - WH_MOUSE - ieframe.dll
       Skype.exe - C:\Program Files\Skype\Phone\Skype.exe - WH_KEYBOARD - ieframe.dll
       XueTr.exe - C:\Nov sloka\XueTr.exe - WH_MSGFILTER - mfc42u.dll
       XueTr.exe - C:\Nov sloka\XueTr.exe - WH_CBT - mfc42u.dll

==========================================================================================

Process Hook

      Image File Name[1000 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x00B001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00B00600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00B00804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x00B003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00B00A08
             Iat - shell32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - shell32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - shell32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1608 explorer.exe]Process Hook
             Iat - Explorer.EXE->SHELL32.dll:[Ordinal:70] - 0x76711FC0->0x765B002E[C:\Windows\system32\SHELL32.dll]
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00140C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00140E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00140804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00140A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001401F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001403FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00140600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00141014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001501F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00150600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00150804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001503FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00150A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - EXPLORERFRAME.dll->SHELL32.dll:[Ordinal:70] - 0x76711FC0->0x765B002E[C:\Windows\system32\SHELL32.dll]
             Iat - EXPLORERFRAME.dll->SHLWAPI.dll:[Ordinal:378] - 0x775A1A4D->0x7759017A[C:\Windows\system32\SHLWAPI.dll]
             Iat - EXPLORERFRAME.dll->SHLWAPI.dll:[Ordinal:361] - 0x764E134C->0x77590169[C:\Windows\system32\SHLWAPI.dll]
             Iat - EXPLORERFRAME.dll->SHLWAPI.dll:[Ordinal:26] - 0x75BA75C1->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - EXPLORERFRAME.dll->SHLWAPI.dll:[Ordinal:821] - 0x775736CF->0x77590335[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1308 AvastSvc.exe]Process Hook
             inline - len(4) kernel32.dll->SetUnhandledExceptionFilter - 0x764EF4FB->_
             inline - len(1) kernel32.dll - 0x765069F4->_
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[268 smss.exe]Process Hook
             Nothing

------------------------------------------------------------------------------------------

      Image File Name[1908 AvastUI.exe]Process Hook
             inline - len(1) AvastUI.exe - 0x012A6795->_
             inline - len(5) AvastUI.exe - 0x012A67EF->0x012A6BE1[C:\Program Files\AVAST Software\Avast\AvastUI.exe]
             inline - len(15) AvastUI.exe - 0x012A6BE1->_
             inline - len(7) AvastUI.exe - 0x012A6C03->_
             inline - len(1) kernel32.dll - 0x765069F4->_
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[5080 Skype.exe]Process Hook
             C:\Program Files\Skype\Phone\Skype.exe - Hijack on Module File
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x003E01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x003E0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x003E0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x003E03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x003E0A08
             Iat - shell32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - shell32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - shell32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - explorerframe.dll->SHELL32.dll:[Ordinal:70] - 0x76711FC0->0x765B002E[C:\Windows\system32\shell32.dll]
             Iat - explorerframe.dll->SHLWAPI.dll:[Ordinal:378] - 0x775A1A4D->0x7759017A[C:\Windows\system32\SHLWAPI.dll]
             Iat - explorerframe.dll->SHLWAPI.dll:[Ordinal:361] - 0x764E134C->0x77590169[C:\Windows\system32\SHLWAPI.dll]
             Iat - explorerframe.dll->SHLWAPI.dll:[Ordinal:26] - 0x75BA75C1->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - explorerframe.dll->SHLWAPI.dll:[Ordinal:821] - 0x775736CF->0x77590335[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[408 csrss.exe]Process Hook
             inline - len(1) kernel32.dll - 0x765069F4->_

------------------------------------------------------------------------------------------

      Image File Name[1508 chrome.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001801F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00180600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00180804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001803FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00180A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00190C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00190E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00190804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00190A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001901F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001903FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00190600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00191014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - RICHED20.dll->USER32.dll:EndPaint - 0x75B95D42->0x5DC8797A[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]
             Iat - RICHED20.dll->USER32.dll:BeginPaint - 0x75B95D14->0x5DC8794B[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]

------------------------------------------------------------------------------------------

      Image File Name[1932 chrome.exe]Process Hook
             Iat - chrome.exe->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001901F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001903FC
             inline - len(6) ntdll.dll->NtCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->NtMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->NtOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->NtOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->NtOpenProcessToken - 0x773D5D9E->0x763D74A4
             inline - len(6) ntdll.dll->NtOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->NtOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->NtOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->NtOpenThreadTokenEx - 0x773D5E2E->0x763D7535
             inline - len(6) ntdll.dll->NtQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->NtQueryFullAttributesFile - 0x773D5FEE->0x763D76F3
             inline - len(6) ntdll.dll->NtSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->NtSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->NtUnmapViewOfSection - 0x773D69BE->_
             inline - len(6) ntdll.dll->ZwCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->ZwMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->ZwOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->ZwOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->ZwOpenProcessToken - 0x773D5D9E->0x763D74A4
             inline - len(6) ntdll.dll->ZwOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->ZwOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->ZwOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->ZwOpenThreadTokenEx - 0x773D5E2E->0x763D7535
             inline - len(6) ntdll.dll->ZwQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->ZwQueryFullAttributesFile - 0x773D5FEE->0x763D76F3
             inline - len(6) ntdll.dll->ZwSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->ZwSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->ZwUnmapViewOfSection - 0x773D69BE->_
             Eat - kernel32.dll->CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(4) kernel32.dll - 0x76555474->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x002301F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00230600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00230804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x002303FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00230A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00240C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00240E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00240804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00240A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x002401F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x002403FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00240600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00241014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - chrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             Iat - pdf.dll->GDI32.dll:GetFontData - 0x75FEBCC4->0x5D94791E[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]
             Iat - ppGoogleNaClPluginChrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(4) avcodec-53.dll->avcodec_get_chroma_sub_sample - 0x60D9E61D->_
             inline - len(4) avcodec-53.dll->ff_is_hwaccel_pix_fmt - 0x60D9E65A->_
             inline - len(4) avcodec-53.dll - 0x60CF9D90->_
             inline - len(4) avcodec-53.dll - 0x60D04E7C->_
             inline - len(4) avcodec-53.dll - 0x60D04E8B->_
             inline - len(4) avcodec-53.dll - 0x60D04EA2->_
             inline - len(4) avcodec-53.dll - 0x60D04EB3->_
             inline - len(4) avcodec-53.dll - 0x60D05060->_
             inline - len(4) avcodec-53.dll - 0x60D05071->_
             inline - len(4) avcodec-53.dll - 0x60D0507D->_
             inline - len(4) avcodec-53.dll - 0x60D05099->_
             inline - len(4) avcodec-53.dll - 0x60D05531->_
             inline - len(4) avcodec-53.dll - 0x60D0553B->_
             inline - len(4) avcodec-53.dll - 0x60D05547->_
             inline - len(4) avcodec-53.dll - 0x60D0555E->_
             inline - len(4) avcodec-53.dll - 0x60D0572C->_
             inline - len(4) avcodec-53.dll - 0x60D05740->_
             inline - len(4) avcodec-53.dll - 0x60D0574E->_
             inline - len(4) avcodec-53.dll - 0x60D05767->_
             inline - len(4) avcodec-53.dll - 0x60D9E825->_
             inline - len(4) avcodec-53.dll - 0x60D9E843->_
             inline - len(4) avcodec-53.dll - 0x60D9E90A->_
             inline - len(4) avcodec-53.dll - 0x60D9E91C->_
             inline - len(10) avcodec-53.dll - 0x60D9E9DC->_
             inline - len(4) avcodec-53.dll - 0x60D9EB8A->_
             inline - len(4) avcodec-53.dll - 0x60D9EB9B->_
             inline - len(4) avcodec-53.dll - 0x60D9EBA9->_
             inline - len(4) avcodec-53.dll - 0x60D9F153->_
             inline - len(4) avcodec-53.dll - 0x60D9F52E->_
             inline - len(4) avcodec-53.dll - 0x60DAC60D->_
             inline - len(4) avcodec-53.dll - 0x60DAC71C->_
             inline - len(4) avcodec-53.dll - 0x60DAC788->_
             inline - len(4) avcodec-53.dll - 0x60DAC7B0->_
             inline - len(4) avcodec-53.dll - 0x60DAC7F7->_
             inline - len(4) avcodec-53.dll - 0x60DB8FA5->_
             inline - len(4) avcodec-53.dll - 0x60DBD37B->_
             inline - len(11) avcodec-53.dll - 0x60DBEE40->_
             inline - len(4) avcodec-53.dll - 0x60DC0B41->_
             inline - len(4) avcodec-53.dll - 0x60DC44DE->_
             inline - len(4) avcodec-53.dll - 0x60DC687C->_
             inline - len(4) avformat-53.dll - 0x71825CF1->_
             inline - len(3) avformat-53.dll - 0x71826034->_
             inline - len(4) avformat-53.dll - 0x7182A02D->_
             inline - len(4) avformat-53.dll - 0x7182A044->_
             inline - len(4) avformat-53.dll - 0x7182A0F0->_
             inline - len(4) avformat-53.dll - 0x7182A105->_
             inline - len(4) avformat-53.dll - 0x7183EC9B->_

------------------------------------------------------------------------------------------

      Image File Name[464 daemonu.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001701F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001703FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x002001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00200600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00200804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x002003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00200A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[468 csrss.exe]Process Hook
             inline - len(1) kernel32.dll - 0x765069F4->_

------------------------------------------------------------------------------------------

      Image File Name[476 wininit.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000301F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000303FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000C01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000C0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000C0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000C03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000C0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000D0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000D0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000D0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000D0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000D01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000D03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000D0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000D1014

------------------------------------------------------------------------------------------

      Image File Name[524 winlogon.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000301F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000303FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000501F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00050600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00050804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000503FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00050A08

------------------------------------------------------------------------------------------

      Image File Name[1364 nvxdsync.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[572 services.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000A01F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000A03FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00140C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00140E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00140804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00140A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001401F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001403FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00140600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00141014

------------------------------------------------------------------------------------------

      Image File Name[580 lsass.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001C01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001C0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001C0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001C03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001C0A08

------------------------------------------------------------------------------------------

      Image File Name[588 lsm.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00180C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00180E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00180804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00180A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001801F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001803FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00180600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00181014

------------------------------------------------------------------------------------------

      Image File Name[3856 WmiPrvSE.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00140C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00140E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00140804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00140A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001401F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001403FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00140600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00141014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001501F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00150600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00150804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001503FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00150A08

------------------------------------------------------------------------------------------

      Image File Name[4008 iPodService.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00100600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00100804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00100A08

------------------------------------------------------------------------------------------

      Image File Name[1376 nvvsvc.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[3140 vmware-usbarbitrator.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00200C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00200E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00200804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00200A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x002001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x002003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00200600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00201014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[692 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014

------------------------------------------------------------------------------------------

      Image File Name[5988 chrome.exe]Process Hook
             Iat - chrome.exe->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000901F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000903FC
             inline - len(6) ntdll.dll->NtCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->NtMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->NtOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->NtOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->NtOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->NtOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->NtOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->NtOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->NtOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->NtQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->NtQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->NtSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->NtSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->NtUnmapViewOfSection - 0x773D69BE->_
             inline - len(6) ntdll.dll->ZwCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->ZwMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->ZwOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->ZwOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->ZwOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->ZwOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->ZwOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->ZwOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->ZwOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->ZwQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->ZwQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->ZwSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->ZwSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->ZwUnmapViewOfSection - 0x773D69BE->_
             Eat - kernel32.dll->CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(4) kernel32.dll - 0x76555474->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000D01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000D0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000D0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000D03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000D0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000E0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000E0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000E0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000E0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000E01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000E03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000E0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000E1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - chrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             Iat - pdf.dll->GDI32.dll:GetFontData - 0x75FEBCC4->0x5D94791E[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]
             Iat - ppGoogleNaClPluginChrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(4) avcodec-53.dll->avcodec_get_chroma_sub_sample - 0x60D9E61D->_
             inline - len(4) avcodec-53.dll->ff_is_hwaccel_pix_fmt - 0x60D9E65A->_
             inline - len(4) avcodec-53.dll - 0x60CF9D90->_
             inline - len(4) avcodec-53.dll - 0x60D04E7C->_
             inline - len(4) avcodec-53.dll - 0x60D04E8B->_
             inline - len(4) avcodec-53.dll - 0x60D04EA2->_
             inline - len(4) avcodec-53.dll - 0x60D04EB3->_
             inline - len(4) avcodec-53.dll - 0x60D05060->_
             inline - len(4) avcodec-53.dll - 0x60D05071->_
             inline - len(4) avcodec-53.dll - 0x60D0507D->_
             inline - len(4) avcodec-53.dll - 0x60D05099->_
             inline - len(4) avcodec-53.dll - 0x60D05531->_
             inline - len(4) avcodec-53.dll - 0x60D0553B->_
             inline - len(4) avcodec-53.dll - 0x60D05547->_
             inline - len(4) avcodec-53.dll - 0x60D0555E->_
             inline - len(4) avcodec-53.dll - 0x60D0572C->_
             inline - len(4) avcodec-53.dll - 0x60D05740->_
             inline - len(4) avcodec-53.dll - 0x60D0574E->_
             inline - len(4) avcodec-53.dll - 0x60D05767->_
             inline - len(4) avcodec-53.dll - 0x60D9E825->_
             inline - len(4) avcodec-53.dll - 0x60D9E843->_
             inline - len(4) avcodec-53.dll - 0x60D9E90A->_
             inline - len(4) avcodec-53.dll - 0x60D9E91C->_
             inline - len(10) avcodec-53.dll - 0x60D9E9DC->_
             inline - len(4) avcodec-53.dll - 0x60D9EB8A->_
             inline - len(4) avcodec-53.dll - 0x60D9EB9B->_
             inline - len(4) avcodec-53.dll - 0x60D9EBA9->_
             inline - len(4) avcodec-53.dll - 0x60D9F153->_
             inline - len(4) avcodec-53.dll - 0x60D9F52E->_
             inline - len(4) avcodec-53.dll - 0x60DAC60D->_
             inline - len(4) avcodec-53.dll - 0x60DAC71C->_
             inline - len(4) avcodec-53.dll - 0x60DAC788->_
             inline - len(4) avcodec-53.dll - 0x60DAC7B0->_
             inline - len(4) avcodec-53.dll - 0x60DAC7F7->_
             inline - len(4) avcodec-53.dll - 0x60DB8FA5->_
             inline - len(4) avcodec-53.dll - 0x60DBD37B->_
             inline - len(11) avcodec-53.dll - 0x60DBEE40->_
             inline - len(4) avcodec-53.dll - 0x60DC0B41->_
             inline - len(4) avcodec-53.dll - 0x60DC44DE->_
             inline - len(4) avcodec-53.dll - 0x60DC687C->_
             inline - len(4) avformat-53.dll - 0x71825CF1->_
             inline - len(3) avformat-53.dll - 0x71826034->_
             inline - len(4) avformat-53.dll - 0x7182A02D->_
             inline - len(4) avformat-53.dll - 0x7182A044->_
             inline - len(4) avformat-53.dll - 0x7182A0F0->_
             inline - len(4) avformat-53.dll - 0x7182A105->_
             inline - len(4) avformat-53.dll - 0x7183EC9B->_

------------------------------------------------------------------------------------------

      Image File Name[2736 PDAgent.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00110C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00110E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00110804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00110A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001101F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001103FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00110600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00111014
             Iat - oledb32.dll->OLEAUT32.dll:[Ordinal:416] - 0x75CB93EC->0x75C701A0[C:\Windows\system32\OLEAUT32.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[780 nvvsvc.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00210C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00210E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00210804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00210A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x002101F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x002103FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00210600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00211014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[804 nvSCPAPISvr.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001501F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001503FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001E0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001E0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001E0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001E0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001E01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001E03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001E0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001E1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001F0A08

------------------------------------------------------------------------------------------

      Image File Name[848 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014

------------------------------------------------------------------------------------------

      Image File Name[944 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00080C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00080E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00080804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00080A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000801F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000803FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00080600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00081014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x002A01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x002A0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x002A0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x002A03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x002A0A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - services.exe->msvcrt.dll:__p__commode - 0x75AE27C3->0x6FF627C3
             Iat - services.exe->msvcrt.dll:__p__fmode - 0x75AE27CE->0x6FF627CE
             Iat - services.exe->msvcrt.dll:__set_app_type - 0x75AE2804->0x6FF62804
             Iat - services.exe->msvcrt.dll:_except_handler4_common - 0x75AF3E27->0x6FF73E27
             Iat - services.exe->msvcrt.dll:?terminate@@YAXXZ - 0x75B261CF->0x6FFA61CF
             Iat - services.exe->msvcrt.dll:__setusermatherr - 0x75B677AD->0x6FFE77AD
             Iat - services.exe->msvcrt.dll:_wtol - 0x75ADC7C8->0x6FF5C7C8
             Iat - services.exe->msvcrt.dll:_initterm - 0x75ADC151->0x6FF5C151
             Iat - services.exe->msvcrt.dll:_controlfp - 0x75ADE1E1->0x6FF5E1E1
             Iat - services.exe->msvcrt.dll:_ltow - 0x75ADFBAB->0x6FF5FBAB
             Iat - services.exe->msvcrt.dll:wcscspn - 0x75ADD9DA->0x6FF5D9DA
             Iat - services.exe->msvcrt.dll:exit - 0x75AE36AA->0x6FF636AA
             Iat - services.exe->msvcrt.dll:_XcptFilter - 0x75AFDC75->0x6FF7DC75
             Iat - services.exe->msvcrt.dll:_exit - 0x75B3B2C0->0x6FFBB2C0
             Iat - services.exe->msvcrt.dll:_cexit - 0x75AE37D4->0x6FF637D4
             Iat - services.exe->msvcrt.dll:__getmainargs - 0x75AE2BC0->0x6FF62BC0
             Iat - services.exe->msvcrt.dll:_ltow_s - 0x75AE120C->0x6FF6120C
             Iat - services.exe->msvcrt.dll:wcschr - 0x75ADAA61->0x6FF5AA61
             Iat - services.exe->msvcrt.dll:_wcslwr - 0x75ADFB25->0x6FF5FB25
             Iat - services.exe->msvcrt.dll:memmove - 0x75AD9E5A->0x6FF59E5A
             Iat - services.exe->msvcrt.dll:_ultow_s - 0x75ADF8E9->0x6FF5F8E9
             Iat - services.exe->msvcrt.dll:time - 0x75ADF708->0x6FF5F708
             Iat - services.exe->msvcrt.dll:wcsrchr - 0x75ADA73F->0x6FF5A73F
             Iat - services.exe->msvcrt.dll:_vsnwprintf - 0x75ADBBCE->0x6FF5BBCE
             Iat - services.exe->msvcrt.dll:_wcsnicmp - 0x75ADAAE3->0x6FF5AAE3
             Iat - services.exe->msvcrt.dll:memset - 0x75AD9790->0x6FF59790
             Iat - services.exe->msvcrt.dll:wcsstr - 0x75ADBF71->0x6FF5BF71
             Iat - services.exe->msvcrt.dll:wcstoul - 0x75ADB319->0x6FF5B319
             Iat - services.exe->msvcrt.dll:memcpy - 0x75AD9910->0x6FF59910
             Iat - services.exe->msvcrt.dll:_wcsicmp - 0x75ADA9E9->0x6FF5A9E9
             Iat - services.exe->msvcrt.dll:_ultow - 0x75ADFAB0->0x6FF5FAB0
             Iat - services.exe->msvcrt.dll:wcsncmp - 0x75ADB05E->0x6FF5B05E
             Iat - services.exe->msvcrt.dll:_amsg_exit - 0x75B3B2EF->0x6FFBB2EF
             Iat - services.exe->RPCRT4.dll:UuidCreate - 0x759E6483->0x77BD3CB7
             Iat - services.exe->RPCRT4.dll:RpcAsyncAbortCall - 0x75A54075->0x77C4406C
             Iat - services.exe->RPCRT4.dll:RpcServerUnsubscribeForNotification - 0x759D4506->0x77BC2414
             Iat - services.exe->RPCRT4.dll:UuidEqual - 0x759E00F9->0x77BCEBF1
             Iat - services.exe->RPCRT4.dll:RpcServerUseProtseqEpW - 0x759E135F->0x77BD29DD
             Iat - services.exe->RPCRT4.dll:RpcServerRegisterIfEx - 0x759E09BC->0x77BD2640
             Iat - services.exe->RPCRT4.dll:RpcServerUseProtseqW - 0x759C7B03->0x77BB6FE9
             Iat - services.exe->RPCRT4.dll:RpcServerInqBindings - 0x759C7B5B->0x77BB6DB9
             Iat - services.exe->RPCRT4.dll:RpcBindingToStringBindingW - 0x759DFFC2->0x77BCED81
             Iat - services.exe->RPCRT4.dll:RpcStringBindingParseW - 0x759E2A35->0x77BD1B3B
             Iat - services.exe->RPCRT4.dll:RpcStringFreeW - 0x759E5465->0x77BD73B1
             Iat - services.exe->RPCRT4.dll:RpcEpRegisterW - 0x759C8146->0x77BB743E
             Iat - services.exe->RPCRT4.dll:RpcServerInqDefaultPrincNameW - 0x759C96DC->0x77BB88E0
             Iat - services.exe->RPCRT4.dll:RpcServerRegisterAuthInfoW - 0x759C9017->0x77BB830A
             Iat - services.exe->RPCRT4.dll:UuidCreateNil - 0x759C732D->0x77BB67E9
             Iat - services.exe->RPCRT4.dll:I_RpcMapWin32Status - 0x759FBF83->0x77BEABAF
             Iat - services.exe->RPCRT4.dll:RpcServerInqCallAttributesW - 0x759F1E30->0x77BE041C
             Iat - services.exe->RPCRT4.dll:RpcAsyncCompleteCall - 0x75A54E80->0x77C45403
             Iat - services.exe->RPCRT4.dll:RpcServerInqBindingHandle - 0x759D4C41->0x77BC2839
             Iat - services.exe->RPCRT4.dll:RpcImpersonateClient - 0x759DD6C1->0x77BCD025
             Iat - services.exe->RPCRT4.dll:RpcRevertToSelf - 0x759D71AF->0x77BC7B94
             Iat - services.exe->RPCRT4.dll:I_RpcBindingInqLocalClientPID - 0x759F2019->0x77BE0B18
             Iat - services.exe->RPCRT4.dll:I_RpcBindingIsClientLocal - 0x759D4E0D->0x77BC27E0
             Iat - services.exe->RPCRT4.dll:I_RpcSessionStrictContextHandle - 0x75A22E46->0x77C11806
             Iat - services.exe->RPCRT4.dll:NdrServerCall2 - 0x75A54304->0x77C442F5
             Iat - services.exe->RPCRT4.dll:NdrAsyncServerCall - 0x75A54A1C->0x77C44634
             Iat - services.exe->RPCRT4.dll:RpcSsGetContextBinding - 0x759E0091->0x77BCF155
             Iat - services.exe->RPCRT4.dll:RpcServerInqCallAttributesA - 0x759D4B9A->0x77BC285B
             Iat - services.exe->RPCRT4.dll:RpcBindingServerFromClient - 0x759D366E->0x77BBC6B6
             Iat - services.exe->RPCRT4.dll:RpcBindingFree - 0x759FAFE1->0x77BED40C
             Iat - services.exe->RPCRT4.dll:RpcBindingVectorFree - 0x759C89E2->0x77BB7D86
             Iat - services.exe->RPCRT4.dll:RpcServerSubscribeForNotification - 0x759D399A->0x77BC24B5
             Iat - services.exe->RPCRT4.dll:UuidFromStringW - 0x759D038C->0x77BC16C7
             Iat - services.exe->SspiCli.dll:LogonUserExExW - 0x753C403B->0x022297D3
             Iat - services.exe->ntdll.dll:EtwRegisterTraceGuidsW - 0x773B867A->0x77EE9627
             Iat - services.exe->ntdll.dll:RtlUnicodeStringToInteger - 0x774003C5->0x77F301BD
             Iat - services.exe->ntdll.dll:RtlSetLastWin32Error - 0x773E308B->0x77F123C2
             Iat - services.exe->ntdll.dll:NtTraceControl - 0x773D6918->0x77F05D60
             Iat - services.exe->ntdll.dll:RtlInitializeCriticalSection - 0x773EA0D9->0x77F1F8BE
             Iat - services.exe->ntdll.dll:NtQueueApcThread - 0x773D6278->0x77F056C0
             Iat - services.exe->ntdll.dll:NtOpenThread - 0x773D5E08->0x77F05250
             Iat - services.exe->ntdll.dll:EvtIntReportEventAndSourceAsync - 0x7739BD27->0x77ECC9BC
             Iat - services.exe->ntdll.dll:RtlSetProcessIsCritical - 0x77391FA4->0x77EC1FA4
             Iat - services.exe->ntdll.dll:NtOpenProcessToken - 0x773D5D98->0x77F051E0
             Iat - services.exe->ntdll.dll:NtSetInformationProcess - 0x773D6678->0x77F05AC0
             Iat - services.exe->ntdll.dll:NtSetEvent - 0x773D65D8->0x77F05A20
             Iat - services.exe->ntdll.dll:EtwEventRegister - 0x773F5ADC->0x77F25A12
             Iat - services.exe->ntdll.dll:EtwEventWrite - 0x773BD5BA->0x77EDF5AB
             Iat - services.exe->ntdll.dll:RtlFreeHeap - 0x773E2BFA->0x77F11F31
             Iat - services.exe->ntdll.dll:NtDeleteFile - 0x773D5808->0x77F04C50
             Iat - services.exe->ntdll.dll:NtQueryDirectoryFile - 0x773D5F98->0x77F053E0
             Iat - services.exe->ntdll.dll:NtWaitForSingleObject - 0x773D6A18->0x77F05E60
             Iat - services.exe->ntdll.dll:RtlAppendUnicodeToString - 0x773EEE62->0x77F1F10C
             Iat - services.exe->ntdll.dll:RtlAppendUnicodeStringToString - 0x773E724E->0x77F18D8B
             Iat - services.exe->ntdll.dll:NtQueryInformationFile - 0x773D6018->0x77F05460
             Iat - services.exe->ntdll.dll:NtSetInformationFile - 0x773D6638->0x77F05A80
             Iat - services.exe->ntdll.dll:NtFilterToken - 0x773D5938->0x77F04D80
             Iat - services.exe->ntdll.dll:RtlCopyUnicodeString - 0x773EA896->0x77F1F18C
             Iat - services.exe->ntdll.dll:RtlMapGenericMask - 0x773A9591->0x77ED89DD
             Iat - services.exe->ntdll.dll:RtlValidRelativeSecurityDescriptor - 0x773B17AF->0x77EDFE15
             Iat - services.exe->ntdll.dll:RtlSetSecurityObject - 0x77397030->0x77EC6FCE
             Iat - services.exe->ntdll.dll:RtlQuerySecurityObject - 0x77431955->0x77F5F9A8
             Iat - services.exe->ntdll.dll:NtQueryInformationToken - 0x773D6078->0x77F054C0
             Iat - services.exe->ntdll.dll:NtDuplicateToken - 0x773D58A8->0x77F04CF0
             Iat - services.exe->ntdll.dll:NtAdjustPrivilegesToken - 0x773D5268->0x77F046B0
             Iat - services.exe->ntdll.dll:NtSetInformationThread - 0x773D6698->0x77F05AE0
             Iat - services.exe->ntdll.dll:NtAccessCheckAndAuditAlarm - 0x773D51C8->0x77F04610
             Iat - services.exe->ntdll.dll:NtAccessCheck - 0x773D51B8->0x77F04600
             Iat - services.exe->ntdll.dll:NtOpenThreadToken - 0x773D5E18->0x77F05260
             Iat - services.exe->ntdll.dll:NtPrivilegeCheck - 0x773D5EC8->0x77F05310
             Iat - services.exe->ntdll.dll:NtPrivilegeObjectAuditAlarm - 0x773D5EE8->0x77F05330
             Iat - services.exe->ntdll.dll:WinSqmAddToStream - 0x773B04C5->0x77EDADD5
             Iat - services.exe->ntdll.dll:RtlSetEnvironmentVariable - 0x773BA10D->0x77EEABDA
             Iat - services.exe->ntdll.dll:RtlLengthSecurityDescriptor - 0x773B3E32->0x77EE137A
             Iat - services.exe->ntdll.dll:RtlValidSecurityDescriptor - 0x773B36CE->0x77EE140C
             Iat - services.exe->ntdll.dll:RtlSetControlSecurityDescriptor - 0x773980E0->0x77EC7DF3
             Iat - services.exe->ntdll.dll:NtDeleteKey - 0x773D5818->0x77F04C60
             Iat - services.exe->ntdll.dll:RtlSubAuthoritySid - 0x773F6729->0x77F1F0F4
             Iat - services.exe->ntdll.dll:NtOpenKey - 0x773D5D08->0x77F05150
             Iat - services.exe->ntdll.dll:NtEnumerateKey - 0x773D58E8->0x77F04D30
             Iat - services.exe->ntdll.dll:NtDeleteValueKey - 0x773D5848->0x77F04C90
             Iat - services.exe->ntdll.dll:NtSetValueKey - 0x773D6808->0x77F05C50
             Iat - services.exe->ntdll.dll:NtQueryValueKey - 0x773D6248->0x77F05690
             Iat - services.exe->ntdll.dll:NtCreateKey - 0x773D5608->0x77F04A50
             Iat - services.exe->ntdll.dll:RtlConvertSharedToExclusive - 0x7739C2E9->0x77ECBD52
             Iat - services.exe->ntdll.dll:RtlConvertExclusiveToShared - 0x77394D45->0x77EC6E13
             Iat - services.exe->ntdll.dll:RtlRegisterWait - 0x773A93CF->0x77EDA49F
             Iat - services.exe->ntdll.dll:RtlCreateServiceSid - 0x773A51DE->0x77ED6498
             Iat - services.exe->ntdll.dll:RtlGetNtProductType - 0x773F6589->0x77F1FE6A
             Iat - services.exe->ntdll.dll:RtlEqualUnicodeString - 0x773E5695->0x77F17666
             Iat - services.exe->ntdll.dll:RtlLengthSid - 0x773EED77->0x77F17E38
             Iat - services.exe->ntdll.dll:RtlCopySid - 0x773EEDE9->0x77F1883A
             Iat - services.exe->ntdll.dll:NtLoadDriver - 0x773D5B58->0x77F04FA0
             Iat - services.exe->ntdll.dll:NtOpenDirectoryObject - 0x773D5C98->0x77F050E0
             Iat - services.exe->ntdll.dll:NtQueryDirectoryObject - 0x773D5FA8->0x77F053F0
             Iat - services.exe->ntdll.dll:RtlCompareUnicodeString - 0x773E73D5->0x77F1A382
             Iat - services.exe->ntdll.dll:NtUnloadDriver - 0x773D6958->0x77F05DA0
             Iat - services.exe->ntdll.dll:DbgPrintEx - 0x773B1A56->0x77EE0866
             Iat - services.exe->ntdll.dll:RtlAdjustPrivilege - 0x7739BC4A->0x77ECAE3F
             Iat - services.exe->ntdll.dll:RtlExpandEnvironmentStrings_U - 0x773F2FB8->0x77F278B0
             Iat - services.exe->ntdll.dll:RtlInitializeSRWLock - 0x773E9911->0x77F19B8E
             Iat - services.exe->ntdll.dll:NtFlushKey - 0x773D5988->0x77F04DD0
             Iat - services.exe->ntdll.dll:NtOpenFile - 0x773D5CD8->0x77F05120
             Iat - services.exe->ntdll.dll:RtlDosPathNameToNtPathName_U - 0x773F2766->0x77F24BA4
             Iat - services.exe->ntdll.dll:NtOpenSymbolicLinkObject - 0x773D5DF8->0x77F05240
             Iat - services.exe->ntdll.dll:NtQuerySymbolicLinkObject - 0x773D61C8->0x77F05610
             Iat - services.exe->ntdll.dll:RtlFreeUnicodeString - 0x773E3296->0x77F12685
             Iat - services.exe->ntdll.dll:RtlAcquireSRWLockShared - 0x773E331E->0x77F15560
             Iat - services.exe->ntdll.dll:NtDeleteObjectAuditAlarm - 0x773D5828->0x77F04C70
             Iat - services.exe->ntdll.dll:RtlReleaseSRWLockShared - 0x773E3367->0x77F155A9
             Iat - services.exe->ntdll.dll:RtlAreAllAccessesGranted - 0x7739EDD6->0x77ECED31
             Iat - services.exe->ntdll.dll:NtCloseObjectAuditAlarm - 0x773D54D8->0x77F04920
             Iat - services.exe->ntdll.dll:RtlDeregisterWait - 0x773AB825->0x77EDACA0
             Iat - services.exe->ntdll.dll:RtlQueueWorkItem - 0x773BDB6D->0x77EEB7E3
             Iat - services.exe->ntdll.dll:RtlCopyLuid - 0x7739EDB8->0x77ECED4D
             Iat - services.exe->ntdll.dll:RtlDeleteSecurityObject - 0x773AA610->0x77EDA063
             Iat - services.exe->ntdll.dll:RtlAcquireSRWLockExclusive - 0x773E32DE->0x77F155FC
             Iat - services.exe->ntdll.dll:RtlReleaseSRWLockExclusive - 0x773E32B4->0x77F155D2
             Iat - services.exe->ntdll.dll:RtlReleaseResource - 0x773B9471->0x77EE87F2
             Iat - services.exe->ntdll.dll:RtlAcquireResourceExclusive - 0x773B94F1->0x77EE94A6
             Iat - services.exe->ntdll.dll:RtlAcquireResourceShared - 0x773BA14C->0x77EE8852
             Iat - services.exe->ntdll.dll:RtlInitializeResource - 0x773B9595->0x77EE9E99
             Iat - services.exe->ntdll.dll:NtInitializeRegistry - 0x773D5AF8->0x77F04F40
             Iat - services.exe->ntdll.dll:NtQueryKey - 0x773D60E8->0x77F05530
             Iat - services.exe->ntdll.dll:NtClose - 0x773D54C8->0x77F04910
             Iat - services.exe->ntdll.dll:RtlInitUnicodeString - 0x773C4180->0x77EF35B8
             Iat - services.exe->ntdll.dll:NtSetSystemEnvironmentValue - 0x773D6768->0x77F05BB0
             Iat - services.exe->ntdll.dll:RtlNtStatusToDosError - 0x773E3BF5->0x77F13AF5
             Iat - services.exe->ntdll.dll:NtShutdownSystem - 0x773D6828->0x77F05C70
             Iat - services.exe->ntdll.dll:EtwTraceMessage - 0x773BE41F->0x77EF18F3
             Iat - services.exe->ntdll.dll:RtlUnhandledExceptionFilter - 0x7744D1AB->0x77F7C2E2
             Iat - services.exe->ntdll.dll:NtQuerySystemInformation - 0x773D61F8->0x77F05640
             Iat - services.exe->ntdll.dll:RtlNtStatusToDosErrorNoTeb - 0x773E3C34->0x77F13B34
             Iat - services.exe->ntdll.dll:RtlInitializeSid - 0x773F6741->0x77F224A1
             Iat - services.exe->ntdll.dll:RtlAllocateHeap - 0x773E2D66->0x77F1209D
             Iat - services.exe->ntdll.dll:RtlLengthRequiredSid - 0x773F21F0->0x77F191B0
             Iat - services.exe->ntdll.dll:RtlSubAuthorityCountSid - 0x77400862->0x77F1C6C5
             Iat - services.exe->ntdll.dll:RtlSetSaclSecurityDescriptor - 0x773B6F58->0x77EE6748
             Iat - services.exe->ntdll.dll:RtlSetDaclSecurityDescriptor - 0x773F30D4->0x77F190B5
             Iat - services.exe->ntdll.dll:RtlSetGroupSecurityDescriptor - 0x773FF622->0x77F19162
             Iat - services.exe->ntdll.dll:RtlSetOwnerSecurityDescriptor - 0x773FF582->0x77F19114
             Iat - services.exe->ntdll.dll:RtlCreateSecurityDescriptor - 0x773F12B9->0x77F18F3A
             Iat - services.exe->ntdll.dll:RtlAddAce - 0x7739B437->0x77ECA558
             Iat - services.exe->ntdll.dll:RtlCreateAcl - 0x773F2595->0x77F19040
             Iat - services.exe->ntdll.dll:RtlNewSecurityObject - 0x7739F535->0x77ECF97B
             Iat - services.exe->ntdll.dll:RtlAnsiStringToUnicodeString - 0x773E56BF->0x77F1284B
             Iat - services.exe->ntdll.dll:RtlInitAnsiString - 0x773C4148->0x77EF3580
             Iat - services.exe->ntdll.dll:RtlUnicodeStringToAnsiString - 0x773E9E1E->0x77F1AD5F
             Iat - services.exe->ntdll.dll:EtwGetTraceEnableFlags - 0x773B8B55->0x77EEA4CA
             Iat - services.exe->ntdll.dll:EtwGetTraceEnableLevel - 0x773B8B1F->0x77EEA494
             Iat - services.exe->ntdll.dll:EtwGetTraceLoggerHandle - 0x773B8AB6->0x77EEA42B
             Iat - services.exe->CRYPTBASE.dll:SystemFunction005 - 0x75437C1C->0x10007C1C
             Iat - services.exe->CRYPTBASE.dll:SystemFunction029 - 0x75437897->0x10007897
             inline - len(9) services.exe - 0x006E1512->_
             inline - len(9) services.exe - 0x006E1522->_
             inline - len(1) services.exe - 0x006E1532->_
             inline - len(1) services.exe - 0x006E1542->_
             inline - len(1) services.exe - 0x006E156E->_
             inline - len(1) services.exe - 0x006E159E->_
             inline - len(1) services.exe - 0x006E15AE->_
             inline - len(13) services.exe - 0x006E15B6->_
             inline - len(1) services.exe - 0x006E266A->_
             inline - len(1) services.exe - 0x006E2765->_
             inline - len(1) services.exe - 0x006E276D->_
             inline - len(1) services.exe - 0x006E27F5->_
             inline - len(1) services.exe - 0x006E27FF->_
             inline - len(1) services.exe - 0x006E283F->_
             inline - len(1) services.exe - 0x006E2857->_
             inline - len(6) services.exe - 0x006E2864->_
             inline - len(1) services.exe - 0x006E289F->_
             inline - len(1) services.exe - 0x006E28E1->_
             inline - len(1) services.exe - 0x006E28EC->_
             inline - len(1) services.exe - 0x006E28FE->_
             inline - len(1) services.exe - 0x006E2909->_
             inline - len(1) services.exe - 0x006E291B->_
             inline - len(1) services.exe - 0x006E2977->_
             inline - len(1) services.exe - 0x006E29BE->_
             inline - len(1) services.exe - 0x006E29C6->_
             inline - len(1) services.exe - 0x006E29D9->_
             inline - len(1) services.exe - 0x006E29E1->_
             inline - len(6) services.exe - 0x006E2A33->_
             inline - len(1) services.exe - 0x006E2A82->_
             inline - len(1) services.exe - 0x006E2A88->_
             inline - len(1) services.exe - 0x006E2A90->_
             inline - len(1) services.exe - 0x006E2A9D->_
             inline - len(1) services.exe - 0x006E2AA7->_
             inline - len(1) services.exe - 0x006E2ABE->_
             inline - len(1) services.exe - 0x006E2AD0->_
             inline - len(1) services.exe - 0x006E2B28->_
             inline - len(1) services.exe - 0x006E2B33->_
             inline - len(1) services.exe - 0x006E2B45->_
             inline - len(6) services.exe - 0x006E2B4E->_
             inline - len(1) services.exe - 0x006E2B5D->_
             inline - len(1) services.exe - 0x006E2B65->_
             inline - len(1) services.exe - 0x006E2BA9->_
             inline - len(1) services.exe - 0x006E2BC9->_
             inline - len(1) services.exe - 0x006E2C02->_
             inline - len(1) services.exe - 0x006E2C0A->_
             inline - len(1) services.exe - 0x006E2C71->_
             inline - len(1) services.exe - 0x006E2D42->_
             inline - len(1) services.exe - 0x006E2D70->_
             inline - len(1) services.exe - 0x006E2D79->_
             inline - len(1) services.exe - 0x006E2D9C->_
             inline - len(6) services.exe - 0x006E2DEF->_
             inline - len(1) services.exe - 0x006E2E5B->_
             inline - len(1) services.exe - 0x006E2E8D->_
             inline - len(1) services.exe - 0x006E2EE8->_
             inline - len(1) services.exe - 0x006E2F04->_
             inline - len(1) services.exe - 0x006E2FBB->_
             inline - len(1) services.exe - 0x006E2FC5->_
             inline - len(1) services.exe - 0x006E3095->_
             inline - len(1) services.exe - 0x006E30C4->_
             inline - len(1) services.exe - 0x006E30EC->_
             inline - len(1) services.exe - 0x006E3102->_
             inline - len(1) services.exe - 0x006E315C->_
             inline - len(1) services.exe - 0x006E3183->_
             inline - len(1) services.exe - 0x006E3198->_
             inline - len(1) services.exe - 0x006E31E5->_
             inline - len(1) services.exe - 0x006E3276->_
             inline - len(1) services.exe - 0x006E327F->_
             inline - len(6) services.exe - 0x006E32A4->_
             inline - len(6) services.exe - 0x006E32C0->_
             inline - len(1) services.exe - 0x006E32CC->_
             inline - len(1) services.exe - 0x006E32EB->_
             inline - len(1) services.exe - 0x006E3330->_
             inline - len(1) services.exe - 0x006E333B->_
             inline - len(6) services.exe - 0x006E334E->_
             inline - len(1) services.exe - 0x006E3383->_
             inline - len(1) services.exe - 0x006E338D->_
             inline - len(1) services.exe - 0x006E3414->_
             inline - len(1) services.exe - 0x006E341A->_
             inline - len(1) services.exe - 0x006E343B->_
             inline - len(1) services.exe - 0x006E345E->_
             inline - len(1) services.exe - 0x006E3481->_
             inline - len(1) services.exe - 0x006E34D8->_
             inline - len(1) services.exe - 0x006E351B->_
             inline - len(1) services.exe - 0x006E3531->_
             inline - len(1) services.exe - 0x006E354F->_
             inline - len(9) services.exe - 0x006E356A->_
             inline - len(1) services.exe - 0x006E469E->_
             inline - len(1) services.exe - 0x006E47D7->_
             inline - len(5) services.exe - 0x006E47DE->_
             inline - len(9) services.exe - 0x006E47F2->_
             inline - len(1) services.exe - 0x006E4802->_
             inline - len(1) services.exe - 0x006E4812->_
             inline - len(1) services.exe - 0x006E486E->_
             inline - len(1) services.exe - 0x006E487E->_
             inline - len(13) services.exe - 0x006E4886->_
             inline - len(9) services.exe - 0x006E48AA->_
             inline - len(1) services.exe - 0x006E495E->_
             inline - len(1) services.exe - 0x006E4977->_
             inline - len(1) services.exe - 0x006E49CA->_
             inline - len(1) services.exe - 0x006E4A3F->_
             inline - len(1) services.exe - 0x006E4B3A->_
             inline - len(1) services.exe - 0x006E4B5F->_
             inline - len(1) services.exe - 0x006E4B69->_
             inline - len(11) services.exe - 0x006E4BB7->_
             inline - len(1) services.exe - 0x006E4BD1->_
             inline - len(1) services.exe - 0x006E4C3C->_
             inline - len(1) services.exe - 0x006E4C45->_
             inline - len(1) services.exe - 0x006E4C4B->_
             inline - len(1) services.exe - 0x006E4C55->_
             inline - len(1) services.exe - 0x006E4CBA->_
             inline - len(6) services.exe - 0x006E4CCA->_
             inline - len(1) services.exe - 0x006E4CEB->_
             inline - len(1) services.exe - 0x006E4CFE->_
             inline - len(6) services.exe - 0x006E4D37->_
             inline - len(1) services.exe - 0x006E4D4C->_
             inline - len(1) services.exe - 0x006E4D57->_
             inline - len(1) services.exe - 0x006E4D69->_
             inline - len(6) services.exe - 0x006E4D93->_
             inline - len(1) services.exe - 0x006E4D9E->_
             inline - len(1) services.exe - 0x006E4DB0->_
             inline - len(1) services.exe - 0x006E4DCD->_
             inline - len(1) services.exe - 0x006E4E0B->_
             inline - len(1) services.exe - 0x006E4E5E->_
             inline - len(1) services.exe - 0x006E4E66->_
             inline - len(6) services.exe - 0x006E4E86->_
             inline - len(1) services.exe - 0x006E4E9B->_
             inline - len(1) services.exe - 0x006E4EE2->_
             inline - len(1) services.exe - 0x006E4F16->_
             inline - len(6) services.exe - 0x006E4F83->_
             inline - len(6) services.exe - 0x006E4F98->_
             inline - len(1) services.exe - 0x006E4FC2->_
             inline - len(6) services.exe - 0x006E4FE3->_
             inline - len(1) services.exe - 0x006E4FF6->_
             inline - len(1) services.exe - 0x006E5007->_
             inline - len(1) services.exe - 0x006E5080->_
             inline - len(1) services.exe - 0x006E50B8->_
             inline - len(1) services.exe - 0x006E50BE->_
             inline - len(1) services.exe - 0x006E50C6->_
             inline - len(1) services.exe - 0x006E50D4->_
             inline - len(1) services.exe - 0x006E5103->_
             inline - len(1) services.exe - 0x006E5110->_
             inline - len(1) services.exe - 0x006E5116->_
             inline - len(1) services.exe - 0x006E5128->_
             inline - len(1) services.exe - 0x006E51E5->_
             inline - len(1) services.exe - 0x006E521C->_
             inline - len(1) services.exe - 0x006E5226->_
             inline - len(1) services.exe - 0x006E5233->_
             inline - len(1) services.exe - 0x006E52BC->_
             inline - len(1) services.exe - 0x006E530C->_
             inline - len(1) services.exe - 0x006E5333->_
             inline - len(1) services.exe - 0x006E5367->_
             inline - len(1) services.exe - 0x006E5385->_
             inline - len(1) services.exe - 0x006E539C->_
             inline - len(1) services.exe - 0x006E53AE->_
             inline - len(1) services.exe - 0x006E5458->_
             inline - len(1) services.exe - 0x006E548B->_
             inline - len(1) services.exe - 0x006E54C7->_
             inline - len(1) services.exe - 0x006E54E4->_
             inline - len(1) services.exe - 0x006E5542->_
             inline - len(1) services.exe - 0x006E556A->_
             inline - len(1) services.exe - 0x006E559E->_
             inline - len(1) services.exe - 0x006E55EB->_
             inline - len(1) services.exe - 0x006E56A0->_
             inline - len(1) services.exe - 0x006E56A6->_
             inline - len(1) services.exe - 0x006E56B6->_
             inline - len(1) services.exe - 0x006E56BD->_
             inline - len(1) services.exe - 0x006E571B->_
             inline - len(1) services.exe - 0x006E5721->_
             inline - len(1) services.exe - 0x006E5744->_
             inline - len(6) services.exe - 0x006E577F->_
             inline - len(1) services.exe - 0x006E5794->_
             inline - len(6) services.exe - 0x006E57DA->_
             inline - len(1) services.exe - 0x006E57F3->_
             inline - len(1) services.exe - 0x006E57FD->_
             inline - len(6) services.exe - 0x006E582A->_
             inline - len(1) services.exe - 0x006E588A->_
             inline - len(1) services.exe - 0x006E58DF->_
             inline - len(1) services.exe - 0x006E5902->_
             inline - len(1) services.exe - 0x006E5931->_
             inline - len(11) services.exe - 0x006E59A1->_
             inline - len(1) services.exe - 0x006E59E1->_
             inline - len(1) services.exe - 0x006E59FB->_
             inline - len(1) services.exe - 0x006E5A12->_
             inline - len(1) services.exe - 0x006E5AA9->_
             inline - len(1) services.exe - 0x006E5B2B->_
             inline - len(1) services.exe - 0x006E5B5F->_
             inline - len(1) services.exe - 0x006E5B7B->_
             inline - len(1) services.exe - 0x006E5BCF->_
             inline - len(6) services.exe - 0x006E5BDC->_
             inline - len(1) services.exe - 0x006E5BF6->_
             inline - len(1) services.exe - 0x006E5C13->_
             inline - len(1) services.exe - 0x006E5C1D->_
             inline - len(1) services.exe - 0x006E5C3C->_
             inline - len(1) services.exe - 0x006E5C62->_
             inline - len(1) services.exe - 0x006E5C8E->_
             inline - len(1) services.exe - 0x006E5CB1->_
             inline - len(6) services.exe - 0x006E5D62->_
             inline - len(6) services.exe - 0x006E5D9D->_
             inline - len(1) services.exe - 0x006E5DCC->_
             inline - len(1) services.exe - 0x006E5DEB->_
             inline - len(1) services.exe - 0x006E5E28->_
             inline - len(1) services.exe - 0x006E5E40->_
             inline - len(1) services.exe - 0x006E5E62->_
             inline - len(1) services.exe - 0x006E5EA4->_
             inline - len(1) services.exe - 0x006E5EAB->_
             inline - len(1) services.exe - 0x006E5EE3->_
             inline - len(1) services.exe - 0x006E5F04->_
             inline - len(1) services.exe - 0x006E5F33->_
             inline - len(1) services.exe - 0x006E5F4F->_
             inline - len(1) services.exe - 0x006E5FC8->_
             inline - len(1) services.exe - 0x006E6076->_
             inline - len(1) services.exe - 0x006E60C0->_
             inline - len(1) services.exe - 0x006E6114->_
             inline - len(1) services.exe - 0x006E613F->_
             inline - len(1) services.exe - 0x006E6155->_
             inline - len(1) services.exe - 0x006E618F->_
             inline - len(1) services.exe - 0x006E6264->_
             inline - len(1) services.exe - 0x006E62A5->_
             inline - len(1) services.exe - 0x006E6312->_
             inline - len(1) services.exe - 0x006E6358->_
             inline - len(1) services.exe - 0x006E639A->_
             inline - len(1) services.exe - 0x006E6468->_
             inline - len(1) services.exe - 0x006E6484->_
             inline - len(1) services.exe - 0x006E649B->_
             inline - len(1) services.exe - 0x006E64C2->_
             inline - len(1) services.exe - 0x006E64DC->_
             inline - len(1) services.exe - 0x006E64EF->_
             inline - len(1) services.exe - 0x006E64F6->_
             inline - len(1) services.exe - 0x006E6541->_
             inline - len(1) services.exe - 0x006E659E->_
             inline - len(1) services.exe - 0x006E65DB->_
             inline - len(1) services.exe - 0x006E660E->_
             inline - len(1) services.exe - 0x006E6670->_
             inline - len(1) services.exe - 0x006E6693->_
             inline - len(1) services.exe - 0x006E66CB->_
             inline - len(1) services.exe - 0x006E6952->_
             inline - len(1) services.exe - 0x006E6959->_
             inline - len(1) services.exe - 0x006E6962->_
             inline - len(1) services.exe - 0x006E696B->_
             inline - len(1) services.exe - 0x006E697D->_
             inline - len(1) services.exe - 0x006E6986->_
             inline - len(1) services.exe - 0x006E698F->_
             inline - len(1) services.exe - 0x006E69A0->_
             inline - len(1) services.exe - 0x006E69A6->_
             inline - len(1) services.exe - 0x006E6A96->_
             inline - len(1) services.exe - 0x006E6AA1->_
             inline - len(1) services.exe - 0x006E6AB7->_
             inline - len(1) services.exe - 0x006E6AC7->_
             inline - len(1) services.exe - 0x006E6ADB->_
             inline - len(1) services.exe - 0x006E6AE7->_
             inline - len(1) services.exe - 0x006E6AF3->_
             inline - len(1) services.exe - 0x006E6BAE->_
             inline - len(1) services.exe - 0x006E6C06->_
             inline - len(1) services.exe - 0x006E6C7B->_
             inline - len(6) services.exe - 0x006E6CC6->_
             inline - len(1) services.exe - 0x006E6CF7->_
             inline - len(1) services.exe - 0x006E6CFD->_
             inline - len(1) services.exe - 0x006E6D1B->_
             inline - len(1) services.exe - 0x006E6D24->_
             inline - len(1) services.exe - 0x006E6D72->_
             inline - len(1) services.exe - 0x006E6D9C->_
             inline - len(6) services.exe - 0x006E6DF2->_
             inline - len(1) services.exe - 0x006E6EA1->_
             inline - len(6) services.exe - 0x006E6ED3->_
             inline - len(1) services.exe - 0x006E6EE8->_
             inline - len(6) services.exe - 0x006E6F14->_
             inline - len(1) services.exe - 0x006E6FA2->_
             inline - len(1) services.exe - 0x006E6FF9->_
             inline - len(1) services.exe - 0x006E7044->_
             inline - len(1) services.exe - 0x006E704A->_
             inline - len(1) services.exe - 0x006E705B->_
             inline - len(1) services.exe - 0x006E706F->_
             inline - len(1) services.exe - 0x006E7093->_
             inline - len(1) services.exe - 0x006E70C2->_
             inline - len(1) services.exe - 0x006E70D0->_
             inline - len(1) services.exe - 0x006E70E1->_
             inline - len(1) services.exe - 0x006E70FD->_
             inline - len(1) services.exe - 0x006E7120->_
             inline - len(1) services.exe - 0x006E714D->_
             inline - len(1) services.exe - 0x006E7154->_
             inline - len(1) services.exe - 0x006E715C->_
             inline - len(1) services.exe - 0x006E7162->_
             inline - len(1) services.exe - 0x006E7168->_
             inline - len(1) services.exe - 0x006E71C1->_
             inline - len(1) services.exe - 0x006E721B->_
             inline - len(1) services.exe - 0x006E7250->_
             inline - len(1) services.exe - 0x006E7267->_
             inline - len(1) services.exe - 0x006E72CB->_
             inline - len(1) services.exe - 0x006E734D->_
             inline - len(6) services.exe - 0x006E7394->_
             inline - len(1) services.exe - 0x006E73A0->_
             inline - len(1) services.exe - 0x006E73A7->_
             inline - len(1) services.exe - 0x006E73FC->_
             inline - len(1) services.exe - 0x006E7435->_
             inline - len(1) services.exe - 0x006E743B->_
             inline - len(1) services.exe - 0x006E7445->_
             inline - len(1) services.exe - 0x006E74A1->_
             inline - len(1) services.exe - 0x006E74B3->_
             inline - len(1) services.exe - 0x006E74C2->_
             inline - len(6) services.exe - 0x006E74CD->_
             inline - len(1) services.exe - 0x006E74FD->_
             inline - len(1) services.exe - 0x006E7555->_
             inline - len(1) services.exe - 0x006E7589->_
             inline - len(1) services.exe - 0x006E75A1->_
             inline - len(1) services.exe - 0x006E75E7->_
             inline - len(1) services.exe - 0x006E75FA->_
             inline - len(1) services.exe - 0x006E7617->_
             inline - len(1) services.exe - 0x006E762E->_
             inline - len(1) services.exe - 0x006E763C->_
             inline - len(1) services.exe - 0x006E764F->_
             inline - len(1) services.exe - 0x006E7659->_
             inline - len(6) services.exe - 0x006E773D->_
             inline - len(1) services.exe - 0x006E7762->_
             inline - len(1) services.exe - 0x006E777C->_
             inline - len(1) services.exe - 0x006E7820->_
             inline - len(1) services.exe - 0x006E78BF->_
             inline - len(1) services.exe - 0x006E78C5->_
             inline - len(1) services.exe - 0x006E78D7->_
             inline - len(1) services.exe - 0x006E78DD->_
             inline - len(1) services.exe - 0x006E7916->_
             inline - len(1) services.exe - 0x006E7952->_
             inline - len(1) services.exe - 0x006E7985->_
             inline - len(1) services.exe - 0x006E799C->_
             inline - len(1) services.exe - 0x006E79CE->_
             inline - len(1) services.exe - 0x006E79DE->_
             inline - len(1) services.exe - 0x006E79EC->_
             inline - len(1) services.exe - 0x006E79F3->_
             inline - len(1) services.exe - 0x006E7A03->_
             inline - len(1) services.exe - 0x006E7A0C->_
             inline - len(6) services.exe - 0x006E7A75->_
             inline - len(6) services.exe - 0x006E7AC8->_
             inline - len(1) services.exe - 0x006E7AF5->_
             inline - len(1) services.exe - 0x006E7B0E->_
             inline - len(1) services.exe - 0x006E7B42->_
             inline - len(1) services.exe - 0x006E7B7A->_
             inline - len(1) services.exe - 0x006E7B92->_
             inline - len(1) services.exe - 0x006E7B99->_
             inline - len(1) services.exe - 0x006E7B9F->_
             inline - len(1) services.exe - 0x006E7BAD->_
             inline - len(1) services.exe - 0x006E7BC5->_
             inline - len(1) services.exe - 0x006E7BCF->_
             inline - len(1) services.exe - 0x006E7C08->_
             inline - len(1) services.exe - 0x006E7C32->_
             inline - len(1) services.exe - 0x006E7C39->_
             inline - len(6) services.exe - 0x006E7C3F->_
             inline - len(1) services.exe - 0x006E7C61->_
             inline - len(1) services.exe - 0x006E7C76->_
             inline - len(1) services.exe - 0x006E7CA4->_
             inline - len(1) services.exe - 0x006E7CBC->_
             inline - len(6) services.exe - 0x006E7CC3->_
             inline - len(6) services.exe - 0x006E7CE5->_
             inline - len(1) services.exe - 0x006E7D37->_
             inline - len(1) services.exe - 0x006E7D3D->_
             inline - len(1) services.exe - 0x006E7D77->_
             inline - len(1) services.exe - 0x006E7D7D->_
             inline - len(1) services.exe - 0x006E7DAC->_
             inline - len(6) services.exe - 0x006E7DF0->_
             inline - len(1) services.exe - 0x006E7DFB->_
             inline - len(1) services.exe - 0x006E7E1B->_
             inline - len(1) services.exe - 0x006E7E6D->_
             inline - len(1) services.exe - 0x006E7EA0->_
             inline - len(1) services.exe - 0x006E7EB7->_
             inline - len(1) services.exe - 0x006E7EF7->_
             inline - len(1) services.exe - 0x006E8015->_
             inline - len(1) services.exe - 0x006E8030->_
             inline - len(1) services.exe - 0x006E8046->_
             inline - len(1) services.exe - 0x006E804C->_
             inline - len(1) services.exe - 0x006E8096->_
             inline - len(1) services.exe - 0x006E812D->_
             inline - len(1) services.exe - 0x006E8139->_
             inline - len(1) services.exe - 0x006E813F->_
             inline - len(1) services.exe - 0x006E814C->_
             inline - len(6) services.exe - 0x006E81B5->_
             inline - len(1) services.exe - 0x006E81CC->_
             inline - len(1) services.exe - 0x006E81DE->_
             inline - len(1) services.exe - 0x006E81F3->_
             inline - len(1) services.exe - 0x006E820D->_
             inline - len(1) services.exe - 0x006E8213->_
             inline - len(1) services.exe - 0x006E8245->_
             inline - len(1) services.exe - 0x006E8268->_
             inline - len(1) services.exe - 0x006E8274->_
             inline - len(1) services.exe - 0x006E82A5->_
             inline - len(1) services.exe - 0x006E82E5->_
             inline - len(1) services.exe - 0x006E82F5->_
             inline - len(1) services.exe - 0x006E82FB->_
             inline - len(1) services.exe - 0x006E8301->_
             inline - len(1) services.exe - 0x006E8358->_
             inline - len(1) services.exe - 0x006E8361->_
             inline - len(1) services.exe - 0x006E8371->_
             inline - len(6) services.exe - 0x006E838F->_
             inline - len(1) services.exe - 0x006E839B->_
             inline - len(1) services.exe - 0x006E83A2->_
             inline - len(1) services.exe - 0x006E83BC->_
             inline - len(1) services.exe - 0x006E83C2->_
             inline - len(1) services.exe - 0x006E83F7->_
             inline - len(1) services.exe - 0x006E83FE->_
             inline - len(1) services.exe - 0x006E8424->_
             inline - len(1) services.exe - 0x006E842B->_
             inline - len(6) services.exe - 0x006E8435->_
             inline - len(1) services.exe - 0x006E8440->_
             inline - len(1) services.exe - 0x006E8450->_
             inline - len(1) services.exe - 0x006E847E->_
             inline - len(1) services.exe - 0x006E84A1->_
             inline - len(1) services.exe - 0x006E84CD->_
             inline - len(11) services.exe - 0x006E84F4->_
             inline - len(1) services.exe - 0x006E8511->_
             inline - len(1) services.exe - 0x006E8523->_
             inline - len(6) services.exe - 0x006E8552->_
             inline - len(1) services.exe - 0x006E85A2->_
             inline - len(6) services.exe - 0x006E85AB->_
             inline - len(1) services.exe - 0x006E85F2->_
             inline - len(1) services.exe - 0x006E85FD->_
             inline - len(1) services.exe - 0x006E860E->_
             inline - len(1) services.exe - 0x006E861D->_
             inline - len(1) services.exe - 0x006E8646->_
             inline - len(1) services.exe - 0x006E8660->_
             inline - len(1) services.exe - 0x006E8666->_
             inline - len(1) services.exe - 0x006E867C->_
             inline - len(1) services.exe - 0x006E86A4->_
             inline - len(1) services.exe - 0x006E86DC->_
             inline - len(1) services.exe - 0x006E86E2->_
             inline - len(1) services.exe - 0x006E870E->_
             inline - len(1) services.exe - 0x006E8714->_
             inline - len(1) services.exe - 0x006E8722->_
             inline - len(6) services.exe - 0x006E873A->_
             inline - len(6) services.exe - 0x006E87E7->_
             inline - len(6) services.exe - 0x006E8824->_
             inline - len(1) services.exe - 0x006E887A->_
             inline - len(1) services.exe - 0x006E8880->_
             inline - len(1) services.exe - 0x006E88B8->_
             inline - len(1) services.exe - 0x006E88D3->_
             inline - len(11) services.exe - 0x006E88D9->_
             inline - len(1) services.exe - 0x006E8939->_
             inline - len(1) services.exe - 0x006E895D->_
             inline - len(1) services.exe - 0x006E8963->_
             inline - len(1) services.exe - 0x006E89FB->_
             inline - len(1) services.exe - 0x006E8A01->_
             inline - len(1) services.exe - 0x006E8A18->_
             inline - len(1) services.exe - 0x006E8A21->_
             inline - len(1) services.exe - 0x006E8A4F->_
             inline - len(6) services.exe - 0x006E8A58->_
             inline - len(1) services.exe - 0x006E8A73->_
             inline - len(1) services.exe - 0x006E8A79->_
             inline - len(6) services.exe - 0x006E8B07->_
             inline - len(1) services.exe - 0x006E8B21->_
             inline - len(1) services.exe - 0x006E8B3C->_
             inline - len(1) services.exe - 0x006E8B4B->_
             inline - len(1) services.exe - 0x006E8B89->_
             inline - len(1) services.exe - 0x006E8B98->_
             inline - len(1) services.exe - 0x006E8BA6->_
             inline - len(1) services.exe - 0x006E8BF7->_
             inline - len(1) services.exe - 0x006E8BFE->_
             inline - len(1) services.exe - 0x006E8C49->_
             inline - len(1) services.exe - 0x006E8C50->_
             inline - len(6) services.exe - 0x006E8C68->_
             inline - len(1) services.exe - 0x006E8C87->_
             inline - len(1) services.exe - 0x006E8D72->_
             inline - len(1) services.exe - 0x006E8D98->_
             inline - len(1) services.exe - 0x006E8DC5->_
             inline - len(1) services.exe - 0x006E8E18->_
             inline - len(6) services.exe - 0x006E8E3F->_
             inline - len(1) services.exe - 0x006E8E5E->_
             inline - len(1) services.exe - 0x006E8EF2->_
             inline - len(1) services.exe - 0x006E8F1F->_
             inline - len(1) services.exe - 0x006E8F8A->_
             inline - len(1) services.exe - 0x006E902D->_
             inline - len(6) services.exe - 0x006E9034->_
             inline - len(1) services.exe - 0x006E9042->_
             inline - len(1) services.exe - 0x006E9053->_
             inline - len(1) services.exe - 0x006E905C->_
             inline - len(1) services.exe - 0x006E9064->_
             inline - len(1) services.exe - 0x006E9082->_
             inline - len(1) services.exe - 0x006E9089->_
             inline - len(6) services.exe - 0x006E909E->_
             inline - len(1) services.exe - 0x006E90B6->_
             inline - len(1) services.exe - 0x006E90CC->_
             inline - len(1) services.exe - 0x006E912F->_
             inline - len(6) services.exe - 0x006E9186->_
             inline - len(1) services.exe - 0x006E91C5->_
             inline - len(1) services.exe - 0x006E91F4->_
             inline - len(6) services.exe - 0x006E9230->_
             inline - len(1) services.exe - 0x006E924D->_
             inline - len(1) services.exe - 0x006E9291->_
             inline - len(6) services.exe - 0x006E92F0->_
             inline - len(1) services.exe - 0x006E9318->_
             inline - len(1) services.exe - 0x006E932A->_
             inline - len(1) services.exe - 0x006E9353->_
             inline - len(1) services.exe - 0x006E9411->_
             inline - len(1) services.exe - 0x006E9418->_
             inline - len(1) services.exe - 0x006E9421->_
             inline - len(1) services.exe - 0x006E94AC->_
             inline - len(1) services.exe - 0x006E94C7->_
             inline - len(1) services.exe - 0x006E95BA->_
             inline - len(1) services.exe - 0x006E95CD->_
             inline - len(1) services.exe - 0x006E95E7->_
             inline - len(1) services.exe - 0x006E9616->_
             inline - len(1) services.exe - 0x006E961C->_
             inline - len(1) services.exe - 0x006E9650->_
             inline - len(1) services.exe - 0x006E9684->_
             inline - len(1) services.exe - 0x006E96E2->_
             inline - len(1) services.exe - 0x006E975E->_
             inline - len(1) services.exe - 0x006E9E08->_
             inline - len(1) services.exe - 0x006E9E0E->_
             inline - len(1) services.exe - 0x006E9E35->_
             inline - len(1) services.exe - 0x006E9E3D->_
             inline - len(1) services.exe - 0x006E9E57->_
             inline - len(1) services.exe - 0x006E9E6E->_
             inline - len(1) services.exe - 0x006E9E89->_
             inline - len(1) services.exe - 0x006E9EBB->_
             inline - len(1) services.exe - 0x006E9EC4->_
             inline - len(1) services.exe - 0x006E9ED9->_
             inline - len(1) services.exe - 0x006E9EFB->_
             inline - len(1) services.exe - 0x006E9F2B->_
             inline - len(1) services.exe - 0x006E9F5C->_
             inline - len(1) services.exe - 0x006E9F78->_
             inline - len(1) services.exe - 0x006EA020->_
             inline - len(1) services.exe - 0x006EA044->_
             inline - len(1) services.exe - 0x006EA053->_
             inline - len(1) services.exe - 0x006EA060->_
             inline - len(1) services.exe - 0x006EA067->_
             inline - len(1) services.exe - 0x006EA099->_
             inline - len(1) services.exe - 0x006EA0DF->_
             inline - len(1) services.exe - 0x006EA0E8->_
             inline - len(1) services.exe - 0x006EA0F6->_
             inline - len(1) services.exe - 0x006EA0FD->_
             inline - len(1) services.exe - 0x006EA114->_
             inline - len(6) services.exe - 0x006EA13C->_
             inline - len(1) services.exe - 0x006EA18E->_
             inline - len(1) services.exe - 0x006EA197->_
             inline - len(1) services.exe - 0x006EA1FE->_
             inline - len(1) services.exe - 0x006EA224->_
             inline - len(1) services.exe - 0x006EA245->_
             inline - len(1) services.exe - 0x006EA2A2->_
             inline - len(1) services.exe - 0x006EA316->_
             inline - len(1) services.exe - 0x006EA360->_
             inline - len(1) services.exe - 0x006EA366->_
             inline - len(1) services.exe - 0x006EA397->_
             inline - len(1) services.exe - 0x006EA3AA->_
             inline - len(1) services.exe - 0x006EA424->_
             inline - len(1) services.exe - 0x006EA42A->_
             inline - len(6) services.exe - 0x006EA560->_
             inline - len(1) services.exe - 0x006EA58D->_
             inline - len(1) services.exe - 0x006EA607->_
             inline - len(1) services.exe - 0x006EA6BE->_
             inline - len(1) services.exe - 0x006EA728->_
             inline - len(1) services.exe - 0x006EA72E->_
             inline - len(1) services.exe - 0x006EA750->_
             inline - len(1) services.exe - 0x006EA760->_
             inline - len(1) services.exe - 0x006EA77A->_
             inline - len(1) services.exe - 0x006EA7EF->_
             inline - len(1) services.exe - 0x006EA7F5->_
             inline - len(1) services.exe - 0x006EA82D->_
             inline - len(1) services.exe - 0x006EA83F->_
             inline - len(1) services.exe - 0x006EA8A4->_
             inline - len(1) services.exe - 0x006EA8AB->_
             inline - len(1) services.exe - 0x006EA8FB->_
             inline - len(1) services.exe - 0x006EA936->_
             inline - len(1) services.exe - 0x006EA942->_
             inline - len(1) services.exe - 0x006EA963->_
             inline - len(1) services.exe - 0x006EA96E->_
             inline - len(1) services.exe - 0x006EA979->_
             inline - len(1) services.exe - 0x006EA984->_
             inline - len(1) services.exe - 0x006EA98F->_
             inline - len(1) services.exe - 0x006EA996->_
             inline - len(1) services.exe - 0x006EAA25->_
             inline - len(1) services.exe - 0x006EAA37->_
             inline - len(1) services.exe - 0x006EAA4C->_
             inline - len(1) services.exe - 0x006EAA80->_
             inline - len(1) services.exe - 0x006EAA8C->_
             inline - len(1) services.exe - 0x006EAA95->_
             inline - len(1) services.exe - 0x006EAAA5->_
             inline - len(6) services.exe - 0x006EAB13->_
             inline - len(1) services.exe - 0x006EAB5F->_
             inline - len(1) services.exe - 0x006EAB71->_
             inline - len(1) services.exe - 0x006EAB77->_
             inline - len(1) services.exe - 0x006EABA3->_
             inline - len(6) services.exe - 0x006EABD9->_
             inline - len(1) services.exe - 0x006EABEE->_
             inline - len(1) services.exe - 0x006EAC21->_
             inline - len(1) services.exe - 0x006EAC9D->_
             inline - len(6) services.exe - 0x006EACB0->_
             inline - len(1) services.exe - 0x006EACC6->_
             inline - len(1) services.exe - 0x006EAD29->_
             inline - len(6) services.exe - 0x006EAD62->_
             inline - len(1) services.exe - 0x006EAD6E->_
             inline - len(1) services.exe - 0x006EADB3->_
             inline - len(1) services.exe - 0x006EAEBC->_
             inline - len(1) services.exe - 0x006EAEC9->_
             inline - len(1) services.exe - 0x006EAEDB->_
             inline - len(1) services.exe - 0x006EAF28->_
             inline - len(1) services.exe - 0x006EAF34->_
             inline - len(1) services.exe - 0x006EAF40->_
             inline - len(1) services.exe - 0x006EAF61->_
             inline - len(6) services.exe - 0x006EAFB4->_
             inline - len(1) services.exe - 0x006EAFD9->_
             inline - len(1) services.exe - 0x006EB00C->_
             inline - len(1) services.exe - 0x006EB015->_
             inline - len(1) services.exe - 0x006EB043->_
             inline - len(1) services.exe - 0x006EB0AF->_
             inline - len(1) services.exe - 0x006EB0B7->_
             inline - len(1) services.exe - 0x006EB0E8->_
             inline - len(1) services.exe - 0x006EB190->_
             inline - len(1) services.exe - 0x006EB1C7->_
             inline - len(1) services.exe - 0x006EB1CE->_
             inline - len(1) services.exe - 0x006EB239->_
             inline - len(1) services.exe - 0x006EB242->_
             inline - len(6) services.exe - 0x006EB294->_
             inline - len(6) services.exe - 0x006EB2AE->_
             inline - len(1) services.exe - 0x006EB2BA->_
             inline - len(1) services.exe - 0x006EB2E4->_
             inline - len(1) services.exe - 0x006EB309->_
             inline - len(6) services.exe - 0x006EB372->_
             inline - len(1) services.exe - 0x006EB37E->_
             inline - len(1) services.exe - 0x006EB3A3->_
             inline - len(1) services.exe - 0x006EB3D7->_
             inline - len(1) services.exe - 0x006EB407->_
             inline - len(1) services.exe - 0x006EB40D->_
             inline - len(1) services.exe - 0x006EB41A->_
             inline - len(6) services.exe - 0x006EB442->_
             inline - len(1) services.exe - 0x006EB44E->_
             inline - len(6) services.exe - 0x006EB459->_
             inline - len(1) services.exe - 0x006EB468->_
             inline - len(1) services.exe - 0x006EB47D->_
             inline - len(1) services.exe - 0x006EB49A->_
             inline - len(1) services.exe - 0x006EB511->_
             inline - len(1) services.exe - 0x006EB54C->_
             inline - len(1) services.exe - 0x006EB552->_
             inline - len(1) services.exe - 0x006EB5A7->_
             inline - len(1) services.exe - 0x006EB5B2->_
             inline - len(1) services.exe - 0x006EB6CA->_
             inline - len(1) services.exe - 0x006EB6D4->_
             inline - len(1) services.exe - 0x006EB6DE->_
             inline - len(1) services.exe - 0x006EB715->_
             inline - len(1) services.exe - 0x006EB71C->_
             inline - len(1) services.exe - 0x006EB742->_
             inline - len(1) services.exe - 0x006EB8E2->_
             inline - len(1) services.exe - 0x006EB96C->_
             inline - len(1) services.exe - 0x006EB98F->_
             inline - len(1) services.exe - 0x006EB9C0->_
             inline - len(11) services.exe - 0x006EBA09->_
             inline - len(1) services.exe - 0x006EBA2B->_
             inline - len(1) services.exe - 0x006EBA3D->_
             inline - len(1) services.exe - 0x006EBA53->_
             inline - len(1) services.exe - 0x006EBA8D->_
             inline - len(1) services.exe - 0x006EBABC->_
             inline - len(1) services.exe - 0x006EBAE7->_
             inline - len(1) services.exe - 0x006EBAF8->_
             inline - len(1) services.exe - 0x006EBAFF->_
             inline - len(1) services.exe - 0x006EBB08->_
             inline - len(1) services.exe - 0x006EBB11->_
             inline - len(6) services.exe - 0x006EBCD9->_
             inline - len(1) services.exe - 0x006EBD07->_
             inline - len(1) services.exe - 0x006EBD19->_
             inline - len(1) services.exe - 0x006EBD85->_
             inline - len(1) services.exe - 0x006EBDA3->_
             inline - len(1) services.exe - 0x006EBDB2->_
             inline - len(1) services.exe - 0x006EBDB8->_
             inline - len(1) services.exe - 0x006EBDC4->_
             inline - len(6) services.exe - 0x006EBDE2->_
             inline - len(6) services.exe - 0x006EBE07->_
             inline - len(1) services.exe - 0x006EBE13->_
             inline - len(1) services.exe - 0x006EBE1A->_
             inline - len(6) services.exe - 0x006EBE39->_
             inline - len(1) services.exe - 0x006EBE6D->_
             inline - len(1) services.exe - 0x006EBE78->_
             inline - len(1) services.exe - 0x006EBEBB->_
             inline - len(1) services.exe - 0x006EBEE0->_
             inline - len(1) services.exe - 0x006EBF1D->_
             inline - len(1) services.exe - 0x006EBFB7->_
             inline - len(1) services.exe - 0x006EBFBD->_
             inline - len(1) services.exe - 0x006EBFED->_
             inline - len(1) services.exe - 0x006EBFF6->_
             inline - len(1) services.exe - 0x006EC04E->_
             inline - len(1) services.exe - 0x006EC054->_
             inline - len(1) services.exe - 0x006EC05B->_
             inline - len(1) services.exe - 0x006EC078->_
             inline - len(1) services.exe - 0x006EC0C1->_
             inline - len(1) services.exe - 0x006EC0F6->_
             inline - len(1) services.exe - 0x006EC173->_
             inline - len(1) services.exe - 0x006EC199->_
             inline - len(11) services.exe - 0x006EC1BB->_
             inline - len(1) services.exe - 0x006EC252->_
             inline - len(1) services.exe - 0x006EC286->_
             inline - len(1) services.exe - 0x006EC2C3->_
             inline - len(1) services.exe - 0x006EC2DB->_
             inline - len(1) services.exe - 0x006EC2EE->_
             inline - len(1) services.exe - 0x006EC2FE->_
             inline - len(1) services.exe - 0x006EC30E->_
             inline - len(6) services.exe - 0x006EC37D->_
             inline - len(1) services.exe - 0x006EC393->_
             inline - len(1) services.exe - 0x006EC39F->_
             inline - len(1) services.exe - 0x006EC403->_
             inline - len(1) services.exe - 0x006EC421->_
             inline - len(1) services.exe - 0x006EC42C->_
             inline - len(1) services.exe - 0x006EC438->_
             inline - len(1) services.exe - 0x006EC458->_
             inline - len(1) services.exe - 0x006EC467->_
             inline - len(1) services.exe - 0x006EC48E->_
             inline - len(1) services.exe - 0x006EC4C7->_
             inline - len(1) services.exe - 0x006EC4FE->_
             inline - len(6) services.exe - 0x006EC50B->_
             inline - len(1) services.exe - 0x006EC55C->_
             inline - len(1) services.exe - 0x006EC562->_
             inline - len(1) services.exe - 0x006EC58E->_
             inline - len(1) services.exe - 0x006EC596->_
             inline - len(1) services.exe - 0x006EC59C->_
             inline - len(1) services.exe - 0x006EC5B5->_
             inline - len(1) services.exe - 0x006EC5CF->_
             inline - len(1) services.exe - 0x006EC5DF->_
             inline - len(1) services.exe - 0x006EC60B->_
             inline - len(1) services.exe - 0x006EC6D7->_
             inline - len(1) services.exe - 0x006EC709->_
             inline - len(33) services.exe - 0x006EC899->_
             inline - len(1) services.exe - 0x006EC8D3->_
             inline - len(1) services.exe - 0x006EC8F6->_
             inline - len(1) services.exe - 0x006EC92F->_
             inline - len(1) services.exe - 0x006EC97A->_
             inline - len(1) services.exe - 0x006EC9A4->_
             inline - len(6) services.exe - 0x006EC9AB->_
             inline - len(1) services.exe - 0x006EC9B6->_
             inline - len(1) services.exe - 0x006ECA9E->_
             inline - len(1) services.exe - 0x006ECAA5->_
             inline - len(1) services.exe - 0x006ECAC9->_
             inline - len(1) services.exe - 0x006ECAEB->_
             inline - len(1) services.exe - 0x006ECB39->_
             inline - len(6) services.exe - 0x006ECB3F->_
             inline - len(1) services.exe - 0x006ECB4A->_
             inline - len(1) services.exe - 0x006ECB85->_
             inline - len(1) services.exe - 0x006ECB94->_
             inline - len(1) services.exe - 0x006ECBB0->_
             inline - len(1) services.exe - 0x006ECBCD->_
             inline - len(1) services.exe - 0x006ECBD4->_
             inline - len(1) services.exe - 0x006ECBDE->_
             inline - len(1) services.exe - 0x006ECBEA->_
             inline - len(1) services.exe - 0x006ECBF6->_
             inline - len(1) services.exe - 0x006ECBFE->_
             inline - len(6) services.exe - 0x006ECC0B->_
             inline - len(1) services.exe - 0x006ECCA7->_
             inline - len(1) services.exe - 0x006ECD0D->_
             inline - len(1) services.exe - 0x006ECD14->_
             inline - len(1) services.exe - 0x006ECD42->_
             inline - len(1) services.exe - 0x006ECD52->_
             inline - len(1) services.exe - 0x006ECD7E->_
             inline - len(1) services.exe - 0x006ECDA3->_
             inline - len(1) services.exe - 0x006ECDA9->_
             inline - len(6) services.exe - 0x006ECDBD->_
             inline - len(6) services.exe - 0x006ECDEB->_
             inline - len(1) services.exe - 0x006ECE1F->_
             inline - len(1) services.exe - 0x006ECE3A->_
             inline - len(1) services.exe - 0x006ECE40->_
             inline - len(1) services.exe - 0x006ECEEF->_
             inline - len(6) services.exe - 0x006ECEF8->_
             inline - len(6) services.exe - 0x006ECF1F->_
             inline - len(6) services.exe - 0x006ECF5D->_
             inline - len(6) services.exe - 0x006ECF8D->_
             inline - len(1) services.exe - 0x006ECFB7->_
             inline - len(1) services.exe - 0x006ECFD6->_
             inline - len(1) services.exe - 0x006ECFF4->_
             inline - len(1) services.exe - 0x006ECFFE->_
             inline - len(1) services.exe - 0x006ED018->_
             inline - len(1) services.exe - 0x006ED08C->_
             inline - len(6) services.exe - 0x006ED09F->_
             inline - len(6) services.exe - 0x006ED0D8->_
             inline - len(6) services.exe - 0x006ED109->_
             inline - len(1) services.exe - 0x006ED181->_
             inline - len(6) services.exe - 0x006ED194->_
             inline - len(6) services.exe - 0x006ED1BA->_
             inline - len(1) services.exe - 0x006ED22E->_
             inline - len(6) services.exe - 0x006ED241->_
             inline - len(6) services.exe - 0x006ED267->_
             inline - len(1) services.exe - 0x006ED2FC->_
             inline - len(6) services.exe - 0x006ED30B->_
             inline - len(6) services.exe - 0x006ED341->_
             inline - len(6) services.exe - 0x006ED36E->_
             inline - len(6) services.exe - 0x006ED394->_
             inline - len(6) services.exe - 0x006ED3DF->_
             inline - len(1) services.exe - 0x006ED423->_
             inline - len(6) services.exe - 0x006ED43D->_
             inline - len(6) services.exe - 0x006ED46D->_
             inline - len(6) services.exe - 0x006ED4A0->_
             inline - len(6) services.exe - 0x006ED4E9->_
             inline - len(1) services.exe - 0x006ED52A->_
             inline - len(6) services.exe - 0x006ED54C->_
             inline - len(6) services.exe - 0x006ED578->_
             inline - len(1) services.exe - 0x006ED5AD->_
             inline - len(1) services.exe - 0x006ED5D7->_
             inline - len(1) services.exe - 0x006ED5E8->_
             inline - len(1) services.exe - 0x006ED5EE->_
             inline - len(1) services.exe - 0x006ED607->_
             inline - len(33) services.exe - 0x006ED61D->_
             inline - len(1) services.exe - 0x006ED667->_
             inline - len(1) services.exe - 0x006ED68A->_
             inline - len(1) services.exe - 0x006ED6AD->_
             inline - len(1) services.exe - 0x006ED6D0->_
             inline - len(1) services.exe - 0x006ED6D6->_
             inline - len(11) services.exe - 0x006ED6E2->_
             inline - len(1) services.exe - 0x006ED706->_
             inline - len(1) services.exe - 0x006ED715->_
             inline - len(1) services.exe - 0x006ED766->_
             inline - len(1) services.exe - 0x006ED77A->_
             inline - len(1) services.exe - 0x006ED7AF->_
             inline - len(1) services.exe - 0x006ED7CA->_
             inline - len(6) services.exe - 0x006ED7D0->_
             inline - len(1) services.exe - 0x006ED7F8->_
             inline - len(1) services.exe - 0x006ED811->_
             inline - len(1) services.exe - 0x006ED817->_
             inline - len(1) services.exe - 0x006ED823->_
             inline - len(1) services.exe - 0x006ED82C->_
             inline - len(1) services.exe - 0x006ED832->_
             inline - len(1) services.exe - 0x006ED843->_
             inline - len(1) services.exe - 0x006ED87F->_
             inline - len(1) services.exe - 0x006ED8E1->_
             inline - len(1) services.exe - 0x006ED90F->_
             inline - len(1) services.exe - 0x006ED941->_
             inline - len(6) services.exe - 0x006ED9F6->_
             inline - len(1) services.exe - 0x006EDA0D->_
             inline - len(1) services.exe - 0x006EDA30->_
             inline - len(1) services.exe - 0x006EDA43->_
             inline - len(1) services.exe - 0x006EDA5F->_
             inline - len(1) services.exe - 0x006EDA91->_
             inline - len(1) services.exe - 0x006EDAE0->_
             inline - len(1) services.exe - 0x006EDB56->_
             inline - len(1) services.exe - 0x006EDB79->_
             inline - len(1) services.exe - 0x006EDB9C->_
             inline - len(11) services.exe - 0x006EDBB8->_
             inline - len(1) services.exe - 0x006EDBD8->_
             inline - len(1) services.exe - 0x006EDBED->_
             inline - len(1) services.exe - 0x006EDC1B->_
             inline - len(1) services.exe - 0x006EDC22->_
             inline - len(1) services.exe - 0x006EDC28->_
             inline - len(1) services.exe - 0x006EDC30->_
             inline - len(1) services.exe - 0x006EDCFA->_
             inline - len(1) services.exe - 0x006EDD5F->_
             inline - len(1) services.exe - 0x006EDE05->_
             inline - len(6) services.exe - 0x006EDFA7->_
             inline - len(1) services.exe - 0x006EDFC5->_
             inline - len(1) services.exe - 0x006EDFD7->_
             inline - len(1) services.exe - 0x006EDFEA->_
             inline - len(1) services.exe - 0x006EE00B->_
             inline - len(1) services.exe - 0x006EE048->_
             inline - len(1) services.exe - 0x006EE04E->_
             inline - len(1) services.exe - 0x006EE054->_
             inline - len(1) services.exe - 0x006EE05A->_
             inline - len(1) services.exe - 0x006EE063->_
             inline - len(1) services.exe - 0x006EE0A6->_
             inline - len(1) services.exe - 0x006EE0AC->_
             inline - len(1) services.exe - 0x006EE0B8->_
             inline - len(6) services.exe - 0x006EE0C0->_
             inline - len(1) services.exe - 0x006EE0D8->_
             inline - len(6) services.exe - 0x006EE0EE->_
             inline - len(1) services.exe - 0x006EE0FA->_
             inline - len(1) services.exe - 0x006EE101->_
             inline - len(1) services.exe - 0x006EE133->_
             inline - len(1) services.exe - 0x006EE1B5->_
             inline - len(1) services.exe - 0x006EE1FC->_
             inline - len(1) services.exe - 0x006EE258->_
             inline - len(1) services.exe - 0x006EE290->_
             inline - len(1) services.exe - 0x006EE2A3->_
             inline - len(1) services.exe - 0x006EE2AD->_
             inline - len(1) services.exe - 0x006EE2B6->_
             inline - len(21) services.exe - 0x006EE2C3->_
             inline - len(1) services.exe - 0x006EE2F0->_
             inline - len(16) services.exe - 0x006EE305->_
             inline - len(1) services.exe - 0x006EE333->_
             inline - len(1) services.exe - 0x006EE33D->_
             inline - len(1) services.exe - 0x006EE366->_
             inline - len(1) services.exe - 0x006EE374->_
             inline - len(1) services.exe - 0x006EE37A->_
             inline - len(1) services.exe - 0x006EE387->_
             inline - len(1) services.exe - 0x006EE391->_
             inline - len(1) services.exe - 0x006EE39A->_
             inline - len(1) services.exe - 0x006EE3AB->_
             inline - len(1) services.exe - 0x006EE3BB->_
             inline - len(1) services.exe - 0x006EE3C6->_
             inline - len(6) services.exe - 0x006EE3DB->_
             inline - len(1) services.exe - 0x006EE3EF->_
             inline - len(1) services.exe - 0x006EE404->_
             inline - len(6) services.exe - 0x006EE419->_
             inline - len(1) services.exe - 0x006EE42D->_
             inline - len(1) services.exe - 0x006EE44B->_
             inline - len(1) services.exe - 0x006EE45D->_
             inline - len(1) services.exe - 0x006EE468->_
             inline - len(6) services.exe - 0x006EE486->_
             inline - len(1) services.exe - 0x006EE498->_
             inline - len(1) services.exe - 0x006EE4BB->_
             inline - len(1) services.exe - 0x006EE4C1->_
             inline - len(1) services.exe - 0x006EE524->_
             inline - len(1) services.exe - 0x006EE52B->_
             inline - len(1) services.exe - 0x006EE545->_
             inline - len(1) services.exe - 0x006EE552->_
             inline - len(1) services.exe - 0x006EE566->_
             inline - len(1) services.exe - 0x006EE589->_
             inline - len(1) services.exe - 0x006EE5A6->_
             inline - len(1) services.exe - 0x006EE5B1->_
             inline - len(1) services.exe - 0x006EE5C9->_
             inline - len(1) services.exe - 0x006EE5D6->_
             inline - len(1) services.exe - 0x006EE5F3->_
             inline - len(1) services.exe - 0x006EE61F->_
             inline - len(1) services.exe - 0x006EE62C->_
             inline - len(1) services.exe - 0x006EE636->_
             inline - len(1) services.exe - 0x006EE63C->_
             inline - len(1) services.exe - 0x006EE642->_
             inline - len(1) services.exe - 0x006EE648->_
             inline - len(1) services.exe - 0x006EE64E->_
             inline - len(1) services.exe - 0x006EE654->_
             inline - len(6) services.exe - 0x006EE65A->_
             inline - len(1) services.exe - 0x006EE667->_
             inline - len(1) services.exe - 0x006EE698->_
             inline - len(1) services.exe - 0x006EE6B9->_
             inline - len(1) services.exe - 0x006EE6C0->_
             inline - len(1) services.exe - 0x006EE6C6->_
             inline - len(1) services.exe - 0x006EE6D1->_
             inline - len(1) services.exe - 0x006EE6E6->_
             inline - len(1) services.exe - 0x006EE6FE->_
             inline - len(1) services.exe - 0x006EE8BE->_
             inline - len(1) services.exe - 0x006EE8C4->_
             inline - len(11) services.exe - 0x006EE8CF->_
             inline - len(1) services.exe - 0x006EE8F9->_
             inline - len(1) services.exe - 0x006EE91B->_
             inline - len(1) services.exe - 0x006EE922->_
             inline - len(1) services.exe - 0x006EE928->_
             inline - len(1) services.exe - 0x006EE92F->_
             inline - len(6) services.exe - 0x006EE93B->_
             inline - len(1) services.exe - 0x006EE950->_
             inline - len(1) services.exe - 0x006EE969->_
             inline - len(1) services.exe - 0x006EE9E8->_
             inline - len(1) services.exe - 0x006EE9F8->_
             inline - len(11) services.exe - 0x006EEA06->_
             inline - len(1) services.exe - 0x006EEA2E->_
             inline - len(1) services.exe - 0x006EEA58->_
             inline - len(1) services.exe - 0x006EEA5F->_
             inline - len(1) services.exe - 0x006EEA8D->_
             inline - len(1) services.exe - 0x006EEA96->_
             inline - len(1) services.exe - 0x006EEAB9->_
             inline - len(1) services.exe - 0x006EEAC7->_
             inline - len(1) services.exe - 0x006EEAD9->_
             inline - len(1) services.exe - 0x006EEB35->_
             inline - len(1) services.exe - 0x006EEB3C->_
             inline - len(1) services.exe - 0x006EEB63->_
             inline - len(1) services.exe - 0x006EEB7E->_
             inline - len(1) services.exe - 0x006EEB87->_
             inline - len(1) services.exe - 0x006EEC14->_
             inline - len(1) services.exe - 0x006EEC33->_
             inline - len(1) services.exe - 0x006EEC66->_
             inline - len(1) services.exe - 0x006EECAE->_
             inline - len(1) services.exe - 0x006EED27->_
             inline - len(1) services.exe - 0x006EED45->_
             inline - len(1) services.exe - 0x006EED4B->_
             inline - len(1) services.exe - 0x006EED5F->_
             inline - len(1) services.exe - 0x006EED93->_
             inline - len(1) services.exe - 0x006EEDB2->_
             inline - len(1) services.exe - 0x006EEE0F->_
             inline - len(1) services.exe - 0x006EEE34->_
             inline - len(1) services.exe - 0x006EEE5C->_
             inline - len(1) services.exe - 0x006EEE87->_
             inline - len(1) services.exe - 0x006EEF02->_
             inline - len(1) services.exe - 0x006EEF1C->_
             inline - len(1) services.exe - 0x006EEF22->_
             inline - len(1) services.exe - 0x006EEF2D->_
             inline - len(1) services.exe - 0x006EEF39->_
             inline - len(6) services.exe - 0x006EEF46->_
             inline - len(6) services.exe - 0x006EEF54->_
             inline - len(1) services.exe - 0x006EEF80->_
             inline - len(1) services.exe - 0x006EEF86->_
             inline - len(1) services.exe - 0x006EEF9B->_
             inline - len(1) services.exe - 0x006EEFA1->_
             inline - len(6) services.exe - 0x006EF01F->_
             inline - len(1) services.exe - 0x006EF03B->_
             inline - len(1) services.exe - 0x006EF064->_
             inline - len(1) services.exe - 0x006EF081->_
             inline - len(1) services.exe - 0x006EF0B3->_
             inline - len(1) services.exe - 0x006EF0D1->_
             inline - len(1) services.exe - 0x006EF0DA->_
             inline - len(1) services.exe - 0x006EF0E1->_
             inline - len(1) services.exe - 0x006EF0F6->_
             inline - len(1) services.exe - 0x006EF11E->_
             inline - len(1) services.exe - 0x006EF133->_
             inline - len(1) services.exe - 0x006EF142->_
             inline - len(1) services.exe - 0x006EF163->_
             inline - len(1) services.exe - 0x006EF16A->_
             inline - len(1) services.exe - 0x006EF173->_
             inline - len(1) services.exe - 0x006EF17F->_
             inline - len(1) services.exe - 0x006EF187->_
             inline - len(1) services.exe - 0x006EF18D->_
             inline - len(1) services.exe - 0x006EF26D->_
             inline - len(1) services.exe - 0x006EF2DF->_
             inline - len(1) services.exe - 0x006EF307->_
             inline - len(1) services.exe - 0x006EF30D->_
             inline - len(1) services.exe - 0x006EF318->_
             inline - len(1) services.exe - 0x006EF326->_
             inline - len(1) services.exe - 0x006EF356->_
             inline - len(1) services.exe - 0x006EF37E->_
             inline - len(1) services.exe - 0x006EF44D->_
             inline - len(1) services.exe - 0x006EF49D->_
             inline - len(1) services.exe - 0x006EF4C6->_
             inline - len(1) services.exe - 0x006EF527->_
             inline - len(1) services.exe - 0x006EF576->_
             inline - len(6) services.exe - 0x006EF597->_
             inline - len(1) services.exe - 0x006EF5BF->_
             inline - len(1) services.exe - 0x006EF5C5->_
             inline - len(1) services.exe - 0x006EF5DE->_
             inline - len(1) services.exe - 0x006EF5E4->_
             inline - len(1) services.exe - 0x006EF601->_
             inline - len(1) services.exe - 0x006EF653->_
             inline - len(1) services.exe - 0x006EF669->_
             inline - len(1) services.exe - 0x006EF699->_
             inline - len(1) services.exe - 0x006EF6AE->_
             inline - len(1) services.exe - 0x006EF6C5->_
             inline - len(1) services.exe - 0x006EF6F2->_
             inline - len(1) services.exe - 0x006EF709->_
             inline - len(1) services.exe - 0x006EF715->_
             inline - len(1) services.exe - 0x006EF71B->_
             inline - len(6) services.exe - 0x006EF78A->_
             inline - len(1) services.exe - 0x006EF7A6->_
             inline - len(1) services.exe - 0x006EF7BC->_
             inline - len(1) services.exe - 0x006EF7C3->_
             inline - len(1) services.exe - 0x006EF7D2->_
             inline - len(1) services.exe - 0x006EF7DD->_
             inline - len(1) services.exe - 0x006EF7E7->_
             inline - len(1) services.exe - 0x006EF7F1->_
             inline - len(1) services.exe - 0x006EF82A->_
             inline - len(1) services.exe - 0x006EF831->_
             inline - len(1) services.exe - 0x006EF848->_
             inline - len(11) services.exe - 0x006EF854->_
             inline - len(1) services.exe - 0x006EF86B->_
             inline - len(1) services.exe - 0x006EF887->_
             inline - len(1) services.exe - 0x006EF892->_
             inline - len(1) services.exe - 0x006EF89E->_
             inline - len(1) services.exe - 0x006EF8BF->_
             inline - len(1) services.exe - 0x006EF8C6->_
             inline - len(6) services.exe - 0x006EF8DE->_
             inline - len(1) services.exe - 0x006EF8F3->_
             inline - len(1) services.exe - 0x006EF905->_
             inline - len(1) services.exe - 0x006EF90B->_
             inline - len(1) services.exe - 0x006EF915->_
             inline - len(1) services.exe - 0x006EF950->_
             inline - len(1) services.exe - 0x006EF980->_
             inline - len(1) services.exe - 0x006EF9A0->_
             inline - len(1) services.exe - 0x006EF9B9->_
             inline - len(16) services.exe - 0x006EF9C0->_
             inline - len(1) services.exe - 0x006EF9EF->_
             inline - len(1) services.exe - 0x006EF9F5->_
             inline - len(1) services.exe - 0x006EFA0A->_
             inline - len(1) services.exe - 0x006EFA35->_
             inline - len(1) services.exe - 0x006EFA53->_
             inline - len(1) services.exe - 0x006EFA60->_
             inline - len(1) services.exe - 0x006EFA71->_
             inline - len(1) services.exe - 0x006EFA80->_
             inline - len(6) services.exe - 0x006EFAA3->_
             inline - len(1) services.exe - 0x006EFAB9->_
             inline - len(1) services.exe - 0x006EFACC->_
             inline - len(1) services.exe - 0x006EFAE3->_
             inline - len(1) services.exe - 0x006EFAE9->_
             inline - len(1) services.exe - 0x006EFAF9->_
             inline - len(1) services.exe - 0x006EFB1D->_
             inline - len(1) services.exe - 0x006EFB2D->_
             inline - len(1) services.exe - 0x006EFB55->_
             inline - len(1) services.exe - 0x006EFB62->_
             inline - len(1) services.exe - 0x006EFB70->_
             inline - len(1) services.exe - 0x006EFB98->_
             inline - len(1) services.exe - 0x006EFC10->_
             inline - len(1) services.exe - 0x006EFC44->_
             inline - len(6) services.exe - 0x006EFC5C->_
             inline - len(1) services.exe - 0x006EFC71->_
             inline - len(1) services.exe - 0x006EFC8E->_
             inline - len(1) services.exe - 0x006EFC95->_
             inline - len(6) services.exe - 0x006EFD0D->_
             inline - len(1) services.exe - 0x006EFD19->_
             inline - len(1) services.exe - 0x006EFD2D->_
             inline - len(1) services.exe - 0x006EFD3D->_
             inline - len(6) services.exe - 0x006EFD67->_
             inline - len(1) services.exe - 0x006EFD79->_
             inline - len(1) services.exe - 0x006EFDA8->_
             inline - len(1) services.exe - 0x006EFDBC->_
             inline - len(1) services.exe - 0x006EFDC7->_
             inline - len(1) services.exe - 0x006EFDD9->_
             inline - len(1) services.exe - 0x006EFE23->_
             inline - len(1) services.exe - 0x006EFE5A->_
             inline - len(1) services.exe - 0x006EFE61->_
             inline - len(1) services.exe - 0x006EFED9->_
             inline - len(1) services.exe - 0x006EFF33->_
             inline - len(1) services.exe - 0x006EFF39->_
             inline - len(1) services.exe - 0x006EFF57->_
             inline - len(1) services.exe - 0x006EFFB4->_
             inline - len(1) services.exe - 0x006EFFC2->_
             inline - len(1) services.exe - 0x006EFFC8->_
             inline - len(1) services.exe - 0x006EFFDD->_
             inline - len(1) services.exe - 0x006EFFF3->_
             inline - len(1) services.exe - 0x006F001F->_
             inline - len(1) services.exe - 0x006F0034->_
             inline - len(1) services.exe - 0x006F0050->_
             inline - len(1) services.exe - 0x006F00A8->_
             inline - len(1) services.exe - 0x006F00CB->_
             inline - len(1) services.exe - 0x006F00EE->_
             inline - len(1) services.exe - 0x006F014D->_
             inline - len(6) services.exe - 0x006F0154->_
             inline - len(1) services.exe - 0x006F015F->_
             inline - len(6) services.exe - 0x006F0175->_
             inline - len(1) services.exe - 0x006F0193->_
             inline - len(1) services.exe - 0x006F0205->_
             inline - len(1) services.exe - 0x006F020B->_
             inline - len(1) services.exe - 0x006F0232->_
             inline - len(1) services.exe - 0x006F027D->_
             inline - len(1) services.exe - 0x006F02A0->_
             inline - len(1) services.exe - 0x006F02E0->_
             inline - len(1) services.exe - 0x006F034E->_
             inline - len(6) services.exe - 0x006F035C->_
             inline - len(1) services.exe - 0x006F0367->_
             inline - len(1) services.exe - 0x006F03A0->_
             inline - len(1) services.exe - 0x006F03D1->_
             inline - len(1) services.exe - 0x006F03E6->_
             inline - len(1) services.exe - 0x006F05D3->_
             inline - len(1) services.exe - 0x006F05F9->_
             inline - len(1) services.exe - 0x006F064F->_
             inline - len(6) services.exe - 0x006F066B->_
             inline - len(1) services.exe - 0x006F0678->_
             inline - len(1) services.exe - 0x006F068F->_
             inline - len(1) services.exe - 0x006F0696->_
             inline - len(1) services.exe - 0x006F06A4->_
             inline - len(1) services.exe - 0x006F0723->_
             inline - len(1) services.exe - 0x006F075C->_
             inline - len(6) services.exe - 0x006F0772->_
             inline - len(1) services.exe - 0x006F0787->_
             inline - len(1) services.exe - 0x006F07A1->_
             inline - len(1) services.exe - 0x006F07B1->_
             inline - len(1) services.exe - 0x006F07FA->_
             inline - len(1) services.exe - 0x006F0812->_
             inline - len(1) services.exe - 0x006F086C->_
             inline - len(1) services.exe - 0x006F08AC->_
             inline - len(1) services.exe - 0x006F08C1->_
             inline - len(6) services.exe - 0x006F08D0->_
             inline - len(1) services.exe - 0x006F08E5->_
             inline - len(1) services.exe - 0x006F0905->_
             inline - len(1) services.exe - 0x006F090B->_
             inline - len(1) services.exe - 0x006F0925->_
             inline - len(1) services.exe - 0x006F0943->_
             inline - len(1) services.exe - 0x006F0970->_
             inline - len(1) services.exe - 0x006F0979->_
             inline - len(1) services.exe - 0x006F098B->_
             inline - len(1) services.exe - 0x006F09A9->_
             inline - len(1) services.exe - 0x006F09F0->_
             inline - len(1) services.exe - 0x006F09FD->_
             inline - len(1) services.exe - 0x006F0A0F->_
             inline - len(1) services.exe - 0x006F0A28->_
             inline - len(1) services.exe - 0x006F0A4D->_
             inline - len(1) services.exe - 0x006F0A7D->_
             inline - len(1) services.exe - 0x006F0A8E->_
             inline - len(6) services.exe - 0x006F0A9D->_
             inline - len(1) services.exe - 0x006F0AAD->_
             inline - len(1) services.exe - 0x006F0ABC->_
             inline - len(1) services.exe - 0x006F0AD9->_
             inline - len(1) services.exe - 0x006F0AFF->_
             inline - len(1) services.exe - 0x006F0B0E->_
             inline - len(1) services.exe - 0x006F0B29->_
             inline - len(1) services.exe - 0x006F0B9B->_
             inline - len(1) services.exe - 0x006F0C1C->_
             inline - len(1) services.exe - 0x006F0C2E->_
             inline - len(21) services.exe - 0x006F0CFF->_
             inline - len(6) services.exe - 0x006F0D1E->_
             inline - len(1) services.exe - 0x006F0D29->_
             inline - len(1) services.exe - 0x006F0D34->_
             inline - len(1) services.exe - 0x006F0D3B->_
             inline - len(1) services.exe - 0x006F0D5F->_
             inline - len(1) services.exe - 0x006F0DC2->_
             inline - len(1) services.exe - 0x006F0DE6->_
             inline - len(6) services.exe - 0x006F0DEC->_
             inline - len(1) services.exe - 0x006F0E0E->_
             inline - len(1) services.exe - 0x006F0E20->_
             inline - len(6) services.exe - 0x006F0E2B->_
             inline - len(1) services.exe - 0x006F0EDC->_
             inline - len(1) services.exe - 0x006F0EE3->_
             inline - len(6) services.exe - 0x006F0F22->_
             inline - len(1) services.exe - 0x006F0F2E->_
             inline - len(1) services.exe - 0x006F0F35->_
             inline - len(1) services.exe - 0x006F0F9E->_
             inline - len(1) services.exe - 0x006F0FB1->_
             inline - len(1) services.exe - 0x006F0FD3->_
             inline - len(1) services.exe - 0x006F0FDC->_
             inline - len(1) services.exe - 0x006F0FEC->_
             inline - len(1) services.exe - 0x006F0FF7->_
             inline - len(1) services.exe - 0x006F1006->_
             inline - len(1) services.exe - 0x006F100F->_
             inline - len(1) services.exe - 0x006F101A->_
             inline - len(1) services.exe - 0x006F1029->_
             inline - len(1) services.exe - 0x006F1036->_
             inline - len(1) services.exe - 0x006F1041->_
             inline - len(1) services.exe - 0x006F1056->_
             inline - len(1) services.exe - 0x006F1060->_
             inline - len(1) services.exe - 0x006F1069->_
             inline - len(6) services.exe - 0x006F106F->_
             inline - len(1) services.exe - 0x006F1081->_
             inline - len(6) services.exe - 0x006F1087->_
             inline - len(6) services.exe - 0x006F1101->_
             inline - len(1) services.exe - 0x006F1113->_
             inline - len(1) services.exe - 0x006F1119->_
             inline - len(6) services.exe - 0x006F1134->_
             inline - len(1) services.exe - 0x006F1146->_
             inline - len(1) services.exe - 0x006F115E->_
             inline - len(1) services.exe - 0x006F1168->_
             inline - len(1) services.exe - 0x006F1173->_
             inline - len(1) services.exe - 0x006F1198->_
             inline - len(1) services.exe - 0x006F11D1->_
             inline - len(1) services.exe - 0x006F11FC->_
             inline - len(1) services.exe - 0x006F1203->_
             inline - len(1) services.exe - 0x006F1215->_
             inline - len(1) services.exe - 0x006F128F->_
             inline - len(1) services.exe - 0x006F1297->_
             inline - len(1) services.exe - 0x006F12CC->_
             inline - len(1) services.exe - 0x006F12D2->_
             inline - len(1) services.exe - 0x006F12EF->_
             inline - len(6) services.exe - 0x006F1349->_
             inline - len(1) services.exe - 0x006F1396->_
             inline - len(1) services.exe - 0x006F13AC->_
             inline - len(1) services.exe - 0x006F13BA->_
             inline - len(1) services.exe - 0x006F13D5->_
             inline - len(1) services.exe - 0x006F13E1->_
             inline - len(1) services.exe - 0x006F1405->_
             inline - len(1) services.exe - 0x006F1437->_
             inline - len(1) services.exe - 0x006F1457->_
             inline - len(1) services.exe - 0x006F145E->_
             inline - len(1) services.exe - 0x006F1493->_
             inline - len(1) services.exe - 0x006F149A->_
             inline - len(1) services.exe - 0x006F14A0->_
             inline - len(1) services.exe - 0x006F14AE->_
             inline - len(1) services.exe - 0x006F14B4->_
             inline - len(1) services.exe - 0x006F14DD->_
             inline - len(1) services.exe - 0x006F14E9->_
             inline - len(1) services.exe - 0x006F14F7->_
             inline - len(1) services.exe - 0x006F157D->_
             inline - len(1) services.exe - 0x006F1584->_
             inline - len(6) services.exe - 0x006F159D->_
             inline - len(1) services.exe - 0x006F15A9->_
             inline - len(1) services.exe - 0x006F15BB->_
             inline - len(1) services.exe - 0x006F15EA->_
             inline - len(1) services.exe - 0x006F1609->_
             inline - len(1) services.exe - 0x006F1611->_
             inline - len(1) services.exe - 0x006F161E->_
             inline - len(1) services.exe - 0x006F1645->_
             inline - len(1) services.exe - 0x006F1670->_
             inline - len(1) services.exe - 0x006F1688->_
             inline - len(6) services.exe - 0x006F16B5->_
             inline - len(1) services.exe - 0x006F1703->_
             inline - len(1) services.exe - 0x006F1713->_
             inline - len(1) services.exe - 0x006F171B->_
             inline - len(1) services.exe - 0x006F172C->_
             inline - len(6) services.exe - 0x006F179C->_
             inline - len(1) services.exe - 0x006F17A8->_
             inline - len(1) services.exe - 0x006F17E6->_
             inline - len(1) services.exe - 0x006F17F9->_
             inline - len(1) services.exe - 0x006F1813->_
             inline - len(1) services.exe - 0x006F1834->_
             inline - len(1) services.exe - 0x006F183E->_
             inline - len(6) services.exe - 0x006F1857->_
             inline - len(1) services.exe - 0x006F186F->_
             inline - len(1) services.exe - 0x006F189E->_
             inline - len(1) services.exe - 0x006F18EF->_
             inline - len(1) services.exe - 0x006F191C->_
             inline - len(1) services.exe - 0x006F1940->_
             inline - len(1) services.exe - 0x006F1970->_
             inline - len(1) services.exe - 0x006F197D->_
             inline - len(1) services.exe - 0x006F19A6->_
             inline - len(1) services.exe - 0x006F19FB->_
             inline - len(6) services.exe - 0x006F1A1F->_
             inline - len(1) services.exe - 0x006F1A3C->_
             inline - len(1) services.exe - 0x006F1A43->_
             inline - len(11) services.exe - 0x006F1A49->_
             inline - len(6) services.exe - 0x006F1A64->_
             inline - len(1) services.exe - 0x006F1A8D->_
             inline - len(1) services.exe - 0x006F1AB2->_
             inline - len(1) services.exe - 0x006F1AB9->_
             inline - len(1) services.exe - 0x006F1AC0->_
             inline - len(1) services.exe - 0x006F1B45->_
             inline - len(11) services.exe - 0x006F1B5A->_
             inline - len(6) services.exe - 0x006F1B96->_
             inline - len(1) services.exe - 0x006F1BA2->_
             inline - len(1) services.exe - 0x006F1BB0->_
             inline - len(1) services.exe - 0x006F1BCF->_
             inline - len(1) services.exe - 0x006F1BDC->_
             inline - len(1) services.exe - 0x006F1BE2->_
             inline - len(1) services.exe - 0x006F1BEF->_
             inline - len(1) services.exe - 0x006F1BFA->_
             inline - len(1) services.exe - 0x006F1C03->_
             inline - len(1) services.exe - 0x006F1C14->_
             inline - len(1) services.exe - 0x006F1C1A->_
             inline - len(1) services.exe - 0x006F1C28->_
             inline - len(1) services.exe - 0x006F1C2F->_
             inline - len(6) services.exe - 0x006F1C41->_
             inline - len(1) services.exe - 0x006F1C57->_
             inline - len(1) services.exe - 0x006F1C68->_
             inline - len(1) services.exe - 0x006F1C79->_
             inline - len(6) services.exe - 0x006F1C8A->_
             inline - len(1) services.exe - 0x006F1D74->_
             inline - len(1) services.exe - 0x006F1D7E->_
             inline - len(1) services.exe - 0x006F1D8C->_
             inline - len(1) services.exe - 0x006F1D9A->_
             inline - len(6) services.exe - 0x006F1DA0->_
             inline - len(1) services.exe - 0x006F1DAB->_
             inline - len(1) services.exe - 0x006F1DB8->_
             inline - len(1) services.exe - 0x006F1DBF->_
             inline - len(11) services.exe - 0x006F1DD9->_
             inline - len(1) services.exe - 0x006F1DF8->_
             inline - len(1) services.exe - 0x006F1E2E->_
             inline - len(1) services.exe - 0x006F1E5C->_
             inline - len(6) services.exe - 0x006F1E69->_
             inline - len(1) services.exe - 0x006F1E96->_
             inline - len(1) services.exe - 0x006F1EC9->_
             inline - len(1) services.exe - 0x006F1EFB->_
             inline - len(1) services.exe - 0x006F1F02->_
             inline - len(1) services.exe - 0x006F209F->_
             inline - len(6) services.exe - 0x006F20A7->_
             inline - len(1) services.exe - 0x006F20BE->_
             inline - len(1) services.exe - 0x006F20C7->_
             inline - len(1) services.exe - 0x006F20D7->_
             inline - len(1) services.exe - 0x006F20E2->_
             inline - len(1) services.exe - 0x006F20E9->_
             inline - len(1) services.exe - 0x006F20F7->_
             inline - len(1) services.exe - 0x006F2107->_
             inline - len(6) services.exe - 0x006F210E->_
             inline - len(1) services.exe - 0x006F212B->_
             inline - len(1) services.exe - 0x006F21A8->_
             inline - len(1) services.exe - 0x006F21B5->_
             inline - len(1) services.exe - 0x006F21C1->_
             inline - len(1) services.exe - 0x006F222B->_
             inline - len(1) services.exe - 0x006F2252->_
             inline - len(1) services.exe - 0x006F225B->_
             inline - len(1) services.exe - 0x006F2263->_
             inline - len(1) services.exe - 0x006F227D->_
             inline - len(1) services.exe - 0x006F22A7->_
             inline - len(1) services.exe - 0x006F22B2->_
             inline - len(6) services.exe - 0x006F22E0->_
             inline - len(11) services.exe - 0x006F22F9->_
             inline - len(26) services.exe - 0x006F233A->_
             inline - len(1) services.exe - 0x006F238A->_
             inline - len(1) services.exe - 0x006F2397->_
             inline - len(1) services.exe - 0x006F23AA->_
             inline - len(1) services.exe - 0x006F23B1->_
             inline - len(1) services.exe - 0x006F2408->_
             inline - len(1) services.exe - 0x006F2436->_
             inline - len(6) services.exe - 0x006F2440->_
             inline - len(1) services.exe - 0x006F2455->_
             inline - len(1) services.exe - 0x006F2494->_
             inline - len(1) services.exe - 0x006F24C8->_
             inline - len(1) services.exe - 0x006F24D2->_
             inline - len(1) services.exe - 0x006F24E1->_
             inline - len(1) services.exe - 0x006F2502->_
             inline - len(1) services.exe - 0x006F251D->_
             inline - len(1) services.exe - 0x006F2524->_
             inline - len(1) services.exe - 0x006F253F->_
             inline - len(1) services.exe - 0x006F255C->_
             inline - len(1) services.exe - 0x006F25A9->_
             inline - len(1) services.exe - 0x006F25C8->_
             inline - len(1) services.exe - 0x006F25CE->_
             inline - len(1) services.exe - 0x006F25D8->_
             inline - len(1) services.exe - 0x006F25FF->_
             inline - len(1) services.exe - 0x006F263E->_
             inline - len(1) services.exe - 0x006F2649->_
             inline - len(1) services.exe - 0x006F266E->_
             inline - len(1) services.exe - 0x006F26F7->_
             inline - len(6) services.exe - 0x006F2709->_
             inline - len(1) services.exe - 0x006F2722->_
             inline - len(1) services.exe - 0x006F272F->_
             inline - len(1) services.exe - 0x006F273D->_
             inline - len(6) services.exe - 0x006F2759->_
             inline - len(1) services.exe - 0x006F2764->_
             inline - len(1) services.exe - 0x006F2775->_
             inline - len(1) services.exe - 0x006F27A0->_
             inline - len(1) services.exe - 0x006F27C6->_
             inline - len(1) services.exe - 0x006F27DD->_
             inline - len(1) services.exe - 0x006F27F4->_
             inline - len(1) services.exe - 0x006F280B->_
             inline - len(1) services.exe - 0x006F2826->_
             inline - len(1) services.exe - 0x006F283D->_
             inline - len(1) services.exe - 0x006F2890->_
             inline - len(1) services.exe - 0x006F28E4->_
             inline - len(1) services.exe - 0x006F28EA->_
             inline - len(1) services.exe - 0x006F2922->_
             inline - len(1) services.exe - 0x006F2947->_
             inline - len(1) services.exe - 0x006F2962->_
             inline - len(1) services.exe - 0x006F2971->_
             inline - len(1) services.exe - 0x006F2978->_
             inline - len(1) services.exe - 0x006F2995->_
             inline - len(1) services.exe - 0x006F29A3->_
             inline - len(1) services.exe - 0x006F29AA->_
             inline - len(1) services.exe - 0x006F29B3->_
             inline - len(1) services.exe - 0x006F29BA->_
             inline - len(1) services.exe - 0x006F2A1A->_
             inline - len(1) services.exe - 0x006F2A23->_
             inline - len(1) services.exe - 0x006F2A29->_
             inline - len(1) services.exe - 0x006F2A4C->_
             inline - len(1) services.exe - 0x006F2A52->_
             inline - len(1) services.exe - 0x006F2A5F->_
             inline - len(6) services.exe - 0x006F2A66->_
             inline - len(6) services.exe - 0x006F2A97->_
             inline - len(21) services.exe - 0x006F2AA2->_
             inline - len(1) services.exe - 0x006F2ABC->_
             inline - len(1) services.exe - 0x006F2AC4->_
             inline - len(1) services.exe - 0x006F2AD0->_
             inline - len(1) services.exe - 0x006F2ADA->_
             inline - len(1) services.exe - 0x006F2AE0->_
             inline - len(1) services.exe - 0x006F2AEE->_
             inline - len(1) services.exe - 0x006F2B08->_
             inline - len(1) services.exe - 0x006F2B2F->_
             inline - len(1) services.exe - 0x006F2B3B->_
             inline - len(1) services.exe - 0x006F2B43->_
             inline - len(1) services.exe - 0x006F2B4B->_
             inline - len(1) services.exe - 0x006F2B57->_
             inline - len(1) services.exe - 0x006F2B69->_
             inline - len(1) services.exe - 0x006F2B71->_
             inline - len(1) services.exe - 0x006F2B79->_
             inline - len(1) services.exe - 0x006F2BAB->_
             inline - len(1) services.exe - 0x006F2BEA->_
             inline - len(1) services.exe - 0x006F2C9A->_
             inline - len(1) services.exe - 0x006F2CA5->_
             inline - len(1) services.exe - 0x006F2CB0->_
             inline - len(1) services.exe - 0x006F2CE7->_
             inline - len(1) services.exe - 0x006F2DBB->_
             inline - len(11) services.exe - 0x006F2DCE->_
             inline - len(1) services.exe - 0x006F2EF5->_
             inline - len(1) services.exe - 0x006F2F1A->_
             inline - len(1) services.exe - 0x006F2F35->_
             inline - len(1) services.exe - 0x006F2F57->_
             inline - len(1) services.exe - 0x006F2F73->_
             inline - len(1) services.exe - 0x006F2F79->_
             inline - len(1) services.exe - 0x006F2F82->_
             inline - len(1) services.exe - 0x006F2FA0->_
             inline - len(1) services.exe - 0x006F2FB5->_
             inline - len(1) services.exe - 0x006F2FC2->_
             inline - len(1) services.exe - 0x006F3024->_
             inline - len(1) services.exe - 0x006F3045->_
             inline - len(1) services.exe - 0x006F3055->_
             inline - len(1) services.exe - 0x006F3065->_
             inline - len(1) services.exe - 0x006F307C->_
             inline - len(1) services.exe - 0x006F308C->_
             inline - len(1) services.exe - 0x006F30B4->_
             inline - len(1) services.exe - 0x006F30BD->_
             inline - len(1) services.exe - 0x006F30E0->_
             inline - len(11) services.exe - 0x006F3102->_
             inline - len(1) services.exe - 0x006F3179->_
             inline - len(1) services.exe - 0x006F3194->_
             inline - len(1) services.exe - 0x006F31A1->_
             inline - len(1) services.exe - 0x006F31AE->_
             inline - len(1) services.exe - 0x006F31D6->_
             inline - len(6) services.exe - 0x006F3217->_
             inline - len(1) services.exe - 0x006F322E->_
             inline - len(1) services.exe - 0x006F3248->_
             inline - len(1) services.exe - 0x006F324E->_
             inline - len(1) services.exe - 0x006F3278->_
             inline - len(1) services.exe - 0x006F328E->_
             inline - len(6) services.exe - 0x006F329F->_
             inline - len(1) services.exe - 0x006F32B5->_
             inline - len(1) services.exe - 0x006F3300->_
             inline - len(1) services.exe - 0x006F331C->_
             inline - len(1) services.exe - 0x006F3325->_
             inline - len(1) services.exe - 0x006F3353->_
             inline - len(1) services.exe - 0x006F3373->_
             inline - len(1) services.exe - 0x006F3399->_
             inline - len(1) services.exe - 0x006F33AB->_
             inline - len(1) services.exe - 0x006F33EE->_
             inline - len(1) services.exe - 0x006F34D3->_
             inline - len(1) services.exe - 0x006F34E2->_
             inline - len(1) services.exe - 0x006F350F->_
             inline - len(1) services.exe - 0x006F3540->_
             inline - len(6) services.exe - 0x006F3562->_
             inline - len(1) services.exe - 0x006F35C0->_
             inline - len(1) services.exe - 0x006F35C6->_
             inline - len(1) services.exe - 0x006F368B->_
             inline - len(1) services.exe - 0x006F36ED->_
             inline - len(1) services.exe - 0x006F371C->_
             inline - len(1) services.exe - 0x006F3723->_
             inline - len(1) services.exe - 0x006F3738->_
             inline - len(1) services.exe - 0x006F3754->_
             inline - len(1) services.exe - 0x006F379A->_
             inline - len(1) services.exe - 0x006F37F7->_
             inline - len(1) services.exe - 0x006F380B->_
             inline - len(1) services.exe - 0x006F3818->_
             inline - len(1) services.exe - 0x006F382B->_
             inline - len(1) services.exe - 0x006F3834->_
             inline - len(1) services.exe - 0x006F3844->_
             inline - len(1) services.exe - 0x006F3874->_
             inline - len(1) services.exe - 0x006F3881->_
             inline - len(1) services.exe - 0x006F3894->_
             inline - len(1) services.exe - 0x006F38AF->_
             inline - len(1) services.exe - 0x006F38B8->_
             inline - len(1) services.exe - 0x006F38C8->_
             inline - len(1) services.exe - 0x006F38D5->_
             inline - len(11) services.exe - 0x006F38DF->_
             inline - len(1) services.exe - 0x006F38FD->_
             inline - len(6) services.exe - 0x006F3906->_
             inline - len(1) services.exe - 0x006F3918->_
             inline - len(1) services.exe - 0x006F3929->_
             inline - len(1) services.exe - 0x006F392F->_
             inline - len(1) services.exe - 0x006F393B->_
             inline - len(1) services.exe - 0x006F3941->_
             inline - len(1) services.exe - 0x006F3947->_
             inline - len(1) services.exe - 0x006F3957->_
             inline - len(1) services.exe - 0x006F3962->_
             inline - len(5) services.exe - 0x006F396E->_
             inline - len(5) services.exe - 0x006F398E->_
             inline - len(1) services.exe - 0x006F39A3->_
             inline - len(1) services.exe - 0x006F39AE->_
             inline - len(1) services.exe - 0x006F39B4->_
             inline - len(1) services.exe - 0x006F39E6->_
             inline - len(1) services.exe - 0x006F39F2->_
             inline - len(1) services.exe - 0x006F39F8->_
             inline - len(1) services.exe - 0x006F39FF->_
             inline - len(1) services.exe - 0x006F3A08->_
             inline - len(1) services.exe - 0x006F3A0E->_
             inline - len(1) services.exe - 0x006F3A16->_
             inline - len(1) services.exe - 0x006F3A1C->_
             inline - len(1) services.exe - 0x006F3A29->_
             inline - len(1) services.exe - 0x006F3A51->_
             inline - len(1) services.exe - 0x006F3A67->_
             inline - len(1) services.exe - 0x006F3A6D->_
             inline - len(1) services.exe - 0x006F3A8C->_
             inline - len(1) services.exe - 0x006F3AE4->_
             inline - len(1) services.exe - 0x006F3B12->_
             inline - len(1) services.exe - 0x006F3B3D->_
             inline - len(1) services.exe - 0x006F3B93->_
             inline - len(1) services.exe - 0x006F3BAB->_
             inline - len(1) services.exe - 0x006F3BC0->_
             inline - len(1) services.exe - 0x006F3BE6->_
             inline - len(1) services.exe - 0x006F3C2F->_
             inline - len(1) services.exe - 0x006F3C5C->_
             inline - len(1) services.exe - 0x006F3C77->_
             inline - len(1) services.exe - 0x006F3C89->_
             inline - len(1) services.exe - 0x006F3CAD->_
             inline - len(1) services.exe - 0x006F3CF9->_
             inline - len(1) services.exe - 0x006F3D00->_
             inline - len(1) services.exe - 0x006F3D41->_
             inline - len(1) services.exe - 0x006F3D47->_
             inline - len(1) services.exe - 0x006F3D7C->_
             inline - len(5) services.exe - 0x006F3D8B->_
             inline - len(1) services.exe - 0x006F3D95->_
             inline - len(1) services.exe - 0x006F3DAD->_
             inline - len(1) services.exe - 0x006F3DCB->_
             inline - len(1) services.exe - 0x006F3E49->_
             inline - len(1) services.exe - 0x006F3E5B->_
             inline - len(1) services.exe - 0x006F3E68->_
             inline - len(1) services.exe - 0x006F3E87->_
             inline - len(1) services.exe - 0x006F3E8D->_
             inline - len(6) services.exe - 0x006F3EB4->_
             inline - len(1) services.exe - 0x006F3EC6->_
             inline - len(1) services.exe - 0x006F3F0A->_
             inline - len(1) services.exe - 0x006F3F3E->_
             inline - len(1) services.exe - 0x006F3F44->_
             inline - len(6) services.exe - 0x006F3F5B->_
             inline - len(1) services.exe - 0x006F3F70->_
             inline - len(1) services.exe - 0x006F3FD0->_
             inline - len(1) services.exe - 0x006F404D->_
             inline - len(1) services.exe - 0x006F40CE->_
             inline - len(1) services.exe - 0x006F4175->_
             inline - len(1) services.exe - 0x006F41CF->_
             inline - len(1) services.exe - 0x006F4287->_
             inline - len(1) services.exe - 0x006F429B->_
             inline - len(1) services.exe - 0x006F42AC->_
             inline - len(1) services.exe - 0x006F42FA->_
             inline - len(1) services.exe - 0x006F4385->_
             inline - len(1) services.exe - 0x006F43BC->_
             inline - len(1) services.exe - 0x006F43E2->_
             inline - len(1) services.exe - 0x006F4402->_
             inline - len(1) services.exe - 0x006F4472->_
             inline - len(6) services.exe - 0x006F4480->_
             inline - len(1) services.exe - 0x006F44DB->_
             inline - len(1) services.exe - 0x006F44E7->_
             inline - len(1) services.exe - 0x006F44F6->_
             inline - len(1) services.exe - 0x006F4536->_
             inline - len(1) services.exe - 0x006F4547->_
             inline - len(1) services.exe - 0x006F4559->_
             inline - len(1) services.exe - 0x006F4566->_
             inline - len(1) services.exe - 0x006F4571->_
             inline - len(1) services.exe - 0x006F457A->_
             inline - len(1) services.exe - 0x006F458B->_
             inline - len(1) services.exe - 0x006F4591->_
             inline - len(1) services.exe - 0x006F4599->_
             inline - len(1) services.exe - 0x006F459F->_
             inline - len(1) services.exe - 0x006F45A8->_
             inline - len(6) services.exe - 0x006F45AF->_
             inline - len(6) services.exe - 0x006F45BD->_
             inline - len(1) services.exe - 0x006F45D0->_
             inline - len(1) services.exe - 0x006F45E4->_
             inline - len(1) services.exe - 0x006F468D->_
             inline - len(1) services.exe - 0x006F4693->_
             inline - len(1) services.exe - 0x006F4699->_
             inline - len(1) services.exe - 0x006F46AC->_
             inline - len(1) services.exe - 0x006F46DE->_
             inline - len(5) services.exe - 0x006F4746->_
             inline - len(1) services.exe - 0x006F475D->_
             inline - len(1) services.exe - 0x006F4764->_
             inline - len(1) services.exe - 0x006F477B->_
             inline - len(1) services.exe - 0x006F4781->_
             inline - len(1) services.exe - 0x006F4796->_
             inline - len(1) services.exe - 0x006F479C->_
             inline - len(1) services.exe - 0x006F47A2->_
             inline - len(1) services.exe - 0x006F47DB->_
             inline - len(1) services.exe - 0x006F47F5->_
             inline - len(1) services.exe - 0x006F4802->_
             inline - len(1) services.exe - 0x006F481C->_
             inline - len(1) services.exe - 0x006F4836->_
             inline - len(1) services.exe - 0x006F48D7->_
             inline - len(1) services.exe - 0x006F48DE->_
             inline - len(1) services.exe - 0x006F4965->_
             inline - len(1) services.exe - 0x006F497A->_
             inline - len(11) services.exe - 0x006F4990->_
             inline - len(1) services.exe - 0x006F49C9->_
             inline - len(1) services.exe - 0x006F49DA->_
             inline - len(1) services.exe - 0x006F49FE->_
             inline - len(1) services.exe - 0x006F4A09->_
             inline - len(6) services.exe - 0x006F4A57->_
             inline - len(1) services.exe - 0x006F4ABF->_
             inline - len(1) services.exe - 0x006F4AC8->_
             inline - len(1) services.exe - 0x006F4AF7->_
             inline - len(1) services.exe - 0x006F4B7F->_
             inline - len(1) services.exe - 0x006F4BF6->_
             inline - len(1) services.exe - 0x006F4C6A->_
             inline - len(1) services.exe - 0x006F4CBB->_
             inline - len(1) services.exe - 0x006F4CF2->_
             inline - len(1) services.exe - 0x006F5051->_
             inline - len(5) services.exe - 0x006F506E->_
             inline - len(5) services.exe - 0x006F507E->_
             inline - len(5) services.exe - 0x006F508E->_
             inline - len(5) services.exe - 0x006F509E->_
             inline - len(5) services.exe - 0x006F50AE->_
             inline - len(6) services.exe - 0x006F50DA->_
             inline - len(1) services.exe - 0x006F50FB->_
             inline - len(1) services.exe - 0x006F5125->_
             inline - len(1) services.exe - 0x006F5195->_
             inline - len(1) services.exe - 0x006F52AE->_
             inline - len(1) services.exe - 0x006F52B5->_
             inline - len(1) services.exe - 0x006F5326->_
             inline - len(1) services.exe - 0x006F547D->_
             inline - len(1) services.exe - 0x006F54D8->_
             inline - len(1) services.exe - 0x006F5531->_
             inline - len(1) services.exe - 0x006F55B6->_
             inline - len(1) services.exe - 0x006F564C->_
             inline - len(1) services.exe - 0x006F5653->_
             inline - len(1) services.exe - 0x006F5869->_
             inline - len(1) services.exe - 0x006F58AE->_
             inline - len(1) services.exe - 0x006F58B4->_
             inline - len(1) services.exe - 0x006F58D3->_
             inline - len(1) services.exe - 0x006F5945->_
             inline - len(6) services.exe - 0x006F595C->_
             inline - len(1) services.exe - 0x006F5968->_
             inline - len(6) services.exe - 0x006F5976->_
             inline - len(1) services.exe - 0x006F598B->_
             inline - len(1) services.exe - 0x006F599D->_
             inline - len(1) services.exe - 0x006F59A7->_
             inline - len(1) services.exe - 0x006F59BD->_
             inline - len(6) services.exe - 0x006F59E6->_
             inline - len(1) services.exe - 0x006F5A04->_
             inline - len(1) services.exe - 0x006F5A32->_
             inline - len(1) services.exe - 0x006F5A76->_
             inline - len(1) services.exe - 0x006F5A7C->_
             inline - len(1) services.exe - 0x006F5A92->_
             inline - len(1) services.exe - 0x006F5AAF->_
             inline - len(1) services.exe - 0x006F5ABA->_
             inline - len(1) services.exe - 0x006F5ADA->_
             inline - len(1) services.exe - 0x006F5B1A->_
             inline - len(1) services.exe - 0x006F5B3D->_
             inline - len(6) services.exe - 0x006F5B87->_
             inline - len(1) services.exe - 0x006F5BF6->_
             inline - len(1) services.exe - 0x006F5BFC->_
             inline - len(11) services.exe - 0x006F5C46->_
             inline - len(1) services.exe - 0x006F5C6B->_
             inline - len(1) services.exe - 0x006F5C75->_
             inline - len(1) services.exe - 0x006F5C9E->_
             inline - len(1) services.exe - 0x006F5CFC->_
             inline - len(1) services.exe - 0x006F5DF2->_
             inline - len(1) services.exe - 0x006F5E0F->_
             inline - len(1) services.exe - 0x006F5E52->_
             inline - len(5) services.exe - 0x006F5EAE->_
             inline - len(1) services.exe - 0x006F5F09->_
             inline - len(1) services.exe - 0x006F5F3B->_
             inline - len(1) services.exe - 0x006F5FAB->_
             inline - len(1) services.exe - 0x006F5FE8->_
             inline - len(1) services.exe - 0x006F5FFC->_
             inline - len(6) services.exe - 0x006F610F->_
             inline - len(1) services.exe - 0x006F612A->_
             inline - len(6) services.exe - 0x006F6143->_
             inline - len(1) services.exe - 0x006F6151->_
             inline - len(1) services.exe - 0x006F61D8->_
             inline - len(1) services.exe - 0x006F6211->_
             inline - len(1) services.exe - 0x006F6218->_
             inline - len(1) services.exe - 0x006F6267->_
             inline - len(1) services.exe - 0x006F62AE->_
             inline - len(1) services.exe - 0x006F62BF->_
             inline - len(1) services.exe - 0x006F62F7->_
             inline - len(1) services.exe - 0x006F631A->_
             inline - len(1) services.exe - 0x006F6367->_
             inline - len(1) services.exe - 0x006F638A->_
             inline - len(1) services.exe - 0x006F63A4->_
             inline - len(1) services.exe - 0x006F63B9->_
             inline - len(1) services.exe - 0x006F63D8->_
             inline - len(1) services.exe - 0x006F63F7->_
             inline - len(1) services.exe - 0x006F641A->_
             inline - len(1) services.exe - 0x006F645D->_
             inline - len(1) services.exe - 0x006F647D->_
             inline - len(1) services.exe - 0x006F6523->_
             inline - len(1) services.exe - 0x006F653D->_
             inline - len(1) services.exe - 0x006F6543->_
             inline - len(1) services.exe - 0x006F655B->_
             inline - len(1) services.exe - 0x006F65D4->_
             inline - len(1) services.exe - 0x006F65DA->_
             inline - len(1) services.exe - 0x006F65EF->_
             inline - len(1) services.exe - 0x006F661F->_
             inline - len(1) services.exe - 0x006F667C->_
             inline - len(1) services.exe - 0x006F66D2->_
             inline - len(1) services.exe - 0x006F6704->_
             inline - len(1) services.exe - 0x006F6712->_
             inline - len(1) services.exe - 0x006F671F->_
             inline - len(6) services.exe - 0x006F672D->_
             inline - len(1) services.exe - 0x006F6781->_
             inline - len(1) services.exe - 0x006F67C3->_
             inline - len(1) services.exe - 0x006F67CD->_
             inline - len(1) services.exe - 0x006F6812->_
             inline - len(1) services.exe - 0x006F681D->_
             inline - len(1) services.exe - 0x006F6829->_
             inline - len(1) services.exe - 0x006F68A9->_
             inline - len(1) services.exe - 0x006F68BB->_
             inline - len(6) services.exe - 0x006F68C8->_
             inline - len(1) services.exe - 0x006F68D5->_
             inline - len(6) services.exe - 0x006F68FA->_
             inline - len(1) services.exe - 0x006F690F->_
             inline - len(1) services.exe - 0x006F6923->_
             inline - len(1) services.exe - 0x006F6929->_
             inline - len(1) services.exe - 0x006F6976->_
             inline - len(1) services.exe - 0x006F69EB->_
             inline - len(1) services.exe - 0x006F6A0E->_
             inline - len(1) services.exe - 0x006F6A14->_
             inline - len(1) services.exe - 0x006F6A1B->_
             inline - len(1) services.exe - 0x006F6A34->_
             inline - len(1) services.exe - 0x006F6A3C->_
             inline - len(1) services.exe - 0x006F6A4F->_
             inline - len(1) services.exe - 0x006F6A69->_
             inline - len(1) services.exe - 0x006F6A9D->_
             inline - len(1) services.exe - 0x006F6AAF->_
             inline - len(1) services.exe - 0x006F6AC8->_
             inline - len(1) services.exe - 0x006F6ACF->_
             inline - len(1) services.exe - 0x006F6ADE->_
             inline - len(1) services.exe - 0x006F6AF6->_
             inline - len(1) services.exe - 0x006F6AFC->_
             inline - len(6) services.exe - 0x006F6B02->_
             inline - len(1) services.exe - 0x006F6B2B->_
             inline - len(1) services.exe - 0x006F6B61->_
             inline - len(6) services.exe - 0x006F6B6B->_
             inline - len(1) services.exe - 0x006F6B85->_
             inline - len(1) services.exe - 0x006F6B97->_
             inline - len(1) services.exe - 0x006F6B9D->_
             inline - len(1) services.exe - 0x006F6BA6->_
             inline - len(1) services.exe - 0x006F6C1F->_
             inline - len(1) services.exe - 0x006F6C25->_
             inline - len(1) services.exe - 0x006F6C43->_
             inline - len(1) services.exe - 0x006F6C69->_
             inline - len(6) services.exe - 0x006F6C83->_
             inline - len(6) services.exe - 0x006F6C8F->_
             inline - len(1) services.exe - 0x006F6CA0->_
             inline - len(1) services.exe - 0x006F6CA8->_
             inline - len(11) services.exe - 0x006F6CCB->_
             inline - len(1) services.exe - 0x006F6CE4->_
             inline - len(1) services.exe - 0x006F6D05->_
             inline - len(1) services.exe - 0x006F6D37->_
             inline - len(1) services.exe - 0x006F6DD1->_
             inline - len(1) services.exe - 0x006F6DE4->_
             inline - len(1) services.exe - 0x006F6DEB->_
             inline - len(6) services.exe - 0x006F6E7E->_
             inline - len(1) services.exe - 0x006F6EAC->_
             inline - len(1) services.exe - 0x006F6EFD->_
             inline - len(1) services.exe - 0x006F6F26->_
             inline - len(1) services.exe - 0x006F6F95->_
             inline - len(6) services.exe - 0x006F6FF5->_
             inline - len(1) services.exe - 0x006F7038->_
             inline - len(1) services.exe - 0x006F7042->_
             inline - len(1) services.exe - 0x006F7056->_
             inline - len(1) services.exe - 0x006F7076->_
             inline - len(6) services.exe - 0x006F70EC->_
             inline - len(1) services.exe - 0x006F7114->_
             inline - len(1) services.exe - 0x006F714E->_
             inline - len(6) services.exe - 0x006F7161->_
             inline - len(1) services.exe - 0x006F7195->_
             inline - len(1) services.exe - 0x006F71FD->_
             inline - len(1) services.exe - 0x006F720D->_
             inline - len(1) services.exe - 0x006F7221->_
             inline - len(11) services.exe - 0x006F7246->_
             inline - len(1) services.exe - 0x006F727F->_
             inline - len(1) services.exe - 0x006F72AE->_
             inline - len(1) services.exe - 0x006F72BC->_
             inline - len(1) services.exe - 0x006F72C3->_
             inline - len(1) services.exe - 0x006F731B->_
             inline - len(6) services.exe - 0x006F73B6->_
             inline - len(1) services.exe - 0x006F73D1->_
             inline - len(1) services.exe - 0x006F73E8->_
             inline - len(6) services.exe - 0x006F7423->_
             inline - len(1) services.exe - 0x006F7440->_
             inline - len(1) services.exe - 0x006F74F9->_
             inline - len(1) services.exe - 0x006F7501->_
             inline - len(1) services.exe - 0x006F7544->_
             inline - len(1) services.exe - 0x006F7569->_
             inline - len(1) services.exe - 0x006F758C->_
             inline - len(1) services.exe - 0x006F764E->_
             inline - len(1) services.exe - 0x006F7656->_
             inline - len(1) services.exe - 0x006F7667->_
             inline - len(1) services.exe - 0x006F7678->_
             inline - len(1) services.exe - 0x006F768D->_
             inline - len(1) services.exe - 0x006F769B->_
             inline - len(1) services.exe - 0x006F76A1->_
             inline - len(1) services.exe - 0x006F76BC->_
             inline - len(1) services.exe - 0x006F7712->_
             inline - len(6) services.exe - 0x006F771F->_
             inline - len(1) services.exe - 0x006F7734->_
             inline - len(1) services.exe - 0x006F774A->_
             inline - len(6) services.exe - 0x006F777E->_
             inline - len(1) services.exe - 0x006F7802->_
             inline - len(1) services.exe - 0x006F780C->_
             inline - len(1) services.exe - 0x006F7870->_
             inline - len(1) services.exe - 0x006F78B9->_
             inline - len(1) services.exe - 0x006F78F5->_
             inline - len(1) services.exe - 0x006F7940->_
             inline - len(1) services.exe - 0x006F796B->_
             inline - len(1) services.exe - 0x006F798B->_
             inline - len(1) services.exe - 0x006F79A5->_
             inline - len(1) services.exe - 0x006F79B6->_
             inline - len(1) services.exe - 0x006F79BF->_
             inline - len(1) services.exe - 0x006F79F8->_
             inline - len(11) services.exe - 0x006F7A10->_
             inline - len(1) services.exe - 0x006F7A37->_
             inline - len(1) services.exe - 0x006F7A3D->_
             inline - len(1) services.exe - 0x006F7A43->_
             inline - len(1) services.exe - 0x006F7A54->_
             inline - len(1) services.exe - 0x006F7A5A->_
             inline - len(1) services.exe - 0x006F7B56->_
             inline - len(1) services.exe - 0x006F7B74->_
             inline - len(1) services.exe - 0x006F7B9A->_
             inline - len(1) services.exe - 0x006F7BB2->_
             inline - len(1) services.exe - 0x006F7BB9->_
             inline - len(1) services.exe - 0x006F7BE1->_
             inline - len(1) services.exe - 0x006F7C39->_
             inline - len(1) services.exe - 0x006F7C40->_
             inline - len(1) services.exe - 0x006F7C59->_
             inline - len(1) services.exe - 0x006F7C8D->_
             inline - len(6) services.exe - 0x006F7D21->_
             inline - len(1) services.exe - 0x006F7D2D->_
             inline - len(1) services.exe - 0x006F7D34->_
             inline - len(1) services.exe - 0x006F7D56->_
             inline - len(1) services.exe - 0x006F7DAF->_
             inline - len(6) services.exe - 0x006F7E52->_
             inline - len(1) services.exe - 0x006F7E5E->_
             inline - len(1) services.exe - 0x006F7ED4->_
             inline - len(1) services.exe - 0x006F7EF2->_
             inline - len(1) services.exe - 0x006F7F38->_
             inline - len(1) services.exe - 0x006F7F61->_
             inline - len(1) services.exe - 0x006F7F82->_
             inline - len(1) services.exe - 0x006F7FE4->_
             inline - len(1) services.exe - 0x006F7FFA->_
             inline - len(1) services.exe - 0x006F801D->_
             inline - len(1) services.exe - 0x006F8039->_
             inline - len(1) services.exe - 0x006F8040->_
             inline - len(1) services.exe - 0x006F8054->_
             inline - len(1) services.exe - 0x006F80EE->_
             inline - len(1) services.exe - 0x006F8111->_
             inline - len(1) services.exe - 0x006F8165->_
             inline - len(1) services.exe - 0x006F818B->_
             inline - len(1) services.exe - 0x006F81B4->_
             inline - len(1) services.exe - 0x006F81DB->_
             inline - len(1) services.exe - 0x006F822F->_
             inline - len(1) services.exe - 0x006F8236->_
             inline - len(1) services.exe - 0x006F8274->_
             inline - len(1) services.exe - 0x006F828C->_
             inline - len(6) services.exe - 0x006F8451->_
             inline - len(1) services.exe - 0x006F84E3->_
             inline - len(1) services.exe - 0x006F8591->_
             inline - len(1) services.exe - 0x006F8599->_
             inline - len(6) services.exe - 0x006F85AD->_
             inline - len(1) services.exe - 0x006F85B9->_
             inline - len(1) services.exe - 0x006F85E4->_
             inline - len(1) services.exe - 0x006F8625->_
             inline - len(1) services.exe - 0x006F8635->_
             inline - len(1) services.exe - 0x006F869E->_
             inline - len(1) services.exe - 0x006F86C1->_
             inline - len(1) services.exe - 0x006F86E4->_
             inline - len(1) services.exe - 0x006F8756->_
             inline - len(1) services.exe - 0x006F87AE->_
             inline - len(1) services.exe - 0x006F87CE->_
             inline - len(1) services.exe - 0x006F87F7->_
             inline - len(1) services.exe - 0x006F880D->_
             inline - len(1) services.exe - 0x006F8813->_
             inline - len(1) services.exe - 0x006F882D->_
             inline - len(1) services.exe - 0x006F8852->_
             inline - len(1) services.exe - 0x006F887C->_
             inline - len(1) services.exe - 0x006F89B5->_
             inline - len(11) services.exe - 0x006F89E2->_
             inline - len(1) services.exe - 0x006F8A1A->_
             inline - len(6) services.exe - 0x006F8A34->_
             inline - len(1) services.exe - 0x006F8A5D->_
             inline - len(6) services.exe - 0x006F8A6F->_
             inline - len(1) services.exe - 0x006F8AC8->_
             inline - len(1) services.exe - 0x006F8AEE->_
             inline - len(11) services.exe - 0x006F8B00->_
             inline - len(1) services.exe - 0x006F8B27->_
             inline - len(1) services.exe - 0x006F8B64->_
             inline - len(1) services.exe - 0x006F8B6F->_
             inline - len(6) services.exe - 0x006F8B9E->_
             inline - len(1) services.exe - 0x006F8BB1->_
             inline - len(1) services.exe - 0x006F8BC7->_
             inline - len(1) services.exe - 0x006F8BCE->_
             inline - len(1) services.exe - 0x006F8BDE->_
             inline - len(6) services.exe - 0x006F8C04->_
             inline - len(1) services.exe - 0x006F8C26->_
             inline - len(6) services.exe - 0x006F8C2C->_
             inline - len(1) services.exe - 0x006F8C60->_
             inline - len(1) services.exe - 0x006F8C6B->_
             inline - len(1) services.exe - 0x006F8C78->_
             inline - len(1) services.exe - 0x006F8C91->_
             inline - len(1) services.exe - 0x006F8C9E->_
             inline - len(1) services.exe - 0x006F8CA5->_
             inline - len(6) services.exe - 0x006F8CAB->_
             inline - len(1) services.exe - 0x006F8CCC->_
             inline - len(1) services.exe - 0x006F8CD3->_
             inline - len(1) services.exe - 0x006F8CE9->_
             inline - len(1) services.exe - 0x006F8D0B->_
             inline - len(1) services.exe - 0x006F8D50->_
             inline - len(1) services.exe - 0x006F8D78->_
             inline - len(1) services.exe - 0x006F8DE4->_
             inline - len(1) services.exe - 0x006F8DEF->_
             inline - len(1) services.exe - 0x006F8DF6->_
             inline - len(1) services.exe - 0x006F8E1C->_
             inline - len(1) services.exe - 0x006F8E6E->_
             inline - len(6) services.exe - 0x006F8ED7->_
             inline - len(1) services.exe - 0x006F8EF3->_
             inline - len(1) services.exe - 0x006F8F53->_
             inline - len(6) services.exe - 0x006F900A->_
             inline - len(1) services.exe - 0x006F9023->_
             inline - len(1) services.exe - 0x006F904D->_
             inline - len(1) services.exe - 0x006F905B->_
             inline - len(1) services.exe - 0x006F909A->_
             inline - len(1) services.exe - 0x006F9130->_
             inline - len(6) services.exe - 0x006F9179->_
             inline - len(1) services.exe - 0x006F9185->_
             inline - len(1) services.exe - 0x006F91AA->_
             inline - len(1) services.exe - 0x006F91F4->_
             inline - len(1) services.exe - 0x006F920C->_
             inline - len(1) services.exe - 0x006F9213->_
             inline - len(1) services.exe - 0x006F925A->_
             inline - len(6) services.exe - 0x006F927F->_
             inline - len(1) services.exe - 0x006F928B->_
             inline - len(1) services.exe - 0x006F92C9->_
             inline - len(6) services.exe - 0x006F92DC->_
             inline - len(1) services.exe - 0x006F92F1->_
             inline - len(1) services.exe - 0x006F931B->_
             inline - len(1) services.exe - 0x006F933A->_
             inline - len(1) services.exe - 0x006F9361->_
             inline - len(1) services.exe - 0x006F93D0->_
             inline - len(1) services.exe - 0x006F93FF->_
             inline - len(1) services.exe - 0x006F943F->_
             inline - len(1) services.exe - 0x006F9470->_
             inline - len(1) services.exe - 0x006F9496->_
             inline - len(1) services.exe - 0x006F94BB->_
             inline - len(1) services.exe - 0x006F94CC->_
             inline - len(1) services.exe - 0x006F94E8->_
             inline - len(1) services.exe - 0x006F94F1->_
             inline - len(1) services.exe - 0x006F951F->_
             inline - len(1) services.exe - 0x006F9529->_
             inline - len(1) services.exe - 0x006F9571->_
             inline - len(1) services.exe - 0x006F95CB->_
             inline - len(1) services.exe - 0x006F96C6->_
             inline - len(1) services.exe - 0x006F96D2->_
             inline - len(1) services.exe - 0x006F972F->_
             inline - len(1) services.exe - 0x006F9773->_
             inline - len(1) services.exe - 0x006F977A->_
             inline - len(1) services.exe - 0x006F97A6->_
             inline - len(1) services.exe - 0x006F97AD->_
             inline - len(1) services.exe - 0x006F97FA->_
             inline - len(11) services.exe - 0x006F9828->_
             inline - len(1) services.exe - 0x006F9852->_
             inline - len(1) services.exe - 0x006F9858->_
             inline - len(1) services.exe - 0x006F9865->_
             inline - len(1) services.exe - 0x006F9887->_
             inline - len(6) services.exe - 0x006F98A6->_
             inline - len(1) services.exe - 0x006F98E7->_
             inline - len(1) services.exe - 0x006F9904->_
             inline - len(1) services.exe - 0x006F9971->_
             inline - len(1) services.exe - 0x006F997A->_
             inline - len(1) services.exe - 0x006F998D->_
             inline - len(1) services.exe - 0x006F9996->_
             inline - len(1) services.exe - 0x006F999D->_
             inline - len(1) services.exe - 0x006F99AC->_
             inline - len(1) services.exe - 0x006F99D3->_
             inline - len(1) services.exe - 0x006F99E0->_
             inline - len(1) services.exe - 0x006F9A1F->_
             inline - len(1) services.exe - 0x006F9A2E->_
             inline - len(1) services.exe - 0x006F9A39->_
             inline - len(1) services.exe - 0x006F9A53->_
             inline - len(6) services.exe - 0x006F9A61->_
             inline - len(1) services.exe - 0x006F9A6D->_
             inline - len(1) services.exe - 0x006F9A74->_
             inline - len(1) services.exe - 0x006F9A80->_
             inline - len(1) services.exe - 0x006F9AAD->_
             inline - len(1) services.exe - 0x006F9AB3->_
             inline - len(1) services.exe - 0x006F9AD5->_
             inline - len(1) services.exe - 0x006F9B18->_
             inline - len(1) services.exe - 0x006F9B41->_
             inline - len(1) services.exe - 0x006F9B63->_
             inline - len(1) services.exe - 0x006F9B70->_
             inline - len(1) services.exe - 0x006F9B76->_
             inline - len(1) services.exe - 0x006F9B7D->_
             inline - len(1) services.exe - 0x006F9B83->_
             inline - len(1) services.exe - 0x006F9B99->_
             inline - len(1) services.exe - 0x006F9BBA->_
             inline - len(1) services.exe - 0x006F9BE0->_
             inline - len(1) services.exe - 0x006F9BED->_
             inline - len(1) services.exe - 0x006F9BFA->_
             inline - len(1) services.exe - 0x006F9C11->_
             inline - len(1) services.exe - 0x006F9C27->_
             inline - len(1) services.exe - 0x006F9C76->_
             inline - len(1) services.exe - 0x006F9C83->_
             inline - len(1) services.exe - 0x006F9C9C->_
             inline - len(1) services.exe - 0x006F9CB4->_
             inline - len(1) services.exe - 0x006F9CBC->_
             inline - len(1) services.exe - 0x006F9CCE->_
             inline - len(1) services.exe - 0x006F9CD4->_
             inline - len(1) services.exe - 0x006F9CFC->_
             inline - len(1) services.exe - 0x006F9D0D->_
             inline - len(1) services.exe - 0x006F9D13->_
             inline - len(1) services.exe - 0x006F9D6E->_
             inline - len(1) services.exe - 0x006F9D94->_
             inline - len(1) services.exe - 0x006F9D9B->_
             inline - len(1) services.exe - 0x006F9DD4->_
             inline - len(1) services.exe - 0x006F9DE3->_
             inline - len(1) services.exe - 0x006F9DFF->_
             inline - len(1) services.exe - 0x006F9E35->_
             inline - len(1) services.exe - 0x006F9E3E->_
             inline - len(1) services.exe - 0x006F9EB5->_
             inline - len(1) services.exe - 0x006F9EC4->_
             inline - len(1) services.exe - 0x006F9EDE->_
             inline - len(1) services.exe - 0x006F9EF7->_
             inline - len(1) services.exe - 0x006F9EFE->_
             inline - len(1) services.exe - 0x006F9F33->_
             inline - len(1) services.exe - 0x006F9FAC->_
             inline - len(1) services.exe - 0x006F9FCD->_
             inline - len(1) services.exe - 0x006F9FFD->_
             inline - len(1) services.exe - 0x006FA004->_
             inline - len(11) services.exe - 0x006FA07F->_
             inline - len(1) services.exe - 0x006FA098->_
             inline - len(1) services.exe - 0x006FA193->_
             inline - len(1) services.exe - 0x006FA1F4->_
             inline - len(1) services.exe - 0x006FA382->_
             inline - len(6) services.exe - 0x006FA3BB->_
             inline - len(1) services.exe - 0x006FA3D0->_
             inline - len(1) services.exe - 0x006FA3E7->_
             inline - len(1) services.exe - 0x006FA3ED->_
             inline - len(1) services.exe - 0x006FA43D->_
             inline - len(1) services.exe - 0x006FA48A->_
             inline - len(1) services.exe - 0x006FA4D0->_
             inline - len(1) services.exe - 0x006FA4E1->_
             inline - len(6) services.exe - 0x006FA4F4->_
             inline - len(1) services.exe - 0x006FA50C->_
             inline - len(1) services.exe - 0x006FA5A3->_
             inline - len(1) services.exe - 0x006FA61E->_
             inline - len(1) services.exe - 0x006FA624->_
             inline - len(6) services.exe - 0x006FA62A->_
             inline - len(1) services.exe - 0x006FA646->_
             inline - len(1) services.exe - 0x006FA64C->_
             inline - len(1) services.exe - 0x006FA652->_
             inline - len(1) services.exe - 0x006FA658->_
             inline - len(1) services.exe - 0x006FA756->_
             inline - len(1) services.exe - 0x006FA76D->_
             inline - len(6) services.exe - 0x006FA773->_
             inline - len(1) services.exe - 0x006FA78A->_
             inline - len(1) services.exe - 0x006FA792->_
             inline - len(1) services.exe - 0x006FA80A->_
             inline - len(1) services.exe - 0x006FA833->_
             inline - len(1) services.exe - 0x006FA8DD->_
             inline - len(1) services.exe - 0x006FA901->_
             inline - len(1) services.exe - 0x006FA929->_
             inline - len(1) services.exe - 0x006FA972->_
             inline - len(1) services.exe - 0x006FA9C2->_
             inline - len(1) services.exe - 0x006FAA22->_
             inline - len(1) services.exe - 0x006FAA29->_
             inline - len(6) services.exe - 0x006FAA46->_
             inline - len(1) services.exe - 0x006FAA5B->_
             inline - len(1) services.exe - 0x006FAA8C->_
             inline - len(1) services.exe - 0x006FAA93->_
             inline - len(1) services.exe - 0x006FAAE1->_
             inline - len(6) services.exe - 0x006FAAEB->_
             inline - len(1) services.exe - 0x006FAAFE->_
             inline - len(6) services.exe - 0x006FAB17->_
             inline - len(1) services.exe - 0x006FAB2A->_
             inline - len(1) services.exe - 0x006FAB3F->_
             inline - len(1) services.exe - 0x006FAB46->_
             inline - len(6) services.exe - 0x006FAB52->_
             inline - len(1) services.exe - 0x006FAB67->_
             inline - len(6) services.exe - 0x006FAB83->_
             inline - len(1) services.exe - 0x006FAB98->_
             inline - len(6) services.exe - 0x006FABB1->_
             inline - len(1) services.exe - 0x006FABC6->_
             inline - len(1) services.exe - 0x006FABDE->_
             inline - len(1) services.exe - 0x006FABE4->_
             inline - len(1) services.exe - 0x006FABF2->_
             inline - len(6) services.exe - 0x006FAC0B->_
             inline - len(1) services.exe - 0x006FAC1E->_
             inline - len(1) services.exe - 0x006FAC32->_
             inline - len(6) services.exe - 0x006FAC3C->_
             inline - len(1) services.exe - 0x006FAC4F->_
             inline - len(6) services.exe - 0x006FAC68->_
             inline - len(1) services.exe - 0x006FAC82->_
             inline - len(6) services.exe - 0x006FAC96->_
             inline - len(1) services.exe - 0x006FACB0->_
             inline - len(6) services.exe - 0x006FACB9->_
             inline - len(1) services.exe - 0x006FACCC->_
             inline - len(1) services.exe - 0x006FACE1->_
             inline - len(1) services.exe - 0x006FACE7->_
             inline - len(1) services.exe - 0x006FACFD->_
             inline - len(6) services.exe - 0x006FAD14->_
             inline - len(1) services.exe - 0x006FAD2E->_
             inline - len(1) services.exe - 0x006FAD85->_
             inline - len(1) services.exe - 0x006FAD94->_
             inline - len(1) services.exe - 0x006FAD9A->_
             inline - len(1) services.exe - 0x006FADB0->_
             inline - len(1) services.exe - 0x006FADC8->_
             inline - len(1) services.exe - 0x006FADCE->_
             inline - len(1) services.exe - 0x006FADE4->_
             inline - len(1) services.exe - 0x006FADFC->_
             inline - len(1) services.exe - 0x006FAE02->_
             inline - len(1) services.exe - 0x006FAE19->_
             inline - len(1) services.exe - 0x006FAE31->_
             inline - len(1) services.exe - 0x006FAE37->_
             inline - len(1) services.exe - 0x006FAE50->_
             inline - len(6) services.exe - 0x006FAE67->_
             inline - len(1) services.exe - 0x006FAE7A->_
             inline - len(6) services.exe - 0x006FAE93->_
             inline - len(1) services.exe - 0x006FAEA5->_
             inline - len(1) services.exe - 0x006FAEB9->_
             inline - len(6) services.exe - 0x006FAEC5->_
             inline - len(1) services.exe - 0x006FAEDF->_
             inline - len(1) services.exe - 0x006FAEF5->_
             inline - len(6) services.exe - 0x006FAF01->_
             inline - len(1) services.exe - 0x006FAF1B->_
             inline - len(1) services.exe - 0x006FAF6E->_
             inline - len(1) services.exe - 0x006FAF97->_
             inline - len(1) services.exe - 0x006FAFB2->_
             inline - len(1) services.exe - 0x006FAFD1->_
             inline - len(1) services.exe - 0x006FB008->_
             inline - len(6) services.exe - 0x006FB035->_
             inline - len(1) services.exe - 0x006FB047->_
             inline - len(1) services.exe - 0x006FB066->_
             inline - len(1) services.exe - 0x006FB077->_
             inline - len(1) services.exe - 0x006FB08C->_
             inline - len(1) services.exe - 0x006FB092->_
             inline - len(1) services.exe - 0x006FB0A9->_
             inline - len(1) services.exe - 0x006FB0CE->_
             inline - len(6) services.exe - 0x006FB0DC->_
             inline - len(1) services.exe - 0x006FB0F6->_
             inline - len(1) services.exe - 0x006FB120->_
             inline - len(1) services.exe - 0x006FB132->_
             inline - len(1) services.exe - 0x006FB138->_
             inline - len(1) services.exe - 0x006FB146->_
             inline - len(1) services.exe - 0x006FB15C->_
             inline - len(1) services.exe - 0x006FB163->_
             inline - len(1) services.exe - 0x006FB16A->_
             inline - len(1) services.exe - 0x006FB174->_
             inline - len(1) services.exe - 0x006FB17A->_
             inline - len(1) services.exe - 0x006FB18A->_
             inline - len(1) services.exe - 0x006FB1C5->_
             inline - len(1) services.exe - 0x006FB1CE->_
             inline - len(1) services.exe - 0x006FB1DD->_
             inline - len(1) services.exe - 0x006FB1F3->_
             inline - len(1) services.exe - 0x006FB24F->_
             inline - len(1) services.exe - 0x006FB259->_
             inline - len(1) services.exe - 0x006FB25F->_
             inline - len(1) services.exe - 0x006FB26F->_
             inline - len(1) services.exe - 0x006FB286->_
             inline - len(1) services.exe - 0x006FB296->_
             inline - len(1) services.exe - 0x006FB29F->_
             inline - len(1) services.exe - 0x006FB2A6->_
             inline - len(1) services.exe - 0x006FB326->_
             inline - len(1) services.exe - 0x006FB32C->_
             inline - len(1) services.exe - 0x006FB33A->_
             inline - len(6) services.exe - 0x006FB353->_
             inline - len(1) services.exe - 0x006FB365->_
             inline - len(1) services.exe - 0x006FB382->_
             inline - len(1) services.exe - 0x006FB38A->_
             inline - len(6) services.exe - 0x006FB39A->_
             inline - len(1) services.exe - 0x006FB3B4->_
             inline - len(11) services.exe - 0x006FB3CB->_
             inline - len(1) services.exe - 0x006FB3F4->_
             inline - len(1) services.exe - 0x006FB3FC->_
             inline - len(1) services.exe - 0x006FB408->_
             inline - len(1) services.exe - 0x006FB41C->_
             inline - len(1) services.exe - 0x006FB423->_
             inline - len(1) services.exe - 0x006FB42D->_
             inline - len(1) services.exe - 0x006FB433->_
             inline - len(1) services.exe - 0x006FB450->_
             inline - len(1) services.exe - 0x006FB456->_
             inline - len(1) services.exe - 0x006FB472->_
             inline - len(1) services.exe - 0x006FB490->_
             inline - len(1) services.exe - 0x006FB497->_
             inline - len(6) services.exe - 0x006FB4A1->_
             inline - len(1) services.exe - 0x006FB4C8->_
             inline - len(6) services.exe - 0x006FB4F2->_
             inline - len(6) services.exe - 0x006FB512->_
             inline - len(1) services.exe - 0x006FB54D->_
             inline - len(1) services.exe - 0x006FB553->_
             inline - len(1) services.exe - 0x006FB570->_
             inline - len(1) services.exe - 0x006FB576->_
             inline - len(1) services.exe - 0x006FB59A->_
             inline - len(1) services.exe - 0x006FB5A3->_
             inline - len(1) services.exe - 0x006FB5AB->_
             inline - len(1) services.exe - 0x006FB5B2->_
             inline - len(1) services.exe - 0x006FB5C3->_
             inline - len(1) services.exe - 0x006FB5E1->_
             inline - len(1) services.exe - 0x006FB631->_
             inline - len(1) services.exe - 0x006FB643->_
             inline - len(1) services.exe - 0x006FB66F->_
             inline - len(1) services.exe - 0x006FB685->_
             inline - len(1) services.exe - 0x006FB6A7->_
             inline - len(1) services.exe - 0x006FB6AF->_
             inline - len(1) services.exe - 0x006FB6EB->_
             inline - len(1) services.exe - 0x006FB701->_
             inline - len(1) services.exe - 0x006FB717->_
             inline - len(1) services.exe - 0x006FB725->_
             inline - len(6) services.exe - 0x006FB73C->_
             inline - len(1) services.exe - 0x006FB757->_
             inline - len(6) services.exe - 0x006FB760->_
             inline - len(6) services.exe - 0x006FB784->_
             inline - len(1) services.exe - 0x006FB796->_
             inline - len(6) services.exe - 0x006FB7AF->_
             inline - len(1) services.exe - 0x006FB7C1->_
             inline - len(6) services.exe - 0x006FB7DB->_
             inline - len(1) services.exe - 0x006FB7ED->_
             inline - len(6) services.exe - 0x006FB807->_
             inline - len(1) services.exe - 0x006FB81C->_
             inline - len(1) services.exe - 0x006FB85E->_
             inline - len(1) services.exe - 0x006FB867->_
             inline - len(1) services.exe - 0x006FB883->_
             inline - len(1) services.exe - 0x006FB88A->_
             inline - len(6) services.exe - 0x006FB8C2->_
             inline - len(1) services.exe - 0x006FB8DF->_
             inline - len(1) services.exe - 0x006FB8E5->_
             inline - len(1) services.exe - 0x006FB8FE->_
             inline - len(1) services.exe - 0x006FB929->_
             inline - len(1) services.exe - 0x006FB941->_
             inline - len(1) services.exe - 0x006FB947->_
             inline - len(6) services.exe - 0x006FB95F->_
             inline - len(1) services.exe - 0x006FB97A->_
             inline - len(1) services.exe - 0x006FB980->_
             inline - len(6) services.exe - 0x006FB998->_
             inline - len(1) services.exe - 0x006FB9C5->_
             inline - len(1) services.exe - 0x006FB9D3->_
             inline - len(6) services.exe - 0x006FB9E0->_
             inline - len(1) services.exe - 0x006FBA12->_
             inline - len(1) services.exe - 0x006FBA18->_
             inline - len(1) services.exe - 0x006FBA3F->_
             inline - len(1) services.exe - 0x006FBA4D->_
             inline - len(6) services.exe - 0x006FBA5F->_
             inline - len(6) services.exe - 0x006FBA8D->_
             inline - len(1) services.exe - 0x006FBA9F->_
             inline - len(6) services.exe - 0x006FBABB->_
             inline - len(1) services.exe - 0x006FBAD8->_
             inline - len(1) services.exe - 0x006FBAEF->_
             inline - len(1) services.exe - 0x006FBB1B->_
             inline - len(1) services.exe - 0x006FBB33->_
             inline - len(1) services.exe - 0x006FBB45->_
             inline - len(1) services.exe - 0x006FBB52->_
             inline - len(1) services.exe - 0x006FBB7F->_
             inline - len(1) services.exe - 0x006FBBB7->_
             inline - len(6) services.exe - 0x006FBBFB->_
             inline - len(1) services.exe - 0x006FBC19->_
             inline - len(1) services.exe - 0x006FBC20->_
             inline - len(6) services.exe - 0x006FBCB1->_
             inline - len(1) services.exe - 0x006FBCC4->_
             inline - len(6) services.exe - 0x006FBCCA->_
             inline - len(1) services.exe - 0x006FBCEA->_
             inline - len(6) services.exe - 0x006FBCF2->_
             inline - len(1) services.exe - 0x006FBD07->_
             inline - len(1) services.exe - 0x006FBD1B->_
             inline - len(6) services.exe - 0x006FBD28->_
             inline - len(1) services.exe - 0x006FBD3A->_
             inline - len(6) services.exe - 0x006FBD54->_
             inline - len(1) services.exe - 0x006FBD6A->_
             inline - len(6) services.exe - 0x006FBD70->_
             inline - len(1) services.exe - 0x006FBD8F->_
             inline - len(1) services.exe - 0x006FBDA9->_
             inline - len(1) services.exe - 0x006FBDC9->_
             inline - len(1) services.exe - 0x006FBDFE->_
             inline - len(1) services.exe - 0x006FBE08->_
             inline - len(6) services.exe - 0x006FBE18->_
             inline - len(1) services.exe - 0x006FBE32->_
             inline - len(6) services.exe - 0x006FBE49->_
             inline - len(1) services.exe - 0x006FBE64->_
             inline - len(6) services.exe - 0x006FBE6A->_
             inline - len(1) services.exe - 0x006FBE9B->_
             inline - len(1) services.exe - 0x006FBEBC->_
             inline - len(6) services.exe - 0x006FBEFA->_
             inline - len(1) services.exe - 0x006FBF17->_
             inline - len(1) services.exe - 0x006FBF32->_
             inline - len(1) services.exe - 0x006FBF4A->_
             inline - len(1) services.exe - 0x006FBF50->_
             inline - len(1) services.exe - 0x006FBF66->_
             inline - len(6) services.exe - 0x006FBF7D->_
             inline - len(1) services.exe - 0x006FBF93->_
             inline - len(1) services.exe - 0x006FBF9A->_
             inline - len(6) services.exe - 0x006FBFBF->_
             inline - len(1) services.exe - 0x006FBFCB->_
             inline - len(1) services.exe - 0x006FBFD2->_
             inline - len(1) services.exe - 0x006FBFEA->_
             inline - len(6) services.exe - 0x006FBFF6->_
             inline - len(1) services.exe - 0x006FC033->_
             inline - len(6) services.exe - 0x006FC045->_
             inline - len(6) services.exe - 0x006FC094->_
             inline - len(1) services.exe - 0x006FC0AE->_
             inline - len(6) services.exe - 0x006FC0C5->_
             inline - len(1) services.exe - 0x006FC0DF->_
             inline - len(6) services.exe - 0x006FC0F6->_
             inline - len(1) services.exe - 0x006FC109->_
             inline - len(6) services.exe - 0x006FC10F->_
             inline - len(1) services.exe - 0x006FC12F->_
             inline - len(1) services.exe - 0x006FC17C->_
             inline - len(1) services.exe - 0x006FC185->_
             inline - len(6) services.exe - 0x006FC190->_
             inline - len(1) services.exe - 0x006FC1A5->_
             inline - len(1) services.exe - 0x006FC1D3->_
             inline - len(1) services.exe - 0x006FC202->_
             inline - len(6) services.exe - 0x006FC229->_
             inline - len(1) services.exe - 0x006FC241->_
             inline - len(6) services.exe - 0x006FC27B->_
             inline - len(1) services.exe - 0x006FC28E->_
             inline - len(6) services.exe - 0x006FC294->_
             inline - len(6) services.exe - 0x006FC2D3->_
             inline - len(1) services.exe - 0x006FC2E6->_
             inline - len(6) services.exe - 0x006FC2EC->_
             inline - len(1) services.exe - 0x006FC315->_
             inline - len(6) services.exe - 0x006FC32F->_
             inline - len(1) services.exe - 0x006FC344->_
             inline - len(6) services.exe - 0x006FC384->_
             inline - len(1) services.exe - 0x006FC39C->_
             inline - len(6) services.exe - 0x006FC3D9->_
             inline - len(1) services.exe - 0x006FC3F4->_
             inline - len(1) services.exe - 0x006FC449->_
             inline - len(1) services.exe - 0x006FC499->_
             inline - len(1) services.exe - 0x006FC4DF->_
             inline - len(1) services.exe - 0x006FC4F5->_
             inline - len(6) services.exe - 0x006FC4FF->_
             inline - len(1) services.exe - 0x006FC512->_
             inline - len(6) services.exe - 0x006FC518->_
             inline - len(1) services.exe - 0x006FC537->_
             inline - len(1) services.exe - 0x006FC54A->_
             inline - len(1) services.exe - 0x006FC576->_
             inline - len(1) services.exe - 0x006FC589->_
             inline - len(1) services.exe - 0x006FC58F->_
             inline - len(6) services.exe - 0x006FC5B8->_
             inline - len(1) services.exe - 0x006FC5DA->_
             inline - len(6) services.exe - 0x006FC5EE->_
             inline - len(1) services.exe - 0x006FC601->_
             inline - len(1) services.exe - 0x006FC607->_
             inline - len(1) services.exe - 0x006FC629->_
             inline - len(1) services.exe - 0x006FC63A->_
             inline - len(6) services.exe - 0x006FC65C->_
             inline - len(1) services.exe - 0x006FC677->_
             inline - len(6) services.exe - 0x006FC69A->_
             inline - len(1) services.exe - 0x006FC6B3->_
             inline - len(1) services.exe - 0x006FC6C7->_
             inline - len(1) services.exe - 0x006FC6E6->_
             inline - len(1) services.exe - 0x006FC6F0->_
             inline - len(1) services.exe - 0x006FC701->_
             inline - len(6) services.exe - 0x006FC722->_
             inline - len(1) services.exe - 0x006FC737->_
             inline - len(1) services.exe - 0x006FC751->_
             inline - len(1) services.exe - 0x006FC75B->_
             inline - len(1) services.exe - 0x006FC77A->_
             inline - len(1) services.exe - 0x006FC782->_
             inline - len(1) services.exe - 0x006FC7AD->_
             inline - len(6) services.exe - 0x006FC7C4->_
             inline - len(1) services.exe - 0x006FC7E0->_
             inline - len(1) services.exe - 0x006FC7F3->_
             inline - len(1) services.exe - 0x006FC81F->_
             inline - len(6) services.exe - 0x006FC829->_
             inline - len(1) services.exe - 0x006FC83C->_
             inline - len(6) services.exe - 0x006FC842->_
             inline - len(6) services.exe - 0x006FC861->_
             inline - len(1) services.exe - 0x006FC87C->_
             inline - len(1) services.exe - 0x006FC893->_
             inline - len(1) services.exe - 0x006FC8A6->_
             inline - len(1) services.exe - 0x006FC8D2->_
             inline - len(6) services.exe - 0x006FC8E6->_
             inline - len(1) services.exe - 0x006FC8F9->_
             inline - len(6) services.exe - 0x006FC932->_
             inline - len(1) services.exe - 0x006FC945->_
             inline - len(1) services.exe - 0x006FC959->_
             inline - len(1) services.exe - 0x006FC96E->_
             inline - len(6) services.exe - 0x006FC97F->_
             inline - len(1) services.exe - 0x006FC9A9->_
             inline - len(1) services.exe - 0x006FC9BF->_
             inline - len(1) services.exe - 0x006FC9D5->_
             inline - len(6) services.exe - 0x006FC9E7->_
             inline - len(1) services.exe - 0x006FC9FD->_
             inline - len(6) services.exe - 0x006FCA25->_
             inline - len(1) services.exe - 0x006FCA3A->_
             inline - len(6) services.exe - 0x006FCAC1->_
             inline - len(1) services.exe - 0x006FCACE->_
             inline - len(1) services.exe - 0x006FCAD6->_
             inline - len(1) services.exe - 0x006FCADD->_
             inline - len(1) services.exe - 0x006FCAEE->_
             inline - len(1) services.exe - 0x006FCAFA->_
             inline - len(1) services.exe - 0x006FCB08->_
             inline - len(6) services.exe - 0x006FCB18->_
             inline - len(1) services.exe - 0x006FCB3B->_
             inline - len(6) services.exe - 0x006FCB78->_
             inline - len(1) services.exe - 0x006FCB98->_
             inline - len(6) services.exe - 0x006FCBAE->_
             inline - len(1) services.exe - 0x006FCBBB->_
             inline - len(1) services.exe - 0x006FCBC3->_
             inline - len(1) services.exe - 0x006FCBCA->_
             inline - len(1) services.exe - 0x006FCBD7->_
             inline - len(1) services.exe - 0x006FCBE6->_
             inline - len(1) services.exe - 0x006FCBF4->_
             inline - len(6) services.exe - 0x006FCC04->_
             inline - len(1) services.exe - 0x006FCC27->_
             inline - len(1) services.exe - 0x006FCC7D->_
             inline - len(1) services.exe - 0x006FCC90->_
             inline - len(1) services.exe - 0x006FCCC5->_
             inline - len(1) services.exe - 0x006FCCF5->_
             inline - len(6) services.exe - 0x006FCD00->_
             inline - len(1) services.exe - 0x006FCD23->_
             inline - len(1) services.exe - 0x006FCD4C->_
             inline - len(1) services.exe - 0x006FCD52->_
             inline - len(1) services.exe - 0x006FCD68->_
             inline - len(6) services.exe - 0x006FCD7F->_
             inline - len(1) services.exe - 0x006FCD92->_
             inline - len(1) services.exe - 0x006FCDA5->_
             inline - len(1) services.exe - 0x006FCDE5->_
             inline - len(1) services.exe - 0x006FCDEB->_
             inline - len(1) services.exe - 0x006FCE08->_
             inline - len(1) services.exe - 0x006FCE1F->_
             inline - len(1) services.exe - 0x006FCE32->_
             inline - len(1) services.exe - 0x006FCE5E->_
             inline - len(6) services.exe - 0x006FCE69->_
             inline - len(1) services.exe - 0x006FCE75->_
             inline - len(6) services.exe - 0x006FCEA2->_
             inline - len(6) services.exe - 0x006FCEE1->_
             inline - len(1) services.exe - 0x006FCF06->_
             inline - len(1) services.exe - 0x006FCF1C->_
             inline - len(1) services.exe - 0x006FCF26->_
             inline - len(1) services.exe - 0x006FCF39->_
             inline - len(1) services.exe - 0x006FCF65->_
             inline - len(6) services.exe - 0x006FCF79->_
             inline - len(1) services.exe - 0x006FCF94->_
             inline - len(1) services.exe - 0x006FCF9A->_
             inline - len(1) services.exe - 0x006FCFA0->_
             inline - len(1) services.exe - 0x006FCFBB->_
             inline - len(1) services.exe - 0x006FCFC7->_
             inline - len(1) services.exe - 0x006FCFDA->_
             inline - len(1) services.exe - 0x006FD006->_
             inline - len(6) services.exe - 0x006FD02E->_
             inline - len(1) services.exe - 0x006FD041->_
             inline - len(6) services.exe - 0x006FD047->_
             inline - len(6) services.exe - 0x006FD073->_
             inline - len(1) services.exe - 0x006FD08D->_
             inline - len(6) services.exe - 0x006FD0A4->_
             inline - len(1) services.exe - 0x006FD0BE->_
             inline - len(6) services.exe - 0x006FD0C7->_
             inline - len(1) services.exe - 0x006FD0E1->_
             inline - len(6) services.exe - 0x006FD0EA->_
             inline - len(1) services.exe - 0x006FD104->_
             inline - len(1) services.exe - 0x006FD115->_
             inline - len(1) services.exe - 0x006FD123->_
             inline - len(1) services.exe - 0x006FD133->_
             inline - len(1) services.exe - 0x006FD139->_
             inline - len(1) services.exe - 0x006FD140->_
             inline - len(1) services.exe - 0x006FD172->_
             inline - len(1) services.exe - 0x006FD18B->_
             inline - len(1) services.exe - 0x006FD19F->_
             inline - len(1) services.exe - 0x006FD1AD->_
             inline - len(1) services.exe - 0x006FD1BD->_
             inline - len(1) services.exe - 0x006FD1C3->_
             inline - len(1) services.exe - 0x006FD1D5->_
             inline - len(1) services.exe - 0x006FD1FB->_
             inline - len(1) services.exe - 0x006FD214->_
             inline - len(1) services.exe - 0x006FD220->_
             inline - len(1) services.exe - 0x006FD238->_
             inline - len(1) services.exe - 0x006FD23E->_
             inline - len(1) services.exe - 0x006FD254->_
             inline - len(1) services.exe - 0x006FD26E->_
             inline - len(1) services.exe - 0x006FD27C->_
             inline - len(1) services.exe - 0x006FD28C->_
             inline - len(6) services.exe - 0x006FD292->_
             inline - len(1) services.exe - 0x006FD2AE->_
             inline - len(1) services.exe - 0x006FD2CC->_
             inline - len(1) services.exe - 0x006FD2FA->_
             inline - len(1) services.exe - 0x006FD304->_
             inline - len(1) services.exe - 0x006FD314->_
             inline - len(1) services.exe - 0x006FD32D->_
             inline - len(1) services.exe - 0x006FD344->_
             inline - len(1) services.exe - 0x006FD354->_
             inline - len(1) services.exe - 0x006FD380->_
             inline - len(6) services.exe - 0x006FD3AC->_
             inline - len(1) services.exe - 0x006FD3BE->_
             inline - len(6) services.exe - 0x006FD3D8->_
             inline - len(1) services.exe - 0x006FD407->_
             inline - len(1) services.exe - 0x006FD40F->_
             inline - len(1) services.exe - 0x006FD42F->_
             inline - len(6) services.exe - 0x006FD437->_
             inline - len(1) services.exe - 0x006FD444->_
             inline - len(1) services.exe - 0x006FD45D->_
             inline - len(1) services.exe - 0x006FD475->_
             inline - len(11) services.exe - 0x006FD47D->_
             inline - len(1) services.exe - 0x006FD49C->_
             inline - len(1) services.exe - 0x006FD4BD->_
             inline - len(11) services.exe - 0x006FD4C5->_
             inline - len(1) services.exe - 0x006FD4DC->_
             inline - len(1) services.exe - 0x006FD4F7->_
             inline - len(1) services.exe - 0x006FD4FF->_
             inline - len(6) services.exe - 0x006FD509->_
             inline - len(1) services.exe - 0x006FD524->_
             inline - len(1) services.exe - 0x006FD55F->_
             inline - len(6) services.exe - 0x006FD573->_
             inline - len(1) services.exe - 0x006FD585->_
             inline - len(1) services.exe - 0x006FD5B5->_
             inline - len(6) services.exe - 0x006FD5C9->_
             inline - len(1) services.exe - 0x006FD5E3->_
             inline - len(6) services.exe - 0x006FD618->_
             inline - len(1) services.exe - 0x006FD635->_
             inline - len(1) services.exe - 0x006FD657->_
             inline - len(6) services.exe - 0x006FD66B->_
             inline - len(1) services.exe - 0x006FD685->_
             inline - len(6) services.exe - 0x006FD6C5->_
             inline - len(1) services.exe - 0x006FD6D8->_
             inline - len(6) services.exe - 0x006FD6DE->_
             inline - len(1) services.exe - 0x006FD701->_
             inline - len(6) services.exe - 0x006FD742->_
             inline - len(1) services.exe - 0x006FD75F->_
             inline - len(6) services.exe - 0x006FD78E->_
             inline - len(1) services.exe - 0x006FD7AB->_
             inline - len(1) services.exe - 0x006FD7CC->_
             inline - len(6) services.exe - 0x006FD7D6->_
             inline - len(1) services.exe - 0x006FD7E8->_
             inline - len(6) services.exe - 0x006FD81A->_
             inline - len(1) services.exe - 0x006FD837->_
             inline - len(6) services.exe - 0x006FD843->_
             inline - len(1) services.exe - 0x006FD860->_
             inline - len(6) services.exe - 0x006FD87E->_
             inline - len(1) services.exe - 0x006FD89B->_
             inline - len(6) services.exe - 0x006FD8D1->_
             inline - len(1) services.exe - 0x006FD8EE->_
             inline - len(1) services.exe - 0x006FD95D->_
             inline - len(1) services.exe - 0x006FD983->_
             inline - len(6) services.exe - 0x006FDAF1->_
             inline - len(1) services.exe - 0x006FDB0E->_
             inline - len(6) services.exe - 0x006FDB37->_
             inline - len(1) services.exe - 0x006FDB54->_
             inline - len(1) services.exe - 0x006FDC85->_
             inline - len(1) services.exe - 0x006FDCC4->_
             inline - len(1) services.exe - 0x006FDCD7->_
             inline - len(1) services.exe - 0x006FDD19->_
             inline - len(1) services.exe - 0x006FDDB4->_
             inline - len(1) services.exe - 0x006FDE7B->_
             inline - len(1) services.exe - 0x006FDE8B->_
             inline - len(1) services.exe - 0x006FDEB7->_
             inline - len(6) services.exe - 0x006FDECB->_
             inline - len(1) services.exe - 0x006FDEDE->_
             inline - len(1) services.exe - 0x006FDF26->_
             inline - len(1) services.exe - 0x006FDF56->_
             inline - len(1) services.exe - 0x006FDF85->_
             inline - len(1) services.exe - 0x006FDF94->_
             inline - len(1) services.exe - 0x006FDFB6->_
             inline - len(1) services.exe - 0x006FDFFD->_
             inline - len(1) services.exe - 0x006FE00B->_
             inline - len(1) services.exe - 0x006FE012->_
             inline - len(6) services.exe - 0x006FE040->_
             inline - len(6) services.exe - 0x006FE06E->_
             inline - len(6) services.exe - 0x006FE08E->_
             inline - len(6) services.exe - 0x006FE0AE->_
             inline - len(6) services.exe - 0x006FE0CE->_
             inline - len(6) services.exe - 0x006FE0FF->_
             inline - len(6) services.exe - 0x006FE122->_
             inline - len(6) services.exe - 0x006FE145->_
             inline - len(6) services.exe - 0x006FE168->_
             inline - len(6) services.exe - 0x006FE18B->_
             inline - len(6) services.exe - 0x006FE1AE->_
             inline - len(6) services.exe - 0x006FE1F0->_
             inline - len(6) services.exe - 0x006FE213->_
             inline - len(6) services.exe - 0x006FE236->_
             inline - len(6) services.exe - 0x006FE26E->_
             inline - len(6) services.exe - 0x006FE291->_
             inline - len(6) services.exe - 0x006FE2D0->_
             inline - len(6) services.exe - 0x006FE2F3->_
             inline - len(6) services.exe - 0x006FE32B->_
             inline - len(6) services.exe - 0x006FE398->_
             inline - len(1) services.exe - 0x006FE3E1->_
             inline - len(1) services.exe - 0x006FE3EB->_
             inline - len(1) services.exe - 0x006FE3FB->_
             inline - len(1) services.exe - 0x006FE427->_
             inline - len(1) services.exe - 0x006FE44E->_
             inline - len(1) services.exe - 0x006FE454->_
             inline - len(1) services.exe - 0x006FE46C->_
             inline - len(1) services.exe - 0x006FE482->_
             inline - len(1) services.exe - 0x006FE498->_
             inline - len(1) services.exe - 0x006FE4AE->_
             inline - len(1) services.exe - 0x006FE4C4->_
             inline - len(1) services.exe - 0x006FE4D7->_
             inline - len(1) services.exe - 0x006FE4E5->_
             inline - len(6) services.exe - 0x006FE508->_
             inline - len(1) services.exe - 0x006FE522->_
             inline - len(6) services.exe - 0x006FE53F->_
             inline - len(1) services.exe - 0x006FE55A->_
             inline - len(6) services.exe - 0x006FE563->_
             inline - len(1) services.exe - 0x006FE580->_
             inline - len(1) services.exe - 0x006FE58A->_
             inline - len(6) services.exe - 0x006FE592->_
             inline - len(1) services.exe - 0x006FE5AF->_
             inline - len(1) services.exe - 0x006FE5D2->_
             inline - len(6) services.exe - 0x006FE5DF->_
             inline - len(1) services.exe - 0x006FE5FF->_
             inline - len(6) services.exe - 0x006FE616->_
             inline - len(1) services.exe - 0x006FE629->_
             inline - len(1) services.exe - 0x006FE63C->_
             inline - len(6) services.exe - 0x006FE659->_
             inline - len(1) services.exe - 0x006FE677->_
             inline - len(1) services.exe - 0x006FE68F->_
             inline - len(6) services.exe - 0x006FE697->_
             inline - len(1) services.exe - 0x006FE6B7->_
             inline - len(6) services.exe - 0x006FE6D4->_
             inline - len(1) services.exe - 0x006FE6F2->_
             inline - len(1) services.exe - 0x006FE705->_
             inline - len(6) services.exe - 0x006FE72C->_
             inline - len(1) services.exe - 0x006FE747->_
             inline - len(6) services.exe - 0x006FE750->_
             inline - len(1) services.exe - 0x006FE76D->_
             inline - len(6) services.exe - 0x006FE775->_
             inline - len(1) services.exe - 0x006FE792->_
             inline - len(1) services.exe - 0x006FE79F->_
             inline - len(6) services.exe - 0x006FE7A7->_
             inline - len(1) services.exe - 0x006FE7C4->_
             inline - len(1) services.exe - 0x006FE7CE->_
             inline - len(6) services.exe - 0x006FE7D6->_
             inline - len(1) services.exe - 0x006FE7F3->_
             inline - len(1) services.exe - 0x006FE7FD->_
             inline - len(6) services.exe - 0x006FE805->_
             inline - len(1) services.exe - 0x006FE822->_
             inline - len(1) services.exe - 0x006FE83D->_
             inline - len(1) services.exe - 0x006FE848->_
             inline - len(6) services.exe - 0x006FE84F->_
             inline - len(1) services.exe - 0x006FE86A->_
             inline - len(1) services.exe - 0x006FE882->_
             inline - len(6) services.exe - 0x006FE889->_
             inline - len(1) services.exe - 0x006FE8A4->_
             inline - len(1) services.exe - 0x006FE8CA->_
             inline - len(1) services.exe - 0x006FE8D5->_
             inline - len(1) services.exe - 0x006FE8DB->_
             inline - len(1) services.exe - 0x006FE8E8->_
             inline - len(1) services.exe - 0x006FE8F5->_
             inline - len(1) services.exe - 0x006FE8FB->_
             inline - len(1) services.exe - 0x006FE90A->_
             inline - len(1) services.exe - 0x006FE925->_
             inline - len(1) services.exe - 0x006FE948->_
             inline - len(6) services.exe - 0x006FE979->_
             inline - len(1) services.exe - 0x006FE994->_
             inline - len(6) services.exe - 0x006FE99A->_
             inline - len(6) services.exe - 0x006FE9B9->_
             inline - len(1) services.exe - 0x006FE9CB->_
             inline - len(6) services.exe - 0x006FE9E5->_
             inline - len(1) services.exe - 0x006FE9FA->_
             inline - len(1) services.exe - 0x006FEA0C->_
             inline - len(1) services.exe - 0x006FEA12->_
             inline - len(1) services.exe - 0x006FEA23->_
             inline - len(1) services.exe - 0x006FEA42->_
             inline - len(1) services.exe - 0x006FEA48->_
             inline - len(6) services.exe - 0x006FEA58->_
             inline - len(1) services.exe - 0x006FEA76->_
             inline - len(6) services.exe - 0x006FEA8D->_
             inline - len(1) services.exe - 0x006FEAA8->_
             inline - len(1) services.exe - 0x006FEAC6->_
             inline - len(6) services.exe - 0x006FEACE->_
             inline - len(1) services.exe - 0x006FEAE3->_
             inline - len(6) services.exe - 0x006FEAF6->_
             inline - len(1) services.exe - 0x006FEB02->_
             inline - len(1) services.exe - 0x006FEB17->_
             inline - len(1) services.exe - 0x006FEB1D->_
             inline - len(1) services.exe - 0x006FEB2F->_
             inline - len(6) services.exe - 0x006FEB35->_
             inline - len(6) services.exe - 0x006FEB4E->_
             inline - len(1) services.exe - 0x006FEB66->_
             inline - len(6) services.exe - 0x006FEB83->_
             inline - len(1) services.exe - 0x006FEBA1->_
             inline - len(1) services.exe - 0x006FEBB3->_
             inline - len(1) services.exe - 0x006FEBB9->_
             inline - len(1) services.exe - 0x006FEBD2->_
             inline - len(1) services.exe - 0x006FEBE2->_
             inline - len(6) services.exe - 0x006FEBEA->_
             inline - len(1) services.exe - 0x006FEC0A->_
             inline - len(6) services.exe - 0x006FEC1C->_
             inline - len(1) services.exe - 0x006FEC3A->_
             inline - len(6) services.exe - 0x006FEC57->_
             inline - len(1) services.exe - 0x006FEC75->_
             inline - len(6) services.exe - 0x006FEC84->_
             inline - len(1) services.exe - 0x006FECA2->_
             inline - len(1) services.exe - 0x006FECD4->_
             inline - len(1) services.exe - 0x006FECDA->_
             inline - len(1) services.exe - 0x006FECF6->_
             inline - len(1) services.exe - 0x006FED26->_
             inline - len(6) services.exe - 0x006FED2E->_
             inline - len(1) services.exe - 0x006FED51->_
             inline - len(1) services.exe - 0x006FED75->_
             inline - len(6) services.exe - 0x006FED84->_
             inline - len(1) services.exe - 0x006FEDA8->_
             inline - len(6) services.exe - 0x006FEDC5->_
             inline - len(1) services.exe - 0x006FEDE7->_
             inline - len(6) services.exe - 0x006FEDF0->_
             inline - len(6) services.exe - 0x006FEE0E->_
             inline - len(1) services.exe - 0x006FEE2D->_
             inline - len(6) services.exe - 0x006FEE47->_
             inline - len(1) services.exe - 0x006FEE6D->_
             inline - len(6) services.exe - 0x006FEE84->_
             inline - len(1) services.exe - 0x006FEEA7->_
             inline - len(6) services.exe - 0x006FEEBE->_
             inline - len(1) services.exe - 0x006FEEDC->_
             inline - len(1) services.exe - 0x006FEF21->_
             inline - len(1) services.exe - 0x006FEF3C->_
             inline - len(1) services.exe - 0x006FEF5C->_
             inline - len(1) services.exe - 0x006FEF62->_
             inline - len(1) services.exe - 0x006FEF7E->_
             inline - len(1) services.exe - 0x006FEF8E->_
             inline - len(1) services.exe - 0x006FEF94->_
             inline - len(1) services.exe - 0x006FEFAD->_
             inline - len(6) services.exe - 0x006FEFCF->_
             inline - len(1) services.exe - 0x006FEFEF->_
             inline - len(6) services.exe - 0x006FF009->_
             inline - len(1) services.exe - 0x006FF024->_
             inline - len(6) services.exe - 0x006FF052->_
             inline - len(1) services.exe - 0x006FF06D->_
             inline - len(6) services.exe - 0x006FF07C->_
             inline - len(1) services.exe - 0x006FF08F->_
             inline - len(1) services.exe - 0x006FF0A5->_
             inline - len(6) services.exe - 0x006FF0BF->_
             inline - len(1) services.exe - 0x006FF0DA->_
             inline - len(6) services.exe - 0x006FF0EA->_
             inline - len(1) services.exe - 0x006FF105->_
             inline - len(1) services.exe - 0x006FF11F->_
             inline - len(1) services.exe - 0x006FF132->_
             inline - len(1) services.exe - 0x006FF15D->_
             inline - len(6) services.exe - 0x006FF252->_
             inline - len(1) services.exe - 0x006FF29F->_
             inline - len(1) services.exe - 0x006FF2A6->_
             inline - len(1) services.exe - 0x006FF2D5->_
             inline - len(6) services.exe - 0x006FF2FC->_
             inline - len(1) services.exe - 0x006FF317->_
             inline - len(6) services.exe - 0x006FF358->_
             inline - len(1) services.exe - 0x006FF374->_
             inline - len(6) services.exe - 0x006FF3AE->_
             inline - len(1) services.exe - 0x006FF3C9->_
             inline - len(6) services.exe - 0x006FF3D5->_
             inline - len(1) services.exe - 0x006FF3F0->_
             inline - len(6) services.exe - 0x006FF40B->_
             inline - len(1) services.exe - 0x006FF426->_
             inline - len(6) services.exe - 0x006FF42F->_
             inline - len(1) services.exe - 0x006FF44A->_
             inline - len(6) services.exe - 0x006FF467->_
             inline - len(1) services.exe - 0x006FF47A->_
             inline - len(6) services.exe - 0x006FF4A5->_
             inline - len(1) services.exe - 0x006FF4B1->_
             inline - len(1) services.exe - 0x006FF4C5->_
             inline - len(1) services.exe - 0x006FF4CB->_
             inline - len(1) services.exe - 0x006FF4E2->_
             inline - len(1) services.exe - 0x006FF505->_
             inline - len(1) services.exe - 0x006FF51B->_
             inline - len(1) services.exe - 0x006FF525->_
             inline - len(11) services.exe - 0x006FF539->_
             inline - len(1) services.exe - 0x006FF551->_
             inline - len(1) services.exe - 0x006FF559->_
             inline - len(1) services.exe - 0x006FF56C->_
             inline - len(6) services.exe - 0x006FF5AC->_
             inline - len(1) services.exe - 0x006FF5C1->_
             inline - len(6) services.exe - 0x006FF5E0->_
             inline - len(1) services.exe - 0x006FF5FD->_
             inline - len(6) services.exe - 0x006FF64E->_
             inline - len(1) services.exe - 0x006FF66E->_
             inline - len(6) services.exe - 0x006FF685->_
             inline - len(1) services.exe - 0x006FF6A0->_
             inline - len(6) services.exe - 0x006FF6A6->_
             inline - len(11) services.exe - 0x006FF6C2->_
             inline - len(1) services.exe - 0x006FF6F5->_
             inline - len(1) services.exe - 0x006FF73A->_
             inline - len(6) services.exe - 0x006FF747->_
             inline - len(1) services.exe - 0x006FF77B->_
             inline - len(1) services.exe - 0x006FF790->_
             inline - len(1) services.exe - 0x006FF799->_
             inline - len(1) services.exe - 0x006FF79F->_
             inline - len(1) services.exe - 0x006FF7B5->_
             inline - len(1) services.exe - 0x006FF7D0->_
             inline - len(1) services.exe - 0x006FF800->_
             inline - len(1) services.exe - 0x006FF857->_
             inline - len(1) services.exe - 0x006FF880->_
             inline - len(1) services.exe - 0x006FF899->_
             inline - len(1) services.exe - 0x006FF8B7->_
             inline - len(1) services.exe - 0x006FF8BF->_
             inline - len(1) services.exe - 0x006FF8EC->_
             inline - len(1) services.exe - 0x006FF90B->_
             inline - len(6) services.exe - 0x006FF92B->_
             inline - len(1) services.exe - 0x006FF983->_
             inline - len(1) services.exe - 0x006FF98E->_
             inline - len(1) services.exe - 0x006FF99E->_
             inline - len(6) services.exe - 0x006FF9C9->_
             inline - len(1) services.exe - 0x006FFA10->_
             inline - len(1) services.exe - 0x006FFA16->_
             inline - len(1) services.exe - 0x006FFA29->_
             inline - len(6) services.exe - 0x006FFA42->_
             inline - len(1) services.exe - 0x006FFA57->_
             inline - len(6) services.exe - 0x006FFA78->_
             inline - len(1) services.exe - 0x006FFA93->_
             inline - len(6) services.exe - 0x006FFAD6->_
             inline - len(1) services.exe - 0x006FFAEE->_
             inline - len(1) services.exe - 0x006FFB08->_
             inline - len(1) services.exe - 0x006FFB59->_
             inline - len(1) services.exe - 0x006FFB61->_
             inline - len(6) services.exe - 0x006FFB90->_
             inline - len(1) services.exe - 0x006FFBA5->_
             inline - len(6) services.exe - 0x006FFBCB->_
             inline - len(1) services.exe - 0x006FFBEE->_
             inline - len(6) services.exe - 0x006FFC60->_
             inline - len(1) services.exe - 0x006FFC75->_
             inline - len(1) services.exe - 0x006FFCFD->_
             inline - len(1) services.exe - 0x006FFD1F->_
             inline - len(6) services.exe - 0x006FFD2A->_
             inline - len(1) services.exe - 0x006FFD43->_
             inline - len(1) services.exe - 0x006FFD56->_
             inline - len(6) services.exe - 0x006FFD70->_
             inline - len(1) services.exe - 0x006FFD89->_
             inline - len(1) services.exe - 0x006FFDBA->_
             inline - len(6) services.exe - 0x006FFDC4->_
             inline - len(1) services.exe - 0x006FFDD6->_
             inline - len(1) services.exe - 0x006FFDFC->_
             inline - len(6) services.exe - 0x006FFE03->_
             inline - len(1) services.exe - 0x006FFE16->_
             inline - len(1) services.exe - 0x006FFE29->_
             inline - len(1) services.exe - 0x006FFE61->_
             inline - len(1) services.exe - 0x006FFE67->_
             inline - len(1) services.exe - 0x006FFE9A->_
             inline - len(6) services.exe - 0x006FFEA8->_
             inline - len(6) services.exe - 0x006FFED6->_
             inline - len(1) services.exe - 0x006FFEFA->_
             inline - len(1) services.exe - 0x006FFF1F->_
             inline - len(6) services.exe - 0x006FFF29->_
             inline - len(1) services.exe - 0x006FFF3C->_
             inline - len(1) services.exe - 0x006FFF52->_
             inline - len(1) services.exe - 0x006FFF67->_
             inline - len(1) services.exe - 0x006FFF6E->_
             inline - len(1) services.exe - 0x006FFF8D->_
             inline - len(1) services.exe - 0x006FFFA3->_
             inline - len(1) services.exe - 0x006FFFBB->_
             inline - len(1) services.exe - 0x006FFFC1->_
             inline - len(6) services.exe - 0x006FFFD9->_
             inline - len(1) services.exe - 0x006FFFFB->_
             inline - len(1) services.exe - 0x00700021->_
             inline - len(1) services.exe - 0x007000CB->_
             inline - len(1) services.exe - 0x0070010C->_
             inline - len(6) services.exe - 0x00700123->_
             inline - len(1) services.exe - 0x00700143->_
             inline - len(11) services.exe - 0x007001C3->_
             inline - len(1) services.exe - 0x007001ED->_
             inline - len(1) services.exe - 0x007001F7->_
             inline - len(1) services.exe - 0x00700206->_
             inline - len(1) services.exe - 0x0070020D->_
             inline - len(1) services.exe - 0x00700238->_
             inline - len(1) services.exe - 0x0070024D->_
             inline - len(1) services.exe - 0x00700254->_
             inline - len(1) services.exe - 0x00700271->_
             inline - len(1) services.exe - 0x007002BC->_
             inline - len(1) services.exe - 0x007002C5->_
             inline - len(1) services.exe - 0x007002D0->_
             inline - len(1) services.exe - 0x00700305->_
             inline - len(1) services.exe - 0x0070033F->_
             inline - len(1) services.exe - 0x00700349->_
             inline - len(1) services.exe - 0x0070034F->_
             inline - len(1) services.exe - 0x00700373->_
             inline - len(1) services.exe - 0x0070037F->_
             inline - len(6) services.exe - 0x0070040E->_
             inline - len(6) services.exe - 0x00700429->_
             inline - len(6) services.exe - 0x00700445->_
             inline - len(1) services.exe - 0x00700460->_
             inline - len(6) services.exe - 0x00700488->_
             inline - len(1) services.exe - 0x007004A3->_
             inline - len(6) services.exe - 0x007004BE->_
             inline - len(1) services.exe - 0x007004D9->_
             inline - len(1) services.exe - 0x007004E2->_
             inline - len(1) services.exe - 0x007004ED->_
             inline - len(1) services.exe - 0x007004FA->_
             inline - len(6) services.exe - 0x00700501->_
             inline - len(1) services.exe - 0x0070051C->_
             inline - len(6) services.exe - 0x00700533->_
             inline - len(1) services.exe - 0x00700564->_
             inline - len(1) services.exe - 0x007005A2->_
             inline - len(1) services.exe - 0x007005A8->_
             inline - len(1) services.exe - 0x007005BF->_
             inline - len(1) services.exe - 0x007005E1->_
             inline - len(1) services.exe - 0x007005E9->_
             inline - len(1) services.exe - 0x007005F1->_
             inline - len(1) services.exe - 0x00700604->_
             inline - len(1) services.exe - 0x00700627->_
             inline - len(1) services.exe - 0x00700648->_
             inline - len(1) services.exe - 0x0070064E->_
             inline - len(1) services.exe - 0x00700656->_
             inline - len(6) services.exe - 0x0070067A->_
             inline - len(1) services.exe - 0x007006AB->_
             inline - len(6) services.exe - 0x00700709->_
             inline - len(1) services.exe - 0x00700727->_
             inline - len(6) services.exe - 0x0070073E->_
             inline - len(1) services.exe - 0x0070075C->_
             inline - len(1) services.exe - 0x00700765->_
             inline - len(1) services.exe - 0x00700784->_
             inline - len(6) services.exe - 0x007007B1->_
             inline - len(1) services.exe - 0x007007CC->_
             inline - len(6) services.exe - 0x007007D2->_
             inline - len(6) services.exe - 0x007007EE->_
             inline - len(1) services.exe - 0x00700809->_
             inline - len(1) services.exe - 0x00700815->_
             inline - len(1) services.exe - 0x0070081B->_
             inline - len(6) services.exe - 0x00700839->_
             inline - len(1) services.exe - 0x0070084C->_
             inline - len(1) services.exe - 0x00700877->_
             inline - len(6) services.exe - 0x00700881->_
             inline - len(1) services.exe - 0x0070089C->_
             inline - len(6) services.exe - 0x007008B3->_
             inline - len(1) services.exe - 0x007008C5->_
             inline - len(1) services.exe - 0x007008E8->_
             inline - len(1) services.exe - 0x007008F3->_
             inline - len(6) services.exe - 0x0070090E->_
             inline - len(1) services.exe - 0x00700920->_
             inline - len(1) services.exe - 0x00700936->_
             inline - len(1) services.exe - 0x0070095B->_
             inline - len(6) services.exe - 0x00700981->_
             inline - len(1) services.exe - 0x0070099E->_
             inline - len(1) services.exe - 0x007009E1->_
             inline - len(6) services.exe - 0x00700A03->_
             inline - len(1) services.exe - 0x00700A18->_
             inline - len(1) services.exe - 0x00700A38->_
             inline - len(1) services.exe - 0x00700A4E->_
             inline - len(1) services.exe - 0x00700A78->_
             inline - len(6) services.exe - 0x00700ACE->_
             inline - len(6) services.exe - 0x00700AF3->_
             inline - len(6) services.exe - 0x00700B24->_
             inline - len(1) services.exe - 0x00700B3A->_
             inline - len(1) services.exe - 0x00700B5D->_
             inline - len(1) services.exe - 0x00700B70->_
             inline - len(6) services.exe - 0x00700B94->_
             inline - len(1) services.exe - 0x00700BA7->_
             inline - len(6) services.exe - 0x00700BDD->_
             inline - len(1) services.exe - 0x00700BEF->_
             inline - len(1) services.exe - 0x00700C23->_
             inline - len(6) services.exe - 0x00700C31->_
             inline - len(1) services.exe - 0x00700C44->_
             inline - len(6) services.exe - 0x00700C4A->_
             inline - len(1) services.exe - 0x00700C69->_
             inline - len(1) services.exe - 0x00700C6F->_
             inline - len(6) services.exe - 0x00700C97->_
             inline - len(1) services.exe - 0x00700CD0->_
             inline - len(6) services.exe - 0x00700CDF->_
             inline - len(1) services.exe - 0x00700D02->_
             inline - len(1) services.exe - 0x00700D09->_
             inline - len(11) services.exe - 0x00700D27->_
             inline - len(1) services.exe - 0x00700D41->_
             inline - len(1) services.exe - 0x00700D6E->_
             inline - len(1) services.exe - 0x00700D91->_
             inline - len(1) services.exe - 0x00700DA7->_
             inline - len(1) services.exe - 0x00700DBD->_
             inline - len(1) services.exe - 0x00700DC8->_
             inline - len(1) services.exe - 0x00700DCE->_
             inline - len(1) services.exe - 0x00700DE4->_
             inline - len(6) services.exe - 0x00700E09->_
             inline - len(6) services.exe - 0x00700E2F->_
             inline - len(1) services.exe - 0x00700E4C->_
             inline - len(6) services.exe - 0x00700E58->_
             inline - len(1) services.exe - 0x00700E76->_
             inline - len(6) services.exe - 0x00700E7F->_
             inline - len(1) services.exe - 0x00700E9D->_
             inline - len(6) services.exe - 0x00700EA9->_
             inline - len(1) services.exe - 0x00700EC7->_
             inline - len(1) services.exe - 0x00700EE8->_
             inline - len(6) services.exe - 0x00700EF9->_
             inline - len(1) services.exe - 0x00700F18->_
             inline - len(1) services.exe - 0x00700F27->_
             inline - len(1) services.exe - 0x00700F2D->_
             inline - len(1) services.exe - 0x00700F3F->_
             inline - len(1) services.exe - 0x00700F45->_
             inline - len(6) services.exe - 0x00700F63->_
             inline - len(6) services.exe - 0x00700F95->_
             inline - len(1) services.exe - 0x00700FB4->_
             inline - len(1) services.exe - 0x00700FBD->_
             inline - len(6) services.exe - 0x00700FD6->_
             inline - len(6) services.exe - 0x0070100C->_
             inline - len(1) services.exe - 0x00701044->_
             inline - len(6) services.exe - 0x0070104E->_
             inline - len(1) services.exe - 0x0070106C->_
             inline - len(6) services.exe - 0x00701072->_
             inline - len(6) services.exe - 0x0070108E->_
             inline - len(1) services.exe - 0x007010AB->_
             inline - len(1) services.exe - 0x007010C3->_
             inline - len(1) services.exe - 0x007010C9->_
             inline - len(1) services.exe - 0x007010E2->_
             inline - len(1) services.exe - 0x007010F1->_
             inline - len(1) services.exe - 0x007010F7->_
             inline - len(1) services.exe - 0x00701110->_
             inline - len(1) services.exe - 0x0070111C->_
             inline - len(1) services.exe - 0x00701122->_
             inline - len(1) services.exe - 0x0070113B->_
             inline - len(1) services.exe - 0x0070114D->_
             inline - len(1) services.exe - 0x00701153->_
             inline - len(1) services.exe - 0x00701159->_
             inline - len(1) services.exe - 0x00701172->_
             inline - len(1) services.exe - 0x0070118F->_
             inline - len(1) services.exe - 0x0070119E->_
             inline - len(1) services.exe - 0x007011A4->_
             inline - len(1) services.exe - 0x007011BD->_
             inline - len(1) services.exe - 0x007011DB->_
             inline - len(1) services.exe - 0x007011E1->_
             inline - len(1) services.exe - 0x007011E7->_
             inline - len(1) services.exe - 0x00701200->_
             inline - len(6) services.exe - 0x00701217->_
             inline - len(1) services.exe - 0x00701234->_
             inline - len(1) services.exe - 0x0070124F->_
             inline - len(1) services.exe - 0x0070125A->_
             inline - len(6) services.exe - 0x00701262->_
             inline - len(1) services.exe - 0x00701285->_
             inline - len(1) services.exe - 0x0070129D->_
             inline - len(6) services.exe - 0x007012A5->_
             inline - len(1) services.exe - 0x007012C8->_
             inline - len(1) services.exe - 0x007012D2->_
             inline - len(6) services.exe - 0x007012DA->_
             inline - len(1) services.exe - 0x007012FA->_
             inline - len(6) services.exe - 0x00701318->_
             inline - len(1) services.exe - 0x00701335->_
             inline - len(1) services.exe - 0x0070134C->_
             inline - len(1) services.exe - 0x0070135C->_
             inline - len(1) services.exe - 0x00701388->_
             inline - len(6) services.exe - 0x007013A0->_
             inline - len(1) services.exe - 0x007013B2->_
             inline - len(6) services.exe - 0x007013CD->_
             inline - len(1) services.exe - 0x007013E0->_
             inline - len(1) services.exe - 0x00701405->_
             inline - len(1) services.exe - 0x0070140B->_
             inline - len(1) services.exe - 0x00701445->_
             inline - len(6) services.exe - 0x00701457->_
             inline - len(6) services.exe - 0x0070148E->_
             inline - len(6) services.exe - 0x007014CA->_
             inline - len(1) services.exe - 0x00701502->_
             inline - len(6) services.exe - 0x0070150A->_
             inline - len(6) services.exe - 0x0070152F->_
             inline - len(6) services.exe - 0x00701561->_
             inline - len(6) services.exe - 0x00701586->_
             inline - len(1) services.exe - 0x007015A6->_
             inline - len(1) services.exe - 0x007015C7->_
             inline - len(1) services.exe - 0x007015D5->_
             inline - len(1) services.exe - 0x007015DD->_
             inline - len(1) services.exe - 0x00701606->_
             inline - len(1) services.exe - 0x00701638->_
             inline - len(1) services.exe - 0x00701640->_
             inline - len(1) services.exe - 0x0070166E->_
             inline - len(1) services.exe - 0x00701676->_
             inline - len(1) services.exe - 0x0070169B->_
             inline - len(1) services.exe - 0x007016C1->_
             inline - len(6) services.exe - 0x007016C9->_
             inline - len(6) services.exe - 0x007016FF->_
             inline - len(1) services.exe - 0x00701717->_
             inline - len(1) services.exe - 0x00701740->_
             inline - len(6) services.exe - 0x0070174A->_
             inline - len(1) services.exe - 0x0070176D->_
             inline - len(1) services.exe - 0x00701773->_
             inline - len(1) services.exe - 0x00701793->_
             inline - len(1) services.exe - 0x007017A0->_
             inline - len(6) services.exe - 0x007017A8->_
             inline - len(1) services.exe - 0x007017FB->_
             inline - len(1) services.exe - 0x0070180C->_
             inline - len(6) services.exe - 0x00701814->_
             inline - len(1) services.exe - 0x00701842->_
             inline - len(6) services.exe - 0x0070184C->_
             inline - len(1) services.exe - 0x0070186F->_
             inline - len(6) services.exe - 0x00701886->_
             inline - len(1) services.exe - 0x007018C8->_
             inline - len(1) services.exe - 0x007018CE->_
             inline - len(1) services.exe - 0x007018F3->_
             inline - len(1) services.exe - 0x00701912->_
             inline - len(6) services.exe - 0x0070191A->_
             inline - len(6) services.exe - 0x00701942->_
             inline - len(1) services.exe - 0x00701969->_
             inline - len(1) services.exe - 0x00701999->_
             inline - len(6) services.exe - 0x007019A1->_
             inline - len(1) services.exe - 0x007019CC->_
             inline - len(1) services.exe - 0x007019D7->_
             inline - len(6) services.exe - 0x007019E4->_
             inline - len(6) services.exe - 0x00701A17->_
             inline - len(6) services.exe - 0x00701A42->_
             inline - len(6) services.exe - 0x00701A78->_
             inline - len(6) services.exe - 0x00701AA0->_
             inline - len(6) services.exe - 0x00701AC8->_
             inline - len(6) services.exe - 0x00701B0A->_
             inline - len(6) services.exe - 0x00701B31->_
             inline - len(1) services.exe - 0x00701B52->_
             inline - len(1) services.exe - 0x00701B75->_
             inline - len(1) services.exe - 0x00701B92->_
             inline - len(1) services.exe - 0x00701BAA->_
             inline - len(1) services.exe - 0x00701BBD->_
             inline - len(6) services.exe - 0x00701BC8->_
             inline - len(1) services.exe - 0x00701BDB->_
             inline - len(1) services.exe - 0x00701C18->_
             inline - len(1) services.exe - 0x00701C1F->_
             inline - len(1) services.exe - 0x00701C2F->_
             inline - len(1) services.exe - 0x00701C42->_
             inline - len(1) services.exe - 0x00701C57->_
             inline - len(1) services.exe - 0x00701C62->_
             inline - len(1) services.exe - 0x00701C8D->_
             inline - len(1) services.exe - 0x00701CA2->_
             inline - len(1) services.exe - 0x00701CAD->_
             inline - len(6) services.exe - 0x00701CB6->_
             inline - len(1) services.exe - 0x00701CCB->_
             inline - len(1) services.exe - 0x00701CEB->_
             inline - len(1) services.exe - 0x00701CF5->_
             inline - len(1) services.exe - 0x00701D0C->_
             inline - len(1) services.exe - 0x00701D1E->_
             inline - len(1) services.exe - 0x00701D3A->_
             inline - len(1) services.exe - 0x00701D4C->_
             inline - len(1) services.exe - 0x00701D5E->_
             inline - len(1) services.exe - 0x00701D70->_
             inline - len(1) services.exe - 0x00701D8A->_
             inline - len(1) services.exe - 0x00701D99->_
             inline - len(1) services.exe - 0x00701DAB->_
             inline - len(1) services.exe - 0x00701DBD->_
             inline - len(1) services.exe - 0x00701DD7->_
             inline - len(1) services.exe - 0x00701DEE->_
             inline - len(1) services.exe - 0x00701E0C->_
             inline - len(1) services.exe - 0x00701E2F->_
             inline - len(1) services.exe - 0x00701E4E->_
             inline - len(1) services.exe - 0x00701E78->_
             inline - len(1) services.exe - 0x00701E8F->_
             inline - len(1) services.exe - 0x00701EB5->_
             inline - len(1) services.exe - 0x00701ECC->_
             inline - len(1) services.exe - 0x00701EE9->_
             inline - len(1) services.exe - 0x00701F06->_
             inline - len(1) services.exe - 0x00701F20->_
             inline - len(1) services.exe - 0x00701F2C->_
             inline - len(1) services.exe - 0x00701F43->_
             inline - len(1) services.exe - 0x00701F58->_
             inline - len(1) services.exe - 0x00701F78->_
             inline - len(1) services.exe - 0x00701F88->_
             inline - len(1) services.exe - 0x00701FB4->_
             inline - len(1) services.exe - 0x00701FDF->_
             inline - len(1) services.exe - 0x00701FF7->_
             inline - len(1) services.exe - 0x00702012->_
             inline - len(1) services.exe - 0x00702018->_
             inline - len(1) services.exe - 0x0070201F->_
             inline - len(1) services.exe - 0x00702037->_
             inline - len(1) services.exe - 0x00702048->_
             inline - len(6) services.exe - 0x00702075->_
             inline - len(6) services.exe - 0x007020CC->_
             inline - len(1) services.exe - 0x007020E7->_
             inline - len(1) services.exe - 0x00702104->_
             inline - len(1) services.exe - 0x00702120->_
             inline - len(6) services.exe - 0x00702128->_
             inline - len(6) services.exe - 0x0070214D->_
             inline - len(6) services.exe - 0x007021A7->_
             inline - len(1) services.exe - 0x007021C2->_
             inline - len(1) services.exe - 0x007021EA->_
             inline - len(1) services.exe - 0x007021FD->_
             inline - len(6) services.exe - 0x00702209->_
             inline - len(1) services.exe - 0x0070221C->_
             inline - len(1) services.exe - 0x0070222F->_
             inline - len(6) services.exe - 0x00702243->_
             inline - len(1) services.exe - 0x00702264->_
             inline - len(1) services.exe - 0x0070228D->_
             inline - len(1) services.exe - 0x0070229D->_
             inline - len(1) services.exe - 0x007022C9->_
             inline - len(1) services.exe - 0x0070232C->_
             inline - len(1) services.exe - 0x0070233E->_
             inline - len(1) services.exe - 0x0070234E->_
             inline - len(1) services.exe - 0x0070237A->_
             inline - len(1) services.exe - 0x0070239D->_
             inline - len(1) services.exe - 0x007023AD->_
             inline - len(1) services.exe - 0x007023D9->_
             inline - len(6) services.exe - 0x00702404->_
             inline - len(1) services.exe - 0x00702416->_
             inline - len(6) services.exe - 0x00702430->_
             inline - len(1) services.exe - 0x00702442->_
             inline - len(1) services.exe - 0x00702479->_
             inline - len(6) services.exe - 0x00702487->_
             inline - len(1) services.exe - 0x00702499->_
             inline - len(6) services.exe - 0x007024C0->_
             inline - len(1) services.exe - 0x007024D3->_
             inline - len(6) services.exe - 0x00702508->_
             inline - len(1) services.exe - 0x0070251A->_
             inline - len(6) services.exe - 0x0070255A->_
             inline - len(1) services.exe - 0x0070256D->_
             inline - len(1) services.exe - 0x0070259D->_
             inline - len(1) services.exe - 0x007025AA->_
             inline - len(6) services.exe - 0x007025C8->_
             inline - len(1) services.exe - 0x007025DA->_
             inline - len(6) services.exe - 0x007025F4->_
             inline - len(1) services.exe - 0x00702606->_
             inline - len(6) services.exe - 0x0070260F->_
             inline - len(1) services.exe - 0x00702621->_
             inline - len(1) services.exe - 0x00702642->_
             inline - len(1) services.exe - 0x00702651->_
             inline - len(1) services.exe - 0x0070266F->_
             inline - len(1) services.exe - 0x0070267E->_
             inline - len(1) services.exe - 0x0070269C->_
             inline - len(1) services.exe - 0x007026AB->_
             inline - len(1) services.exe - 0x007026C9->_
             inline - len(1) services.exe - 0x007026D8->_
             inline - len(1) services.exe - 0x007026F6->_
             inline - len(1) services.exe - 0x00702705->_
             inline - len(1) services.exe - 0x0070272F->_
             inline - len(1) services.exe - 0x00702755->_
             inline - len(1) services.exe - 0x00702799->_
             inline - len(11) services.exe - 0x007027A1->_
             inline - len(1) services.exe - 0x007027BB->_
             inline - len(1) services.exe - 0x007027D2->_
             inline - len(1) services.exe - 0x007027EB->_
             inline - len(1) services.exe - 0x007027F3->_
             inline - len(1) services.exe - 0x00702801->_
             inline - len(1) services.exe - 0x0070281F->_
             inline - len(1) services.exe - 0x00702825->_
             inline - len(6) services.exe - 0x00702843->_
             inline - len(1) services.exe - 0x0070285B->_
             inline - len(1) services.exe - 0x0070287D->_
             inline - len(1) services.exe - 0x00702883->_
             inline - len(6) services.exe - 0x00702895->_
             inline - len(1) services.exe - 0x007028AE->_
             inline - len(6) services.exe - 0x007028C2->_
             inline - len(1) services.exe - 0x007028F0->_
             inline - len(1) services.exe - 0x007028F6->_
             inline - len(1) services.exe - 0x0070290F->_
             inline - len(1) services.exe - 0x00702916->_
             inline - len(1) services.exe - 0x00702920->_
             inline - len(6) services.exe - 0x00702937->_
             inline - len(1) services.exe - 0x00702954->_
             inline - len(1) services.exe - 0x00702964->_
             inline - len(1) services.exe - 0x007029AE->_
             inline - len(6) services.exe - 0x007029B8->_
             inline - len(1) services.exe - 0x007029D3->_
             inline - len(6) services.exe - 0x007029F5->_
             inline - len(1) services.exe - 0x00702A08->_
             inline - len(6) services.exe - 0x00702A0E->_
             inline - len(6) services.exe - 0x00702A26->_
             inline - len(1) services.exe - 0x00702A32->_
             inline - len(6) services.exe - 0x00702A39->_
             inline - len(1) services.exe - 0x00702A4B->_
             inline - len(1) services.exe - 0x00702A70->_
             inline - len(1) services.exe - 0x00702A96->_
             inline - len(1) services.exe - 0x00702AB4->_
             inline - len(6) services.exe - 0x00702AC4->_
             inline - len(1) services.exe - 0x00702AD9->_
             inline - len(1) services.exe - 0x00702AFD->_
             inline - len(1) services.exe - 0x00702B06->_
             inline - len(1) services.exe - 0x00702B17->_
             inline - len(1) services.exe - 0x00702B2D->_
             inline - len(6) services.exe - 0x00702B3B->_
             inline - len(6) services.exe - 0x00702B50->_
             inline - len(1) services.exe - 0x00702B6B->_
             inline - len(1) services.exe - 0x00702B83->_
             inline - len(1) services.exe - 0x00702B8A->_
             inline - len(1) services.exe - 0x00702B9A->_
             inline - len(1) services.exe - 0x00702BA5->_
             inline - len(1) services.exe - 0x00702BAB->_
             inline - len(1) services.exe - 0x00702BBC->_
             inline - len(1) services.exe - 0x00702BD2->_
             inline - len(6) services.exe - 0x00702BE0->_
             inline - len(1) services.exe - 0x00702BF2->_
             inline - len(1) services.exe - 0x00702C07->_
             inline - len(1) services.exe - 0x00702C1B->_
             inline - len(6) services.exe - 0x00702C2A->_
             inline - len(1) services.exe - 0x00702C45->_
             inline - len(6) services.exe - 0x00702C4B->_
             inline - len(6) services.exe - 0x00702C6F->_
             inline - len(1) services.exe - 0x00702C81->_
             inline - len(1) services.exe - 0x00702C9F->_
             inline - len(6) services.exe - 0x00702CD5->_
             inline - len(1) services.exe - 0x00702CE7->_
             inline - len(6) services.exe - 0x00702D13->_
             inline - len(1) services.exe - 0x00702D25->_
             inline - len(1) services.exe - 0x00702D82->_
             inline - len(1) services.exe - 0x00702D8D->_
             inline - len(1) services.exe - 0x00702D98->_
             inline - len(6) services.exe - 0x00702DDC->_
             inline - len(1) services.exe - 0x00702DFB->_
             inline - len(6) services.exe - 0x00702E15->_
             inline - len(1) services.exe - 0x00702E34->_
             inline - len(6) services.exe - 0x00702E4E->_
             inline - len(1) services.exe - 0x00702E83->_
             inline - len(1) services.exe - 0x00702EAD->_
             inline - len(1) services.exe - 0x00702EB3->_
             inline - len(1) services.exe - 0x00702EB9->_
             inline - len(1) services.exe - 0x00702ECF->_
             inline - len(1) services.exe - 0x00702EF2->_
             inline - len(1) services.exe - 0x00702F10->_
             inline - len(6) services.exe - 0x00702F29->_
             inline - len(1) services.exe - 0x00702F3E->_
             inline - len(6) services.exe - 0x00702F54->_
             inline - len(1) services.exe - 0x00702F60->_
             inline - len(1) services.exe - 0x00702F6D->_
             inline - len(1) services.exe - 0x00702F73->_
             inline - len(1) services.exe - 0x00702F79->_
             inline - len(1) services.exe - 0x00702F87->_
             inline - len(1) services.exe - 0x00702FA0->_
             inline - len(1) services.exe - 0x00702FA8->_
             inline - len(1) services.exe - 0x00702FAE->_
             inline - len(1) services.exe - 0x00702FBD->_
             inline - len(6) services.exe - 0x00702FC9->_
             inline - len(1) services.exe - 0x00702FE9->_
             inline - len(1) services.exe - 0x00702FEF->_
             inline - len(1) services.exe - 0x00702FF5->_
             inline - len(1) services.exe - 0x00703011->_
             inline - len(1) services.exe - 0x00703025->_
             inline - len(1) services.exe - 0x0070302B->_
             inline - len(1) services.exe - 0x00703031->_
             inline - len(1) services.exe - 0x0070304D->_
             inline - len(1) services.exe - 0x0070305A->_
             inline - len(1) services.exe - 0x00703060->_
             inline - len(1) services.exe - 0x00703077->_
             inline - len(6) services.exe - 0x00703080->_
             inline - len(1) services.exe - 0x007030A0->_
             inline - len(1) services.exe - 0x007030A6->_
             inline - len(1) services.exe - 0x007030AC->_
             inline - len(1) services.exe - 0x007030C5->_
             inline - len(1) services.exe - 0x007030D9->_
             inline - len(1) services.exe - 0x007030DF->_
             inline - len(1) services.exe - 0x007030E5->_
             inline - len(1) services.exe - 0x007030FE->_
             inline - len(1) services.exe - 0x0070310B->_
             inline - len(1) services.exe - 0x00703111->_
             inline - len(1) services.exe - 0x00703127->_
             inline - len(6) services.exe - 0x0070314E->_
             inline - len(1) services.exe - 0x0070316B->_
             inline - len(6) services.exe - 0x0070318D->_
             inline - len(1) services.exe - 0x007031AB->_
             inline - len(6) services.exe - 0x007031D0->_
             inline - len(1) services.exe - 0x007031FC->_
             inline - len(6) services.exe - 0x0070320B->_
             inline - len(1) services.exe - 0x0070323C->_
             inline - len(6) services.exe - 0x0070324B->_
             inline - len(1) services.exe - 0x0070327C->_
             inline - len(6) services.exe - 0x0070328B->_
             inline - len(1) services.exe - 0x007032B8->_
             inline - len(6) services.exe - 0x007032D2->_
             inline - len(1) services.exe - 0x00703308->_
             inline - len(6) services.exe - 0x00703314->_
             inline - len(1) services.exe - 0x0070334B->_
             inline - len(6) services.exe - 0x00703365->_
             inline - len(1) services.exe - 0x00703384->_
             inline - len(6) services.exe - 0x0070339B->_
             inline - len(1) services.exe - 0x007033BA->_
             inline - len(6) services.exe - 0x007033DA->_
             inline - len(1) services.exe - 0x007033F9->_
             inline - len(6) services.exe - 0x00703410->_
             inline - len(6) services.exe - 0x0070342E->_
             inline - len(6) services.exe - 0x00703453->_
             inline - len(1) services.exe - 0x00703472->_
             inline - len(6) services.exe - 0x00703489->_
             inline - len(1) services.exe - 0x007034A4->_
             inline - len(6) services.exe - 0x007034BB->_
             inline - len(1) services.exe - 0x007034DA->_
             inline - len(6) services.exe - 0x00703512->_
             inline - len(1) services.exe - 0x00703530->_
             inline - len(6) services.exe - 0x00703547->_
             inline - len(1) services.exe - 0x00703565->_
             inline - len(6) services.exe - 0x0070357C->_
             inline - len(1) services.exe - 0x0070359A->_
             inline - len(6) services.exe - 0x007035B1->_
             inline - len(1) services.exe - 0x007035CF->_
             inline - len(6) services.exe - 0x007035E6->_
             inline - len(1) services.exe - 0x007035F9->_
             inline - len(1) services.exe - 0x00703605->_
             inline - len(1) services.exe - 0x0070360C->_
             inline - len(6) services.exe - 0x00703624->_
             inline - len(1) services.exe - 0x00703637->_
             inline - len(1) services.exe - 0x00703643->_
             inline - len(6) services.exe - 0x0070364C->_
             inline - len(1) services.exe - 0x00703678->_
             inline - len(6) services.exe - 0x0070368F->_
             inline - len(1) services.exe - 0x007036A2->_
             inline - len(1) services.exe - 0x007036A8->_
             inline - len(1) services.exe - 0x007036AE->_
             inline - len(6) services.exe - 0x007036C8->_
             inline - len(1) services.exe - 0x007036E0->_
             inline - len(1) services.exe - 0x007036F5->_
             inline - len(6) services.exe - 0x00703707->_
             inline - len(1) services.exe - 0x00703719->_
             inline - len(6) services.exe - 0x0070374C->_
             inline - len(1) services.exe - 0x0070375E->_
             inline - len(1) services.exe - 0x00703771->_
             inline - len(1) services.exe - 0x00703792->_
             inline - len(6) services.exe - 0x007037B4->_
             inline - len(1) services.exe - 0x007037CF->_
             inline - len(6) services.exe - 0x007037E6->_
             inline - len(1) services.exe - 0x007037FC->_
             inline - len(6) services.exe - 0x00703816->_
             inline - len(1) services.exe - 0x00703833->_
             inline - len(1) services.exe - 0x0070384C->_
             inline - len(1) services.exe - 0x00703878->_
             inline - len(6) services.exe - 0x0070389C->_
             inline - len(1) services.exe - 0x007038B4->_
             inline - len(1) services.exe - 0x007038DA->_
             inline - len(1) services.exe - 0x007038F5->_
             inline - len(1) services.exe - 0x00703919->_
             inline - len(1) services.exe - 0x0070393F->_
             inline - len(1) services.exe - 0x0070396A->_
             inline - len(1) services.exe - 0x007039A3->_
             inline - len(1) services.exe - 0x007039EC->_
             inline - len(6) services.exe - 0x00703A23->_
             inline - len(1) services.exe - 0x00703A3B->_
             inline - len(1) services.exe - 0x00703A51->_
             inline - len(6) services.exe - 0x00703A67->_
             inline - len(1) services.exe - 0x00703A7F->_
             inline - len(1) services.exe - 0x00703A95->_
             inline - len(6) services.exe - 0x00703A9F->_
             inline - len(1) services.exe - 0x00703AB2->_
             inline - len(6) services.exe - 0x00703AB8->_
             inline - len(6) services.exe - 0x00703ADB->_
             inline - len(1) services.exe - 0x00703AEE->_
             inline - len(6) services.exe - 0x00703B0A->_
             inline - len(1) services.exe - 0x00703B26->_
             inline - len(1) services.exe - 0x00703B44->_
             inline - len(6) services.exe - 0x00703B5C->_
             inline - len(1) services.exe - 0x00703B6F->_
             inline - len(1) services.exe - 0x00703B86->_
             inline - len(1) services.exe - 0x00703B9B->_
             inline - len(6) services.exe - 0x00703BA6->_
             inline - len(1) services.exe - 0x00703BB9->_
             inline - len(1) services.exe - 0x00703BD3->_
             inline - len(1) services.exe - 0x00703BEE->_
             inline - len(1) services.exe - 0x00703C10->_
             inline - len(6) services.exe - 0x00703C19->_
             inline - len(1) services.exe - 0x00703C35->_
             inline - len(6) services.exe - 0x00703C4C->_
             inline - len(1) services.exe - 0x00703C58->_
             inline - len(6) services.exe - 0x00703C5F->_
             inline - len(1) services.exe - 0x00703C7E->_
             inline - len(6) services.exe - 0x00703C9B->_
             inline - len(1) services.exe - 0x00703CAD->_
             inline - len(6) services.exe - 0x00703CC3->_
             inline - len(1) services.exe - 0x00703CCF->_
             inline - len(6) services.exe - 0x00703CDF->_
             inline - len(1) services.exe - 0x00703CF1->_
             inline - len(6) services.exe - 0x00703D1D->_
             inline - len(1) services.exe - 0x00703D38->_
             inline - len(6) services.exe - 0x00703D44->_
             inline - len(1) services.exe - 0x00703D5F->_
             inline - len(1) services.exe - 0x00703D84->_
             inline - len(6) services.exe - 0x00703D8B->_
             inline - len(1) services.exe - 0x00703DA9->_
             inline - len(6) services.exe - 0x00703DCB->_
             inline - len(1) services.exe - 0x00703DEC->_
             inline - len(1) services.exe - 0x00703E22->_
             inline - len(1) services.exe - 0x00703E2E->_
             inline - len(6) services.exe - 0x00703E35->_
             inline - len(1) services.exe - 0x00703E56->_
             inline - len(6) services.exe - 0x00703E8A->_
             inline - len(1) services.exe - 0x00703EAB->_
             inline - len(1) services.exe - 0x00703EB8->_
             inline - len(6) services.exe - 0x00703EBF->_
             inline - len(1) services.exe - 0x00703EE0->_
             inline - len(6) services.exe - 0x00703EFA->_
             inline - len(1) services.exe - 0x00703F16->_
             inline - len(6) services.exe - 0x00703F25->_
             inline - len(1) services.exe - 0x00703F41->_
             inline - len(1) services.exe - 0x00703F50->_
             inline - len(6) services.exe - 0x00703F63->_
             inline - len(1) services.exe - 0x00703F7F->_
             inline - len(6) services.exe - 0x00703F8E->_
             inline - len(1) services.exe - 0x00703FA9->_
             inline - len(6) services.exe - 0x00703FC6->_
             inline - len(1) services.exe - 0x00703FE2->_
             inline - len(1) services.exe - 0x00703FF5->_
             inline - len(1) services.exe - 0x00703FFC->_
             inline - len(1) services.exe - 0x00704018->_
             inline - len(6) services.exe - 0x0070402A->_
             inline - len(1) services.exe - 0x00704055->_
             inline - len(6) services.exe - 0x00704064->_
             inline - len(1) services.exe - 0x00704086->_
             inline - len(6) services.exe - 0x00704095->_
             inline - len(1) services.exe - 0x007040C4->_
             inline - len(6) services.exe - 0x007040D0->_
             inline - len(1) services.exe - 0x00704100->_
             inline - len(6) services.exe - 0x0070411A->_
             inline - len(1) services.exe - 0x0070413C->_
             inline - len(6) services.exe - 0x00704156->_
             inline - len(1) services.exe - 0x00704181->_
             inline - len(6) services.exe - 0x0070419B->_
             inline - len(1) services.exe - 0x007041D9->_
             inline - len(6) services.exe - 0x007041E5->_
             inline - len(1) services.exe - 0x00704222->_
             inline - len(6) services.exe - 0x0070423C->_
             inline - len(1) services.exe - 0x0070425D->_
             inline - len(1) services.exe - 0x0070426A->_
             inline - len(6) services.exe - 0x00704271->_
             inline - len(1) services.exe - 0x00704292->_
             inline - len(6) services.exe - 0x007042AF->_
             inline - len(1) services.exe - 0x007042D0->_
             inline - len(6) services.exe - 0x007042DC->_
             inline - len(1) services.exe - 0x00704303->_
             inline - len(6) services.exe - 0x00704312->_
             inline - len(1) services.exe - 0x00704337->_
             inline - len(6) services.exe - 0x00704349->_
             inline - len(1) services.exe - 0x0070436A->_
             inline - len(6) services.exe - 0x00704379->_
             inline - len(1) services.exe - 0x0070439E->_
             inline - len(6) services.exe - 0x007043B0->_
             inline - len(1) services.exe - 0x007043D5->_
             inline - len(6) services.exe - 0x007043E4->_
             inline - len(1) services.exe - 0x00704409->_
             inline - len(6) services.exe - 0x0070441B->_
             inline - len(1) services.exe - 0x00704440->_
             inline - len(6) services.exe - 0x0070444F->_
             inline - len(1) services.exe - 0x00704474->_
             inline - len(6) services.exe - 0x00704480->_
             inline - len(1) services.exe - 0x007044A5->_
             inline - len(1) services.exe - 0x007044C0->_
             inline - len(6) services.exe - 0x007044C7->_
             inline - len(1) services.exe - 0x007044E8->_
             inline - len(6) services.exe - 0x007044F7->_
             inline - len(1) services.exe - 0x0070451E->_
             inline - len(6) services.exe - 0x00704538->_
             inline - len(1) services.exe - 0x00704561->_
             inline - len(6) services.exe - 0x00704570->_
             inline - len(1) services.exe - 0x0070459B->_
             inline - len(6) services.exe - 0x007045B5->_
             inline - len(1) services.exe - 0x007045DE->_
             inline - len(1) services.exe - 0x007045F9->_
             inline - len(6) services.exe - 0x00704600->_
             inline - len(1) services.exe - 0x00704621->_
             inline - len(6) services.exe - 0x00704630->_
             inline - len(1) services.exe - 0x0070465F->_
             inline - len(6) services.exe - 0x00704679->_
             inline - len(1) services.exe - 0x007046A8->_
             inline - len(1) services.exe - 0x007046B5->_
             inline - len(6) services.exe - 0x007046BC->_
             inline - len(1) services.exe - 0x007046DD->_
             inline - len(6) services.exe - 0x007046EC->_
             inline - len(1) services.exe - 0x00704717->_
             inline - len(6) services.exe - 0x00704726->_
             inline - len(1) services.exe - 0x00704751->_
             inline - len(1) services.exe - 0x0070476C->_
             inline - len(6) services.exe - 0x00704773->_
             inline - len(1) services.exe - 0x00704794->_
             inline - len(1) services.exe - 0x007047AA->_
             inline - len(1) services.exe - 0x007047B1->_
             inline - len(1) services.exe - 0x007047E2->_
             inline - len(1) services.exe - 0x007047E8->_
             inline - len(1) services.exe - 0x007047FF->_
             inline - len(1) services.exe - 0x00704815->_
             inline - len(1) services.exe - 0x0070481B->_
             inline - len(1) services.exe - 0x00704832->_
             inline - len(1) services.exe - 0x0070483F->_
             inline - len(1) services.exe - 0x00704845->_
             inline - len(1) services.exe - 0x00704853->_
             inline - len(1) services.exe - 0x0070486D->_
             inline - len(1) services.exe - 0x00704873->_
             inline - len(1) services.exe - 0x0070487A->_
             inline - len(1) services.exe - 0x00704880->_
             inline - len(1) services.exe - 0x00704889->_
             inline - len(1) services.exe - 0x0070488F->_
             inline - len(1) services.exe - 0x00704895->_
             inline - len(1) services.exe - 0x0070489C->_
             inline - len(1) services.exe - 0x007048A2->_
             inline - len(6) services.exe - 0x007048AE->_
             inline - len(1) services.exe - 0x007048C4->_
             inline - len(6) services.exe - 0x007048DD->_
             inline - len(1) services.exe - 0x007048F3->_
             inline - len(6) services.exe - 0x00704907->_
             inline - len(1) services.exe - 0x00704922->_
             inline - len(6) services.exe - 0x00704939->_
             inline - len(1) services.exe - 0x00704954->_
             inline - len(1) services.exe - 0x0070496C->_
             inline - len(1) services.exe - 0x00704972->_
             inline - len(1) services.exe - 0x00704988->_
             inline - len(1) services.exe - 0x007049A0->_
             inline - len(1) services.exe - 0x007049A6->_
             inline - len(1) services.exe - 0x007049BC->_
             inline - len(1) services.exe - 0x007049C6->_
             inline - len(1) services.exe - 0x007049CC->_
             inline - len(1) services.exe - 0x007049E2->_
             inline - len(1) services.exe - 0x007049FB->_
             inline - len(1) services.exe - 0x00704A17->_
             inline - len(6) services.exe - 0x00704A26->_
             inline - len(1) services.exe - 0x00704A39->_
             inline - len(1) services.exe - 0x00704A4F->_
             inline - len(1) services.exe - 0x00704A66->_
             inline - len(1) services.exe - 0x00704AA5->_
             inline - len(1) services.exe - 0x00704AAB->_
             inline - len(1) services.exe - 0x00704ABC->_
             inline - len(1) services.exe - 0x00704B06->_
             inline - len(1) services.exe - 0x00704B42->_
             inline - len(1) services.exe - 0x00704B61->_
             inline - len(1) services.exe - 0x00704B6D->_
             inline - len(1) services.exe - 0x00704B84->_
             inline - len(1) services.exe - 0x00704B8B->_
             inline - len(6) services.exe - 0x00704B95->_
             inline - len(1) services.exe - 0x00704BAA->_
             inline - len(6) services.exe - 0x00704BC3->_
             inline - len(1) services.exe - 0x00704BE1->_
             inline - len(6) services.exe - 0x00704BF8->_
             inline - len(1) services.exe - 0x00704C15->_
             inline - len(6) services.exe - 0x00704C1E->_
             inline - len(1) services.exe - 0x00704C3B->_
             inline - len(1) services.exe - 0x00704C69->_
             inline - len(1) services.exe - 0x00704C9F->_
             inline - len(1) services.exe - 0x00704CFF->_
             inline - len(1) services.exe - 0x00704D47->_
             inline - len(1) services.exe - 0x00704D5E->_
             inline - len(1) services.exe - 0x00704D78->_
             inline - len(1) services.exe - 0x00704DA9->_
             inline - len(1) services.exe - 0x00704DB1->_
             inline - len(1) services.exe - 0x00704DD6->_
             inline - len(1) services.exe - 0x00704E08->_
             inline - len(1) services.exe - 0x00704E0F->_
             inline - len(1) services.exe - 0x00704E46->_
             inline - len(6) services.exe - 0x00704E4E->_
             inline - len(1) services.exe - 0x00704E6E->_
             inline - len(6) services.exe - 0x00704E85->_
             inline - len(1) services.exe - 0x00704E9B->_
             inline - len(1) services.exe - 0x00704EAE->_
             inline - len(6) services.exe - 0x00704EC7->_
             inline - len(1) services.exe - 0x00704ED3->_
             inline - len(1) services.exe - 0x00704EDA->_
             inline - len(1) services.exe - 0x00704EE9->_
             inline - len(1) services.exe - 0x00704EEF->_
             inline - len(1) services.exe - 0x00704EFD->_
             inline - len(11) services.exe - 0x00704F12->_
             inline - len(1) services.exe - 0x00704F4B->_
             inline - len(1) services.exe - 0x00704F52->_
             inline - len(6) services.exe - 0x00704F58->_
             inline - len(1) services.exe - 0x00704F64->_
             inline - len(1) services.exe - 0x00704F6B->_
             inline - len(1) services.exe - 0x00704F79->_
             inline - len(1) services.exe - 0x00704FAC->_
             inline - len(1) services.exe - 0x00704FDE->_
             inline - len(1) services.exe - 0x00705003->_
             inline - len(1) services.exe - 0x0070500A->_
             inline - len(6) services.exe - 0x0070501F->_
             inline - len(1) services.exe - 0x0070503A->_
             inline - len(1) services.exe - 0x0070505E->_
             inline - len(1) services.exe - 0x00705064->_
             inline - len(6) services.exe - 0x0070507E->_
             inline - len(1) services.exe - 0x00705099->_
             inline - len(1) services.exe - 0x007050CB->_
             inline - len(1) services.exe - 0x007050D1->_
             inline - len(6) services.exe - 0x007050EB->_
             inline - len(1) services.exe - 0x00705106->_
             inline - len(6) services.exe - 0x0070512E->_
             inline - len(1) services.exe - 0x00705141->_
             inline - len(6) services.exe - 0x00705165->_
             inline - len(1) services.exe - 0x00705178->_
             inline - len(6) services.exe - 0x007051E5->_
             inline - len(1) services.exe - 0x007051F8->_
             inline - len(6) services.exe - 0x00705210->_
             inline - len(1) services.exe - 0x0070522D->_
             inline - len(6) services.exe - 0x00705251->_
             inline - len(1) services.exe - 0x00705264->_
             inline - len(1) services.exe - 0x00705277->_
             inline - len(6) services.exe - 0x00705295->_
             inline - len(1) services.exe - 0x007052A8->_
             inline - len(6) services.exe - 0x007052CF->_
             inline - len(1) services.exe - 0x007052E4->_
             inline - len(1) services.exe - 0x007052FA->_
             inline - len(1) services.exe - 0x0070531C->_
             inline - len(6) services.exe - 0x00705324->_
             inline - len(1) services.exe - 0x00705357->_
             inline - len(1) services.exe - 0x0070535F->_
             inline - len(1) services.exe - 0x0070538C->_
             inline - len(1) services.exe - 0x007053AB->_
             inline - len(6) services.exe - 0x007053C1->_
             inline - len(1) services.exe - 0x007053D4->_
             inline - len(1) services.exe - 0x007053EF->_
             inline - len(6) services.exe - 0x007053F6->_
             inline - len(1) services.exe - 0x00705409->_
             inline - len(6) services.exe - 0x00705422->_
             inline - len(1) services.exe - 0x00705435->_
             inline - len(1) services.exe - 0x0070544B->_
             inline - len(6) services.exe - 0x00705452->_
             inline - len(1) services.exe - 0x00705465->_
             inline - len(6) services.exe - 0x0070546E->_
             inline - len(1) services.exe - 0x00705481->_
             inline - len(1) services.exe - 0x00705495->_
             inline - len(1) services.exe - 0x0070549E->_
             inline - len(1) services.exe - 0x007054A5->_
             inline - len(1) services.exe - 0x007054B1->_
             inline - len(6) services.exe - 0x007054C5->_
             inline - len(1) services.exe - 0x007054E0->_
             inline - len(6) services.exe - 0x007054F7->_
             inline - len(1) services.exe - 0x0070550C->_
             inline - len(6) services.exe - 0x0070552B->_
             inline - len(1) services.exe - 0x0070553E->_
             inline - len(6) services.exe - 0x00705544->_
             inline - len(6) services.exe - 0x00705567->_
             inline - len(1) services.exe - 0x0070557A->_
             inline - len(1) services.exe - 0x0070558F->_
             inline - len(6) services.exe - 0x0070559C->_
             inline - len(1) services.exe - 0x007055AF->_
             inline - len(1) services.exe - 0x007055C2->_
             inline - len(6) services.exe - 0x007055D8->_
             inline - len(1) services.exe - 0x007055F3->_
             inline - len(6) services.exe - 0x0070560F->_
             inline - len(1) services.exe - 0x00705624->_
             inline - len(6) services.exe - 0x0070563D->_
             inline - len(1) services.exe - 0x00705658->_
             inline - len(1) services.exe - 0x007056BE->_
             inline - len(6) services.exe - 0x007056E8->_
             inline - len(1) services.exe - 0x007056FB->_
             inline - len(1) services.exe - 0x00705721->_
             inline - len(6) services.exe - 0x0070572B->_
             inline - len(1) services.exe - 0x0070573E->_
             inline - len(6) services.exe - 0x00705744->_
             inline - len(6) services.exe - 0x0070575F->_
             inline - len(1) services.exe - 0x00705775->_
             inline - len(6) services.exe - 0x0070577B->_
             inline - len(1) services.exe - 0x00705793->_
             inline - len(1) services.exe - 0x00705799->_
             inline - len(1) services.exe - 0x0070579F->_
             inline - len(6) services.exe - 0x007057A7->_
             inline - len(1) services.exe - 0x007057BA->_
             inline - len(1) services.exe - 0x007057CD->_
             inline - len(6) services.exe - 0x0070580F->_
             inline - len(1) services.exe - 0x00705821->_
             inline - len(1) services.exe - 0x0070583B->_
             inline - len(1) services.exe - 0x00705841->_
             inline - len(1) services.exe - 0x0070584F->_
             inline - len(6) services.exe - 0x0070588C->_
             inline - len(1) services.exe - 0x0070589F->_
             inline - len(1) services.exe - 0x007058B2->_
             inline - len(1) services.exe - 0x007058F7->_
             inline - len(1) services.exe - 0x007058FD->_
             inline - len(1) services.exe - 0x00705914->_
             inline - len(1) services.exe - 0x0070591A->_
             inline - len(1) services.exe - 0x00705927->_
             inline - len(1) services.exe - 0x0070593A->_
             inline - len(1) services.exe - 0x0070594D->_
             inline - len(1) services.exe - 0x0070595C->_
             inline - len(6) services.exe - 0x00705964->_
             inline - len(1) services.exe - 0x00705981->_
             inline - len(1) services.exe - 0x0070598E->_
             inline - len(6) services.exe - 0x00705996->_
             inline - len(1) services.exe - 0x007059B3->_
             inline - len(1) services.exe - 0x007059C1->_
             inline - len(1) services.exe - 0x007059C9->_
             inline - len(1) services.exe - 0x007059E3->_
             inline - len(1) services.exe - 0x007059F3->_
             inline - len(1) services.exe - 0x00705A5B->_
             inline - len(1) services.exe - 0x00705A92->_
             inline - len(1) services.exe - 0x00705AAA->_
             inline - len(1) services.exe - 0x00705AB2->_
             inline - len(1) services.exe - 0x00705ACC->_
             inline - len(1) services.exe - 0x00705AE0->_
             inline - len(1) services.exe - 0x00705AF9->_
             inline - len(1) services.exe - 0x00705AFF->_
             inline - len(1) services.exe - 0x00705B06->_
             inline - len(1) services.exe - 0x00705B0E->_
             inline - len(1) services.exe - 0x00705B16->_
             inline - len(1) services.exe - 0x00705B30->_
             inline - len(1) services.exe - 0x00705B3B->_
             inline - len(1) services.exe - 0x00705B43->_
             inline - len(1) services.exe - 0x00705B5D->_
             inline - len(1) services.exe - 0x00705B75->_
             inline - len(6) services.exe - 0x00705B7D->_
             inline - len(1) services.exe - 0x00705B9A->_
             inline - len(1) services.exe - 0x00705BA7->_
             inline - len(6) services.exe - 0x00705BAF->_
             inline - len(1) services.exe - 0x00705BCC->_
             inline - len(1) services.exe - 0x00705BD9->_
             inline - len(6) services.exe - 0x00705BE1->_
             inline - len(1) services.exe - 0x00705BFE->_
             inline - len(1) services.exe - 0x00705C0B->_
             inline - len(6) services.exe - 0x00705C13->_
             inline - len(1) services.exe - 0x00705C30->_
             inline - len(1) services.exe - 0x00705C3D->_
             inline - len(6) services.exe - 0x00705C4E->_
             inline - len(1) services.exe - 0x00705C61->_
             inline - len(1) services.exe - 0x00705C7D->_
             inline - len(6) services.exe - 0x00705C85->_
             inline - len(1) services.exe - 0x00705CA2->_
             inline - len(6) services.exe - 0x00705CAE->_
             inline - len(1) services.exe - 0x00705CCB->_
             inline - len(1) services.exe - 0x00705CD8->_
             inline - len(1) services.exe - 0x00705CDE->_
             inline - len(1) services.exe - 0x00705CEC->_
             inline - len(6) services.exe - 0x00705D01->_
             inline - len(1) services.exe - 0x00705D14->_
             inline - len(6) services.exe - 0x00705D1A->_
             inline - len(6) services.exe - 0x00705D4A->_
             inline - len(1) services.exe - 0x00705D5F->_
             inline - len(1) services.exe - 0x00705D74->_
             inline - len(1) services.exe - 0x00705D8B->_
             inline - len(1) services.exe - 0x00705D92->_
             inline - len(1) services.exe - 0x00705DA4->_
             inline - len(1) services.exe - 0x00705DAD->_
             inline - len(1) services.exe - 0x00705DB4->_
             inline - len(1) services.exe - 0x00705DC2->_
             inline - len(1) services.exe - 0x00705DD4->_
             inline - len(1) services.exe - 0x00705DDB->_
             inline - len(1) services.exe - 0x00705DE9->_
             inline - len(6) services.exe - 0x00705DF1->_
             inline - len(1) services.exe - 0x00705E0B->_
             inline - len(1) services.exe - 0x00705E2B->_
             inline - len(1) services.exe - 0x00705E36->_
             inline - len(1) services.exe - 0x00705E41->_
             inline - len(1) services.exe - 0x00705E93->_
             inline - len(1) services.exe - 0x00705EA3->_
             inline - len(11) services.exe - 0x00705EB4->_
             inline - len(1) services.exe - 0x00705EDE->_
             inline - len(6) services.exe - 0x00705F14->_
             inline - len(1) services.exe - 0x00705F29->_
             inline - len(1) services.exe - 0x00705FC0->_
             inline - len(6) services.exe - 0x00705FDC->_
             inline - len(1) services.exe - 0x00705FF5->_
             inline - len(6) services.exe - 0x0070600E->_
             inline - len(1) services.exe - 0x00706026->_
             inline - len(1) services.exe - 0x00706044->_
             inline - len(1) services.exe - 0x00706051->_
             inline - len(1) services.exe - 0x00706078->_
             inline - len(1) services.exe - 0x007060A1->_
             inline - len(1) services.exe - 0x007060A7->_
             inline - len(1) services.exe - 0x007060B5->_
             inline - len(6) services.exe - 0x007060C9->_
             inline - len(1) services.exe - 0x007060E9->_
             inline - len(6) services.exe - 0x00706100->_
             inline - len(1) services.exe - 0x00706118->_
             inline - len(1) services.exe - 0x00706138->_
             inline - len(6) services.exe - 0x00706147->_
             inline - len(1) services.exe - 0x00706161->_
             inline - len(1) services.exe - 0x00706176->_
             inline - len(1) services.exe - 0x00706197->_
             inline - len(1) services.exe - 0x007061C3->_
             inline - len(1) services.exe - 0x007061CE->_
             inline - len(1) services.exe - 0x007061D4->_
             inline - len(1) services.exe - 0x007061DA->_
             inline - len(1) services.exe - 0x007061E8->_
             inline - len(1) services.exe - 0x00706200->_
             inline - len(1) services.exe - 0x00706206->_
             inline - len(1) services.exe - 0x0070620C->_
             inline - len(1) services.exe - 0x00706222->_
             inline - len(1) services.exe - 0x0070622C->_
             inline - len(1) services.exe - 0x00706232->_
             inline - len(1) services.exe - 0x00706238->_
             inline - len(1) services.exe - 0x00706251->_
             inline - len(1) services.exe - 0x0070625E->_
             inline - len(6) services.exe - 0x0070626E->_
             inline - len(1) services.exe - 0x00706284->_
             inline - len(1) services.exe - 0x007062C1->_
             inline - len(1) services.exe - 0x007062C7->_
             inline - len(1) services.exe - 0x007062CD->_
             inline - len(1) services.exe - 0x007062E6->_
             inline - len(11) services.exe - 0x007062FF->_
             inline - len(1) services.exe - 0x00706322->_
             inline - len(1) services.exe - 0x0070633A->_
             inline - len(1) services.exe - 0x0070634C->_
             inline - len(1) services.exe - 0x00706353->_
             inline - len(1) services.exe - 0x00706371->_
             inline - len(6) services.exe - 0x00706384->_
             inline - len(1) services.exe - 0x0070639B->_
             inline - len(1) services.exe - 0x007063BA->_
             inline - len(1) services.exe - 0x007063E1->_
             inline - len(1) services.exe - 0x007063EB->_
             inline - len(1) services.exe - 0x00706442->_
             inline - len(6) services.exe - 0x00706449->_
             inline - len(1) services.exe - 0x00706464->_
             inline - len(1) services.exe - 0x0070646E->_
             inline - len(6) services.exe - 0x00706475->_
             inline - len(1) services.exe - 0x00706490->_
             inline - len(1) services.exe - 0x007064A8->_
             inline - len(6) services.exe - 0x007064AF->_
             inline - len(1) services.exe - 0x007064CA->_
             inline - len(1) services.exe - 0x007064D7->_
             inline - len(1) services.exe - 0x007064E7->_
             inline - len(1) services.exe - 0x00706505->_
             inline - len(1) services.exe - 0x0070651D->_
             inline - len(1) services.exe - 0x0070652D->_
             inline - len(1) services.exe - 0x00706545->_
             inline - len(1) services.exe - 0x00706555->_
             inline - len(1) services.exe - 0x0070656D->_
             inline - len(1) services.exe - 0x0070657A->_
             inline - len(1) services.exe - 0x00706592->_
             inline - len(1) services.exe - 0x0070659F->_
             inline - len(1) services.exe - 0x007065B7->_
             inline - len(1) services.exe - 0x007065C4->_
             inline - len(1) services.exe - 0x007065DC->_
             inline - len(1) services.exe - 0x00706639->_
             inline - len(1) services.exe - 0x00706664->_
             inline - len(6) services.exe - 0x0070669E->_
             inline - len(1) services.exe - 0x007066AD->_
             inline - len(1) services.exe - 0x007066B8->_
             inline - len(1) services.exe - 0x007066C4->_
             inline - len(1) services.exe - 0x007066CD->_
             inline - len(1) services.exe - 0x007066D8->_
             inline - len(1) services.exe - 0x007066E1->_
             inline - len(1) services.exe - 0x0070674C->_
             inline - len(1) services.exe - 0x00706798->_
             inline - len(1) services.exe - 0x007067B8->_
             inline - len(1) services.exe - 0x007067EC->_
             inline - len(1) services.exe - 0x00706803->_
             inline - len(1) services.exe - 0x00706898->_
             inline - len(1) services.exe - 0x007068A1->_
             inline - len(1) services.exe - 0x007068AC->_
             inline - len(6) services.exe - 0x007068B9->_
             inline - len(1) services.exe - 0x007068CB->_
             inline - len(1) services.exe - 0x007068E2->_
             inline - len(1) services.exe - 0x007068F8->_
             inline - len(6) services.exe - 0x00706907->_
             inline - len(1) services.exe - 0x0070691C->_
             inline - len(6) services.exe - 0x00706935->_
             inline - len(1) services.exe - 0x00706950->_
             inline - len(1) services.exe - 0x00706977->_
             inline - len(1) services.exe - 0x0070697D->_
             inline - len(1) services.exe - 0x00706994->_
             inline - len(11) services.exe - 0x007069BE->_
             inline - len(1) services.exe - 0x007069DE->_
             inline - len(1) services.exe - 0x00706A1F->_
             inline - len(1) services.exe - 0x00706A26->_
             inline - len(1) services.exe - 0x00706A2D->_
             inline - len(1) services.exe - 0x00706A4F->_
             inline - len(1) services.exe - 0x00706A76->_
             inline - len(1) services.exe - 0x00706A80->_
             inline - len(1) services.exe - 0x00706AA1->_
             inline - len(1) services.exe - 0x00706AD0->_
             inline - len(1) services.exe - 0x00706AEF->_
             inline - len(1) services.exe - 0x00706B22->_
             inline - len(1) services.exe - 0x00706B41->_
             inline - len(6) services.exe - 0x00706B6E->_
             inline - len(1) services.exe - 0x00706B81->_
             inline - len(1) services.exe - 0x00706B95->_
             inline - len(1) services.exe - 0x00706BA2->_
             inline - len(6) services.exe - 0x00706BA9->_
             inline - len(1) services.exe - 0x00706BC5->_
             inline - len(1) services.exe - 0x00706BDD->_
             inline - len(6) services.exe - 0x00706BE4->_
             inline - len(1) services.exe - 0x00706BFF->_
             inline - len(1) services.exe - 0x00706C16->_
             inline - len(1) services.exe - 0x00706C2E->_
             inline - len(1) services.exe - 0x00706C34->_
             inline - len(1) services.exe - 0x00706C4D->_
             inline - len(1) services.exe - 0x00706C83->_
             inline - len(1) services.exe - 0x00706C92->_
             inline - len(1) services.exe - 0x00706C9D->_
             inline - len(1) services.exe - 0x00706CA3->_
             inline - len(1) services.exe - 0x00706CBA->_
             inline - len(1) services.exe - 0x00706CDB->_
             inline - len(1) services.exe - 0x00706CE1->_
             inline - len(1) services.exe - 0x00706CF7->_
             inline - len(1) services.exe - 0x00706D0F->_
             inline - len(1) services.exe - 0x00706D15->_
             inline - len(1) services.exe - 0x00706D1B->_
             inline - len(1) services.exe - 0x00706D31->_
             inline - len(1) services.exe - 0x00706D3B->_
             inline - len(1) services.exe - 0x00706D41->_
             inline - len(1) services.exe - 0x00706D47->_
             inline - len(1) services.exe - 0x00706D5D->_
             inline - len(1) services.exe - 0x00706D76->_
             inline - len(1) services.exe - 0x00706D83->_
             inline - len(1) services.exe - 0x00706D8A->_
             inline - len(6) services.exe - 0x00706DB5->_
             inline - len(1) services.exe - 0x00706DDF->_
             inline - len(6) services.exe - 0x00706DE9->_
             inline - len(6) services.exe - 0x00706E09->_
             inline - len(6) services.exe - 0x00706E36->_
             inline - len(6) services.exe - 0x00706E56->_
             inline - len(6) services.exe - 0x00706E9E->_
             inline - len(1) services.exe - 0x00706EB8->_
             inline - len(6) services.exe - 0x00706ED3->_
             inline - len(1) services.exe - 0x00706EED->_
             inline - len(1) services.exe - 0x00706F07->_
             inline - len(6) services.exe - 0x00706F11->_
             inline - len(6) services.exe - 0x00706F33->_
             inline - len(6) services.exe - 0x00706F55->_
             inline - len(6) services.exe - 0x00706F77->_
             inline - len(1) services.exe - 0x00706F9A->_
             inline - len(1) services.exe - 0x00706FA0->_
             inline - len(1) services.exe - 0x00706FBF->_
             inline - len(1) services.exe - 0x00706FC5->_
             inline - len(6) services.exe - 0x00706FE3->_
             inline - len(1) services.exe - 0x00706FF8->_
             inline - len(1) services.exe - 0x00706FFE->_
             inline - len(1) services.exe - 0x00707012->_
             inline - len(1) services.exe - 0x00707018->_
             inline - len(1) services.exe - 0x0070701F->_
             inline - len(1) services.exe - 0x00707025->_
             inline - len(6) services.exe - 0x00707031->_
             inline - len(1) services.exe - 0x00707061->_
             inline - len(1) services.exe - 0x00707080->_
             inline - len(1) services.exe - 0x0070709F->_
             inline - len(1) services.exe - 0x007070BE->_
             inline - len(1) services.exe - 0x007070DD->_
             inline - len(1) services.exe - 0x007070FC->_
             inline - len(1) services.exe - 0x0070711B->_
             inline - len(1) services.exe - 0x0070713A->_
             inline - len(1) services.exe - 0x0070715D->_
             inline - len(1) services.exe - 0x00707166->_
             inline - len(1) services.exe - 0x00707176->_
             inline - len(1) services.exe - 0x00707180->_
             inline - len(6) services.exe - 0x00707189->_
             inline - len(1) services.exe - 0x0070719D->_
             inline - len(1) services.exe - 0x007071AE->_
             inline - len(1) services.exe - 0x007071B8->_
             inline - len(1) services.exe - 0x007071C3->_
             inline - len(1) services.exe - 0x007071CB->_
             inline - len(1) services.exe - 0x007071D2->_
             inline - len(1) services.exe - 0x007071DC->_
             inline - len(1) services.exe - 0x007071E7->_
             inline - len(6) services.exe - 0x007071ED->_
             inline - len(1) services.exe - 0x00707201->_
             inline - len(1) services.exe - 0x0070720D->_
             inline - len(1) services.exe - 0x00707217->_
             inline - len(1) services.exe - 0x00707241->_
             inline - len(1) services.exe - 0x0070726C->_
             inline - len(1) services.exe - 0x0070728D->_
             inline - len(1) services.exe - 0x007072AD->_
             inline - len(1) services.exe - 0x007072C5->_
             inline - len(1) services.exe - 0x007072CB->_
             inline - len(1) services.exe - 0x007072E3->_
             inline - len(1) services.exe - 0x007072FB->_
             inline - len(1) services.exe - 0x00707301->_
             inline - len(1) services.exe - 0x0070731A->_
             inline - len(1) services.exe - 0x00707345->_
             inline - len(1) services.exe - 0x0070735D->_
             inline - len(1) services.exe - 0x00707363->_
             inline - len(1) services.exe - 0x0070737C->_
             inline - len(1) services.exe - 0x007073A8->_
             inline - len(1) services.exe - 0x007073C9->_
             inline - len(1) services.exe - 0x007073E6->_
             inline - len(6) services.exe - 0x007073F3->_
             inline - len(1) services.exe - 0x0070743A->_
             inline - len(1) services.exe - 0x00707457->_
             inline - len(1) services.exe - 0x00707462->_
             inline - len(1) services.exe - 0x0070747C->_
             inline - len(1) services.exe - 0x00707486->_
             inline - len(1) services.exe - 0x007074A3->_
             inline - len(1) services.exe - 0x007074AC->_
             inline - len(6) services.exe - 0x0070759B->_
             inline - len(6) services.exe - 0x007075B9->_
             inline - len(1) services.exe - 0x007075D8->_
             inline - len(6) services.exe - 0x0070764A->_
             inline - len(6) services.exe - 0x00707668->_
             inline - len(6) services.exe - 0x0070768B->_
             inline - len(1) services.exe - 0x007076A6->_
             inline - len(1) services.exe - 0x007076AF->_
             inline - len(6) services.exe - 0x007076B5->_
             inline - len(6) services.exe - 0x007076D1->_
             inline - len(1) services.exe - 0x007076F2->_
             inline - len(1) services.exe - 0x007076F9->_
             inline - len(1) services.exe - 0x007076FF->_
             inline - len(6) services.exe - 0x00707706->_
             inline - len(1) services.exe - 0x00707723->_
             inline - len(1) services.exe - 0x00707729->_
             inline - len(1) services.exe - 0x0070773F->_
             inline - len(1) services.exe - 0x00707757->_
             inline - len(1) services.exe - 0x0070775D->_
             inline - len(1) services.exe - 0x00707774->_
             inline - len(1) services.exe - 0x00707848->_
             inline - len(1) services.exe - 0x0070784E->_
             inline - len(1) services.exe - 0x0070786A->_
             inline - len(6) services.exe - 0x00707889->_
             inline - len(1) services.exe - 0x007078B0->_
             inline - len(1) services.exe - 0x007078B6->_
             inline - len(1) services.exe - 0x007078FD->_
             inline - len(1) services.exe - 0x00707908->_
             inline - len(6) services.exe - 0x0070791C->_
             inline - len(1) services.exe - 0x00707936->_
             inline - len(6) services.exe - 0x0070794D->_
             inline - len(1) services.exe - 0x0070795F->_
             inline - len(1) services.exe - 0x0070797B->_
             inline - len(6) services.exe - 0x00707982->_
             inline - len(1) services.exe - 0x0070799D->_
             inline - len(1) services.exe - 0x007079D1->_
             inline - len(1) services.exe - 0x007079FF->_
             inline - len(1) services.exe - 0x00707A16->_
             inline - len(1) services.exe - 0x00707A28->_
             inline - len(1) services.exe - 0x00707A34->_
             inline - len(1) services.exe - 0x00707A3E->_
             inline - len(1) services.exe - 0x00707A4E->_
             inline - len(6) services.exe - 0x00707A61->_
             inline - len(1) services.exe - 0x00707A6D->_
             inline - len(1) services.exe - 0x00707A7A->_
             inline - len(1) services.exe - 0x00707A80->_
             inline - len(1) services.exe - 0x00707A86->_
             inline - len(1) services.exe - 0x00707A97->_
             inline - len(6) services.exe - 0x00707AAC->_
             inline - len(1) services.exe - 0x00707AC6->_
             inline - len(1) services.exe - 0x00707AF9->_
             inline - len(1) services.exe - 0x00707B0F->_
             inline - len(1) services.exe - 0x00707B25->_
             inline - len(1) services.exe - 0x00707B3B->_
             inline - len(1) services.exe - 0x00707B46->_
             inline - len(6) services.exe - 0x00707B4E->_
             inline - len(1) services.exe - 0x00707B6B->_
             inline - len(1) services.exe - 0x00707B75->_
             inline - len(6) services.exe - 0x00707B7D->_
             inline - len(1) services.exe - 0x00707B9A->_
             inline - len(1) services.exe - 0x00707BB1->_
             inline - len(1) services.exe - 0x00707BCF->_
             inline - len(1) services.exe - 0x00707BD5->_
             inline - len(1) services.exe - 0x00707BEC->_
             inline - len(6) services.exe - 0x00707C10->_
             inline - len(1) services.exe - 0x00707C41->_
             inline - len(6) services.exe - 0x00707C5C->_
             inline - len(1) services.exe - 0x00707C8D->_
             inline - len(6) services.exe - 0x00707CA8->_
             inline - len(1) services.exe - 0x00707CD9->_
             inline - len(6) services.exe - 0x00707D00->_
             inline - len(1) services.exe - 0x00707D17->_
             inline - len(1) services.exe - 0x00707D3D->_
             inline - len(6) services.exe - 0x00707D74->_
             inline - len(1) services.exe - 0x00707D90->_
             inline - len(6) services.exe - 0x00707DB8->_
             inline - len(1) services.exe - 0x00707DD4->_
             inline - len(6) services.exe - 0x00707DEB->_
             inline - len(1) services.exe - 0x00707E02->_
             inline - len(1) services.exe - 0x00707E18->_
             inline - len(1) services.exe - 0x00707E26->_
             inline - len(1) services.exe - 0x00707E2C->_
             inline - len(1) services.exe - 0x00707E42->_
             inline - len(1) services.exe - 0x00707E52->_
             inline - len(1) services.exe - 0x00707E60->_
             inline - len(1) services.exe - 0x00707E66->_
             inline - len(1) services.exe - 0x00707E7C->_
             inline - len(1) services.exe - 0x00707E94->_
             inline - len(1) services.exe - 0x00707E9A->_
             inline - len(1) services.exe - 0x00707EA0->_
             inline - len(1) services.exe - 0x00707EB6->_
             inline - len(1) services.exe - 0x00707EC0->_
             inline - len(1) services.exe - 0x00707EC6->_
             inline - len(1) services.exe - 0x00707ECC->_
             inline - len(1) services.exe - 0x00707EE2->_
             inline - len(1) services.exe - 0x00707EF9->_
             inline - len(1) services.exe - 0x00707F0C->_
             inline - len(1) services.exe - 0x00707F38->_
             inline - len(6) services.exe - 0x00707F60->_
             inline - len(1) services.exe - 0x00707F7B->_
             inline - len(6) services.exe - 0x00707FB5->_
             inline - len(1) services.exe - 0x00707FD1->_
             inline - len(6) services.exe - 0x00707FF6->_
             inline - len(1) services.exe - 0x0070800E->_
             inline - len(1) services.exe - 0x00708068->_
             inline - len(1) services.exe - 0x00708076->_
             inline - len(1) services.exe - 0x007080A7->_
             inline - len(1) services.exe - 0x007080B7->_
             inline - len(1) services.exe - 0x007080CE->_
             inline - len(1) services.exe - 0x007080D4->_
             inline - len(1) services.exe - 0x007080DE->_
             inline - len(1) services.exe - 0x007080F1->_
             inline - len(1) services.exe - 0x0070811D->_
             inline - len(6) services.exe - 0x00708133->_
             inline - len(1) services.exe - 0x00708149->_
             inline - len(1) services.exe - 0x00708174->_
             inline - len(1) services.exe - 0x0070817A->_
             inline - len(1) services.exe - 0x0070818F->_
             inline - len(1) services.exe - 0x007081B2->_
             inline - len(1) services.exe - 0x007081C9->_
             inline - len(1) services.exe - 0x007081E2->_
             inline - len(1) services.exe - 0x00708202->_
             inline - len(6) services.exe - 0x00708265->_
             inline - len(6) services.exe - 0x0070827A->_
             inline - len(1) services.exe - 0x007082B9->_
             inline - len(1) services.exe - 0x007082DE->_
             inline - len(1) services.exe - 0x007082F7->_
             inline - len(6) services.exe - 0x00708346->_
             inline - len(1) services.exe - 0x00708364->_
             inline - len(6) services.exe - 0x00708376->_
             inline - len(1) services.exe - 0x00708395->_
             inline - len(6) services.exe - 0x007083A7->_
             inline - len(1) services.exe - 0x007083C6->_
             inline - len(6) services.exe - 0x007083E0->_
             inline - len(1) services.exe - 0x007083FF->_
             inline - len(6) services.exe - 0x00708419->_
             inline - len(1) services.exe - 0x00708438->_
             inline - len(6) services.exe - 0x0070844A->_
             inline - len(1) services.exe - 0x00708468->_
             inline - len(1) services.exe - 0x00708478->_
             inline - len(1) services.exe - 0x0070847E->_
             inline - len(1) services.exe - 0x00708497->_
             inline - len(6) services.exe - 0x007084B2->_
             inline - len(1) services.exe - 0x007084D1->_
             inline - len(6) services.exe - 0x007084EE->_
             inline - len(1) services.exe - 0x0070850C->_
             inline - len(6) services.exe - 0x0070851E->_
             inline - len(1) services.exe - 0x0070853C->_
             inline - len(1) services.exe - 0x00708549->_
             inline - len(1) services.exe - 0x0070854F->_
             inline - len(1) services.exe - 0x00708568->_
             inline - len(1) services.exe - 0x00708578->_
             inline - len(6) services.exe - 0x00708580->_
             inline - len(1) services.exe - 0x007085A0->_
             inline - len(1) services.exe - 0x007085B8->_
             inline - len(6) services.exe - 0x007085C0->_
             inline - len(1) services.exe - 0x007085E1->_
             inline - len(6) services.exe - 0x00708600->_
             inline - len(1) services.exe - 0x00708627->_
             inline - len(6) services.exe - 0x0070863E->_
             inline - len(1) services.exe - 0x00708660->_
             inline - len(1) services.exe - 0x00708678->_
             inline - len(6) services.exe - 0x00708680->_
             inline - len(1) services.exe - 0x007086A0->_
             inline - len(1) services.exe - 0x007086B8->_
             inline - len(6) services.exe - 0x007086C0->_
             inline - len(1) services.exe - 0x007086E0->_
             inline - len(6) services.exe - 0x007086FF->_
             inline - len(1) services.exe - 0x00708725->_
             inline - len(6) services.exe - 0x0070873C->_
             inline - len(1) services.exe - 0x0070875C->_
             inline - len(1) services.exe - 0x00708775->_
             inline - len(6) services.exe - 0x0070877D->_
             inline - len(1) services.exe - 0x0070879D->_
             inline - len(1) services.exe - 0x007087B7->_
             inline - len(1) services.exe - 0x007087BD->_
             inline - len(1) services.exe - 0x007087D2->_
             inline - len(6) services.exe - 0x007087E1->_
             inline - len(1) services.exe - 0x007087FB->_
             inline - len(1) services.exe - 0x0070882A->_
             inline - len(1) services.exe - 0x00708831->_
             inline - len(6) services.exe - 0x0070883A->_
             inline - len(1) services.exe - 0x0070884D->_
             inline - len(6) services.exe - 0x00708853->_
             inline - len(1) services.exe - 0x0070886B->_
             inline - len(1) services.exe - 0x00708872->_
             inline - len(6) services.exe - 0x00708891->_
             inline - len(1) services.exe - 0x007088A7->_
             inline - len(6) services.exe - 0x007088BA->_
             inline - len(1) services.exe - 0x007088C5->_
             inline - len(1) services.exe - 0x007088CB->_
             inline - len(1) services.exe - 0x007088DE->_
             inline - len(1) services.exe - 0x007088F7->_
             inline - len(1) services.exe - 0x00708919->_
             inline - len(1) services.exe - 0x00708920->_
             inline - len(1) services.exe - 0x00708969->_
             inline - len(1) services.exe - 0x0070896F->_
             inline - len(1) services.exe - 0x0070897A->_
             inline - len(1) services.exe - 0x00708980->_
             inline - len(1) services.exe - 0x00708987->_
             inline - len(11) services.exe - 0x00708992->_
             inline - len(1) services.exe - 0x007089AC->_
             inline - len(6) services.exe - 0x007089C0->_
             inline - len(1) services.exe - 0x007089CE->_
             inline - len(1) services.exe - 0x007089E2->_
             inline - len(1) services.exe - 0x007089F0->_
             inline - len(1) services.exe - 0x00708A02->_
             inline - len(6) services.exe - 0x00708A1A->_
             inline - len(1) services.exe - 0x00708A3D->_
             inline - len(6) services.exe - 0x00708A48->_
             inline - len(1) services.exe - 0x00708A63->_
             inline - len(6) services.exe - 0x00708A69->_
             inline - len(1) services.exe - 0x00708A86->_
             inline - len(1) services.exe - 0x00708A8C->_
             inline - len(1) services.exe - 0x00708AB1->_
             inline - len(6) services.exe - 0x00708AFC->_
             inline - len(1) services.exe - 0x00708B1F->_
             inline - len(6) services.exe - 0x00708B3D->_
             inline - len(1) services.exe - 0x00708B5A->_
             inline - len(6) services.exe - 0x00708B78->_
             inline - len(1) services.exe - 0x00708B9B->_
             inline - len(6) services.exe - 0x00708BB9->_
             inline - len(1) services.exe - 0x00708BD6->_
             inline - len(6) services.exe - 0x00708BDF->_
             inline - len(1) services.exe - 0x00708BFC->_
             inline - len(1) services.exe - 0x00708C14->_
             inline - len(6) services.exe - 0x00708C1C->_
             inline - len(1) services.exe - 0x00708C3C->_
             inline - len(1) services.exe - 0x00708C6A->_
             inline - len(1) services.exe - 0x00708C8A->_
             inline - len(1) services.exe - 0x00708CA1->_
             inline - len(1) services.exe - 0x00708CBE->_
             inline - len(1) services.exe - 0x00708CC5->_
             inline - len(1) services.exe - 0x00708CD7->_
             inline - len(1) services.exe - 0x00708D0A->_
             inline - len(1) services.exe - 0x00708D2B->_
             inline - len(1) services.exe - 0x00708D44->_
             inline - len(1) services.exe - 0x00708D78->_
             inline - len(1) services.exe - 0x00708DC5->_
             inline - len(1) services.exe - 0x00708DD0->_
             inline - len(1) services.exe - 0x00708DD6->_
             inline - len(1) services.exe - 0x00708DF7->_
             inline - len(1) services.exe - 0x00708E23->_
             inline - len(1) services.exe - 0x00708E3E->_
             inline - len(6) services.exe - 0x00708E4C->_
             inline - len(1) services.exe - 0x00708E6E->_
             inline - len(6) services.exe - 0x00708EC7->_
             inline - len(1) services.exe - 0x00708EEC->_
             inline - len(1) services.exe - 0x00708F24->_
             inline - len(1) services.exe - 0x00708F2A->_
             inline - len(1) services.exe - 0x00708F46->_
             inline - len(1) services.exe - 0x00708F81->_
             inline - len(1) services.exe - 0x00708F87->_
             inline - len(1) services.exe - 0x00708FA6->_
             inline - len(6) services.exe - 0x00708FC0->_
             inline - len(1) services.exe - 0x00708FE3->_
             inline - len(1) services.exe - 0x00708FFB->_
             inline - len(6) services.exe - 0x00709003->_
             inline - len(1) services.exe - 0x00709026->_
             inline - len(6) services.exe - 0x0070902F->_
             inline - len(1) services.exe - 0x00709052->_
             inline - len(1) services.exe - 0x0070905C->_
             inline - len(6) services.exe - 0x00709064->_
             inline - len(1) services.exe - 0x00709087->_
             inline - len(6) services.exe - 0x0070909E->_
             inline - len(1) services.exe - 0x007090B9->_
             inline - len(1) services.exe - 0x007090CB->_
             inline - len(1) services.exe - 0x007090D1->_
             inline - len(1) services.exe - 0x0070910D->_
             inline - len(1) services.exe - 0x00709128->_
             inline - len(1) services.exe - 0x0070913B->_
             inline - len(1) services.exe - 0x00709167->_
             inline - len(6) services.exe - 0x0070919A->_
             inline - len(1) services.exe - 0x007091B7->_
             inline - len(6) services.exe - 0x007091E0->_
             inline - len(1) services.exe - 0x007091FF->_
             inline - len(1) services.exe - 0x0070920E->_
             inline - len(6) services.exe - 0x0070922F->_
             inline - len(1) services.exe - 0x0070924E->_
             inline - len(1) services.exe - 0x0070925F->_
             inline - len(1) services.exe - 0x00709276->_
             inline - len(1) services.exe - 0x00709295->_
             inline - len(1) services.exe - 0x007092BD->_
             inline - len(1) services.exe - 0x007092D5->_
             inline - len(1) services.exe - 0x007092E2->_
             inline - len(1) services.exe - 0x007092E8->_
             inline - len(1) services.exe - 0x007092F1->_
             inline - len(1) services.exe - 0x00709310->_
             inline - len(1) services.exe - 0x00709318->_
             inline - len(1) services.exe - 0x00709321->_
             inline - len(1) services.exe - 0x00709327->_
             inline - len(1) services.exe - 0x0070932F->_
             inline - len(1) services.exe - 0x0070933B->_
             inline - len(1) services.exe - 0x0070936C->_
             inline - len(1) services.exe - 0x00709372->_
             inline - len(1) services.exe - 0x007093A7->_
             inline - len(1) services.exe - 0x007093D6->_
             inline - len(1) services.exe - 0x007093E3->_
             inline - len(1) services.exe - 0x00709407->_
             inline - len(1) services.exe - 0x00709422->_
             inline - len(1) services.exe - 0x0070942E->_
             inline - len(1) services.exe - 0x0070944A->_
             inline - len(1) services.exe - 0x00709468->_
             inline - len(1) services.exe - 0x00709480->_
             inline - len(1) services.exe - 0x007095A3->_
             inline - len(1) services.exe - 0x007095C8->_
             inline - len(1) services.exe - 0x00709620->_
             inline - len(1) services.exe - 0x0070964B->_
             inline - len(1) services.exe - 0x0070965F->_
             inline - len(1) services.exe - 0x00709725->_
             inline - len(1) services.exe - 0x0070972F->_
             inline - len(1) services.exe - 0x00709739->_
             inline - len(1) services.exe - 0x00709743->_
             inline - len(1) services.exe - 0x00709758->_
             inline - len(1) services.exe - 0x0070975E->_
             inline - len(1) services.exe - 0x007097CF->_
             inline - len(1) services.exe - 0x007097EE->_
             inline - len(1) services.exe - 0x007097FE->_
             inline - len(1) services.exe - 0x00709824->_
             inline - len(1) services.exe - 0x00709834->_
             inline - len(1) services.exe - 0x00709852->_
             inline - len(1) services.exe - 0x00709862->_
             inline - len(1) services.exe - 0x00709886->_
             inline - len(1) services.exe - 0x007098A3->_
             inline - len(1) services.exe - 0x007098AF->_
             inline - len(1) services.exe - 0x007098BB->_
             inline - len(13) services.exe - 0x00709966->_
             inline - len(5) services.exe - 0x00709A76->_
             inline - len(1) services.exe - 0x00709A95->_
             inline - len(1) services.exe - 0x00709AA4->_
             inline - len(1) services.exe - 0x00709AAA->_
             inline - len(1) services.exe - 0x00709AB0->_
             inline - len(1) services.exe - 0x00709ABD->_
             inline - len(1) services.exe - 0x00709AC3->_
             inline - len(11) services.exe - 0x00709ACF->_
             inline - len(1) services.exe - 0x00709B31->_
             inline - len(6) services.exe - 0x00709B59->_
             inline - len(1) services.exe - 0x00709B69->_
             inline - len(1) services.exe - 0x00709B7D->_
             inline - len(1) services.exe - 0x00709B84->_
             inline - len(1) services.exe - 0x00709B8E->_
             inline - len(1) services.exe - 0x00709BB8->_
             inline - len(6) services.exe - 0x00709BE4->_
             inline - len(1) services.exe - 0x00709BEF->_
             inline - len(1) services.exe - 0x00709BF7->_
             inline - len(1) services.exe - 0x00709C02->_
             inline - len(1) services.exe - 0x00709C27->_
             inline - len(1) services.exe - 0x00709C93->_
             inline - len(6) services.exe - 0x00709CD8->_
             inline - len(1) services.exe - 0x00709CEB->_
             inline - len(1) services.exe - 0x00709D13->_
             inline - len(1) services.exe - 0x00709D28->_
             inline - len(1) services.exe - 0x00709D55->_
             inline - len(6) services.exe - 0x00709D5C->_
             inline - len(1) services.exe - 0x00709D98->_
             inline - len(1) services.exe - 0x00709DD2->_
             inline - len(1) services.exe - 0x00709DE0->_
             inline - len(1) services.exe - 0x00709DF6->_
             inline - len(1) services.exe - 0x00709E0B->_
             inline - len(1) services.exe - 0x00709E11->_
             inline - len(1) services.exe - 0x00709E28->_
             inline - len(1) services.exe - 0x00709E3F->_
             inline - len(6) services.exe - 0x00709E52->_
             inline - len(1) services.exe - 0x00709E6E->_
             inline - len(1) services.exe - 0x00709E7E->_
             inline - len(1) services.exe - 0x00709EA3->_
             inline - len(1) services.exe - 0x00709EC6->_
             inline - len(1) services.exe - 0x00709ED9->_
             inline - len(1) services.exe - 0x00709EDF->_
             inline - len(1) services.exe - 0x00709F34->_
             inline - len(1) services.exe - 0x00709F3A->_
             inline - len(1) services.exe - 0x00709F50->_
             inline - len(1) services.exe - 0x00709F69->_
             inline - len(1) services.exe - 0x00709F70->_
             inline - len(6) services.exe - 0x00709F86->_
             inline - len(1) services.exe - 0x00709F98->_
             inline - len(6) services.exe - 0x00709FB1->_
             inline - len(1) services.exe - 0x00709FC3->_
             inline - len(1) services.exe - 0x00709FD7->_
             inline - len(1) services.exe - 0x00709FE2->_
             inline - len(1) services.exe - 0x00709FF1->_
             inline - len(1) services.exe - 0x00709FF7->_
             inline - len(1) services.exe - 0x0070A004->_
             inline - len(1) services.exe - 0x0070A00A->_
             inline - len(1) services.exe - 0x0070A048->_
             inline - len(1) services.exe - 0x0070A052->_
             inline - len(6) services.exe - 0x0070A05B->_
             inline - len(1) services.exe - 0x0070A06E->_
             inline - len(6) services.exe - 0x0070A074->_
             inline - len(1) services.exe - 0x0070A094->_
             inline - len(1) services.exe - 0x0070A0DF->_
             inline - len(1) services.exe - 0x0070A0E6->_
             inline - len(1) services.exe - 0x0070A10C->_
             inline - len(1) services.exe - 0x0070A13F->_
             inline - len(1) services.exe - 0x0070A16A->_
             inline - len(6) services.exe - 0x0070A186->_
             inline - len(1) services.exe - 0x0070A199->_
             inline - len(1) services.exe - 0x0070A1AD->_
             inline - len(6) services.exe - 0x0070A1B3->_
             inline - len(1) services.exe - 0x0070A1BF->_
             inline - len(1) services.exe - 0x0070A1C6->_
             inline - len(1) services.exe - 0x0070A1D3->_
             inline - len(1) services.exe - 0x0070A1D9->_
             inline - len(1) services.exe - 0x0070A1EE->_
             inline - len(1) services.exe - 0x0070A201->_
             inline - len(1) services.exe - 0x0070A20F->_
             inline - len(1) services.exe - 0x0070A219->_
             inline - len(1) services.exe - 0x0070A229->_
             inline - len(1) services.exe - 0x0070A23C->_
             inline - len(1) services.exe - 0x0070A24F->_
             inline - len(1) services.exe - 0x0070A255->_
             inline - len(1) services.exe - 0x0070A282->_
             inline - len(1) services.exe - 0x0070A295->_
             inline - len(1) services.exe - 0x0070A29D->_
             inline - len(6) services.exe - 0x0070A2EE->_
             inline - len(6) services.exe - 0x0070A318->_
             inline - len(1) services.exe - 0x0070A324->_
             inline - len(1) services.exe - 0x0070A32B->_
             inline - len(1) services.exe - 0x0070A351->_
             inline - len(1) services.exe - 0x0070A359->_
             inline - len(1) services.exe - 0x0070A362->_
             inline - len(1) services.exe - 0x0070A36A->_
             inline - len(6) services.exe - 0x0070A38D->_
             inline - len(1) services.exe - 0x0070A3A4->_
             inline - len(6) services.exe - 0x0070A3B8->_
             inline - len(1) services.exe - 0x0070A3CA->_
             inline - len(1) services.exe - 0x0070A3FD->_
             inline - len(1) services.exe - 0x0070A4B4->_
             inline - len(6) services.exe - 0x0070A4C3->_
             inline - len(6) services.exe - 0x0070A4E6->_
             inline - len(1) services.exe - 0x0070A506->_
             inline - len(1) services.exe - 0x0070A511->_
             inline - len(1) services.exe - 0x0070A54A->_
             inline - len(1) services.exe - 0x0070A561->_
             inline - len(1) services.exe - 0x0070A571->_
             inline - len(1) services.exe - 0x0070A59D->_
             inline - len(6) services.exe - 0x0070A5AB->_
             inline - len(1) services.exe - 0x0070A5BE->_
             inline - len(6) services.exe - 0x0070A5C4->_
             inline - len(6) services.exe - 0x0070A5E9->_
             inline - len(1) services.exe - 0x0070A5FF->_
             inline - len(6) services.exe - 0x0070A647->_
             inline - len(1) services.exe - 0x0070A65E->_
             inline - len(1) services.exe - 0x0070A671->_
             inline - len(1) services.exe - 0x0070A677->_
             inline - len(1) services.exe - 0x0070A6E5->_
             inline - len(6) services.exe - 0x0070A783->_
             inline - len(1) services.exe - 0x0070A795->_
             inline - len(1) services.exe - 0x0070A7B0->_
             inline - len(1) services.exe - 0x0070A802->_
             inline - len(1) services.exe - 0x0070A809->_
             inline - len(1) services.exe - 0x0070A85A->_
             inline - len(1) services.exe - 0x0070A928->_
             inline - len(1) services.exe - 0x0070A92E->_
             inline - len(1) services.exe - 0x0070A942->_
             inline - len(6) services.exe - 0x0070A950->_
             inline - len(1) services.exe - 0x0070A963->_
             inline - len(6) services.exe - 0x0070A969->_
             inline - len(1) services.exe - 0x0070A999->_
             inline - len(1) services.exe - 0x0070A9AC->_
             inline - len(1) services.exe - 0x0070A9BF->_
             inline - len(6) services.exe - 0x0070A9CD->_
             inline - len(1) services.exe - 0x0070A9E8->_
             inline - len(6) services.exe - 0x0070A9EE->_
             inline - len(1) services.exe - 0x0070AA0A->_
             inline - len(1) services.exe - 0x0070AA31->_
             inline - len(1) services.exe - 0x0070AA43->_
             inline - len(6) services.exe - 0x0070AA58->_
             inline - len(1) services.exe - 0x0070AA6B->_
             inline - len(6) services.exe - 0x0070AA76->_
             inline - len(1) services.exe - 0x0070AA9B->_
             inline - len(6) services.exe - 0x0070AAA5->_
             inline - len(1) services.exe - 0x0070AAB8->_
             inline - len(1) services.exe - 0x0070AAD1->_
             inline - len(1) services.exe - 0x0070AAE7->_
             inline - len(1) services.exe - 0x0070AAFB->_
             inline - len(6) services.exe - 0x0070AB17->_
             inline - len(1) services.exe - 0x0070AB2A->_
             inline - len(1) services.exe - 0x0070AB37->_
             inline - len(1) services.exe - 0x0070AB3E->_
             inline - len(1) services.exe - 0x0070AB6F->_
             inline - len(6) services.exe - 0x0070AB94->_
             inline - len(1) services.exe - 0x0070ABA7->_
             inline - len(1) services.exe - 0x0070ABB0->_
             inline - len(1) services.exe - 0x0070ABB9->_
             inline - len(1) services.exe - 0x0070ABD0->_
             inline - len(1) services.exe - 0x0070ABDA->_
             inline - len(1) services.exe - 0x0070AC09->_
             inline - len(1) services.exe - 0x0070AC17->_
             inline - len(6) services.exe - 0x0070AC43->_
             inline - len(1) services.exe - 0x0070AC56->_
             inline - len(6) services.exe - 0x0070AC7E->_
             inline - len(1) services.exe - 0x0070AC99->_
             inline - len(1) services.exe - 0x0070ACA2->_
             inline - len(1) services.exe - 0x0070ACE9->_
             inline - len(6) services.exe - 0x0070AD0E->_
             inline - len(1) services.exe - 0x0070AD29->_
             inline - len(1) services.exe - 0x0070AD32->_
             inline - len(1) services.exe - 0x0070AD3E->_
             inline - len(1) services.exe - 0x0070AD71->_
             inline - len(1) services.exe - 0x0070AD7A->_
             inline - len(1) services.exe - 0x0070AD86->_
             inline - len(6) services.exe - 0x0070AE08->_
             inline - len(1) services.exe - 0x0070AE26->_
             inline - len(1) services.exe - 0x0070AE49->_
             inline - len(6) services.exe - 0x0070AE6A->_
             inline - len(1) services.exe - 0x0070AE8B->_
             inline - len(1) services.exe - 0x0070AEA4->_
             inline - len(1) services.exe - 0x0070AEB1->_
             inline - len(6) services.exe - 0x0070AEB8->_
             inline - len(1) services.exe - 0x0070AED9->_
             inline - len(6) services.exe - 0x0070AEFF->_
             inline - len(1) services.exe - 0x0070AF20->_
             inline - len(6) services.exe - 0x0070AF43->_
             inline - len(1) services.exe - 0x0070AF64->_
             inline - len(1) services.exe - 0x0070AF76->_
             inline - len(6) services.exe - 0x0070AF8E->_
             inline - len(1) services.exe - 0x0070AFAF->_
             inline - len(6) services.exe - 0x0070B03B->_
             inline - len(1) services.exe - 0x0070B05C->_
             inline - len(6) services.exe - 0x0070B0B2->_
             inline - len(1) services.exe - 0x0070B0C7->_
             inline - len(1) services.exe - 0x0070B0E3->_
             inline - len(1) services.exe - 0x0070B0FF->_
             inline - len(1) services.exe - 0x0070B106->_
             inline - len(1) services.exe - 0x0070B10F->_
             inline - len(1) services.exe - 0x0070B120->_
             inline - len(1) services.exe - 0x0070B126->_
             inline - len(1) services.exe - 0x0070B15C->_
             inline - len(1) services.exe - 0x0070B170->_
             inline - len(1) services.exe - 0x0070B1FB->_
             inline - len(1) services.exe - 0x0070B21F->_
             inline - len(1) services.exe - 0x0070B240->_
             inline - len(1) services.exe - 0x0070B2D7->_
             inline - len(1) services.exe - 0x0070B2EC->_
             inline - len(1) services.exe - 0x0070B2F2->_
             inline - len(1) services.exe - 0x0070B306->_
             inline - len(1) services.exe - 0x0070B31C->_
             inline - len(1) services.exe - 0x0070B34F->_
             inline - len(1) services.exe - 0x0070B3BC->_
             inline - len(1) services.exe - 0x0070B3C3->_
             inline - len(1) services.exe - 0x0070B43B->_
             inline - len(1) services.exe - 0x0070B442->_
             inline - len(1) services.exe - 0x0070B4CF->_
             inline - len(1) services.exe - 0x0070B4F1->_
             inline - len(6) services.exe - 0x0070B4FD->_
             inline - len(1) services.exe - 0x0070B51A->_
             inline - len(1) services.exe - 0x0070B539->_
             inline - len(6) services.exe - 0x0070B55A->_
             inline - len(1) services.exe - 0x0070B577->_
             inline - len(6) services.exe - 0x0070B592->_
             inline - len(1) services.exe - 0x0070B5AF->_
             inline - len(6) services.exe - 0x0070B5D2->_
             inline - len(1) services.exe - 0x0070B5ED->_
             inline - len(6) services.exe - 0x0070B614->_
             inline - len(1) services.exe - 0x0070B630->_
             inline - len(1) services.exe - 0x0070B64E->_
             inline - len(1) services.exe - 0x0070B65B->_
             inline - len(6) services.exe - 0x0070B663->_
             inline - len(1) services.exe - 0x0070B680->_
             inline - len(6) services.exe - 0x0070B68C->_
             inline - len(1) services.exe - 0x0070B69E->_
             inline - len(1) services.exe - 0x0070B6C2->_
             inline - len(6) services.exe - 0x0070B708->_
             inline - len(1) services.exe - 0x0070B728->_
             inline - len(6) services.exe - 0x0070B766->_
             inline - len(1) services.exe - 0x0070B783->_
             inline - len(6) services.exe - 0x0070B79D->_
             inline - len(1) services.exe - 0x0070B7BA->_
             inline - len(1) services.exe - 0x0070B7D0->_
             inline - len(6) services.exe - 0x0070B822->_
             inline - len(1) services.exe - 0x0070B83A->_
             inline - len(1) services.exe - 0x0070B841->_
             inline - len(1) services.exe - 0x0070B84A->_
             inline - len(6) services.exe - 0x0070B856->_
             inline - len(1) services.exe - 0x0070B869->_
             inline - len(1) services.exe - 0x0070B87B->_
             inline - len(6) services.exe - 0x0070B904->_
             inline - len(1) services.exe - 0x0070B920->_
             inline - len(1) services.exe - 0x0070B940->_
             inline - len(1) services.exe - 0x0070B94F->_
             inline - len(6) services.exe - 0x0070B957->_
             inline - len(1) services.exe - 0x0070B974->_
             inline - len(1) services.exe - 0x0070B98E->_
             inline - len(1) services.exe - 0x0070B9B4->_
             inline - len(1) services.exe - 0x0070B9C8->_
             inline - len(1) services.exe - 0x0070BA04->_
             inline - len(1) services.exe - 0x0070BA69->_
             inline - len(1) services.exe - 0x0070BA7B->_
             inline - len(1) services.exe - 0x0070BAA7->_
             inline - len(1) services.exe - 0x0070BACD->_
             inline - len(1) services.exe - 0x0070BAE9->_
             inline - len(1) services.exe - 0x0070BAFF->_
             inline - len(1) services.exe - 0x0070BB11->_
             inline - len(6) services.exe - 0x0070BB25->_
             inline - len(1) services.exe - 0x0070BB31->_
             inline - len(6) services.exe - 0x0070BB6F->_
             inline - len(1) services.exe - 0x0070BB7A->_
             inline - len(1) services.exe - 0x0070BB9D->_
             inline - len(6) services.exe - 0x0070BBB0->_
             inline - len(1) services.exe - 0x0070BBBC->_
             inline - len(1) services.exe - 0x0070BBC6->_
             inline - len(1) services.exe - 0x0070BBCE->_
             inline - len(1) services.exe - 0x0070BBE0->_
             inline - len(6) services.exe - 0x0070BBF3->_
             inline - len(1) services.exe - 0x0070BBFF->_
             inline - len(6) services.exe - 0x0070BC46->_
             inline - len(1) services.exe - 0x0070BC64->_
             inline - len(1) services.exe - 0x0070BC78->_
             inline - len(6) services.exe - 0x0070BC94->_
             inline - len(1) services.exe - 0x0070BCAA->_
             inline - len(6) services.exe - 0x0070BCC7->_
             inline - len(1) services.exe - 0x0070BCE0->_
             inline - len(1) services.exe - 0x0070BCFC->_
             inline - len(1) services.exe - 0x0070BD03->_
             inline - len(6) services.exe - 0x0070BD1A->_
             inline - len(1) services.exe - 0x0070BD2F->_
             inline - len(1) services.exe - 0x0070BD5E->_
             inline - len(1) services.exe - 0x0070BD8C->_
             inline - len(6) services.exe - 0x0070BD9B->_
             inline - len(1) services.exe - 0x0070BDAD->_
             inline - len(1) services.exe - 0x0070BDBF->_
             inline - len(1) services.exe - 0x0070BDC5->_
             inline - len(1) services.exe - 0x0070BDCF->_
             inline - len(1) services.exe - 0x0070BDD5->_
             inline - len(1) services.exe - 0x0070BDE9->_
             inline - len(1) services.exe - 0x0070BE02->_
             inline - len(1) services.exe - 0x0070BE0F->_
             inline - len(1) services.exe - 0x0070BE9B->_
             inline - len(6) services.exe - 0x0070BEA8->_
             inline - len(1) services.exe - 0x0070BEC2->_
             inline - len(1) services.exe - 0x0070BEF6->_
             inline - len(1) services.exe - 0x0070BF08->_
             inline - len(6) services.exe - 0x0070BF3E->_
             inline - len(1) services.exe - 0x0070BF60->_
             inline - len(1) services.exe - 0x0070BF73->_
             inline - len(1) services.exe - 0x0070BF93->_
             inline - len(1) services.exe - 0x0070BFAB->_
             inline - len(1) services.exe - 0x0070BFBD->_
             inline - len(6) services.exe - 0x0070BFD0->_
             inline - len(1) services.exe - 0x0070C012->_
             inline - len(1) services.exe - 0x0070C02E->_
             inline - len(1) services.exe - 0x0070C040->_
             inline - len(1) services.exe - 0x0070C055->_
             inline - len(1) services.exe - 0x0070C069->_
             inline - len(1) services.exe - 0x0070C07B->_
             inline - len(1) services.exe - 0x0070C082->_
             inline - len(1) services.exe - 0x0070C098->_
             inline - len(1) services.exe - 0x0070C0AA->_
             inline - len(1) services.exe - 0x0070C0E9->_
             inline - len(6) services.exe - 0x0070C0F8->_
             inline - len(1) services.exe - 0x0070C10B->_
             inline - len(1) services.exe - 0x0070C11D->_
             inline - len(1) services.exe - 0x0070C126->_
             inline - len(1) services.exe - 0x0070C133->_
             inline - len(1) services.exe - 0x0070C145->_
             inline - len(1) services.exe - 0x0070C157->_
             inline - len(1) services.exe - 0x0070C166->_
             inline - len(1) services.exe - 0x0070C174->_
             inline - len(1) services.exe - 0x0070C17A->_
             inline - len(1) services.exe - 0x0070C19E->_
             inline - len(1) services.exe - 0x0070C1A9->_
             inline - len(1) services.exe - 0x0070C1CA->_
             inline - len(1) services.exe - 0x0070C1D1->_
             inline - len(1) services.exe - 0x0070C203->_
             inline - len(1) services.exe - 0x0070C209->_
             inline - len(1) services.exe - 0x0070C215->_
             inline - len(1) services.exe - 0x0070C21E->_
             inline - len(1) services.exe - 0x0070C224->_
             inline - len(1) services.exe - 0x0070C235->_
             inline - len(6) services.exe - 0x0070C249->_
             inline - len(1) services.exe - 0x0070C25C->_
             inline - len(6) services.exe - 0x0070C262->_
             inline - len(1) services.exe - 0x0070C30D->_
             inline - len(1) services.exe - 0x0070C313->_
             inline - len(1) services.exe - 0x0070C326->_
             inline - len(1) services.exe - 0x0070C40E->_
             inline - len(6) services.exe - 0x0070C41B->_
             inline - len(1) services.exe - 0x0070C43B->_
             inline - len(6) services.exe - 0x0070C452->_
             inline - len(1) services.exe - 0x0070C469->_
             inline - len(1) services.exe - 0x0070C496->_
             inline - len(11) services.exe - 0x0070C49C->_
             inline - len(1) services.exe - 0x0070C4C1->_
             inline - len(6) services.exe - 0x0070C4DE->_
             inline - len(1) services.exe - 0x0070C4F5->_
             inline - len(1) services.exe - 0x0070C521->_
             inline - len(1) services.exe - 0x0070C52E->_
             inline - len(6) services.exe - 0x0070C535->_
             inline - len(1) services.exe - 0x0070C550->_
             inline - len(1) services.exe - 0x0070C5AA->_
             inline - len(11) services.exe - 0x0070C5B0->_
             inline - len(1) services.exe - 0x0070C5CC->_
             inline - len(1) services.exe - 0x0070C5FA->_
             inline - len(1) services.exe - 0x0070C60D->_
             inline - len(6) services.exe - 0x0070C621->_
             inline - len(1) services.exe - 0x0070C636->_
             inline - len(1) services.exe - 0x0070C648->_
             inline - len(1) services.exe - 0x0070C64E->_
             inline - len(1) services.exe - 0x0070C658->_
             inline - len(1) services.exe - 0x0070C67D->_
             inline - len(1) services.exe - 0x0070C683->_
             inline - len(1) services.exe - 0x0070C698->_
             inline - len(1) services.exe - 0x0070C69E->_
             inline - len(6) services.exe - 0x0070C6A8->_
             inline - len(1) services.exe - 0x0070C6CD->_
             inline - len(1) services.exe - 0x0070C6E4->_
             inline - len(1) services.exe - 0x0070C704->_
             inline - len(1) services.exe - 0x0070C748->_
             inline - len(1) services.exe - 0x0070C78B->_
             inline - len(1) services.exe - 0x0070C791->_
             inline - len(1) services.exe - 0x0070C7B6->_
             inline - len(1) services.exe - 0x0070C7BC->_
             inline - len(1) services.exe - 0x0070C80A->_
             inline - len(1) services.exe - 0x0070C810->_
             inline - len(1) services.exe - 0x0070C85F->_
             inline - len(1) services.exe - 0x0070C865->_
             inline - len(1) services.exe - 0x0070C8AC->_
             inline - len(1) services.exe - 0x0070C8B2->_
             inline - len(1) services.exe - 0x0070C8BA->_
             inline - len(1) services.exe - 0x0070C8DC->_
             inline - len(1) services.exe - 0x0070C8FB->_
             inline - len(1) services.exe - 0x0070C901->_
             inline - len(1) services.exe - 0x0070C950->_
             inline - len(1) services.exe - 0x0070C95F->_
             inline - len(1) services.exe - 0x0070C99F->_
             inline - len(1) services.exe - 0x0070C9E1->_
             inline - len(1) services.exe - 0x0070C9EC->_
             inline - len(1) services.exe - 0x0070CA11->_
             inline - len(6) services.exe - 0x0070CA35->_
             inline - len(1) services.exe - 0x0070CA4D->_
             inline - len(6) services.exe - 0x0070CA6B->_
             inline - len(1) services.exe - 0x0070CA83->_
             inline - len(1) services.exe - 0x0070CAAC->_
             inline - len(1) services.exe - 0x0070CAC6->_
             inline - len(1) services.exe - 0x0070CACD->_
             inline - len(6) services.exe - 0x0070CAD6->_
             inline - len(1) services.exe - 0x0070CAE9->_
             inline - len(6) services.exe - 0x0070CAEF->_
             inline - len(1) services.exe - 0x0070CB41->_
             inline - len(1) services.exe - 0x0070CB47->_
             inline - len(1) services.exe - 0x0070CB71->_
             inline - len(1) services.exe - 0x0070CB77->_
             inline - len(1) services.exe - 0x0070CBA1->_
             inline - len(1) services.exe - 0x0070CBA7->_
             inline - len(6) services.exe - 0x0070CC08->_
             inline - len(1) services.exe - 0x0070CC22->_
             inline - len(6) services.exe - 0x0070CC5A->_
             inline - len(1) services.exe - 0x0070CC6F->_
             inline - len(6) services.exe - 0x0070CC90->_
             inline - len(1) services.exe - 0x0070CCA7->_
             inline - len(6) services.exe - 0x0070CCBA->_
             inline - len(1) services.exe - 0x0070CCC6->_
             inline - len(6) services.exe - 0x0070CCD5->_
             inline - len(1) services.exe - 0x0070CCF5->_
             inline - len(1) services.exe - 0x0070CD08->_
             inline - len(1) services.exe - 0x0070CD0E->_
             inline - len(1) services.exe - 0x0070CD16->_
             inline - len(1) services.exe - 0x0070CD1D->_
             inline - len(1) services.exe - 0x0070CD35->_
             inline - len(1) services.exe - 0x0070CD5C->_
             inline - len(1) services.exe - 0x0070CD74->_
             inline - len(1) services.exe - 0x0070CD90->_
             inline - len(1) services.exe - 0x0070CDA5->_
             inline - len(1) services.exe - 0x0070CE00->_
             inline - len(1) services.exe - 0x0070CE10->_
             inline - len(6) services.exe - 0x0070CE25->_
             inline - len(1) services.exe - 0x0070CE37->_
             inline - len(1) services.exe - 0x0070CE5D->_
             inline - len(1) services.exe - 0x0070CE63->_
             inline - len(1) services.exe - 0x0070CE71->_
             inline - len(6) services.exe - 0x0070CEFB->_
             inline - len(1) services.exe - 0x0070CF18->_
             inline - len(6) services.exe - 0x0070CF53->_
             inline - len(1) services.exe - 0x0070CF68->_
             inline - len(6) services.exe - 0x0070CF8C->_
             inline - len(1) services.exe - 0x0070CFA3->_
             inline - len(6) services.exe - 0x0070CFB6->_
             inline - len(1) services.exe - 0x0070CFC2->_
             inline - len(1) services.exe - 0x0070CFEE->_
             inline - len(1) services.exe - 0x0070CFFB->_
             inline - len(6) services.exe - 0x0070D003->_
             inline - len(1) services.exe - 0x0070D01E->_
             inline - len(6) services.exe - 0x0070D031->_
             inline - len(1) services.exe - 0x0070D03D->_
             inline - len(1) services.exe - 0x0070D06E->_
             inline - len(1) services.exe - 0x0070D07B->_
             inline - len(6) services.exe - 0x0070D083->_
             inline - len(1) services.exe - 0x0070D09E->_
             inline - len(1) services.exe - 0x0070D0B5->_
             inline - len(11) services.exe - 0x0070D0CC->_
             inline - len(6) services.exe - 0x0070D100->_
             inline - len(1) services.exe - 0x0070D10C->_
             inline - len(1) services.exe - 0x0070D153->_
             inline - len(1) services.exe - 0x0070D1B8->_
             inline - len(1) services.exe - 0x0070D1C2->_
             inline - len(1) services.exe - 0x0070D1E6->_
             inline - len(1) services.exe - 0x0070D1F3->_
             inline - len(1) services.exe - 0x0070D226->_
             inline - len(1) services.exe - 0x0070D230->_
             inline - len(1) services.exe - 0x0070D238->_
             inline - len(1) services.exe - 0x0070D2A3->_
             inline - len(1) services.exe - 0x0070D2AD->_
             inline - len(1) services.exe - 0x0070D2B5->_
             inline - len(1) services.exe - 0x0070D2D6->_
             inline - len(6) services.exe - 0x0070D2DE->_
             inline - len(1) services.exe - 0x0070D303->_
             inline - len(1) services.exe - 0x0070D31A->_
             inline - len(1) services.exe - 0x0070D32A->_
             inline - len(1) services.exe - 0x0070D33E->_
             inline - len(1) services.exe - 0x0070D366->_
             inline - len(1) services.exe - 0x0070D36C->_
             inline - len(1) services.exe - 0x0070D386->_
             inline - len(1) services.exe - 0x0070D38C->_
             inline - len(1) services.exe - 0x0070D3D3->_
             inline - len(1) services.exe - 0x0070D3D9->_
             inline - len(1) services.exe - 0x0070D3FA->_
             inline - len(1) services.exe - 0x0070D440->_
             inline - len(1) services.exe - 0x0070D44E->_
             inline - len(1) services.exe - 0x0070D456->_
             inline - len(1) services.exe - 0x0070D4AB->_
             inline - len(1) services.exe - 0x0070D4DA->_
             inline - len(1) services.exe - 0x0070D51B->_
             inline - len(1) services.exe - 0x0070D521->_
             inline - len(1) services.exe - 0x0070D532->_
             inline - len(1) services.exe - 0x0070D566->_
             inline - len(1) services.exe - 0x0070D592->_
             inline - len(1) services.exe - 0x0070D5D6->_
             inline - len(1) services.exe - 0x0070D5DC->_
             inline - len(1) services.exe - 0x0070D5F0->_
             inline - len(1) services.exe - 0x0070D61A->_
             inline - len(1) services.exe - 0x0070D66E->_
             inline - len(1) services.exe - 0x0070D674->_
             inline - len(1) services.exe - 0x0070D682->_
             inline - len(1) services.exe - 0x0070D6AB->_
             inline - len(1) services.exe - 0x0070D6B1->_
             inline - len(1) services.exe - 0x0070D6D5->_
             inline - len(1) services.exe - 0x0070D6E2->_
             inline - len(1) services.exe - 0x0070D6EF->_
             inline - len(1) services.exe - 0x0070D712->_
             inline - len(1) services.exe - 0x0070D756->_
             inline - len(1) services.exe - 0x0070D764->_
             inline - len(1) services.exe - 0x0070D77D->_
             inline - len(1) services.exe - 0x0070D786->_
             inline - len(1) services.exe - 0x0070D79D->_
             inline - len(1) services.exe - 0x0070D7A4->_
             inline - len(6) services.exe - 0x0070D7AD->_
             inline - len(6) services.exe - 0x0070D7C2->_
             inline - len(1) services.exe - 0x0070D7D9->_
             inline - len(6) services.exe - 0x0070D7E6->_
             inline - len(1) services.exe - 0x0070D7FF->_
             inline - len(1) services.exe - 0x0070D85D->_
             inline - len(6) services.exe - 0x0070D870->_
             inline - len(1) services.exe - 0x0070D882->_
             inline - len(1) services.exe - 0x0070D8B3->_
             inline - len(6) services.exe - 0x0070D8E2->_
             inline - len(6) services.exe - 0x0070D8F7->_
             inline - len(1) services.exe - 0x0070D918->_
             inline - len(1) services.exe - 0x0070D93A->_
             inline - len(6) services.exe - 0x0070D944->_
             inline - len(1) services.exe - 0x0070D959->_
             inline - len(1) services.exe - 0x0070D983->_
             inline - len(1) services.exe - 0x0070D9AA->_
             inline - len(1) services.exe - 0x0070D9B9->_
             inline - len(1) services.exe - 0x0070D9D2->_
             inline - len(1) services.exe - 0x0070D9F8->_
             inline - len(1) services.exe - 0x0070DA08->_
             inline - len(1) services.exe - 0x0070DA30->_
             inline - len(6) services.exe - 0x0070DA6D->_
             inline - len(1) services.exe - 0x0070DA7F->_
             inline - len(1) services.exe - 0x0070DA95->_
             inline - len(1) services.exe - 0x0070DAB1->_
             inline - len(1) services.exe - 0x0070DAB7->_
             inline - len(1) services.exe - 0x0070DAC5->_
             inline - len(1) services.exe - 0x0070DAFD->_
             inline - len(6) services.exe - 0x0070DB12->_
             inline - len(1) services.exe - 0x0070DB24->_
             inline - len(1) services.exe - 0x0070DB4E->_
             inline - len(1) services.exe - 0x0070DB54->_
             inline - len(1) services.exe - 0x0070DB62->_
             inline - len(6) services.exe - 0x0070DB9E->_
             inline - len(1) services.exe - 0x0070DBB0->_
             inline - len(1) services.exe - 0x0070DBD5->_
             inline - len(1) services.exe - 0x0070DBDB->_
             inline - len(1) services.exe - 0x0070DBE9->_
             inline - len(1) services.exe - 0x0070DC11->_
             inline - len(1) services.exe - 0x0070DC18->_
             inline - len(1) services.exe - 0x0070DC4B->_
             inline - len(11) services.exe - 0x0070DC5E->_
             inline - len(1) services.exe - 0x0070DC97->_
             inline - len(1) services.exe - 0x0070DCA1->_
             inline - len(1) services.exe - 0x0070DCCD->_
             inline - len(1) services.exe - 0x0070DCE8->_
             inline - len(1) services.exe - 0x0070DCEF->_
             inline - len(1) services.exe - 0x0070DCF5->_
             inline - len(1) services.exe - 0x0070DD24->_
             inline - len(1) services.exe - 0x0070DD36->_
             inline - len(1) services.exe - 0x0070DD75->_
             inline - len(1) services.exe - 0x0070DD8F->_
             inline - len(1) services.exe - 0x0070DDC3->_
             inline - len(1) services.exe - 0x0070DDF4->_
             inline - len(6) services.exe - 0x0070DE08->_
             inline - len(1) services.exe - 0x0070DE1C->_
             inline - len(1) services.exe - 0x0070DE30->_
             inline - len(1) services.exe - 0x0070DE3E->_
             inline - len(1) services.exe - 0x0070DE4B->_
             inline - len(1) services.exe - 0x0070DE56->_
             inline - len(1) services.exe - 0x0070DE5F->_
             inline - len(1) services.exe - 0x0070DE6E->_
             inline - len(1) services.exe - 0x0070DE77->_
             inline - len(1) services.exe - 0x0070DE7D->_
             inline - len(1) services.exe - 0x0070DE86->_
             inline - len(6) services.exe - 0x0070DE9C->_
             inline - len(1) services.exe - 0x0070DEB2->_
             inline - len(6) services.exe - 0x0070DED2->_
             inline - len(1) services.exe - 0x0070DEEC->_
             inline - len(1) services.exe - 0x0070DF35->_
             inline - len(1) services.exe - 0x0070DF4A->_
             inline - len(1) services.exe - 0x0070DF6E->_
             inline - len(1) services.exe - 0x0070DF7C->_
             inline - len(1) services.exe - 0x0070DFA0->_
             inline - len(1) services.exe - 0x0070E051->_
             inline - len(1) services.exe - 0x0070E05A->_
             inline - len(1) services.exe - 0x0070E060->_
             inline - len(6) services.exe - 0x0070E08E->_
             inline - len(1) services.exe - 0x0070E0A3->_
             inline - len(1) services.exe - 0x0070E0E3->_
             inline - len(6) services.exe - 0x0070E0F9->_
             inline - len(1) services.exe - 0x0070E116->_
             inline - len(6) services.exe - 0x0070E12F->_
             inline - len(1) services.exe - 0x0070E147->_
             inline - len(1) services.exe - 0x0070E173->_
             inline - len(1) services.exe - 0x0070E179->_
             inline - len(1) services.exe - 0x0070E192->_
             inline - len(1) services.exe - 0x0070E1AA->_
             inline - len(1) services.exe - 0x0070E1BB->_
             inline - len(1) services.exe - 0x0070E1C6->_
             inline - len(6) services.exe - 0x0070E1D4->_
             inline - len(1) services.exe - 0x0070E1F4->_
             inline - len(1) services.exe - 0x0070E203->_
             inline - len(6) services.exe - 0x0070E221->_
             inline - len(1) services.exe - 0x0070E241->_
             inline - len(1) services.exe - 0x0070E256->_
             inline - len(1) services.exe - 0x0070E26D->_
             inline - len(1) services.exe - 0x0070E27A->_
             inline - len(1) services.exe - 0x0070E28F->_
             inline - len(1) services.exe - 0x0070E2A4->_
             inline - len(1) services.exe - 0x0070E2AA->_
             inline - len(1) services.exe - 0x0070E2C1->_
             inline - len(1) services.exe - 0x0070E2D9->_
             inline - len(1) services.exe - 0x0070E505->_
             inline - len(6) services.exe - 0x0070E555->_
             inline - len(1) services.exe - 0x0070E56E->_
             inline - len(1) services.exe - 0x0070E580->_
             inline - len(6) services.exe - 0x0070E5AA->_
             inline - len(1) services.exe - 0x0070E5C2->_
             inline - len(1) services.exe - 0x0070E5F4->_
             inline - len(1) services.exe - 0x0070E5FA->_
             inline - len(6) services.exe - 0x0070E60C->_
             inline - len(1) services.exe - 0x0070E622->_
             inline - len(1) services.exe - 0x0070E6B0->_
             inline - len(1) services.exe - 0x0070E6C3->_
             inline - len(1) services.exe - 0x0070E6DF->_
             inline - len(1) services.exe - 0x0070E6FE->_
             inline - len(1) services.exe - 0x0070E70F->_
             inline - len(1) services.exe - 0x0070E71D->_
             inline - len(6) services.exe - 0x0070E735->_
             inline - len(1) services.exe - 0x0070E748->_
             inline - len(1) services.exe - 0x0070E75C->_
             inline - len(6) services.exe - 0x0070E763->_
             inline - len(1) services.exe - 0x0070E778->_
             inline - len(1) services.exe - 0x0070E79E->_
             inline - len(1) services.exe - 0x0070E7A6->_
             inline - len(1) services.exe - 0x0070E7B6->_
             inline - len(1) services.exe - 0x0070E81A->_
             inline - len(6) services.exe - 0x0070E880->_
             inline - len(1) services.exe - 0x0070E892->_
             inline - len(1) services.exe - 0x0070E8BA->_
             inline - len(1) services.exe - 0x0070E8C0->_
             inline - len(1) services.exe - 0x0070E8E0->_
             inline - len(1) services.exe - 0x0070E8EA->_
             inline - len(1) services.exe - 0x0070E90A->_
             inline - len(1) services.exe - 0x0070E91D->_
             inline - len(1) services.exe - 0x0070E94A->_
             inline - len(1) services.exe - 0x0070E995->_
             inline - len(6) services.exe - 0x0070E9A3->_
             inline - len(1) services.exe - 0x0070E9B6->_
             inline - len(6) services.exe - 0x0070E9BC->_
             inline - len(1) services.exe - 0x0070E9DB->_
             inline - len(6) services.exe - 0x0070EA1E->_
             inline - len(1) services.exe - 0x0070EA31->_
             inline - len(1) services.exe - 0x0070EA45->_
             inline - len(6) services.exe - 0x0070EA6B->_
             inline - len(1) services.exe - 0x0070EA7E->_
             inline - len(1) services.exe - 0x0070EA92->_
             inline - len(1) services.exe - 0x0070EAD3->_
             inline - len(1) services.exe - 0x0070EAD9->_
             inline - len(1) services.exe - 0x0070EAEF->_
             inline - len(6) services.exe - 0x0070EB0B->_
             inline - len(1) services.exe - 0x0070EB25->_
             inline - len(1) services.exe - 0x0070EB52->_
             inline - len(6) services.exe - 0x0070EB60->_
             inline - len(1) services.exe - 0x0070EB73->_
             inline - len(6) services.exe - 0x0070EB79->_
             inline - len(1) services.exe - 0x0070EB9D->_
             inline - len(1) services.exe - 0x0070EBA7->_
             inline - len(6) services.exe - 0x0070EBAF->_
             inline - len(1) services.exe - 0x0070EBC4->_
             inline - len(1) services.exe - 0x0070EBED->_
             inline - len(1) services.exe - 0x0070EC07->_
             inline - len(1) services.exe - 0x0070EC0E->_
             inline - len(1) services.exe - 0x0070EC2B->_
             inline - len(1) services.exe - 0x0070EC37->_
             inline - len(6) services.exe - 0x0070EC9F->_
             inline - len(1) services.exe - 0x0070ECB1->_
             inline - len(6) services.exe - 0x0070ECBC->_
             inline - len(1) services.exe - 0x0070ECD0->_
             inline - len(1) services.exe - 0x0070ED63->_
             inline - len(1) services.exe - 0x0070ED81->_
             inline - len(1) services.exe - 0x0070ED94->_
             inline - len(1) services.exe - 0x0070EDC0->_
             inline - len(1) services.exe - 0x0070EDEE->_
             inline - len(1) services.exe - 0x0070EE03->_
             inline - len(1) services.exe - 0x0070EE09->_
             inline - len(1) services.exe - 0x0070EE2C->_
             inline - len(1) services.exe - 0x0070EE32->_
             inline - len(1) services.exe - 0x0070EE98->_
             inline - len(1) services.exe - 0x0070EEA8->_
             inline - len(1) services.exe - 0x0070EEE8->_
             inline - len(1) services.exe - 0x0070EF0C->_
             inline - len(1) services.exe - 0x0070EF2A->_
             inline - len(1) services.exe - 0x0070EF3A->_
             inline - len(1) services.exe - 0x0070EF66->_
             inline - len(6) services.exe - 0x0070EF76->_
             inline - len(1) services.exe - 0x0070EF89->_
             inline - len(1) services.exe - 0x0070EFB5->_
             inline - len(6) services.exe - 0x0070EFD0->_
             inline - len(1) services.exe - 0x0070EFE5->_
             inline - len(1) services.exe - 0x0070F046->_
             inline - len(1) services.exe - 0x0070F055->_
             inline - len(1) services.exe - 0x0070F095->_
             inline - len(1) services.exe - 0x0070F12C->_
             inline - len(1) services.exe - 0x0070F13A->_
             inline - len(1) services.exe - 0x0070F175->_
             inline - len(1) services.exe - 0x0070F180->_
             inline - len(1) services.exe - 0x0070F1BC->_
             inline - len(1) services.exe - 0x0070F1C7->_
             inline - len(1) services.exe - 0x0070F241->_
             inline - len(1) services.exe - 0x0070F250->_
             inline - len(1) services.exe - 0x0070F290->_
             inline - len(6) services.exe - 0x0070F2DE->_
             inline - len(1) services.exe - 0x0070F2F0->_
             inline - len(6) services.exe - 0x0070F304->_
             inline - len(1) services.exe - 0x0070F31C->_
             inline - len(6) services.exe - 0x0070F44A->_
             inline - len(1) services.exe - 0x0070F45C->_
             inline - len(6) services.exe - 0x0070F465->_
             inline - len(1) services.exe - 0x0070F477->_
             inline - len(6) services.exe - 0x0070F4CF->_
             inline - len(1) services.exe - 0x0070F4E9->_
             inline - len(6) services.exe - 0x0070F50A->_
             inline - len(1) services.exe - 0x0070F51C->_
             inline - len(6) services.exe - 0x0070F53A->_
             inline - len(1) services.exe - 0x0070F54C->_
             inline - len(6) services.exe - 0x0070F56A->_
             inline - len(1) services.exe - 0x0070F57C->_
             inline - len(1) services.exe - 0x0070F5C5->_
             inline - len(1) services.exe - 0x0070F608->_
             inline - len(6) services.exe - 0x0070F63B->_
             inline - len(1) services.exe - 0x0070F655->_
             inline - len(6) services.exe - 0x0070F69C->_
             inline - len(1) services.exe - 0x0070F6AE->_
             inline - len(6) services.exe - 0x0070F6CF->_
             inline - len(1) services.exe - 0x0070F6E1->_
             inline - len(1) services.exe - 0x0070F73B->_
             inline - len(1) services.exe - 0x0070F74D->_
             inline - len(33) services.exe - 0x0070F75A->_
             inline - len(6) services.exe - 0x0070F7B4->_
             inline - len(1) services.exe - 0x0070F7CE->_
             inline - len(6) services.exe - 0x0070F7EF->_
             inline - len(1) services.exe - 0x0070F809->_
             inline - len(6) services.exe - 0x0070F82A->_
             inline - len(1) services.exe - 0x0070F83C->_
             inline - len(6) services.exe - 0x0070F85A->_
             inline - len(1) services.exe - 0x0070F86C->_
             inline - len(6) services.exe - 0x0070F88A->_
             inline - len(1) services.exe - 0x0070F89C->_
             inline - len(1) services.exe - 0x0070F8EE->_
             inline - len(6) services.exe - 0x0070F9B7->_
             inline - len(1) services.exe - 0x0070F9C9->_
             inline - len(6) services.exe - 0x0070F9D2->_
             inline - len(1) services.exe - 0x0070F9E4->_
             inline - len(6) services.exe - 0x0070FABD->_
             inline - len(1) services.exe - 0x0070FAD7->_
             inline - len(6) services.exe - 0x0070FB10->_
             inline - len(1) services.exe - 0x0070FB2A->_
             inline - len(6) services.exe - 0x0070FB67->_
             inline - len(1) services.exe - 0x0070FB79->_
             inline - len(6) services.exe - 0x0070FBAE->_
             inline - len(1) services.exe - 0x0070FBC0->_
             inline - len(6) services.exe - 0x0070FC32->_
             inline - len(1) services.exe - 0x0070FC44->_
             inline - len(6) services.exe - 0x0070FC96->_
             inline - len(1) services.exe - 0x0070FCB0->_
             inline - len(6) services.exe - 0x0070FCD1->_
             inline - len(1) services.exe - 0x0070FCEB->_
             inline - len(6) services.exe - 0x0070FD0C->_
             inline - len(1) services.exe - 0x0070FD1E->_
             inline - len(6) services.exe - 0x0070FD3C->_
             inline - len(1) services.exe - 0x0070FD4E->_
             inline - len(6) services.exe - 0x0070FD6C->_
             inline - len(1) services.exe - 0x0070FD7E->_
             inline - len(1) services.exe - 0x0070FDD0->_
             inline - len(6) services.exe - 0x0070FE30->_
             inline - len(1) services.exe - 0x0070FE4B->_
             inline - len(6) services.exe - 0x0070FE74->_
             inline - len(1) services.exe - 0x0070FE86->_
             inline - len(1) services.exe - 0x0070FED2->_
             inline - len(6) services.exe - 0x0070FF74->_
             inline - len(1) services.exe - 0x0070FF86->_
             inline - len(1) services.exe - 0x0070FFB2->_
             inline - len(1) services.exe - 0x0070FFBE->_
             inline - len(6) services.exe - 0x00710005->_
             inline - len(1) services.exe - 0x00710017->_
             inline - len(1) services.exe - 0x00710060->_
             inline - len(6) services.exe - 0x007100A3->_
             inline - len(1) services.exe - 0x007100B5->_
             inline - len(1) services.exe - 0x007100E1->_
             inline - len(1) services.exe - 0x007100ED->_
             inline - len(6) services.exe - 0x00710134->_
             inline - len(1) services.exe - 0x00710146->_
             inline - len(1) services.exe - 0x0071018F->_
             inline - len(1) services.exe - 0x00710203->_
             inline - len(1) services.exe - 0x00710211->_
             inline - len(1) services.exe - 0x0071024C->_
             inline - len(1) services.exe - 0x00710257->_
             inline - len(1) services.exe - 0x00710293->_
             inline - len(1) services.exe - 0x0071029E->_
             inline - len(1) services.exe - 0x0071031E->_
             inline - len(1) services.exe - 0x0071032D->_
             inline - len(1) services.exe - 0x0071036D->_
             inline - len(1) services.exe - 0x007103F1->_
             inline - len(1) services.exe - 0x00710400->_
             inline - len(1) services.exe - 0x00710440->_
             inline - len(1) services.exe - 0x0071049D->_
             inline - len(1) services.exe - 0x007104D5->_
             inline - len(1) services.exe - 0x007104E2->_
             inline - len(1) services.exe - 0x007104E9->_
             inline - len(1) services.exe - 0x00710506->_
             inline - len(6) services.exe - 0x00710527->_
             inline - len(1) services.exe - 0x0071053A->_
             inline - len(1) services.exe - 0x0071054E->_
             inline - len(1) services.exe - 0x0071055F->_
             inline - len(1) services.exe - 0x00710569->_
             inline - len(6) services.exe - 0x00710570->_
             inline - len(1) services.exe - 0x00710583->_
             inline - len(1) services.exe - 0x00710599->_
             inline - len(1) services.exe - 0x007105A7->_
             inline - len(1) services.exe - 0x007105B1->_
             inline - len(1) services.exe - 0x007105BB->_
             inline - len(6) services.exe - 0x007105C2->_
             inline - len(1) services.exe - 0x007105D5->_
             inline - len(11) services.exe - 0x007105E8->_
             inline - len(1) services.exe - 0x007105FC->_
             inline - len(1) services.exe - 0x0071061E->_
             inline - len(1) services.exe - 0x00710637->_
             inline - len(1) services.exe - 0x0071065C->_
             inline - len(1) services.exe - 0x00710676->_
             inline - len(1) services.exe - 0x0071069A->_
             inline - len(1) services.exe - 0x007106AD->_
             inline - len(1) services.exe - 0x007106BA->_
             inline - len(1) services.exe - 0x007106C1->_
             inline - len(1) services.exe - 0x007106FE->_
             inline - len(1) services.exe - 0x0071072E->_
             inline - len(1) services.exe - 0x00710738->_
             inline - len(1) services.exe - 0x0071073F->_
             inline - len(1) services.exe - 0x00710760->_
             inline - len(1) services.exe - 0x00710766->_
             inline - len(1) services.exe - 0x00710774->_
             inline - len(1) services.exe - 0x00710781->_
             inline - len(1) services.exe - 0x00710788->_
             inline - len(1) services.exe - 0x007107BB->_
             inline - len(1) services.exe - 0x007107C7->_
             inline - len(1) services.exe - 0x007107CE->_
             inline - len(1) services.exe - 0x007107D8->_
             inline - len(1) services.exe - 0x007107DF->_
             inline - len(1) services.exe - 0x0071080C->_
             inline - len(1) services.exe - 0x00710819->_
             inline - len(1) services.exe - 0x00710820->_
             inline - len(1) services.exe - 0x00710845->_
             inline - len(1) services.exe - 0x0071084F->_
             inline - len(1) services.exe - 0x00710856->_
             inline - len(1) services.exe - 0x0071088C->_
             inline - len(1) services.exe - 0x00710896->_
             inline - len(1) services.exe - 0x0071089D->_
             inline - len(1) services.exe - 0x007108C4->_
             inline - len(1) services.exe - 0x007108CE->_
             inline - len(1) services.exe - 0x007108D5->_
             inline - len(1) services.exe - 0x007108FE->_
             inline - len(1) services.exe - 0x00710908->_
             inline - len(1) services.exe - 0x0071090F->_
             inline - len(1) services.exe - 0x00710932->_
             inline - len(1) services.exe - 0x0071093D->_
             inline - len(1) services.exe - 0x0071095E->_
             inline - len(1) services.exe - 0x00710978->_
             inline - len(1) services.exe - 0x007109A5->_
             inline - len(1) services.exe - 0x007109BA->_
             inline - len(1) services.exe - 0x007109E1->_
             inline - len(1) services.exe - 0x007109F8->_
             inline - len(1) services.exe - 0x007109FE->_
             inline - len(1) services.exe - 0x00710A0C->_
             inline - len(1) services.exe - 0x00710A1E->_
             inline - len(1) services.exe - 0x00710A35->_
             inline - len(1) services.exe - 0x00710A3B->_
             inline - len(1) services.exe - 0x00710A49->_
             inline - len(1) services.exe - 0x00710A6D->_
             inline - len(6) services.exe - 0x00710A79->_
             inline - len(1) services.exe - 0x00710A8C->_
             inline - len(6) services.exe - 0x00710A92->_
             inline - len(1) services.exe - 0x00710B2B->_
             inline - len(6) services.exe - 0x00710B43->_
             inline - len(1) services.exe - 0x00710B5E->_
             inline - len(1) services.exe - 0x00710B75->_
             inline - len(1) services.exe - 0x00710B8D->_
             inline - len(6) services.exe - 0x00710BA5->_
             inline - len(1) services.exe - 0x00710BB8->_
             inline - len(1) services.exe - 0x00710BDC->_
             inline - len(1) services.exe - 0x00710BEF->_
             inline - len(6) services.exe - 0x00710BF9->_
             inline - len(1) services.exe - 0x00710C0D->_
             inline - len(6) services.exe - 0x00710C66->_
             inline - len(1) services.exe - 0x00710C79->_
             inline - len(1) services.exe - 0x00710C9C->_
             inline - len(6) services.exe - 0x00710CAF->_
             inline - len(1) services.exe - 0x00710CC2->_
             inline - len(1) services.exe - 0x00710CD8->_
             inline - len(1) services.exe - 0x00710CDF->_
             inline - len(6) services.exe - 0x00710CFB->_
             inline - len(1) services.exe - 0x00710D12->_
             inline - len(1) services.exe - 0x00710D3A->_
             inline - len(1) services.exe - 0x00710D48->_
             inline - len(1) services.exe - 0x00710D4E->_
             inline - len(1) services.exe - 0x00710D5C->_
             inline - len(1) services.exe - 0x00710D9B->_
             inline - len(6) services.exe - 0x00710DB5->_
             inline - len(1) services.exe - 0x00710DD3->_
             inline - len(6) services.exe - 0x00710DFC->_
             inline - len(1) services.exe - 0x00710E19->_
             inline - len(6) services.exe - 0x00710E38->_
             inline - len(1) services.exe - 0x00710E55->_
             inline - len(1) services.exe - 0x00710E68->_
             inline - len(1) services.exe - 0x00710E70->_
             inline - len(1) services.exe - 0x00710E99->_
             inline - len(1) services.exe - 0x00710EAE->_
             inline - len(1) services.exe - 0x00710EC4->_
             inline - len(1) services.exe - 0x00710EF7->_
             inline - len(1) services.exe - 0x00710F0D->_
             inline - len(1) services.exe - 0x00710F15->_
             inline - len(1) services.exe - 0x00710F32->_
             inline - len(1) services.exe - 0x00710F51->_
             inline - len(1) services.exe - 0x00710F65->_
             inline - len(1) services.exe - 0x00710F77->_
             inline - len(1) services.exe - 0x00710F9A->_
             inline - len(1) services.exe - 0x00710FAC->_
             inline - len(1) services.exe - 0x00710FD8->_
             inline - len(1) services.exe - 0x00710FF8->_
             inline - len(6) services.exe - 0x0071100B->_
             inline - len(1) services.exe - 0x00711026->_
             inline - len(6) services.exe - 0x00711041->_
             inline - len(1) services.exe - 0x00711054->_
             inline - len(6) services.exe - 0x0071107A->_
             inline - len(1) services.exe - 0x00711092->_
             inline - len(6) services.exe - 0x007110DB->_
             inline - len(1) services.exe - 0x007110F6->_
             inline - len(6) services.exe - 0x00711186->_
             inline - len(1) services.exe - 0x007111A1->_
             inline - len(1) services.exe - 0x007111CA->_
             inline - len(6) services.exe - 0x00711211->_
             inline - len(1) services.exe - 0x0071121D->_
             inline - len(6) services.exe - 0x00711245->_
             inline - len(1) services.exe - 0x0071125F->_
             inline - len(6) services.exe - 0x00711287->_
             inline - len(1) services.exe - 0x0071129D->_
             inline - len(6) services.exe - 0x007112B3->_
             inline - len(1) services.exe - 0x007112BF->_
             inline - len(6) services.exe - 0x007112D0->_
             inline - len(1) services.exe - 0x007112ED->_
             inline - len(6) services.exe - 0x00711303->_
             inline - len(1) services.exe - 0x0071130F->_
             inline - len(6) services.exe - 0x007113F9->_
             inline - len(1) services.exe - 0x00711410->_
             inline - len(6) services.exe - 0x00711422->_
             inline - len(1) services.exe - 0x00711435->_
             inline - len(6) services.exe - 0x0071145E->_
             inline - len(1) services.exe - 0x00711474->_
             inline - len(6) services.exe - 0x0071148A->_
             inline - len(1) services.exe - 0x00711496->_
             inline - len(1) services.exe - 0x0071158F->_
             inline - len(1) services.exe - 0x007115D9->_
             inline - len(1) services.exe - 0x00711605->_
             inline - len(1) services.exe - 0x00711611->_
             inline - len(6) services.exe - 0x00711619->_
             inline - len(1) services.exe - 0x00711657->_
             inline - len(1) services.exe - 0x00711681->_
             inline - len(1) services.exe - 0x00711694->_
             inline - len(1) services.exe - 0x007116B6->_
             inline - len(1) services.exe - 0x007116D4->_
             inline - len(6) services.exe - 0x00711732->_
             inline - len(1) services.exe - 0x00711746->_
             inline - len(1) services.exe - 0x0071175C->_
             inline - len(1) services.exe - 0x00711763->_
             inline - len(1) services.exe - 0x0071176C->_
             inline - len(6) services.exe - 0x00711791->_
             inline - len(1) services.exe - 0x007117B0->_
             inline - len(6) services.exe - 0x007117CA->_
             inline - len(1) services.exe - 0x007117DF->_
             inline - len(6) services.exe - 0x00711809->_
             inline - len(1) services.exe - 0x00711815->_
             inline - len(6) services.exe - 0x0071184E->_
             inline - len(1) services.exe - 0x0071186E->_
             inline - len(6) services.exe - 0x007118A6->_
             inline - len(1) services.exe - 0x007118BE->_
             inline - len(6) services.exe - 0x007118D5->_
             inline - len(1) services.exe - 0x007118E1->_
             inline - len(1) services.exe - 0x007118EF->_
             inline - len(6) services.exe - 0x007119A0->_
             inline - len(1) services.exe - 0x007119AB->_
             inline - len(1) services.exe - 0x007119E3->_
             inline - len(1) services.exe - 0x00711A10->_
             inline - len(1) services.exe - 0x00711A16->_
             inline - len(1) services.exe - 0x00711A1F->_
             inline - len(1) services.exe - 0x00711A2D->_
             inline - len(1) services.exe - 0x00711A45->_
             inline - len(1) services.exe - 0x00711A9C->_
             inline - len(1) services.exe - 0x00711AA3->_
             inline - len(1) services.exe - 0x00711AAA->_
             inline - len(6) services.exe - 0x00711ADF->_
             inline - len(1) services.exe - 0x00711AF3->_
             inline - len(6) services.exe - 0x00711B1D->_
             inline - len(1) services.exe - 0x00711B31->_
             inline - len(1) services.exe - 0x00711B5D->_
             inline - len(1) services.exe - 0x00711B64->_
             inline - len(1) services.exe - 0x00711B81->_
             inline - len(1) services.exe - 0x00711BAC->_
             inline - len(1) services.exe - 0x00711BC5->_
             inline - len(1) services.exe - 0x00711BCB->_
             inline - len(1) services.exe - 0x00711BE1->_
             inline - len(1) services.exe - 0x00711C18->_
             inline - len(1) services.exe - 0x00711C3E->_
             inline - len(1) services.exe - 0x00711C4A->_
             inline - len(1) services.exe - 0x00711C63->_
             inline - len(1) services.exe - 0x00711C80->_
             inline - len(1) services.exe - 0x00711C86->_
             inline - len(1) services.exe - 0x00711C94->_
             inline - len(1) services.exe - 0x00711CCF->_
             inline - len(1) services.exe - 0x00711CD6->_
             inline - len(1) services.exe - 0x00711CF3->_
             inline - len(6) services.exe - 0x00711D20->_
             inline - len(1) services.exe - 0x00711D2F->_
             inline - len(1) services.exe - 0x00711D52->_
             inline - len(1) services.exe - 0x00711D67->_
             inline - len(1) services.exe - 0x00711D6D->_
             inline - len(1) services.exe - 0x00711D74->_
             inline - len(1) services.exe - 0x00711D9A->_
             inline - len(1) services.exe - 0x00711DB8->_
             inline - len(1) services.exe - 0x00711DCB->_
             inline - len(1) services.exe - 0x00711DF7->_
             inline - len(1) services.exe - 0x00711E4D->_
             inline - len(1) services.exe - 0x00711E82->_
             inline - len(6) services.exe - 0x00711E94->_
             inline - len(1) services.exe - 0x00711EA1->_
             inline - len(6) services.exe - 0x00711EB2->_
             inline - len(1) services.exe - 0x00711EC4->_
             inline - len(1) services.exe - 0x00711EF0->_
             inline - len(1) services.exe - 0x00711F32->_
             inline - len(1) services.exe - 0x00711F50->_
             inline - len(1) services.exe - 0x00711F60->_
             inline - len(1) services.exe - 0x00711F8C->_
             inline - len(1) services.exe - 0x00711FC1->_
             inline - len(1) services.exe - 0x0071201A->_
             inline - len(1) services.exe - 0x00712052->_
             inline - len(1) services.exe - 0x00712072->_
             inline - len(1) services.exe - 0x0071207A->_
             inline - len(6) services.exe - 0x00712085->_
             inline - len(1) services.exe - 0x00712098->_
             inline - len(1) services.exe - 0x007120AB->_
             inline - len(6) services.exe - 0x007120C2->_
             inline - len(1) services.exe - 0x007120D5->_
             inline - len(1) services.exe - 0x007120E9->_
             inline - len(1) services.exe - 0x0071210A->_
             inline - len(1) services.exe - 0x00712118->_
             inline - len(1) services.exe - 0x00712127->_
             inline - len(1) services.exe - 0x00712134->_
             inline - len(6) services.exe - 0x0071213B->_
             inline - len(1) services.exe - 0x00712156->_
             inline - len(1) services.exe - 0x00712174->_
             inline - len(6) services.exe - 0x0071217E->_
             inline - len(1) services.exe - 0x00712194->_
             inline - len(1) services.exe - 0x0071219A->_
             inline - len(6) services.exe - 0x007121AA->_
             inline - len(1) services.exe - 0x007121C5->_
             inline - len(1) services.exe - 0x00712218->_
             inline - len(6) services.exe - 0x0071222C->_
             inline - len(1) services.exe - 0x0071223F->_
             inline - len(1) services.exe - 0x00712255->_
             inline - len(1) services.exe - 0x00712261->_
             inline - len(1) services.exe - 0x00712278->_
             inline - len(1) services.exe - 0x00712285->_
             inline - len(1) services.exe - 0x00712298->_
             inline - len(1) services.exe - 0x007122A1->_
             inline - len(1) services.exe - 0x007122A7->_
             inline - len(1) services.exe - 0x007122B6->_
             inline - len(1) services.exe - 0x007122BF->_
             inline - len(1) services.exe - 0x007122D6->_
             inline - len(1) services.exe - 0x007122DC->_
             inline - len(1) services.exe - 0x007122E4->_
             inline - len(1) services.exe - 0x007122EA->_
             inline - len(6) services.exe - 0x0071236F->_
             inline - len(1) services.exe - 0x00712382->_
             inline - len(1) services.exe - 0x007123CC->_
             inline - len(6) services.exe - 0x007123D9->_
             inline - len(1) services.exe - 0x007123F7->_
             inline - len(6) services.exe - 0x0071241C->_
             inline - len(1) services.exe - 0x00712432->_
             inline - len(6) services.exe - 0x00712446->_
             inline - len(1) services.exe - 0x00712460->_
             inline - len(1) services.exe - 0x00712487->_
             inline - len(1) services.exe - 0x007124BC->_
             inline - len(6) services.exe - 0x007124D6->_
             inline - len(1) services.exe - 0x007124E9->_
             inline - len(6) services.exe - 0x007124EF->_
             inline - len(1) services.exe - 0x00712520->_
             inline - len(6) services.exe - 0x0071252E->_
             inline - len(1) services.exe - 0x00712540->_
             inline - len(1) services.exe - 0x00712563->_
             inline - len(1) services.exe - 0x0071256B->_
             inline - len(6) services.exe - 0x0071258A->_
             inline - len(1) services.exe - 0x0071259C->_
             inline - len(6) services.exe - 0x007125F0->_
             inline - len(1) services.exe - 0x00712603->_
             inline - len(6) services.exe - 0x00712609->_
             inline - len(1) services.exe - 0x00712647->_
             inline - len(6) services.exe - 0x0071265E->_
             inline - len(1) services.exe - 0x00712678->_
             inline - len(6) services.exe - 0x007126AE->_
             inline - len(1) services.exe - 0x007126C1->_
             inline - len(6) services.exe - 0x00712719->_
             inline - len(1) services.exe - 0x0071272E->_
             inline - len(1) services.exe - 0x0071275B->_
             inline - len(1) services.exe - 0x007127AB->_
             inline - len(6) services.exe - 0x007127B9->_
             inline - len(1) services.exe - 0x007127CC->_
             inline - len(6) services.exe - 0x007127D2->_
             inline - len(1) services.exe - 0x007127EE->_
             inline - len(1) services.exe - 0x0071282C->_
             inline - len(1) services.exe - 0x00712833->_
             inline - len(1) services.exe - 0x00712844->_
             inline - len(6) services.exe - 0x00712897->_
             inline - len(1) services.exe - 0x007128AE->_
             inline - len(6) services.exe - 0x007128CA->_
             inline - len(1) services.exe - 0x007128E1->_
             inline - len(6) services.exe - 0x007128F5->_
             inline - len(1) services.exe - 0x0071290B->_
             inline - len(1) services.exe - 0x0071293E->_
             inline - len(1) services.exe - 0x0071295C->_
             inline - len(6) services.exe - 0x0071296A->_
             inline - len(1) services.exe - 0x00712982->_
             inline - len(6) services.exe - 0x00712998->_
             inline - len(1) services.exe - 0x007129AE->_
             inline - len(1) services.exe - 0x007129C1->_
             inline - len(1) services.exe - 0x007129D9->_
             inline - len(1) services.exe - 0x007129F4->_
             inline - len(1) services.exe - 0x00712A21->_
             inline - len(1) services.exe - 0x00712A2E->_
             inline - len(6) services.exe - 0x00712A44->_
             inline - len(1) services.exe - 0x00712A5A->_
             inline - len(1) services.exe - 0x00712A6D->_
             inline - len(6) services.exe - 0x00712A83->_
             inline - len(1) services.exe - 0x00712A9B->_
             inline - len(1) services.exe - 0x00712AB3->_
             inline - len(1) services.exe - 0x00712ACF->_
             inline - len(1) services.exe - 0x00712AEE->_
             inline - len(6) services.exe - 0x00712B5E->_
             inline - len(1) services.exe - 0x00712B71->_
             inline - len(1) services.exe - 0x00712B87->_
             inline - len(6) services.exe - 0x00712B8E->_
             inline - len(1) services.exe - 0x00712BA1->_
             inline - len(1) services.exe - 0x00712C2B->_
             inline - len(1) services.exe - 0x00712C3A->_
             inline - len(6) services.exe - 0x00712C78->_
             inline - len(1) services.exe - 0x00712C93->_
             inline - len(6) services.exe - 0x00712C9F->_
             inline - len(1) services.exe - 0x00712CBA->_
             inline - len(1) services.exe - 0x00712CD2->_
             inline - len(1) services.exe - 0x00712CDB->_
             inline - len(1) services.exe - 0x00712CEE->_
             inline - len(1) services.exe - 0x00712D68->_
             inline - len(1) services.exe - 0x00712D82->_
             inline - len(1) services.exe - 0x00712DC0->_
             inline - len(1) services.exe - 0x00712DCB->_
             inline - len(1) services.exe - 0x00712E37->_
             inline - len(1) services.exe - 0x00712E55->_
             inline - len(1) services.exe - 0x00712E5E->_
             inline - len(11) services.exe - 0x00712E7B->_
             inline - len(1) services.exe - 0x00712EA2->_
             inline - len(1) services.exe - 0x00712EA8->_
             inline - len(6) services.exe - 0x00712ECE->_
             inline - len(1) services.exe - 0x00712EEA->_
             inline - len(1) services.exe - 0x00712EF0->_
             inline - len(1) services.exe - 0x00712EFA->_
             inline - len(1) services.exe - 0x00712F10->_
             inline - len(1) services.exe - 0x00712F1A->_
             inline - len(1) services.exe - 0x00712F4F->_
             inline - len(1) services.exe - 0x00712F6E->_
             inline - len(1) services.exe - 0x00712F7E->_
             inline - len(1) services.exe - 0x00712F8A->_
             inline - len(1) services.exe - 0x00712F99->_
             inline - len(1) services.exe - 0x00712FA3->_
             inline - len(1) services.exe - 0x00712FCC->_
             inline - len(1) services.exe - 0x00712FD3->_
             inline - len(1) services.exe - 0x00712FF0->_
             inline - len(6) services.exe - 0x00713003->_
             inline - len(1) services.exe - 0x0071301C->_
             inline - len(1) services.exe - 0x007130C2->_
             inline - len(1) services.exe - 0x007130C9->_
             inline - len(1) services.exe - 0x0071313B->_
             inline - len(1) services.exe - 0x00713142->_
             inline - len(1) services.exe - 0x007131FE->_
             inline - len(1) services.exe - 0x00713205->_
             inline - len(1) services.exe - 0x00713248->_
             inline - len(1) services.exe - 0x0071324E->_
             inline - len(1) services.exe - 0x00713264->_
             inline - len(1) services.exe - 0x007132D0->_
             inline - len(6) services.exe - 0x007132E6->_
             inline - len(1) services.exe - 0x00713307->_
             inline - len(6) services.exe - 0x00713318->_
             inline - len(1) services.exe - 0x00713333->_
             inline - len(1) services.exe - 0x0071335D->_
             inline - len(1) services.exe - 0x00713368->_
             inline - len(1) services.exe - 0x00713379->_
             inline - len(1) services.exe - 0x0071339E->_
             inline - len(1) services.exe - 0x007133AF->_
             inline - len(6) services.exe - 0x00713455->_
             inline - len(1) services.exe - 0x00713472->_
             inline - len(1) services.exe - 0x00713493->_
             inline - len(1) services.exe - 0x007134AD->_
             inline - len(1) services.exe - 0x007134B8->_
             inline - len(1) services.exe - 0x007134C3->_
             inline - len(1) services.exe - 0x007134C9->_
             inline - len(1) services.exe - 0x007134DF->_
             inline - len(6) services.exe - 0x007134F1->_
             inline - len(1) services.exe - 0x0071350A->_
             inline - len(11) services.exe - 0x0071354C->_
             inline - len(6) services.exe - 0x00713564->_
             inline - len(1) services.exe - 0x0071357B->_
             inline - len(1) services.exe - 0x00713587->_
             inline - len(1) services.exe - 0x0071359E->_
             inline - len(1) services.exe - 0x007135F2->_
             inline - len(1) services.exe - 0x00713604->_
             inline - len(1) services.exe - 0x0071360B->_
             inline - len(1) services.exe - 0x0071361C->_
             inline - len(1) services.exe - 0x00713630->_
             inline - len(1) services.exe - 0x00713647->_
             inline - len(6) services.exe - 0x0071364F->_
             inline - len(6) services.exe - 0x0071367F->_
             inline - len(1) services.exe - 0x007136B5->_
             inline - len(1) services.exe - 0x007136C8->_
             inline - len(1) services.exe - 0x007136D1->_
             inline - len(1) services.exe - 0x007136DE->_
             inline - len(1) services.exe - 0x007136E4->_
             inline - len(6) services.exe - 0x00713724->_
             inline - len(1) services.exe - 0x0071373E->_
             inline - len(6) services.exe - 0x00713762->_
             inline - len(1) services.exe - 0x0071377D->_
             inline - len(1) services.exe - 0x00713794->_
             inline - len(1) services.exe - 0x0071379D->_
             inline - len(6) services.exe - 0x007137AA->_
             inline - len(1) services.exe - 0x007137C5->_
             inline - len(1) services.exe - 0x007137D3->_
             inline - len(1) services.exe - 0x007137DF->_
             inline - len(6) services.exe - 0x007137E7->_
             inline - len(1) services.exe - 0x00713804->_
             inline - len(1) services.exe - 0x00713836->_
             inline - len(1) services.exe - 0x0071383C->_
             inline - len(6) services.exe - 0x00713847->_
             inline - len(6) services.exe - 0x0071385F->_
             inline - len(1) services.exe - 0x00713875->_
             inline - len(1) services.exe - 0x0071388F->_
             inline - len(1) services.exe - 0x007138AF->_
             inline - len(1) services.exe - 0x007138E0->_
             inline - len(1) services.exe - 0x007138E6->_
             inline - len(6) services.exe - 0x0071390B->_
             inline - len(1) services.exe - 0x00713921->_
             inline - len(6) services.exe - 0x00713927->_
             inline - len(1) services.exe - 0x0071394B->_
             inline - len(1) services.exe - 0x007139CD->_
             inline - len(1) services.exe - 0x007139D8->_
             inline - len(1) services.exe - 0x007139E1->_
             inline - len(1) services.exe - 0x007139EE->_
             inline - len(1) services.exe - 0x00713A09->_
             inline - len(1) services.exe - 0x00713A4F->_
             inline - len(1) services.exe - 0x00713A77->_
             inline - len(1) services.exe - 0x00713A8B->_
             inline - len(1) services.exe - 0x00713A99->_
             inline - len(6) services.exe - 0x00713AAB->_
             inline - len(1) services.exe - 0x00713AC5->_
             inline - len(6) services.exe - 0x00713AF7->_
             inline - len(1) services.exe - 0x00713B11->_
             inline - len(1) services.exe - 0x00713B53->_
             inline - len(1) services.exe - 0x00713B64->_
             inline - len(1) services.exe - 0x00713BF3->_
             inline - len(1) services.exe - 0x00713C01->_
             inline - len(5) services.exe - 0x00713C76->_
             inline - len(1) services.exe - 0x00713C85->_
             inline - len(1) services.exe - 0x00713C95->_
             inline - len(1) services.exe - 0x00713C9B->_
             inline - len(1) services.exe - 0x00713CA1->_
             inline - len(1) services.exe - 0x00713CA7->_
             inline - len(1) services.exe - 0x00713CAD->_
             inline - len(1) services.exe - 0x00713CB3->_
             inline - len(1) services.exe - 0x00713CB9->_
             inline - len(1) services.exe - 0x00713CBF->_
             inline - len(1) services.exe - 0x00713CC5->_
             inline - len(1) services.exe - 0x00713CCB->_
             inline - len(1) services.exe - 0x00713CD1->_
             inline - len(1) services.exe - 0x00713CD7->_
             inline - len(1) services.exe - 0x00713CDE->_
             inline - len(1) services.exe - 0x00713CE6->_
             inline - len(1) services.exe - 0x00713CEE->_
             inline - len(1) services.exe - 0x00713CF6->_
             inline - len(1) services.exe - 0x00713D02->_
             inline - len(6) services.exe - 0x00713D0B->_
             inline - len(1) services.exe - 0x00713D16->_
             inline - len(1) services.exe - 0x00713D20->_
             inline - len(1) services.exe - 0x00713D29->_
             inline - len(1) services.exe - 0x00713D34->_
             inline - len(6) services.exe - 0x00713D42->_
             inline - len(1) services.exe - 0x00713D4D->_
             inline - len(1) services.exe - 0x00713D58->_
             inline - len(1) services.exe - 0x00713D5F->_
             inline - len(5) services.exe - 0x00713D66->_
             inline - len(1) services.exe - 0x00713D75->_
             inline - len(1) services.exe - 0x00713D80->_
             inline - len(1) services.exe - 0x00713DD0->_
             inline - len(1) services.exe - 0x00713DDC->_
             inline - len(1) services.exe - 0x00713E39->_
             inline - len(1) services.exe - 0x00713E6B->_
             inline - len(1) services.exe - 0x00713E76->_
             inline - len(1) services.exe - 0x00713ECB->_
             inline - len(1) services.exe - 0x00713F06->_
             inline - len(1) services.exe - 0x00713F3A->_
             inline - len(1) services.exe - 0x00713F93->_
             inline - len(1) services.exe - 0x00714049->_
             inline - len(1) services.exe - 0x00714050->_
             inline - len(1) services.exe - 0x007140B2->_
             inline - len(1) services.exe - 0x007140FA->_
             inline - len(1) services.exe - 0x00714105->_
             inline - len(1) services.exe - 0x00714110->_
             inline - len(1) services.exe - 0x0071411B->_
             inline - len(1) services.exe - 0x00714126->_
             Iat - winlogon.exe->USER32.dll:CloseDesktop - 0x75B8C4CE->0x77D1C4CE
             Iat - winlogon.exe->USER32.dll:FindWindowW - 0x75B8AE0D->0x77D1AE0D
             Iat - winlogon.exe->USER32.dll:EnumWindows - 0x75B9375B->0x77D2375B
             Iat - winlogon.exe->USER32.dll:RealGetWindowClassW - 0x75B8ADB3->0x77D1ADB3
             Iat - winlogon.exe->USER32.dll:ShowWindow - 0x75B8F2A9->0x77D1F2A9
             Iat - winlogon.exe->USER32.dll:DialogBoxParamW - 0x75BA3B9B->0x77D33B9B
             Iat - winlogon.exe->USER32.dll:GetDlgItemTextW - 0x75BAECBC->0x77D3ECBC
             Iat - winlogon.exe->USER32.dll:EndDialog - 0x75BB3BA3->0x77D43BA3
             Iat - winlogon.exe->USER32.dll:LoadImageW - 0x75B912EB->0x77D212EB
             Iat - winlogon.exe->USER32.dll:GetDlgItem - 0x75BB42BB->0x77D442BB
             Iat - winlogon.exe->USER32.dll:SetThreadDesktop - 0x75B8B829->0x77D1B829
             Iat - winlogon.exe->USER32.dll:LockWindowStation - 0x75B8478A->0x77D1478A
             Iat - winlogon.exe->USER32.dll:UnlockWindowStation - 0x75B84A30->0x77D14A30
             Iat - winlogon.exe->USER32.dll:SetWindowStationUser - 0x75B83CAD->0x77D13CAD
             Iat - winlogon.exe->USER32.dll:UpdatePerUserSystemParameters - 0x75B83310->0x77D13310
             Iat - winlogon.exe->USER32.dll:GetUserObjectInformationW - 0x75B8E355->0x77D1E355
             Iat - winlogon.exe->USER32.dll:OpenInputDesktop - 0x75B85C39->0x77D15C39
             Iat - winlogon.exe->USER32.dll:MessageBoxW - 0x75BDEA5F->0x77D6EA5F
             Iat - winlogon.exe->USER32.dll:GetSystemMetrics - 0x75B967CF->0x77D267CF
             Iat - winlogon.exe->USER32.dll:ExitWindowsEx - 0x75BD06C7->0x77D606C7
             Iat - winlogon.exe->USER32.dll:GetAsyncKeyState - 0x75B8A256->0x77D1A256
             Iat - winlogon.exe->USER32.dll:CancelShutdown - 0x75BCFD1B->0x77D5FD1B
             Iat - winlogon.exe->USER32.dll:CreateDesktopW - 0x75B840CF->0x77D140CF
             Iat - winlogon.exe->USER32.dll:SystemParametersInfoW - 0x75B8E09A->0x77D1E09A
             Iat - winlogon.exe->USER32.dll:GetKeyState - 0x75B92B4D->0x77D22B4D
             Iat - winlogon.exe->USER32.dll:GetLastInputInfo - 0x75B93834->0x77D23834
             Iat - winlogon.exe->USER32.dll:SetForegroundWindow - 0x75B8B225->0x77D1B225
             Iat - winlogon.exe->USER32.dll:SetWindowPos - 0x75B91BC4->0x77D21BC4
             Iat - winlogon.exe->USER32.dll:GetDesktopWindow - 0x75B901A9->0x77D201A9
             Iat - winlogon.exe->USER32.dll:GetParent - 0x75B96029->0x77D26029
             Iat - winlogon.exe->USER32.dll:GetWindowLongW - 0x75B961B8->0x77D261B8
             Iat - winlogon.exe->USER32.dll:SwitchDesktopWithFade - 0x75B84A0F->0x77D14A0F
             Iat - winlogon.exe->USER32.dll:LoadLocalFonts - 0x75B82227->0x77D12227
             Iat - winlogon.exe->USER32.dll:RegisterLogonProcess - 0x75B8474B->0x77D1474B
             Iat - winlogon.exe->USER32.dll:GetWindowRect - 0x75B9558C->0x77D2558C
             Iat - winlogon.exe->USER32.dll:LoadStringW - 0x75B8DFBA->0x77D1DFBA
             Iat - winlogon.exe->USER32.dll:SendMessageW - 0x75B95539->0x77D25539
             Iat - winlogon.exe->USER32.dll:CreateWindowStationW - 0x75B8164C->0x77D1164C
             Iat - winlogon.exe->USER32.dll:SetProcessWindowStation - 0x75B8B83D->0x77D1B83D
             Iat - winlogon.exe->USER32.dll:CloseWindowStation - 0x75B8C6F2->0x77D1C6F2
             Iat - winlogon.exe->USER32.dll:SetUserObjectSecurity - 0x75B82285->0x77D12285
             Iat - winlogon.exe->USER32.dll:SwitchDesktop - 0x75B8476B->0x77D1476B
             Iat - winlogon.exe->msvcrt.dll:wcschr - 0x75ADAA61->0x6FF5AA61
             Iat - winlogon.exe->msvcrt.dll:wcsstr - 0x75ADBF71->0x6FF5BF71
             Iat - winlogon.exe->msvcrt.dll:__isascii - 0x75AED57B->0x6FF6D57B
             Iat - winlogon.exe->msvcrt.dll:isupper - 0x75AEC1CA->0x6FF6C1CA
             Iat - winlogon.exe->msvcrt.dll:_tolower - 0x75AEC1FC->0x6FF6C1FC
             Iat - winlogon.exe->msvcrt.dll:??2@YAPAXI@Z - 0x75ADB0C9->0x6FF5B0C9
             Iat - winlogon.exe->msvcrt.dll:memcpy - 0x75AD9910->0x6FF59910
             Iat - winlogon.exe->msvcrt.dll:memset - 0x75AD9790->0x6FF59790
             Iat - winlogon.exe->msvcrt.dll:_vsnwprintf - 0x75ADBBCE->0x6FF5BBCE
             Iat - winlogon.exe->msvcrt.dll:memmove - 0x75AD9E5A->0x6FF59E5A
             Iat - winlogon.exe->msvcrt.dll:_wcsicmp - 0x75ADA9E9->0x6FF5A9E9
             Iat - winlogon.exe->msvcrt.dll:wcsrchr - 0x75ADA73F->0x6FF5A73F
             Iat - winlogon.exe->msvcrt.dll:iswspace - 0x75ADAACB->0x6FF5AACB
             Iat - winlogon.exe->msvcrt.dll:wcstok - 0x75AE076E->0x6FF6076E
             Iat - winlogon.exe->msvcrt.dll:??3@YAXPAX@Z - 0x75ADB0B9->0x6FF5B0B9
             Iat - winlogon.exe->msvcrt.dll:_ultow - 0x75ADFAB0->0x6FF5FAB0
             Iat - winlogon.exe->msvcrt.dll:_wtoi - 0x75ADC823->0x6FF5C823
             Iat - winlogon.exe->msvcrt.dll:__getmainargs - 0x75AE2BC0->0x6FF62BC0
             Iat - winlogon.exe->msvcrt.dll:_cexit - 0x75AE37D4->0x6FF637D4
             Iat - winlogon.exe->msvcrt.dll:_exit - 0x75B3B2C0->0x6FFBB2C0
             Iat - winlogon.exe->msvcrt.dll:_XcptFilter - 0x75AFDC75->0x6FF7DC75
             Iat - winlogon.exe->msvcrt.dll:_ismbblead - 0x75ADF607->0x6FF5F607
             Iat - winlogon.exe->msvcrt.dll:exit - 0x75AE36AA->0x6FF636AA
             Iat - winlogon.exe->msvcrt.dll:_acmdln - 0x75B704D8->0x6FFF04D8
             Iat - winlogon.exe->msvcrt.dll:_initterm - 0x75ADC151->0x6FF5C151
             Iat - winlogon.exe->msvcrt.dll:_amsg_exit - 0x75B3B2EF->0x6FFBB2EF
             Iat - winlogon.exe->msvcrt.dll:__setusermatherr - 0x75B677AD->0x6FFE77AD
             Iat - winlogon.exe->msvcrt.dll:__p__commode - 0x75AE27C3->0x6FF627C3
             Iat - winlogon.exe->msvcrt.dll:__p__fmode - 0x75AE27CE->0x6FF627CE
             Iat - winlogon.exe->msvcrt.dll:__set_app_type - 0x75AE2804->0x6FF62804
             Iat - winlogon.exe->msvcrt.dll:_except_handler4_common - 0x75AF3E27->0x6FF73E27
             Iat - winlogon.exe->msvcrt.dll:?terminate@@YAXXZ - 0x75B261CF->0x6FFA61CF
             Iat - winlogon.exe->msvcrt.dll:_controlfp - 0x75ADE1E1->0x6FF5E1E1
             Iat - winlogon.exe->ntdll.dll:RtlEnterCriticalSection - 0x773D7720->0x77F077A0
             Iat - winlogon.exe->ntdll.dll:EtwTraceMessage - 0x773BE41F->0x77EEE3FF
             Iat - winlogon.exe->ntdll.dll:NtShutdownSystem - 0x773D6828->0x77F06828
             Iat - winlogon.exe->ntdll.dll:RtlNtStatusToDosError - 0x773E3BF5->0x77F13C65
             Iat - winlogon.exe->ntdll.dll:NtClose - 0x773D54C8->0x77F054C8
             Iat - winlogon.exe->ntdll.dll:NtQueryInformationToken - 0x773D6078->0x77F06078
             Iat - winlogon.exe->ntdll.dll:NtOpenProcessToken - 0x773D5D98->0x77F05D98
             Iat - winlogon.exe->ntdll.dll:WinSqmStartSession - 0x773A0F9D->0x77ED0F8D
             Iat - winlogon.exe->ntdll.dll:WinSqmEndSession - 0x773A12A7->0x77ED1297
             Iat - winlogon.exe->ntdll.dll:EtwEventWrite - 0x773BD5BA->0x77EED59A
             Iat - winlogon.exe->ntdll.dll:EtwEventEnabled - 0x773C2083->0x77EF206F
             Iat - winlogon.exe->ntdll.dll:RtlGetNtProductType - 0x773F6589->0x77F265B9
             Iat - winlogon.exe->ntdll.dll:NtQuerySystemInformation - 0x773D61F8->0x77F061F8
             Iat - winlogon.exe->ntdll.dll:NtSystemDebugControl - 0x773D68A8->0x77F068A8
             Iat - winlogon.exe->ntdll.dll:EtwGetTraceEnableFlags - 0x773B8B55->0x77EE8B35
             Iat - winlogon.exe->ntdll.dll:EtwGetTraceEnableLevel - 0x773B8B1F->0x77EE8AFF
             Iat - winlogon.exe->ntdll.dll:EtwGetTraceLoggerHandle - 0x773B8AB6->0x77EE8A96
             Iat - winlogon.exe->ntdll.dll:EtwRegisterTraceGuidsW - 0x773B867A->0x77EE865A
             Iat - winlogon.exe->ntdll.dll:EtwUnregisterTraceGuids - 0x773BB085->0x77EEB065
             Iat - winlogon.exe->ntdll.dll:RtlRemovePrivileges - 0x77398F5E->0x77EC8F5E
             Iat - winlogon.exe->ntdll.dll:EtwEventRegister - 0x773F5ADC->0x77F25B0C
             Iat - winlogon.exe->ntdll.dll:EtwEventUnregister - 0x773ED96D->0x77F1D9DD
             Iat - winlogon.exe->ntdll.dll:RtlDeleteCriticalSection - 0x773E9A55->0x77F19AC5
             Iat - winlogon.exe->ntdll.dll:WinSqmSetDWORD - 0x773ABA91->0x77EDBA71
             Iat - winlogon.exe->ntdll.dll:RtlpVerifyAndCommitUILanguageSettings - 0x7739382E->0x77EC382E
             Iat - winlogon.exe->ntdll.dll:EtwEventWriteEndScenario - 0x77393A93->0x77EC3A93
             Iat - winlogon.exe->ntdll.dll:EtwEventWriteStartScenario - 0x77393A36->0x77EC3A36
             Iat - winlogon.exe->ntdll.dll:EtwEventActivityIdControl - 0x773A27E7->0x77ED27D7
             Iat - winlogon.exe->ntdll.dll:NtOpenThreadToken - 0x773D5E18->0x77F05E18
             Iat - winlogon.exe->ntdll.dll:RtlCompareUnicodeString - 0x773E73D5->0x77F17445
             Iat - winlogon.exe->ntdll.dll:RtlInitUnicodeStringEx - 0x773E6E9A->0x77F16F0A
             Iat - winlogon.exe->ntdll.dll:RtlSetEnvironmentVariable - 0x773BA10D->0x77EEA0ED
             Iat - winlogon.exe->ntdll.dll:RtlQueryEnvironmentVariable_U - 0x773F4EE6->0x77F24F26
             Iat - winlogon.exe->ntdll.dll:RtlInitUnicodeString - 0x773C4180->0x77EF4168
             Iat - winlogon.exe->ntdll.dll:RtlInitializeCriticalSection - 0x773EA0D9->0x77F1A149
             Iat - winlogon.exe->ntdll.dll:RtlLengthSid - 0x773EED77->0x77F1EDE7
             Iat - winlogon.exe->ntdll.dll:RtlInitString - 0x773C4110->0x77EF40F8
             Iat - winlogon.exe->ntdll.dll:NtAllocateLocallyUniqueId - 0x773D5298->0x77F05298
             Iat - winlogon.exe->ntdll.dll:WinSqmAddToStream - 0x773B04C5->0x77EE04A5
             Iat - winlogon.exe->ntdll.dll:RtlDestroyEnvironment - 0x774017B6->0x77F317D6
             Iat - winlogon.exe->ntdll.dll:TpSimpleTryPost - 0x773AC90E->0x77EDC8E8
             Iat - winlogon.exe->ntdll.dll:TpReleaseWork - 0x773A2121->0x77ED2111
             Iat - winlogon.exe->ntdll.dll:TpWaitForWork - 0x77409088->0x77F390A0
             Iat - winlogon.exe->ntdll.dll:TpReleaseWait - 0x773AB587->0x77EDB567
             Iat - winlogon.exe->ntdll.dll:TpWaitForWait - 0x7739F227->0x77ECF217
             Iat - winlogon.exe->ntdll.dll:TpSetWait - 0x773B8C1B->0x77EE8BFB
             Iat - winlogon.exe->ntdll.dll:TpPostWork - 0x773A26B9->0x77ED26A9
             Iat - winlogon.exe->ntdll.dll:TpAllocWork - 0x773A2486->0x77ED2476
             Iat - winlogon.exe->ntdll.dll:TpAllocWait - 0x773A9308->0x77ED92E8
             Iat - winlogon.exe->ntdll.dll:RtlExpandEnvironmentStrings_U - 0x773F2FB8->0x77F23032
             Iat - winlogon.exe->ntdll.dll:RtlCreateEnvironment - 0x7739BB77->0x77ECBB67
             Iat - winlogon.exe->ntdll.dll:NtSetInformationToken - 0x773D66A8->0x77F066A8
             Iat - winlogon.exe->ntdll.dll:NtCreateToken - 0x773D5748->0x77F05748
             Iat - winlogon.exe->ntdll.dll:RtlAdjustPrivilege - 0x7739BC4A->0x77ECBC3A
             Iat - winlogon.exe->ntdll.dll:TpWaitForTimer - 0x773AC04A->0x77EDC02A
             Iat - winlogon.exe->ntdll.dll:RtlGetDaclSecurityDescriptor - 0x773B257D->0x77EE255D
             Iat - winlogon.exe->ntdll.dll:RtlSetDaclSecurityDescriptor - 0x773F30D4->0x77F2314E
             Iat - winlogon.exe->ntdll.dll:RtlAddAce - 0x7739B437->0x77ECB427
             Iat - winlogon.exe->ntdll.dll:NtAdjustPrivilegesToken - 0x773D5268->0x77F05268
             Iat - winlogon.exe->ntdll.dll:NtDuplicateToken - 0x773D58A8->0x77F058A8
             Iat - winlogon.exe->ntdll.dll:RtlUnhandledExceptionFilter - 0x7744D1AB->0x77F7D157
             Iat - winlogon.exe->ntdll.dll:NtQueryInformationProcess - 0x773D6048->0x77F06048
             Iat - winlogon.exe->ntdll.dll:TpReleaseTimer - 0x773AC0F2->0x77EDC0D2
             Iat - winlogon.exe->ntdll.dll:NtReplyPort - 0x773D6408->0x77F06408
             Iat - winlogon.exe->ntdll.dll:NtCompleteConnectPort - 0x773D5538->0x77F05538
             Iat - winlogon.exe->ntdll.dll:NtReplyWaitReceivePort - 0x773D6418->0x77F06418
             Iat - winlogon.exe->ntdll.dll:NtAcceptConnectPort - 0x773D51A8->0x77F051A8
             Iat - winlogon.exe->ntdll.dll:NtCreatePort - 0x773D5678->0x77F05678
             Iat - winlogon.exe->ntdll.dll:NtCreateEvent - 0x773D55A8->0x77F055A8
             Iat - winlogon.exe->ntdll.dll:RtlNtStatusToDosErrorNoTeb - 0x773E3C34->0x77F13CA4
             Iat - winlogon.exe->ntdll.dll:RtlCopySid - 0x773EEDE9->0x77F1EE59
             Iat - winlogon.exe->ntdll.dll:RtlOpenCurrentUser - 0x773FA8CE->0x77F2A8FE
             Iat - winlogon.exe->ntdll.dll:RtlFreeSid - 0x773F3892->0x77F2390C
             Iat - winlogon.exe->ntdll.dll:NtSetSecurityObject - 0x773D6758->0x77F06758
             Iat - winlogon.exe->ntdll.dll:RtlSetSaclSecurityDescriptor - 0x773B6F58->0x77EE6F38
             Iat - winlogon.exe->ntdll.dll:RtlAddMandatoryAce - 0x773ADDE9->0x77EDDDBD
             Iat - winlogon.exe->ntdll.dll:RtlCreateAcl - 0x773F2595->0x77F2260F
             Iat - winlogon.exe->ntdll.dll:RtlCreateSecurityDescriptor - 0x773F12B9->0x77F21333
             Iat - winlogon.exe->ntdll.dll:RtlAllocateAndInitializeSid - 0x773F22F6->0x77F22370
             Iat - winlogon.exe->ntdll.dll:RtlTimeToSecondsSince1980 - 0x773F8CD4->0x77F28D04
             Iat - winlogon.exe->ntdll.dll:TpSetTimer - 0x773B89DE->0x77EE89BE
             Iat - winlogon.exe->ntdll.dll:TpAllocTimer - 0x773FF2CB->0x77F2F2F5
             Iat - winlogon.exe->ntdll.dll:NtOpenDirectoryObject - 0x773D5C98->0x77F05C98
             Iat - winlogon.exe->ntdll.dll:NtInitiatePowerAction - 0x773D5B08->0x77F05B08
             Iat - winlogon.exe->ntdll.dll:RtlFreeUnicodeString - 0x773E3296->0x77F13306
             Iat - winlogon.exe->ntdll.dll:RtlDuplicateUnicodeString - 0x774026F8->0x77F32718
             Iat - winlogon.exe->ntdll.dll:NtFilterToken - 0x773D5938->0x77F05938
             Iat - winlogon.exe->ntdll.dll:RtlEqualSid - 0x773FE1A5->0x77F2E1D5
             Iat - winlogon.exe->ntdll.dll:RtlLeaveCriticalSection - 0x773D76E0->0x77F07760
             Iat - winlogon.exe->WINSTA.dll:WinStationGetUserCredentials - 0x75458412->0x41058412
             Iat - winlogon.exe->WINSTA.dll:WinStationDisconnect - 0x7544C0ED->0x4104C0ED
             Iat - winlogon.exe->WINSTA.dll:WinStationIsSessionRemoteable - 0x754437F5->0x410437F5
             Iat - winlogon.exe->WINSTA.dll:_WinStationWaitForConnect - 0x7544B7CF->0x4104B7CF
             Iat - winlogon.exe->WINSTA.dll:WinStationIsSessionPermitted - 0x7544B714->0x4104B714
             Iat - winlogon.exe->WINSTA.dll:WinStationQueryInformationW - 0x75443AE5->0x41043AE5
             Iat - winlogon.exe->WINSTA.dll:WinStationFreeMemory - 0x75445A9F->0x41045A9F
             Iat - winlogon.exe->WINSTA.dll:WinStationNegotiateSession - 0x7544B5DA->0x4104B5DA
             Iat - winlogon.exe->WINSTA.dll:WinStationFreeUserCredentials - 0x754572D0->0x410572D0
             Iat - winlogon.exe->WINSTA.dll:WinStationReportUIResult - 0x75457539->0x41057539
             Iat - winlogon.exe->RPCRT4.dll:RpcAsyncInitializeHandle - 0x75A555B0->0x77C455B0
             Iat - winlogon.exe->RPCRT4.dll:RpcAsyncCancelCall - 0x759D8DCF->0x77BC8DCF
             Iat - winlogon.exe->RPCRT4.dll:RpcMgmtIsServerListening - 0x759C55D9->0x77BB55D9
             Iat - winlogon.exe->RPCRT4.dll:RpcStringFreeW - 0x759E5465->0x77BD5465
             Iat - winlogon.exe->RPCRT4.dll:RpcStringBindingComposeW - 0x759E5DC8->0x77BD5DC8
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingFromStringBindingW - 0x759E5CB6->0x77BD5CB6
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingSetAuthInfoExW - 0x759E960B->0x77BD960B
             Iat - winlogon.exe->RPCRT4.dll:UuidFromStringW - 0x759D038C->0x77BC038C
             Iat - winlogon.exe->RPCRT4.dll:NdrAsyncClientCall - 0x75A546D2->0x77C446D2
             Iat - winlogon.exe->RPCRT4.dll:RpcServerUnsubscribeForNotification - 0x759D4506->0x77BC4506
             Iat - winlogon.exe->RPCRT4.dll:RpcServerSubscribeForNotification - 0x759D399A->0x77BC399A
             Iat - winlogon.exe->RPCRT4.dll:I_RpcBindingIsClientLocal - 0x759D4E0D->0x77BC4E0D
             Iat - winlogon.exe->RPCRT4.dll:RpcServerUnregisterIf - 0x759E37FC->0x77BD37FC
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingVectorFree - 0x759C89E2->0x77BB89E2
             Iat - winlogon.exe->RPCRT4.dll:RpcEpUnregister - 0x759C8A6F->0x77BB8A6F
             Iat - winlogon.exe->RPCRT4.dll:RpcServerListen - 0x759C8E9B->0x77BB8E9B
             Iat - winlogon.exe->RPCRT4.dll:RpcEpRegisterW - 0x759C8146->0x77BB8146
             Iat - winlogon.exe->RPCRT4.dll:RpcServerInqBindings - 0x759C7B5B->0x77BB7B5B
             Iat - winlogon.exe->RPCRT4.dll:RpcServerRegisterIfEx - 0x759E09BC->0x77BD09BC
             Iat - winlogon.exe->RPCRT4.dll:RpcServerUseProtseqW - 0x759C7B03->0x77BB7B03
             Iat - winlogon.exe->RPCRT4.dll:NdrServerCall2 - 0x75A54304->0x77C44304
             Iat - winlogon.exe->RPCRT4.dll:NdrAsyncServerCall - 0x75A54A1C->0x77C44A1C
             Iat - winlogon.exe->RPCRT4.dll:RpcRaiseException - 0x759DE0BB->0x77BCE0BB
             Iat - winlogon.exe->RPCRT4.dll:RpcServerInqCallAttributesW - 0x759F1E30->0x77BE1E30
             Iat - winlogon.exe->RPCRT4.dll:RpcServerTestCancel - 0x759C6FDC->0x77BB6FDC
             Iat - winlogon.exe->RPCRT4.dll:I_RpcMapWin32Status - 0x759FBF83->0x77BEBF83
             Iat - winlogon.exe->RPCRT4.dll:NdrClientCall2 - 0x75A5560F->0x77C4560F
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingCreateW - 0x759FBBA3->0x77BEBBA3
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingBind - 0x759FB871->0x77BEB871
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingUnbind - 0x759E2C3E->0x77BD2C3E
             Iat - winlogon.exe->RPCRT4.dll:RpcBindingFree - 0x759FAFE1->0x77BEAFE1
             Iat - winlogon.exe->RPCRT4.dll:I_RpcExceptionFilter - 0x759DD4CE->0x77BCD4CE
             Iat - winlogon.exe->RPCRT4.dll:RpcAsyncAbortCall - 0x75A54075->0x77C44075
             Iat - winlogon.exe->RPCRT4.dll:RpcAsyncCompleteCall - 0x75A54E80->0x77C44E80
             Iat - winlogon.exe->RPCRT4.dll:RpcServerUseProtseqEpW - 0x759E135F->0x77BD135F
             Iat - winlogon.exe->RPCRT4.dll:I_RpcBindingInqLocalClientPID - 0x759F2019->0x77BE2019
             Iat - winlogon.exe->RPCRT4.dll:RpcImpersonateClient - 0x759DD6C1->0x77BCD6C1
             Iat - winlogon.exe->RPCRT4.dll:RpcRevertToSelf - 0x759D71AF->0x77BC71AF
             Iat - winlogon.exe->KERNEL32.dll:RegDeleteTreeW - 0x764D2345->0x77E1213E
             Iat - winlogon.exe->KERNEL32.dll:RegEnumKeyExW - 0x764E51D7->0x77E2575A
             Iat - winlogon.exe->KERNEL32.dll:CreateProcessInternalW - 0x764F07A2->0x77E2DE78
             Iat - winlogon.exe->KERNEL32.dll:BaseInitAppcompatCacheSupport - 0x764D1C0A->0x77E11D75
             Iat - winlogon.exe->KERNEL32.dll:SleepEx - 0x764E0846->0x77E20296
             Iat - winlogon.exe->KERNEL32.dll:GetFileAttributesW - 0x764F4C14->0x77E364FF
             Iat - winlogon.exe->KERNEL32.dll:SetTimerQueueTimer - 0x764D1BD4->0x77E11D3F
             Iat - winlogon.exe->KERNEL32.dll:CreateRemoteThread - 0x7652FAF3->0x77E6F33B
             Iat - winlogon.exe->KERNEL32.dll:GetThreadUILanguage - 0x764DB3B7->0x77E1AE42
             Iat - winlogon.exe->KERNEL32.dll:GetVersionExW - 0x764E99A1->0x77E23B1A
             Iat - winlogon.exe->KERNEL32.dll:GetTickCount64 - 0x764DF108->0x77E1EB4E
             Iat - winlogon.exe->KERNEL32.dll:WideCharToMultiByte - 0x764EEEFA->0x77E3450E
             Iat - winlogon.exe->KERNEL32.dll:DebugBreak - 0x7652FB1D->0x77E6F365
             Iat - winlogon.exe->KERNEL32.dll:UnhandledExceptionFilter - 0x76500651->0x77E3ED38
             Iat - winlogon.exe->KERNEL32.dll:GetCurrentThreadId - 0x764EC410->0x77E2BB80
             Iat - winlogon.exe->KERNEL32.dll:QueryPerformanceCounter - 0x764EC422->0x77E2BB9F
             Iat - winlogon.exe->KERNEL32.dll:GetModuleHandleA - 0x764ED8F3->0x77E2CF41
             Iat - winlogon.exe->KERNEL32.dll:SetUnhandledExceptionFilter - 0x764EF4FB->0x77E33D01
             Iat - winlogon.exe->KERNEL32.dll:GetStartupInfoA - 0x764A1E10->0x77DE1E10
             Iat - winlogon.exe->KERNEL32.dll:LoadLibraryExA - 0x764E4466->0x77E247FA
             Iat - winlogon.exe->KERNEL32.dll:DelayLoadFailureHook - 0x764C01FC->0x77E0028C
             Iat - winlogon.exe->KERNEL32.dll:GetSystemDirectoryW - 0x764EEE37->0x77E340FB
             Iat - winlogon.exe->KERNEL32.dll:SetInformationJobObject - 0x764D5889->0x77E15789
             Iat - winlogon.exe->KERNEL32.dll:WaitForMultipleObjects - 0x764EBD74->0x77E2BCE4
             Iat - winlogon.exe->KERNEL32.dll:CreateThread - 0x764EDCC2->0x77E3375D
             Iat - winlogon.exe->KERNEL32.dll:SetErrorMode - 0x764F0178->0x77E34A51
             Iat - winlogon.exe->KERNEL32.dll:CreateFileW - 0x764EE8A5->0x77E2CC56
             Iat - winlogon.exe->KERNEL32.dll:ReadFile - 0x764E9B66->0x77E296FB
             Iat - winlogon.exe->KERNEL32.dll:GetModuleHandleW - 0x764ECCAC->0x77E3374D
             Iat - winlogon.exe->KERNEL32.dll:GetProcessId - 0x764DB9B8->0x77E1B3BB
             Iat - winlogon.exe->KERNEL32.dll:OpenEventW - 0x764E4A28->0x77E2548B
             Iat - winlogon.exe->KERNEL32.dll:CreateTimerQueueTimer - 0x764DBC15->0x77E1B655
             Iat - winlogon.exe->KERNEL32.dll:DeleteTimerQueueTimer - 0x764DBC2D->0x77E1B662
             Iat - winlogon.exe->KERNEL32.dll:CreateProcessW - 0x764A204D->0x77DE204D
             Iat - winlogon.exe->KERNEL32.dll:SearchPathW - 0x764E43A5->0x77E23DAC
             Iat - winlogon.exe->KERNEL32.dll:AssignProcessToJobObject - 0x764D5ACE->0x77E159CE
             Iat - winlogon.exe->KERNEL32.dll:TerminateProcess - 0x764E2BBD->0x77E22331
             Iat - winlogon.exe->KERNEL32.dll:GetTickCount - 0x764EC260->0x77E2BA60
             Iat - winlogon.exe->KERNEL32.dll:CompareFileTime - 0x764F617E->0x77E313F3
             Iat - winlogon.exe->KERNEL32.dll:ResumeThread - 0x764E16D7->0x77E20F1C
             Iat - winlogon.exe->KERNEL32.dll:FileTimeToSystemTime - 0x764EBDC5->0x77E31DFE
             Iat - winlogon.exe->KERNEL32.dll:SystemTimeToTzSpecificLocalTime - 0x764DB72E->0x77E1B149
             Iat - winlogon.exe->KERNEL32.dll:GetTimeFormatW - 0x764EAFC0->0x77E2AC29
             Iat - winlogon.exe->KERNEL32.dll:VirtualLock - 0x764E029D->0x77E1FCED
             Iat - winlogon.exe->KERNEL32.dll:GetProcessWorkingSetSize - 0x764D60A3->0x77E15E04
             Iat - winlogon.exe->KERNEL32.dll:SetProcessWorkingSetSize - 0x764D75F9->0x77E173A3
             Iat - winlogon.exe->KERNEL32.dll:VirtualUnlock - 0x764D8DBC->0x77E188AA
             Iat - winlogon.exe->KERNEL32.dll:VirtualFree - 0x764F6B15->0x77E31DA4
             Iat - winlogon.exe->KERNEL32.dll:CreateJobObjectW - 0x764D5815->0x77E15715
             Iat - winlogon.exe->KERNEL32.dll:GetCommandLineW - 0x764F5304->0x77E3679E
             Iat - winlogon.exe->KERNEL32.dll:TerminateJobObject - 0x764D57A9->0x77E15572
             Iat - winlogon.exe->KERNEL32.dll:ResetEvent - 0x764EBD44->0x77E2BCB4
             Iat - winlogon.exe->KERNEL32.dll:InterlockedCompareExchange - 0x764EC3FB->0x77E2BB92
             Iat - winlogon.exe->KERNEL32.dll:GetComputerNameW - 0x764E09C7->0x77E203FF
             Iat - winlogon.exe->KERNEL32.dll:InterlockedIncrement - 0x764EC3B0->0x77E2BBC0
             Iat - winlogon.exe->KERNEL32.dll:InterlockedDecrement - 0x764EC3E0->0x77E2BBF0
             Iat - winlogon.exe->KERNEL32.dll:DuplicateHandle - 0x764ED888->0x77E2CDD9
             Iat - winlogon.exe->KERNEL32.dll:QueryInformationJobObject - 0x76537401->0x77E76CDD
             Iat - winlogon.exe->KERNEL32.dll:RegisterWaitForSingleObject - 0x764DB93C->0x77E1B357
             Iat - winlogon.exe->KERNEL32.dll:OpenProcess - 0x764E549F->0x77E259D7
             Iat - winlogon.exe->KERNEL32.dll:UnregisterWait - 0x764DB9D3->0x77E1B495
             Iat - winlogon.exe->KERNEL32.dll:QueryFullProcessImageNameW - 0x764E6857->0x77E25C28
             Iat - winlogon.exe->KERNEL32.dll:GetExitCodeProcess - 0x764F614D->0x77E31462
             Iat - winlogon.exe->KERNEL32.dll:GetProcessHeap - 0x764EFCDD->0x77E31280
             Iat - winlogon.exe->KERNEL32.dll:SetEnvironmentVariableW - 0x764EF69C->0x77E2D9F5
             Iat - winlogon.exe->KERNEL32.dll:CompareStringW - 0x764EA01A->0x77E29BEE
             Iat - winlogon.exe->KERNEL32.dll:GetShortPathNameW - 0x764E134C->0x77E20BBC
             Iat - winlogon.exe->KERNEL32.dll:lstrlenW - 0x764EBDA0->0x77E2D9E8
             Iat - winlogon.exe->KERNEL32.dll:ExpandEnvironmentStringsW - 0x764E43D7->0x77E24680
             Iat - winlogon.exe->KERNEL32.dll:VirtualAlloc - 0x764EC43A->0x77E32FB6
             Iat - winlogon.exe->KERNEL32.dll:GetCurrentProcessId - 0x764ED7B5->0x77E2CAC4
             Iat - winlogon.exe->KERNEL32.dll:HeapSetInformation - 0x764EF6B4->0x77E34157
             Iat - winlogon.exe->KERNEL32.dll:LoadLibraryW - 0x764EEF42->0x77E33C01
             Iat - winlogon.exe->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x77E333D3
             Iat - winlogon.exe->KERNEL32.dll:FreeLibrary - 0x764EEF67->0x77E2D9D0
             Iat - winlogon.exe->KERNEL32.dll:WaitForSingleObjectEx - 0x764EC2B0->0x77E2BAB0
             Iat - winlogon.exe->KERNEL32.dll:InterlockedExchange - 0x764EC452->0x77E2BF0A
             Iat - winlogon.exe->KERNEL32.dll:UnregisterWaitEx - 0x764D5B02->0x77E15A02
             Iat - winlogon.exe->KERNEL32.dll:Sleep - 0x764EC246->0x77E2BA46
             Iat - winlogon.exe->KERNEL32.dll:GetSystemTimeAsFileTime - 0x764ED816->0x77E32FDE
             Iat - winlogon.exe->KERNEL32.dll:MoveFileExW - 0x764E8DB0->0x77E24A91
             Iat - winlogon.exe->KERNEL32.dll:LocalSize - 0x764E05E2->0x77E20032
             Iat - winlogon.exe->KERNEL32.dll:LocalReAlloc - 0x764E6E27->0x77E27328
             Iat - winlogon.exe->KERNEL32.dll:CreateEventW - 0x764ED7BC->0x77E33386
             Iat - winlogon.exe->KERNEL32.dll:SetEvent - 0x764EBD5C->0x77E2BCCC
             Iat - winlogon.exe->KERNEL32.dll:CloseHandle - 0x764EE868->0x77E2CA7C
             Iat - winlogon.exe->KERNEL32.dll:WaitForSingleObject - 0x764EC290->0x77E2BA90
             Iat - winlogon.exe->KERNEL32.dll:GetModuleFileNameW - 0x764EEF35->0x77E33C26
             Iat - winlogon.exe->KERNEL32.dll:LocalAlloc - 0x764ECC66->0x77E33363
             Iat - winlogon.exe->KERNEL32.dll:LocalFree - 0x764ECBFC->0x77E2CA64
             Iat - winlogon.exe->KERNEL32.dll:SetLastError - 0x764EC3F0->0x77E2BB08
             Iat - winlogon.exe->KERNEL32.dll:FormatMessageW - 0x764E8DD0->0x77E254A3
             Iat - winlogon.exe->KERNEL32.dll:FindResourceExW - 0x764E43B2->0x77E247EA
             Iat - winlogon.exe->KERNEL32.dll:LoadResource - 0x764E9C72->0x77E2984D
             Iat - winlogon.exe->KERNEL32.dll:LockResource - 0x764E02D9->0x77E1FD29
             Iat - winlogon.exe->KERNEL32.dll:GetCurrentProcess - 0x764ED7A0->0x77E2CDCF
             Iat - winlogon.exe->KERNEL32.dll:SetPriorityClass - 0x764DF4EA->0x77E1EF32
             Iat - winlogon.exe->KERNEL32.dll:GetCurrentThread - 0x764ED799->0x77E33351
             Iat - winlogon.exe->KERNEL32.dll:SetThreadPriority - 0x764E44C6->0x77E24815
             Iat - winlogon.exe->KERNEL32.dll:HeapSize - 0x773E9B7C->0x77F19BEC
             Iat - winlogon.exe->KERNEL32.dll:HeapFree - 0x764EC3C0->0x77E2BBD0
             Iat - winlogon.exe->KERNEL32.dll:HeapAlloc - 0x773E2D66->0x77F12DD6
             Iat - winlogon.exe->KERNEL32.dll:HeapDestroy - 0x764E2B8D->0x77E22301
             Iat - winlogon.exe->KERNEL32.dll:HeapCreate - 0x764EEF74->0x77E33EA2
             Iat - winlogon.exe->KERNEL32.dll:GetLastError - 0x764ECDE0->0x77E2BF00
             Iat - winlogon.exe->KERNEL32.dll:RegGetValueA - 0x764D4247->0x77E140C9
             Iat - winlogon.exe->KERNEL32.dll:GetDateFormatW - 0x764EB1A2->0x77E2AFAB
             inline - len(1) winlogon.exe - 0x00F21593->_
             inline - len(1) winlogon.exe - 0x00F215B0->_
             inline - len(1) winlogon.exe - 0x00F215DF->_
             inline - len(1) winlogon.exe - 0x00F2161A->_
             inline - len(1) winlogon.exe - 0x00F21636->_
             inline - len(1) winlogon.exe - 0x00F21641->_
             inline - len(1) winlogon.exe - 0x00F21661->_
             inline - len(1) winlogon.exe - 0x00F2166A->_
             inline - len(1) winlogon.exe - 0x00F21676->_
             inline - len(1) winlogon.exe - 0x00F2168C->_
             inline - len(1) winlogon.exe - 0x00F21752->_
             inline - len(1) winlogon.exe - 0x00F217A7->_
             inline - len(1) winlogon.exe - 0x00F217C0->_
             inline - len(1) winlogon.exe - 0x00F217D9->_
             inline - len(1) winlogon.exe - 0x00F217E3->_
             inline - len(1) winlogon.exe - 0x00F217EB->_
             inline - len(1) winlogon.exe - 0x00F217F9->_
             inline - len(1) winlogon.exe - 0x00F21804->_
             inline - len(1) winlogon.exe - 0x00F21811->_
             inline - len(1) winlogon.exe - 0x00F21831->_
             inline - len(1) winlogon.exe - 0x00F21875->_
             inline - len(1) winlogon.exe - 0x00F218BA->_
             inline - len(6) winlogon.exe - 0x00F21910->_
             inline - len(1) winlogon.exe - 0x00F21946->_
             inline - len(1) winlogon.exe - 0x00F219C9->_
             inline - len(1) winlogon.exe - 0x00F219EA->_
             inline - len(1) winlogon.exe - 0x00F219FE->_
             inline - len(6) winlogon.exe - 0x00F21A1D->_
             inline - len(1) winlogon.exe - 0x00F21A54->_
             inline - len(1) winlogon.exe - 0x00F21A91->_
             inline - len(1) winlogon.exe - 0x00F21ABF->_
             inline - len(1) winlogon.exe - 0x00F21ACB->_
             inline - len(1) winlogon.exe - 0x00F21AE8->_
             inline - len(6) winlogon.exe - 0x00F21B9F->_
             inline - len(1) winlogon.exe - 0x00F21C0D->_
             inline - len(6) winlogon.exe - 0x00F21C3B->_
             inline - len(1) winlogon.exe - 0x00F21C59->_
             inline - len(1) winlogon.exe - 0x00F21C83->_
             inline - len(1) winlogon.exe - 0x00F21C94->_
             inline - len(6) winlogon.exe - 0x00F21CA1->_
             inline - len(6) winlogon.exe - 0x00F21CE1->_
             inline - len(1) winlogon.exe - 0x00F21D10->_
             inline - len(1) winlogon.exe - 0x00F21D58->_
             inline - len(6) winlogon.exe - 0x00F21D7B->_
             inline - len(1) winlogon.exe - 0x00F21D9E->_
             inline - len(1) winlogon.exe - 0x00F21DA7->_
             inline - len(6) winlogon.exe - 0x00F21DEE->_
             inline - len(1) winlogon.exe - 0x00F21E3A->_
             inline - len(1) winlogon.exe - 0x00F21E48->_
             inline - len(1) winlogon.exe - 0x00F21E55->_
             inline - len(1) winlogon.exe - 0x00F21E69->_
             inline - len(1) winlogon.exe - 0x00F21E71->_
             inline - len(1) winlogon.exe - 0x00F21E8A->_
             inline - len(6) winlogon.exe - 0x00F21EA2->_
             inline - len(1) winlogon.exe - 0x00F21EF2->_
             inline - len(1) winlogon.exe - 0x00F21F07->_
             inline - len(1) winlogon.exe - 0x00F21F95->_
             inline - len(1) winlogon.exe - 0x00F21FAD->_
             inline - len(1) winlogon.exe - 0x00F21FB3->_
             inline - len(1) winlogon.exe - 0x00F21FD0->_
             inline - len(1) winlogon.exe - 0x00F21FD6->_
             inline - len(1) winlogon.exe - 0x00F22062->_
             inline - len(1) winlogon.exe - 0x00F2208B->_
             inline - len(1) winlogon.exe - 0x00F22091->_
             inline - len(1) winlogon.exe - 0x00F220A2->_
             inline - len(1) winlogon.exe - 0x00F22122->_
             inline - len(1) winlogon.exe - 0x00F22145->_
             inline - len(1) winlogon.exe - 0x00F22164->_
             inline - len(1) winlogon.exe - 0x00F22179->_
             inline - len(1) winlogon.exe - 0x00F2219E->_
             inline - len(1) winlogon.exe - 0x00F221EE->_
             inline - len(6) winlogon.exe - 0x00F221F6->_
             inline - len(1) winlogon.exe - 0x00F22239->_
             inline - len(6) winlogon.exe - 0x00F222AA->_
             inline - len(6) winlogon.exe - 0x00F222EB->_
             inline - len(1) winlogon.exe - 0x00F2231B->_
             inline - len(1) winlogon.exe - 0x00F2234B->_
             inline - len(1) winlogon.exe - 0x00F223E5->_
             inline - len(1) winlogon.exe - 0x00F22415->_
             inline - len(6) winlogon.exe - 0x00F22429->_
             inline - len(1) winlogon.exe - 0x00F22447->_
             inline - len(1) winlogon.exe - 0x00F2248A->_
             inline - len(1) winlogon.exe - 0x00F22498->_
             inline - len(1) winlogon.exe - 0x00F224A4->_
             inline - len(1) winlogon.exe - 0x00F224E3->_
             inline - len(1) winlogon.exe - 0x00F224F3->_
             inline - len(1) winlogon.exe - 0x00F22508->0x00F21AC1[C:\Windows\System32\winlogon.exe]
             inline - len(17) winlogon.exe - 0x00F2253A->_
             inline - len(13) winlogon.exe - 0x00F22552->_
             inline - len(5) winlogon.exe - 0x00F22566->_
             inline - len(1) winlogon.exe - 0x00F2257A->_
             inline - len(6) winlogon.exe - 0x00F22584->_
             inline - len(1) winlogon.exe - 0x00F2259F->_
             inline - len(1) winlogon.exe - 0x00F225EA->_
             inline - len(1) winlogon.exe - 0x00F2260E->_
             inline - len(1) winlogon.exe - 0x00F22624->_
             inline - len(1) winlogon.exe - 0x00F2262A->_
             inline - len(1) winlogon.exe - 0x00F22633->_
             inline - len(11) winlogon.exe - 0x00F2264B->_
             inline - len(1) winlogon.exe - 0x00F2266B->_
             inline - len(1) winlogon.exe - 0x00F22671->_
             inline - len(1) winlogon.exe - 0x00F22677->_
             inline - len(1) winlogon.exe - 0x00F22684->_
             inline - len(1) winlogon.exe - 0x00F226C2->_
             inline - len(1) winlogon.exe - 0x00F226C8->_
             inline - len(1) winlogon.exe - 0x00F226EF->_
             inline - len(1) winlogon.exe - 0x00F226F5->_
             inline - len(1) winlogon.exe - 0x00F22702->_
             inline - len(1) winlogon.exe - 0x00F22711->_
             inline - len(1) winlogon.exe - 0x00F22717->_
             inline - len(1) winlogon.exe - 0x00F2271F->_
             inline - len(1) winlogon.exe - 0x00F22729->_
             inline - len(1) winlogon.exe - 0x00F22733->_
             inline - len(6) winlogon.exe - 0x00F22740->_
             inline - len(1) winlogon.exe - 0x00F22760->_
             inline - len(1) winlogon.exe - 0x00F22792->_
             inline - len(1) winlogon.exe - 0x00F2279C->_
             inline - len(1) winlogon.exe - 0x00F227A2->_
             inline - len(1) winlogon.exe - 0x00F227B3->_
             inline - len(1) winlogon.exe - 0x00F227D0->_
             inline - len(1) winlogon.exe - 0x00F22810->_
             inline - len(1) winlogon.exe - 0x00F22836->_
             inline - len(1) winlogon.exe - 0x00F2286C->_
             inline - len(1) winlogon.exe - 0x00F2289B->_
             inline - len(1) winlogon.exe - 0x00F228CE->_
             inline - len(1) winlogon.exe - 0x00F228D4->_
             inline - len(1) winlogon.exe - 0x00F228E8->_
             inline - len(1) winlogon.exe - 0x00F2291C->_
             inline - len(1) winlogon.exe - 0x00F22938->_
             inline - len(1) winlogon.exe - 0x00F229F9->_
             inline - len(1) winlogon.exe - 0x00F22A60->_
             inline - len(1) winlogon.exe - 0x00F22A72->0x00F23510[C:\Windows\System32\winlogon.exe]
             inline - len(9) winlogon.exe - 0x00F22AEA->_
             inline - len(1) winlogon.exe - 0x00F22B0A->_
             inline - len(1) winlogon.exe - 0x00F22B66->_
             inline - len(1) winlogon.exe - 0x00F22B76->_
             inline - len(13) winlogon.exe - 0x00F22B7E->_
             inline - len(13) winlogon.exe - 0x00F22BA2->_
             inline - len(1) winlogon.exe - 0x00F22C83->_
             inline - len(1) winlogon.exe - 0x00F22CB9->_
             inline - len(1) winlogon.exe - 0x00F22CE3->_
             inline - len(1) winlogon.exe - 0x00F22D37->_
             inline - len(1) winlogon.exe - 0x00F22D82->_
             inline - len(1) winlogon.exe - 0x00F22D96->_
             inline - len(1) winlogon.exe - 0x00F22E21->_
             inline - len(6) winlogon.exe - 0x00F22E42->_
             inline - len(1) winlogon.exe - 0x00F22E5D->_
             inline - len(1) winlogon.exe - 0x00F22E7A->_
             inline - len(1) winlogon.exe - 0x00F22E8E->_
             inline - len(1) winlogon.exe - 0x00F22E9B->_
             inline - len(1) winlogon.exe - 0x00F22EA2->_
             inline - len(1) winlogon.exe - 0x00F22EA8->_
             inline - len(1) winlogon.exe - 0x00F22EB0->_
             inline - len(1) winlogon.exe - 0x00F22EB6->_
             inline - len(1) winlogon.exe - 0x00F22EC0->_
             inline - len(6) winlogon.exe - 0x00F22ECB->_
             inline - len(1) winlogon.exe - 0x00F22EE0->_
             inline - len(1) winlogon.exe - 0x00F22EEE->_
             inline - len(1) winlogon.exe - 0x00F22EF4->_
             inline - len(1) winlogon.exe - 0x00F22EFA->_
             inline - len(1) winlogon.exe - 0x00F22F04->_
             inline - len(1) winlogon.exe - 0x00F22F40->_
             inline - len(1) winlogon.exe - 0x00F22F47->_
             inline - len(1) winlogon.exe - 0x00F22F54->_
             inline - len(1) winlogon.exe - 0x00F22F5A->_
             inline - len(1) winlogon.exe - 0x00F22F67->_
             inline - len(13) winlogon.exe - 0x00F2331A->_
             inline - len(1) winlogon.exe - 0x00F2333A->_
             inline - len(1) winlogon.exe - 0x00F2349E->_
             inline - len(1) winlogon.exe - 0x00F234A5->_
             inline - len(1) winlogon.exe - 0x00F234B1->_
             inline - len(1) winlogon.exe - 0x00F234D9->_
             inline - len(1) winlogon.exe - 0x00F23509->_
             inline - len(1) winlogon.exe - 0x00F23524->_
             inline - len(1) winlogon.exe - 0x00F2353D->_
             inline - len(1) winlogon.exe - 0x00F23588->_
             inline - len(1) winlogon.exe - 0x00F23597->_
             inline - len(1) winlogon.exe - 0x00F235EF->_
             inline - len(1) winlogon.exe - 0x00F235FC->_
             inline - len(1) winlogon.exe - 0x00F23608->_
             inline - len(6) winlogon.exe - 0x00F23674->_
             inline - len(1) winlogon.exe - 0x00F2368F->_
             inline - len(1) winlogon.exe - 0x00F236B2->_
             inline - len(1) winlogon.exe - 0x00F236C6->_
             inline - len(1) winlogon.exe - 0x00F236D2->_
             inline - len(1) winlogon.exe - 0x00F236FA->_
             inline - len(5) winlogon.exe - 0x00F23736->_
             inline - len(6) winlogon.exe - 0x00F2379E->_
             inline - len(1) winlogon.exe - 0x00F237C1->_
             inline - len(1) winlogon.exe - 0x00F23825->_
             inline - len(1) winlogon.exe - 0x00F23845->0x00F2187C[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F2385F->_
             inline - len(1) winlogon.exe - 0x00F2386A->_
             inline - len(1) winlogon.exe - 0x00F2388C->_
             inline - len(1) winlogon.exe - 0x00F23895->_
             inline - len(1) winlogon.exe - 0x00F238EA->_
             inline - len(1) winlogon.exe - 0x00F2392E->_
             inline - len(1) winlogon.exe - 0x00F2395B->_
             inline - len(5) winlogon.exe - 0x00F2398E->_
             inline - len(6) winlogon.exe - 0x00F239A6->_
             inline - len(1) winlogon.exe - 0x00F239EF->_
             inline - len(1) winlogon.exe - 0x00F239F5->_
             inline - len(1) winlogon.exe - 0x00F23A09->_
             inline - len(9) winlogon.exe - 0x00F23A62->_
             inline - len(1) winlogon.exe - 0x00F23A82->_
             inline - len(1) winlogon.exe - 0x00F23ADE->_
             inline - len(1) winlogon.exe - 0x00F23AEE->_
             inline - len(13) winlogon.exe - 0x00F23AF6->_
             inline - len(5) winlogon.exe - 0x00F23B1A->_
             inline - len(53) winlogon.exe - 0x00F23B96->_
             inline - len(1) winlogon.exe - 0x00F23D32->_
             inline - len(1) winlogon.exe - 0x00F23D38->_
             inline - len(1) winlogon.exe - 0x00F23D3E->_
             inline - len(13) winlogon.exe - 0x00F24012->_
             inline - len(1) winlogon.exe - 0x00F24032->_
             inline - len(1) winlogon.exe - 0x00F24109->_
             inline - len(1) winlogon.exe - 0x00F2411C->_
             inline - len(1) winlogon.exe - 0x00F2417F->_
             inline - len(1) winlogon.exe - 0x00F24212->_
             inline - len(5) winlogon.exe - 0x00F2421A->_
             inline - len(6) winlogon.exe - 0x00F24281->_
             inline - len(1) winlogon.exe - 0x00F2429F->_
             inline - len(1) winlogon.exe - 0x00F242A8->_
             inline - len(1) winlogon.exe - 0x00F242E1->_
             inline - len(1) winlogon.exe - 0x00F242E7->_
             inline - len(53) winlogon.exe - 0x00F242FD->_
             inline - len(1) winlogon.exe - 0x00F2433D->_
             inline - len(1) winlogon.exe - 0x00F24362->_
             inline - len(6) winlogon.exe - 0x00F2436C->_
             inline - len(1) winlogon.exe - 0x00F24386->_
             inline - len(1) winlogon.exe - 0x00F2438C->_
             inline - len(1) winlogon.exe - 0x00F2439E->_
             inline - len(1) winlogon.exe - 0x00F243AE->_
             inline - len(1) winlogon.exe - 0x00F243C3->_
             inline - len(1) winlogon.exe - 0x00F243D7->_
             inline - len(1) winlogon.exe - 0x00F243EE->_
             inline - len(1) winlogon.exe - 0x00F24403->_
             inline - len(1) winlogon.exe - 0x00F24409->_
             inline - len(1) winlogon.exe - 0x00F2441D->_
             inline - len(5) winlogon.exe - 0x00F24466->_
             inline - len(1) winlogon.exe - 0x00F244AB->_
             inline - len(1) winlogon.exe - 0x00F2454B->_
             inline - len(1) winlogon.exe - 0x00F2456A->_
             inline - len(1) winlogon.exe - 0x00F24571->_
             inline - len(1) winlogon.exe - 0x00F24583->_
             inline - len(1) winlogon.exe - 0x00F245B4->_
             inline - len(1) winlogon.exe - 0x00F24626->_
             inline - len(1) winlogon.exe - 0x00F2462C->_
             inline - len(1) winlogon.exe - 0x00F2463D->_
             inline - len(1) winlogon.exe - 0x00F24659->_
             inline - len(1) winlogon.exe - 0x00F246D6->_
             inline - len(1) winlogon.exe - 0x00F2470C->_
             inline - len(1) winlogon.exe - 0x00F24781->_
             inline - len(1) winlogon.exe - 0x00F248A4->_
             inline - len(1) winlogon.exe - 0x00F248BB->_
             inline - len(1) winlogon.exe - 0x00F2490A->_
             inline - len(1) winlogon.exe - 0x00F24928->_
             inline - len(1) winlogon.exe - 0x00F2492E->_
             inline - len(1) winlogon.exe - 0x00F2493F->_
             inline - len(1) winlogon.exe - 0x00F2497A->_
             inline - len(1) winlogon.exe - 0x00F24998->_
             inline - len(1) winlogon.exe - 0x00F249EA->_
             inline - len(1) winlogon.exe - 0x00F24A6F->_
             inline - len(1) winlogon.exe - 0x00F24A9D->_
             inline - len(1) winlogon.exe - 0x00F24ABA->_
             inline - len(1) winlogon.exe - 0x00F24AC5->_
             inline - len(1) winlogon.exe - 0x00F24AE3->_
             inline - len(1) winlogon.exe - 0x00F24AFC->_
             inline - len(1) winlogon.exe - 0x00F24B29->_
             inline - len(1) winlogon.exe - 0x00F24BCE->_
             inline - len(1) winlogon.exe - 0x00F24C00->_
             inline - len(1) winlogon.exe - 0x00F24C42->_
             inline - len(1) winlogon.exe - 0x00F24C6A->_
             inline - len(1) winlogon.exe - 0x00F24C9C->_
             inline - len(1) winlogon.exe - 0x00F24CA7->_
             inline - len(1) winlogon.exe - 0x00F24CB9->_
             inline - len(1) winlogon.exe - 0x00F24CD9->_
             inline - len(1) winlogon.exe - 0x00F24D22->_
             inline - len(1) winlogon.exe - 0x00F24D75->_
             inline - len(6) winlogon.exe - 0x00F24DB5->_
             inline - len(1) winlogon.exe - 0x00F24DD9->_
             inline - len(1) winlogon.exe - 0x00F24E56->_
             inline - len(1) winlogon.exe - 0x00F24E6C->_
             inline - len(1) winlogon.exe - 0x00F24E78->_
             inline - len(1) winlogon.exe - 0x00F24E88->_
             inline - len(1) winlogon.exe - 0x00F24E95->_
             inline - len(1) winlogon.exe - 0x00F24E9B->_
             inline - len(1) winlogon.exe - 0x00F24EA5->_
             inline - len(1) winlogon.exe - 0x00F24EAC->_
             inline - len(1) winlogon.exe - 0x00F24EC1->_
             inline - len(1) winlogon.exe - 0x00F24EE7->0x00F24EE3[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F24F22->_
             inline - len(1) winlogon.exe - 0x00F24F49->_
             inline - len(1) winlogon.exe - 0x00F24F63->_
             inline - len(1) winlogon.exe - 0x00F24FB0->_
             inline - len(1) winlogon.exe - 0x00F24FBB->_
             inline - len(1) winlogon.exe - 0x00F24FD0->_
             inline - len(1) winlogon.exe - 0x00F24FF8->_
             inline - len(6) winlogon.exe - 0x00F25014->_
             inline - len(1) winlogon.exe - 0x00F2502E->_
             inline - len(6) winlogon.exe - 0x00F25040->_
             inline - len(1) winlogon.exe - 0x00F2506D->_
             inline - len(1) winlogon.exe - 0x00F25082->_
             inline - len(6) winlogon.exe - 0x00F25094->_
             inline - len(1) winlogon.exe - 0x00F250CA->_
             inline - len(1) winlogon.exe - 0x00F250DF->_
             inline - len(6) winlogon.exe - 0x00F250F1->_
             inline - len(1) winlogon.exe - 0x00F2512E->_
             inline - len(1) winlogon.exe - 0x00F25134->_
             inline - len(1) winlogon.exe - 0x00F252F0->_
             inline - len(1) winlogon.exe - 0x00F25349->_
             inline - len(1) winlogon.exe - 0x00F25366->_
             inline - len(1) winlogon.exe - 0x00F2538A->_
             inline - len(1) winlogon.exe - 0x00F2539E->_
             inline - len(1) winlogon.exe - 0x00F253D2->_
             inline - len(1) winlogon.exe - 0x00F253F1->_
             inline - len(1) winlogon.exe - 0x00F25432->_
             inline - len(1) winlogon.exe - 0x00F25452->_
             inline - len(1) winlogon.exe - 0x00F2549F->_
             inline - len(6) winlogon.exe - 0x00F254AA->_
             inline - len(11) winlogon.exe - 0x00F254E4->_
             inline - len(6) winlogon.exe - 0x00F25560->_
             inline - len(1) winlogon.exe - 0x00F255A4->_
             inline - len(1) winlogon.exe - 0x00F255C0->_
             inline - len(5) winlogon.exe - 0x00F25606->_
             inline - len(6) winlogon.exe - 0x00F2561E->_
             inline - len(1) winlogon.exe - 0x00F25830->_
             inline - len(1) winlogon.exe - 0x00F25839->_
             inline - len(1) winlogon.exe - 0x00F25855->_
             inline - len(1) winlogon.exe - 0x00F2586D->_
             inline - len(1) winlogon.exe - 0x00F258D8->_
             inline - len(1) winlogon.exe - 0x00F258E6->_
             inline - len(1) winlogon.exe - 0x00F2591D->_
             inline - len(1) winlogon.exe - 0x00F25951->_
             inline - len(1) winlogon.exe - 0x00F25965->_
             inline - len(1) winlogon.exe - 0x00F25A72->_
             inline - len(1) winlogon.exe - 0x00F25AB6->_
             inline - len(6) winlogon.exe - 0x00F25AC1->_
             inline - len(1) winlogon.exe - 0x00F25AE8->_
             inline - len(1) winlogon.exe - 0x00F25AF1->_
             inline - len(1) winlogon.exe - 0x00F25B00->_
             inline - len(11) winlogon.exe - 0x00F25B0A->_
             inline - len(1) winlogon.exe - 0x00F25B50->_
             inline - len(1) winlogon.exe - 0x00F25BA6->_
             inline - len(6) winlogon.exe - 0x00F25BF0->_
             inline - len(1) winlogon.exe - 0x00F25C08->_
             inline - len(1) winlogon.exe - 0x00F25C4A->_
             inline - len(1) winlogon.exe - 0x00F25CD8->_
             inline - len(1) winlogon.exe - 0x00F25CE2->_
             inline - len(6) winlogon.exe - 0x00F25CEC->_
             inline - len(1) winlogon.exe - 0x00F25D07->_
             inline - len(1) winlogon.exe - 0x00F25DB0->_
             inline - len(1) winlogon.exe - 0x00F25E0A->_
             inline - len(1) winlogon.exe - 0x00F25EFD->_
             inline - len(1) winlogon.exe - 0x00F25F83->_
             inline - len(1) winlogon.exe - 0x00F25F8F->_
             inline - len(1) winlogon.exe - 0x00F25FA7->_
             inline - len(1) winlogon.exe - 0x00F25FB8->_
             inline - len(1) winlogon.exe - 0x00F25FFA->_
             inline - len(6) winlogon.exe - 0x00F2601A->_
             inline - len(1) winlogon.exe - 0x00F26035->_
             inline - len(6) winlogon.exe - 0x00F26060->_
             inline - len(1) winlogon.exe - 0x00F2607B->_
             inline - len(6) winlogon.exe - 0x00F26096->_
             inline - len(1) winlogon.exe - 0x00F260DC->_
             inline - len(1) winlogon.exe - 0x00F26130->_
             inline - len(1) winlogon.exe - 0x00F26163->_
             inline - len(1) winlogon.exe - 0x00F2617D->_
             inline - len(1) winlogon.exe - 0x00F26186->0x3BD6FF00
             inline - len(1) winlogon.exe - 0x00F261BC->_
             inline - len(1) winlogon.exe - 0x00F261DB->_
             inline - len(1) winlogon.exe - 0x00F26212->_
             inline - len(1) winlogon.exe - 0x00F2629A->_
             inline - len(6) winlogon.exe - 0x00F262A9->_
             inline - len(1) winlogon.exe - 0x00F262C4->_
             inline - len(1) winlogon.exe - 0x00F262FC->_
             inline - len(1) winlogon.exe - 0x00F26326->_
             inline - len(1) winlogon.exe - 0x00F2633F->_
             inline - len(6) winlogon.exe - 0x00F26354->_
             inline - len(1) winlogon.exe - 0x00F263C2->_
             inline - len(1) winlogon.exe - 0x00F263E2->_
             inline - len(1) winlogon.exe - 0x00F263E8->_
             inline - len(1) winlogon.exe - 0x00F26405->_
             inline - len(1) winlogon.exe - 0x00F2640B->_
             inline - len(1) winlogon.exe - 0x00F2641C->_
             inline - len(1) winlogon.exe - 0x00F2644A->_
             inline - len(21) winlogon.exe - 0x00F26452->_
             inline - len(1) winlogon.exe - 0x00F26476->_
             inline - len(1) winlogon.exe - 0x00F2647D->_
             inline - len(1) winlogon.exe - 0x00F26486->_
             inline - len(1) winlogon.exe - 0x00F2648C->_
             inline - len(1) winlogon.exe - 0x00F26551->_
             inline - len(1) winlogon.exe - 0x00F26594->_
             inline - len(1) winlogon.exe - 0x00F265D1->_
             inline - len(1) winlogon.exe - 0x00F265E6->_
             inline - len(1) winlogon.exe - 0x00F26682->_
             inline - len(1) winlogon.exe - 0x00F266A8->_
             inline - len(1) winlogon.exe - 0x00F266CD->_
             inline - len(1) winlogon.exe - 0x00F266F5->_
             inline - len(1) winlogon.exe - 0x00F26708->_
             inline - len(6) winlogon.exe - 0x00F26795->_
             inline - len(1) winlogon.exe - 0x00F267C5->_
             inline - len(1) winlogon.exe - 0x00F26819->_
             inline - len(1) winlogon.exe - 0x00F26820->_
             inline - len(1) winlogon.exe - 0x00F2685D->_
             inline - len(1) winlogon.exe - 0x00F26863->_
             inline - len(1) winlogon.exe - 0x00F26880->_
             inline - len(1) winlogon.exe - 0x00F26886->_
             inline - len(6) winlogon.exe - 0x00F268AD->_
             inline - len(1) winlogon.exe - 0x00F268BE->_
             inline - len(1) winlogon.exe - 0x00F268F0->_
             inline - len(1) winlogon.exe - 0x00F26912->_
             inline - len(1) winlogon.exe - 0x00F2691A->_
             inline - len(6) winlogon.exe - 0x00F26969->_
             inline - len(1) winlogon.exe - 0x00F2698F->_
             inline - len(1) winlogon.exe - 0x00F269CD->_
             inline - len(1) winlogon.exe - 0x00F269DA->_
             inline - len(1) winlogon.exe - 0x00F26A01->_
             inline - len(1) winlogon.exe - 0x00F26A1C->_
             inline - len(1) winlogon.exe - 0x00F26A2F->_
             inline - len(1) winlogon.exe - 0x00F26A43->_
             inline - len(1) winlogon.exe - 0x00F26A4F->_
             inline - len(1) winlogon.exe - 0x00F26A7B->_
             inline - len(1) winlogon.exe - 0x00F26A87->_
             inline - len(1) winlogon.exe - 0x00F26A9B->_
             inline - len(1) winlogon.exe - 0x00F26AAB->_
             inline - len(1) winlogon.exe - 0x00F26AD8->_
             inline - len(1) winlogon.exe - 0x00F26AE4->_
             inline - len(1) winlogon.exe - 0x00F26AFD->_
             inline - len(1) winlogon.exe - 0x00F26B09->_
             inline - len(1) winlogon.exe - 0x00F26B34->_
             inline - len(1) winlogon.exe - 0x00F26B55->_
             inline - len(1) winlogon.exe - 0x00F26B70->_
             inline - len(1) winlogon.exe - 0x00F26B88->_
             inline - len(1) winlogon.exe - 0x00F26BD6->_
             inline - len(1) winlogon.exe - 0x00F26C1A->_
             inline - len(1) winlogon.exe - 0x00F26C2E->_
             inline - len(1) winlogon.exe - 0x00F26C71->_
             inline - len(1) winlogon.exe - 0x00F26CB2->_
             inline - len(1) winlogon.exe - 0x00F26CC6->_
             inline - len(1) winlogon.exe - 0x00F26D22->_
             inline - len(1) winlogon.exe - 0x00F26D49->_
             inline - len(1) winlogon.exe - 0x00F26D4F->_
             inline - len(1) winlogon.exe - 0x00F26D60->_
             inline - len(1) winlogon.exe - 0x00F26D80->_
             inline - len(1) winlogon.exe - 0x00F26D9D->_
             inline - len(1) winlogon.exe - 0x00F26DA3->_
             inline - len(1) winlogon.exe - 0x00F26DA9->_
             inline - len(1) winlogon.exe - 0x00F26ED6->_
             inline - len(9) winlogon.exe - 0x00F26EEA->_
             inline - len(1) winlogon.exe - 0x00F26F0A->_
             inline - len(1) winlogon.exe - 0x00F26F66->_
             inline - len(1) winlogon.exe - 0x00F26F76->_
             inline - len(13) winlogon.exe - 0x00F26F82->_
             inline - len(17) winlogon.exe - 0x00F26FAA->_
             inline - len(1) winlogon.exe - 0x00F27122->_
             inline - len(1) winlogon.exe - 0x00F27172->_
             inline - len(1) winlogon.exe - 0x00F271CD->_
             inline - len(1) winlogon.exe - 0x00F27242->_
             inline - len(1) winlogon.exe - 0x00F2728E->_
             inline - len(1) winlogon.exe - 0x00F272A1->_
             inline - len(1) winlogon.exe - 0x00F272B3->_
             inline - len(1) winlogon.exe - 0x00F272D2->_
             inline - len(6) winlogon.exe - 0x00F272EF->_
             inline - len(1) winlogon.exe - 0x00F273AA->_
             inline - len(1) winlogon.exe - 0x00F27438->_
             inline - len(1) winlogon.exe - 0x00F2746E->_
             inline - len(1) winlogon.exe - 0x00F274A6->_
             inline - len(1) winlogon.exe - 0x00F274EB->_
             inline - len(1) winlogon.exe - 0x00F2752A->_
             inline - len(1) winlogon.exe - 0x00F2755A->_
             inline - len(1) winlogon.exe - 0x00F27561->_
             inline - len(1) winlogon.exe - 0x00F2757A->_
             inline - len(1) winlogon.exe - 0x00F275B3->_
             inline - len(1) winlogon.exe - 0x00F275D5->_
             inline - len(1) winlogon.exe - 0x00F2761D->_
             inline - len(1) winlogon.exe - 0x00F2763F->_
             inline - len(1) winlogon.exe - 0x00F27654->_
             inline - len(1) winlogon.exe - 0x00F27676->_
             inline - len(1) winlogon.exe - 0x00F27681->_
             inline - len(1) winlogon.exe - 0x00F276B2->_
             inline - len(1) winlogon.exe - 0x00F276FE->_
             inline - len(1) winlogon.exe - 0x00F27704->_
             inline - len(1) winlogon.exe - 0x00F2770A->_
             inline - len(1) winlogon.exe - 0x00F277B2->_
             inline - len(1) winlogon.exe - 0x00F278B6->_
             inline - len(1) winlogon.exe - 0x00F278D7->_
             inline - len(1) winlogon.exe - 0x00F27909->_
             inline - len(1) winlogon.exe - 0x00F27977->0x00F2716A[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F2799A->0x00F2716A[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F27A23->_
             inline - len(1) winlogon.exe - 0x00F27B4A->_
             inline - len(1) winlogon.exe - 0x00F27B89->_
             inline - len(1) winlogon.exe - 0x00F27BB5->_
             inline - len(6) winlogon.exe - 0x00F27BC8->_
             inline - len(1) winlogon.exe - 0x00F27BE5->_
             inline - len(1) winlogon.exe - 0x00F27C47->_
             inline - len(1) winlogon.exe - 0x00F27C72->_
             inline - len(1) winlogon.exe - 0x00F27C90->_
             inline - len(1) winlogon.exe - 0x00F27CA8->_
             inline - len(1) winlogon.exe - 0x00F27CBB->_
             inline - len(1) winlogon.exe - 0x00F27CC3->_
             inline - len(1) winlogon.exe - 0x00F27CCE->_
             inline - len(1) winlogon.exe - 0x00F27CDC->0x00F229EC[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F27D96->_
             inline - len(1) winlogon.exe - 0x00F27DFA->_
             inline - len(1) winlogon.exe - 0x00F27E69->_
             inline - len(6) winlogon.exe - 0x00F27E76->_
             inline - len(1) winlogon.exe - 0x00F27E91->_
             inline - len(1) winlogon.exe - 0x00F27EB5->_
             inline - len(1) winlogon.exe - 0x00F27EC1->_
             inline - len(1) winlogon.exe - 0x00F27ED3->_
             inline - len(1) winlogon.exe - 0x00F27EDD->_
             inline - len(1) winlogon.exe - 0x00F27EF2->_
             inline - len(1) winlogon.exe - 0x00F27F07->_
             inline - len(1) winlogon.exe - 0x00F27F0E->_
             inline - len(1) winlogon.exe - 0x00F27F21->_
             inline - len(1) winlogon.exe - 0x00F27F3D->_
             inline - len(1) winlogon.exe - 0x00F27F85->_
             inline - len(1) winlogon.exe - 0x00F27F9E->_
             inline - len(1) winlogon.exe - 0x00F27FAD->_
             inline - len(1) winlogon.exe - 0x00F27FB9->_
             inline - len(6) winlogon.exe - 0x00F27FCB->_
             inline - len(1) winlogon.exe - 0x00F27FE6->_
             inline - len(1) winlogon.exe - 0x00F2805E->_
             inline - len(1) winlogon.exe - 0x00F2807F->_
             inline - len(1) winlogon.exe - 0x00F2809B->_
             inline - len(1) winlogon.exe - 0x00F280CC->_
             inline - len(1) winlogon.exe - 0x00F280E1->_
             inline - len(1) winlogon.exe - 0x00F28131->_
             inline - len(1) winlogon.exe - 0x00F2814B->_
             inline - len(1) winlogon.exe - 0x00F2817D->_
             inline - len(1) winlogon.exe - 0x00F28193->_
             inline - len(1) winlogon.exe - 0x00F281B3->_
             inline - len(1) winlogon.exe - 0x00F281E4->_
             inline - len(1) winlogon.exe - 0x00F28210->_
             inline - len(1) winlogon.exe - 0x00F28223->_
             inline - len(1) winlogon.exe - 0x00F28280->_
             inline - len(1) winlogon.exe - 0x00F282A4->0x00F27494[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F282C9->0x00F27494[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F2836A->_
             inline - len(1) winlogon.exe - 0x00F2837E->_
             inline - len(6) winlogon.exe - 0x00F283DF->_
             inline - len(1) winlogon.exe - 0x00F28402->_
             inline - len(1) winlogon.exe - 0x00F28439->_
             inline - len(1) winlogon.exe - 0x00F2844A->_
             inline - len(1) winlogon.exe - 0x00F28482->_
             inline - len(1) winlogon.exe - 0x00F284A4->_
             inline - len(6) winlogon.exe - 0x00F284C6->_
             inline - len(1) winlogon.exe - 0x00F284E1->_
             inline - len(1) winlogon.exe - 0x00F2853E->_
             inline - len(1) winlogon.exe - 0x00F28560->_
             inline - len(6) winlogon.exe - 0x00F2857A->_
             inline - len(1) winlogon.exe - 0x00F2858D->_
             inline - len(1) winlogon.exe - 0x00F2859A->_
             inline - len(1) winlogon.exe - 0x00F285A4->_
             inline - len(1) winlogon.exe - 0x00F285AE->_
             inline - len(1) winlogon.exe - 0x00F285BE->_
             inline - len(1) winlogon.exe - 0x00F285C8->_
             inline - len(6) winlogon.exe - 0x00F285DC->_
             inline - len(1) winlogon.exe - 0x00F285EB->_
             inline - len(1) winlogon.exe - 0x00F28600->_
             inline - len(1) winlogon.exe - 0x00F28636->_
             inline - len(1) winlogon.exe - 0x00F286C2->_
             inline - len(1) winlogon.exe - 0x00F286E6->_
             inline - len(6) winlogon.exe - 0x00F2871A->_
             inline - len(6) winlogon.exe - 0x00F28732->_
             inline - len(1) winlogon.exe - 0x00F2874D->_
             inline - len(1) winlogon.exe - 0x00F28768->_
             inline - len(1) winlogon.exe - 0x00F2878E->_
             inline - len(1) winlogon.exe - 0x00F28794->_
             inline - len(1) winlogon.exe - 0x00F287D7->_
             inline - len(1) winlogon.exe - 0x00F287E0->_
             inline - len(1) winlogon.exe - 0x00F287F9->_
             inline - len(1) winlogon.exe - 0x00F28800->_
             inline - len(11) winlogon.exe - 0x00F2883F->_
             inline - len(1) winlogon.exe - 0x00F28862->_
             inline - len(1) winlogon.exe - 0x00F2892A->_
             inline - len(1) winlogon.exe - 0x00F28957->_
             inline - len(1) winlogon.exe - 0x00F28999->_
             inline - len(1) winlogon.exe - 0x00F289A0->_
             inline - len(1) winlogon.exe - 0x00F28A0A->_
             inline - len(1) winlogon.exe - 0x00F28A1E->_
             inline - len(1) winlogon.exe - 0x00F28A4A->_
             inline - len(1) winlogon.exe - 0x00F28A8A->_
             inline - len(1) winlogon.exe - 0x00F28A9E->_
             inline - len(1) winlogon.exe - 0x00F28AC2->_
             inline - len(1) winlogon.exe - 0x00F28AC9->_
             inline - len(1) winlogon.exe - 0x00F28B02->_
             inline - len(11) winlogon.exe - 0x00F28B29->_
             inline - len(1) winlogon.exe - 0x00F28B5B->_
             inline - len(6) winlogon.exe - 0x00F28B9C->_
             inline - len(1) winlogon.exe - 0x00F28C20->_
             inline - len(1) winlogon.exe - 0x00F28C2B->_
             inline - len(1) winlogon.exe - 0x00F28C3D->_
             inline - len(1) winlogon.exe - 0x00F28C7B->_
             inline - len(1) winlogon.exe - 0x00F28CFD->_
             inline - len(1) winlogon.exe - 0x00F28D38->_
             inline - len(1) winlogon.exe - 0x00F28D4F->_
             inline - len(6) winlogon.exe - 0x00F28D58->_
             inline - len(1) winlogon.exe - 0x00F28D63->_
             inline - len(1) winlogon.exe - 0x00F28D9A->_
             inline - len(6) winlogon.exe - 0x00F28DAE->_
             inline - len(1) winlogon.exe - 0x00F28DC9->_
             inline - len(11) winlogon.exe - 0x00F28DED->_
             inline - len(1) winlogon.exe - 0x00F28E11->_
             inline - len(1) winlogon.exe - 0x00F28E25->_
             inline - len(1) winlogon.exe - 0x00F28E2B->_
             inline - len(1) winlogon.exe - 0x00F28E38->_
             inline - len(1) winlogon.exe - 0x00F28E3E->_
             inline - len(1) winlogon.exe - 0x00F28E47->_
             inline - len(1) winlogon.exe - 0x00F28E5C->_
             inline - len(1) winlogon.exe - 0x00F28E70->_
             inline - len(1) winlogon.exe - 0x00F28E76->_
             inline - len(1) winlogon.exe - 0x00F28E7C->_
             inline - len(1) winlogon.exe - 0x00F28EA2->_
             inline - len(11) winlogon.exe - 0x00F28EAC->_
             inline - len(1) winlogon.exe - 0x00F28F15->_
             inline - len(1) winlogon.exe - 0x00F28F62->_
             inline - len(1) winlogon.exe - 0x00F28F82->_
             inline - len(1) winlogon.exe - 0x00F28F8D->_
             inline - len(1) winlogon.exe - 0x00F28FD1->_
             inline - len(1) winlogon.exe - 0x00F28FEC->_
             inline - len(1) winlogon.exe - 0x00F29003->0x00F22910[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F29026->_
             inline - len(1) winlogon.exe - 0x00F29047->_
             inline - len(1) winlogon.exe - 0x00F29051->_
             inline - len(1) winlogon.exe - 0x00F2911A->_
             inline - len(1) winlogon.exe - 0x00F29147->_
             inline - len(1) winlogon.exe - 0x00F29183->_
             inline - len(1) winlogon.exe - 0x00F291DF->_
             inline - len(1) winlogon.exe - 0x00F29217->_
             inline - len(1) winlogon.exe - 0x00F2922A->_
             inline - len(1) winlogon.exe - 0x00F29231->_
             inline - len(6) winlogon.exe - 0x00F2924D->_
             inline - len(6) winlogon.exe - 0x00F2929B->_
             inline - len(1) winlogon.exe - 0x00F292C2->_
             inline - len(1) winlogon.exe - 0x00F292D2->_
             inline - len(1) winlogon.exe - 0x00F292E7->_
             inline - len(1) winlogon.exe - 0x00F29332->_
             inline - len(6) winlogon.exe - 0x00F2937A->_
             inline - len(1) winlogon.exe - 0x00F2939F->0x00F22051[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F293AE->_
             inline - len(6) winlogon.exe - 0x00F293C8->_
             inline - len(6) winlogon.exe - 0x00F293F4->_
             inline - len(1) winlogon.exe - 0x00F29407->_
             inline - len(1) winlogon.exe - 0x00F2940E->_
             inline - len(1) winlogon.exe - 0x00F2941A->_
             inline - len(1) winlogon.exe - 0x00F29431->_
             inline - len(1) winlogon.exe - 0x00F2943D->_
             inline - len(1) winlogon.exe - 0x00F29449->_
             inline - len(1) winlogon.exe - 0x00F2945C->_
             inline - len(1) winlogon.exe - 0x00F29466->_
             inline - len(1) winlogon.exe - 0x00F29482->_
             inline - len(1) winlogon.exe - 0x00F29494->_
             inline - len(1) winlogon.exe - 0x00F2949A->_
             inline - len(1) winlogon.exe - 0x00F294A9->_
             inline - len(1) winlogon.exe - 0x00F294B8->_
             inline - len(1) winlogon.exe - 0x00F294BE->_
             inline - len(1) winlogon.exe - 0x00F294D0->_
             inline - len(1) winlogon.exe - 0x00F294D6->_
             inline - len(1) winlogon.exe - 0x00F294DC->_
             inline - len(1) winlogon.exe - 0x00F2950D->_
             inline - len(1) winlogon.exe - 0x00F29518->_
             inline - len(1) winlogon.exe - 0x00F29524->_
             inline - len(1) winlogon.exe - 0x00F2952A->_
             inline - len(1) winlogon.exe - 0x00F29530->_
             inline - len(6) winlogon.exe - 0x00F2953C->_
             inline - len(1) winlogon.exe - 0x00F29548->_
             inline - len(1) winlogon.exe - 0x00F2954E->_
             inline - len(1) winlogon.exe - 0x00F29563->_
             inline - len(1) winlogon.exe - 0x00F29569->_
             inline - len(1) winlogon.exe - 0x00F295F0->_
             inline - len(6) winlogon.exe - 0x00F29712->_
             inline - len(1) winlogon.exe - 0x00F2972F->_
             inline - len(1) winlogon.exe - 0x00F2976A->_
             inline - len(1) winlogon.exe - 0x00F29775->_
             inline - len(1) winlogon.exe - 0x00F297C4->_
             inline - len(1) winlogon.exe - 0x00F297D0->_
             inline - len(1) winlogon.exe - 0x00F297EF->_
             inline - len(1) winlogon.exe - 0x00F29811->_
             inline - len(1) winlogon.exe - 0x00F2982B->_
             inline - len(1) winlogon.exe - 0x00F29831->_
             inline - len(1) winlogon.exe - 0x00F298B2->_
             inline - len(1) winlogon.exe - 0x00F298FF->_
             inline - len(6) winlogon.exe - 0x00F29A0E->_
             inline - len(1) winlogon.exe - 0x00F29AA1->_
             inline - len(11) winlogon.exe - 0x00F29AAE->_
             inline - len(1) winlogon.exe - 0x00F29B3D->_
             inline - len(1) winlogon.exe - 0x00F29B7B->_
             inline - len(1) winlogon.exe - 0x00F29BC1->_
             inline - len(1) winlogon.exe - 0x00F29BC7->_
             inline - len(1) winlogon.exe - 0x00F29BDC->_
             inline - len(1) winlogon.exe - 0x00F29C2B->_
             inline - len(1) winlogon.exe - 0x00F29C38->_
             inline - len(1) winlogon.exe - 0x00F29C3E->_
             inline - len(1) winlogon.exe - 0x00F29C64->_
             inline - len(1) winlogon.exe - 0x00F29C75->_
             inline - len(1) winlogon.exe - 0x00F29CA7->_
             inline - len(1) winlogon.exe - 0x00F29CD3->_
             inline - len(1) winlogon.exe - 0x00F29CEF->_
             inline - len(1) winlogon.exe - 0x00F29D12->_
             inline - len(1) winlogon.exe - 0x00F29D3E->_
             inline - len(1) winlogon.exe - 0x00F29D90->_
             inline - len(1) winlogon.exe - 0x00F29D9E->_
             inline - len(1) winlogon.exe - 0x00F29DAE->_
             inline - len(1) winlogon.exe - 0x00F29DB8->_
             inline - len(1) winlogon.exe - 0x00F29DDE->_
             inline - len(1) winlogon.exe - 0x00F29DEF->_
             inline - len(1) winlogon.exe - 0x00F29E33->_
             inline - len(1) winlogon.exe - 0x00F29E94->0x00F24C65[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F29F62->_
             inline - len(1) winlogon.exe - 0x00F29F6D->_
             inline - len(6) winlogon.exe - 0x00F29F7C->_
             inline - len(1) winlogon.exe - 0x00F29F97->_
             inline - len(1) winlogon.exe - 0x00F29FC2->_
             inline - len(11) winlogon.exe - 0x00F29FEA->_
             inline - len(1) winlogon.exe - 0x00F2A04C->_
             inline - len(1) winlogon.exe - 0x00F2A078->_
             inline - len(1) winlogon.exe - 0x00F2A0BF->_
             inline - len(1) winlogon.exe - 0x00F2A11A->_
             inline - len(1) winlogon.exe - 0x00F2A125->_
             inline - len(1) winlogon.exe - 0x00F2A130->_
             inline - len(6) winlogon.exe - 0x00F2A282->_
             inline - len(1) winlogon.exe - 0x00F2A29D->_
             inline - len(1) winlogon.exe - 0x00F2A2C1->_
             inline - len(6) winlogon.exe - 0x00F2A2ED->_
             inline - len(1) winlogon.exe - 0x00F2A308->_
             inline - len(1) winlogon.exe - 0x00F2A42E->_
             inline - len(1) winlogon.exe - 0x00F2A451->_
             inline - len(1) winlogon.exe - 0x00F2A45B->_
             inline - len(6) winlogon.exe - 0x00F2A46B->_
             inline - len(1) winlogon.exe - 0x00F2A47A->_
             inline - len(1) winlogon.exe - 0x00F2A484->_
             inline - len(1) winlogon.exe - 0x00F2A48E->_
             inline - len(1) winlogon.exe - 0x00F2A498->_
             inline - len(1) winlogon.exe - 0x00F2A4A2->_
             inline - len(1) winlogon.exe - 0x00F2A4AC->_
             inline - len(1) winlogon.exe - 0x00F2A4B6->_
             inline - len(1) winlogon.exe - 0x00F2A4C0->_
             inline - len(1) winlogon.exe - 0x00F2A4CA->_
             inline - len(1) winlogon.exe - 0x00F2A4D4->_
             inline - len(1) winlogon.exe - 0x00F2A4E4->_
             inline - len(1) winlogon.exe - 0x00F2A547->_
             inline - len(1) winlogon.exe - 0x00F2A594->_
             inline - len(1) winlogon.exe - 0x00F2A5A9->0x00F263F7[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F2A5C2->_
             inline - len(1) winlogon.exe - 0x00F2A5DC->_
             inline - len(1) winlogon.exe - 0x00F2A622->_
             inline - len(1) winlogon.exe - 0x00F2A640->_
             inline - len(1) winlogon.exe - 0x00F2A67F->_
             inline - len(1) winlogon.exe - 0x00F2A6BB->0x00F2A797[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F2A6CF->_
             inline - len(1) winlogon.exe - 0x00F2A700->_
             inline - len(1) winlogon.exe - 0x00F2A70B->_
             inline - len(1) winlogon.exe - 0x00F2A725->_
             inline - len(1) winlogon.exe - 0x00F2A72F->_
             inline - len(1) winlogon.exe - 0x00F2A882->_
             inline - len(1) winlogon.exe - 0x00F2A8CB->_
             inline - len(1) winlogon.exe - 0x00F2A8E1->_
             inline - len(1) winlogon.exe - 0x00F2A8FD->_
             inline - len(1) winlogon.exe - 0x00F2A91C->_
             inline - len(1) winlogon.exe - 0x00F2A925->_
             inline - len(1) winlogon.exe - 0x00F2AA74->_
             inline - len(1) winlogon.exe - 0x00F2AA81->_
             inline - len(6) winlogon.exe - 0x00F2AAB3->_
             inline - len(1) winlogon.exe - 0x00F2AAD0->_
             inline - len(1) winlogon.exe - 0x00F2AB0C->_
             inline - len(1) winlogon.exe - 0x00F2AB44->_
             inline - len(1) winlogon.exe - 0x00F2AB5C->_
             inline - len(1) winlogon.exe - 0x00F2ABB1->_
             inline - len(1) winlogon.exe - 0x00F2ACBC->_
             inline - len(1) winlogon.exe - 0x00F2AE53->_
             inline - len(1) winlogon.exe - 0x00F2AE76->_
             inline - len(1) winlogon.exe - 0x00F2AEB4->_
             inline - len(1) winlogon.exe - 0x00F2AF72->_
             inline - len(1) winlogon.exe - 0x00F2B01E->_
             inline - len(1) winlogon.exe - 0x00F2B02A->_
             inline - len(1) winlogon.exe - 0x00F2B054->_
             inline - len(1) winlogon.exe - 0x00F2B132->_
             inline - len(6) winlogon.exe - 0x00F2B173->_
             inline - len(1) winlogon.exe - 0x00F2B18E->_
             inline - len(1) winlogon.exe - 0x00F2B1C2->_
             inline - len(6) winlogon.exe - 0x00F2B275->_
             inline - len(1) winlogon.exe - 0x00F2B291->_
             inline - len(1) winlogon.exe - 0x00F2B2DA->_
             inline - len(1) winlogon.exe - 0x00F2B2E4->_
             inline - len(1) winlogon.exe - 0x00F2B323->_
             inline - len(1) winlogon.exe - 0x00F2B349->_
             inline - len(1) winlogon.exe - 0x00F2B357->_
             inline - len(1) winlogon.exe - 0x00F2B362->_
             inline - len(1) winlogon.exe - 0x00F2B393->_
             inline - len(1) winlogon.exe - 0x00F2B39C->_
             inline - len(1) winlogon.exe - 0x00F2B3A2->_
             inline - len(1) winlogon.exe - 0x00F2B3B1->_
             inline - len(1) winlogon.exe - 0x00F2B3C0->_
             inline - len(1) winlogon.exe - 0x00F2B3CE->_
             inline - len(1) winlogon.exe - 0x00F2B3D6->_
             inline - len(1) winlogon.exe - 0x00F2B3E5->_
             inline - len(1) winlogon.exe - 0x00F2B3EC->_
             inline - len(1) winlogon.exe - 0x00F2B3F3->_
             inline - len(1) winlogon.exe - 0x00F2B442->_
             inline - len(1) winlogon.exe - 0x00F2B455->_
             inline - len(1) winlogon.exe - 0x00F2B45D->_
             inline - len(1) winlogon.exe - 0x00F2B46B->_
             inline - len(1) winlogon.exe - 0x00F2B4F2->_
             inline - len(1) winlogon.exe - 0x00F2B506->_
             inline - len(1) winlogon.exe - 0x00F2B58A->_
             inline - len(1) winlogon.exe - 0x00F2B59E->_
             inline - len(1) winlogon.exe - 0x00F2B602->_
             inline - len(1) winlogon.exe - 0x00F2B616->_
             inline - len(1) winlogon.exe - 0x00F2B643->_
             inline - len(1) winlogon.exe - 0x00F2B668->_
             inline - len(1) winlogon.exe - 0x00F2B6AA->_
             inline - len(1) winlogon.exe - 0x00F2B6BE->_
             inline - len(6) winlogon.exe - 0x00F2B6D6->_
             inline - len(1) winlogon.exe - 0x00F2B6F3->_
             inline - len(1) winlogon.exe - 0x00F2B70D->_
             inline - len(1) winlogon.exe - 0x00F2B749->_
             inline - len(1) winlogon.exe - 0x00F2B7BA->_
             inline - len(6) winlogon.exe - 0x00F2B7E3->_
             inline - len(1) winlogon.exe - 0x00F2B801->_
             inline - len(1) winlogon.exe - 0x00F2B80B->_
             inline - len(1) winlogon.exe - 0x00F2B831->_
             inline - len(1) winlogon.exe - 0x00F2B84C->_
             inline - len(1) winlogon.exe - 0x00F2B856->_
             inline - len(1) winlogon.exe - 0x00F2B894->_
             inline - len(1) winlogon.exe - 0x00F2B8D7->_
             inline - len(1) winlogon.exe - 0x00F2B8E1->_
             inline - len(1) winlogon.exe - 0x00F2B9DA->_
             inline - len(1) winlogon.exe - 0x00F2BA05->_
             inline - len(1) winlogon.exe - 0x00F2BA2E->_
             inline - len(1) winlogon.exe - 0x00F2BA40->_
             inline - len(1) winlogon.exe - 0x00F2BA49->_
             inline - len(1) winlogon.exe - 0x00F2BAB2->_
             inline - len(1) winlogon.exe - 0x00F2BAC5->_
             inline - len(1) winlogon.exe - 0x00F2BB69->_
             inline - len(1) winlogon.exe - 0x00F2BB88->_
             inline - len(1) winlogon.exe - 0x00F2BBF2->_
             inline - len(6) winlogon.exe - 0x00F2BC0D->_
             inline - len(1) winlogon.exe - 0x00F2BC28->_
             inline - len(1) winlogon.exe - 0x00F2BC4D->_
             inline - len(1) winlogon.exe - 0x00F2BCED->_
             inline - len(1) winlogon.exe - 0x00F2BD25->_
             inline - len(1) winlogon.exe - 0x00F2BDF9->_
             inline - len(1) winlogon.exe - 0x00F2BE77->_
             inline - len(1) winlogon.exe - 0x00F2BFCF->_
             inline - len(1) winlogon.exe - 0x00F2BFD5->_
             inline - len(1) winlogon.exe - 0x00F2BFE5->_
             inline - len(1) winlogon.exe - 0x00F2C010->_
             inline - len(1) winlogon.exe - 0x00F2C029->_
             inline - len(1) winlogon.exe - 0x00F2C056->_
             inline - len(1) winlogon.exe - 0x00F2C0E2->_
             inline - len(6) winlogon.exe - 0x00F2C110->_
             inline - len(1) winlogon.exe - 0x00F2C12D->_
             inline - len(1) winlogon.exe - 0x00F2C13F->_
             inline - len(1) winlogon.exe - 0x00F2C1C2->_
             inline - len(1) winlogon.exe - 0x00F2C1D9->_
             inline - len(1) winlogon.exe - 0x00F2C23D->_
             inline - len(1) winlogon.exe - 0x00F2C267->_
             inline - len(1) winlogon.exe - 0x00F2C283->_
             inline - len(1) winlogon.exe - 0x00F2C2AD->_
             inline - len(1) winlogon.exe - 0x00F2C2EB->_
             inline - len(1) winlogon.exe - 0x00F2C2FC->_
             inline - len(1) winlogon.exe - 0x00F2C312->_
             inline - len(1) winlogon.exe - 0x00F2C32B->_
             inline - len(1) winlogon.exe - 0x00F2C381->_
             inline - len(1) winlogon.exe - 0x00F2C396->_
             inline - len(1) winlogon.exe - 0x00F2C3AA->_
             inline - len(1) winlogon.exe - 0x00F2C3DB->_
             inline - len(1) winlogon.exe - 0x00F2C409->_
             inline - len(1) winlogon.exe - 0x00F2C414->_
             inline - len(1) winlogon.exe - 0x00F2C43E->_
             inline - len(1) winlogon.exe - 0x00F2C47C->_
             inline - len(1) winlogon.exe - 0x00F2C48D->_
             inline - len(1) winlogon.exe - 0x00F2C4A1->_
             inline - len(1) winlogon.exe - 0x00F2C4B5->_
             inline - len(1) winlogon.exe - 0x00F2C4CA->_
             inline - len(1) winlogon.exe - 0x00F2C510->_
             inline - len(1) winlogon.exe - 0x00F2C5AA->_
             inline - len(1) winlogon.exe - 0x00F2C5CA->_
             inline - len(1) winlogon.exe - 0x00F2C5D2->_
             inline - len(1) winlogon.exe - 0x00F2C5F1->_
             inline - len(1) winlogon.exe - 0x00F2C5F7->_
             inline - len(1) winlogon.exe - 0x00F2C5FD->_
             inline - len(1) winlogon.exe - 0x00F2C616->_
             inline - len(1) winlogon.exe - 0x00F2C621->_
             inline - len(1) winlogon.exe - 0x00F2C62B->_
             inline - len(1) winlogon.exe - 0x00F2C63A->_
             inline - len(1) winlogon.exe - 0x00F2C665->_
             inline - len(1) winlogon.exe - 0x00F2C76A->_
             inline - len(1) winlogon.exe - 0x00F2C788->_
             inline - len(1) winlogon.exe - 0x00F2C7DD->_
             inline - len(1) winlogon.exe - 0x00F2C7EB->_
             inline - len(1) winlogon.exe - 0x00F2C7F9->_
             inline - len(1) winlogon.exe - 0x00F2C80C->_
             inline - len(1) winlogon.exe - 0x00F2C81F->_
             inline - len(1) winlogon.exe - 0x00F2C838->_
             inline - len(1) winlogon.exe - 0x00F2C858->_
             inline - len(1) winlogon.exe - 0x00F2C882->_
             inline - len(1) winlogon.exe - 0x00F2C896->_
             inline - len(1) winlogon.exe - 0x00F2C8A9->_
             inline - len(6) winlogon.exe - 0x00F2C8B3->_
             inline - len(1) winlogon.exe - 0x00F2C8D0->_
             inline - len(1) winlogon.exe - 0x00F2C919->_
             inline - len(1) winlogon.exe - 0x00F2C93D->_
             inline - len(1) winlogon.exe - 0x00F2C9AA->_
             inline - len(6) winlogon.exe - 0x00F2C9E5->_
             inline - len(1) winlogon.exe - 0x00F2C9F4->_
             inline - len(6) winlogon.exe - 0x00F2CA21->_
             inline - len(1) winlogon.exe - 0x00F2CA30->_
             inline - len(1) winlogon.exe - 0x00F2CA45->_
             inline - len(1) winlogon.exe - 0x00F2CA66->_
             inline - len(5) winlogon.exe - 0x00F2CA9E->_
             inline - len(6) winlogon.exe - 0x00F2CAB6->_
             inline - len(1) winlogon.exe - 0x00F2CAD9->_
             inline - len(11) winlogon.exe - 0x00F2CAED->_
             inline - len(1) winlogon.exe - 0x00F2CB1D->_
             inline - len(1) winlogon.exe - 0x00F2CB6A->_
             inline - len(1) winlogon.exe - 0x00F2CB94->_
             inline - len(1) winlogon.exe - 0x00F2CBA3->_
             inline - len(1) winlogon.exe - 0x00F2CBA9->_
             inline - len(1) winlogon.exe - 0x00F2CBCD->_
             inline - len(1) winlogon.exe - 0x00F2CBEF->_
             inline - len(1) winlogon.exe - 0x00F2CBFE->_
             inline - len(1) winlogon.exe - 0x00F2CC6A->_
             inline - len(6) winlogon.exe - 0x00F2CCA1->_
             inline - len(1) winlogon.exe - 0x00F2CCBC->_
             inline - len(1) winlogon.exe - 0x00F2CCF0->_
             inline - len(6) winlogon.exe - 0x00F2CD15->_
             inline - len(1) winlogon.exe - 0x00F2CD31->_
             inline - len(1) winlogon.exe - 0x00F2CD41->_
             inline - len(6) winlogon.exe - 0x00F2CD85->_
             inline - len(1) winlogon.exe - 0x00F2CDA6->_
             inline - len(1) winlogon.exe - 0x00F2CDC6->_
             inline - len(1) winlogon.exe - 0x00F2CDE1->_
             inline - len(1) winlogon.exe - 0x00F2CE03->_
             inline - len(1) winlogon.exe - 0x00F2CE15->_
             inline - len(1) winlogon.exe - 0x00F2CE1F->_
             inline - len(11) winlogon.exe - 0x00F2CE36->_
             inline - len(6) winlogon.exe - 0x00F2CE64->_
             inline - len(1) winlogon.exe - 0x00F2CED5->_
             inline - len(1) winlogon.exe - 0x00F2CEDB->_
             inline - len(1) winlogon.exe - 0x00F2CEE1->_
             inline - len(1) winlogon.exe - 0x00F2CF1A->_
             inline - len(1) winlogon.exe - 0x00F2CF20->_
             inline - len(1) winlogon.exe - 0x00F2CF26->_
             inline - len(1) winlogon.exe - 0x00F2CF3D->_
             inline - len(1) winlogon.exe - 0x00F2CF47->_
             inline - len(1) winlogon.exe - 0x00F2CF4D->_
             inline - len(1) winlogon.exe - 0x00F2CF64->_
             inline - len(1) winlogon.exe - 0x00F2CF91->_
             inline - len(1) winlogon.exe - 0x00F2CFA3->_
             inline - len(1) winlogon.exe - 0x00F2CFA9->_
             inline - len(1) winlogon.exe - 0x00F2CFB1->_
             inline - len(1) winlogon.exe - 0x00F2CFD5->_
             inline - len(1) winlogon.exe - 0x00F2CFDD->_
             inline - len(1) winlogon.exe - 0x00F2D02C->_
             inline - len(1) winlogon.exe - 0x00F2D039->_
             inline - len(6) winlogon.exe - 0x00F2D05B->_
             inline - len(1) winlogon.exe - 0x00F2D081->_
             inline - len(1) winlogon.exe - 0x00F2D0B7->_
             inline - len(1) winlogon.exe - 0x00F2D0CE->_
             inline - len(1) winlogon.exe - 0x00F2D0E5->_
             inline - len(1) winlogon.exe - 0x00F2D162->_
             inline - len(1) winlogon.exe - 0x00F2D199->_
             inline - len(1) winlogon.exe - 0x00F2D1A2->_
             inline - len(6) winlogon.exe - 0x00F2D1A9->_
             inline - len(1) winlogon.exe - 0x00F2D222->_
             inline - len(11) winlogon.exe - 0x00F2D22F->_
             inline - len(1) winlogon.exe - 0x00F2D25E->_
             inline - len(6) winlogon.exe - 0x00F2D2BC->_
             inline - len(1) winlogon.exe - 0x00F2D35D->_
             inline - len(1) winlogon.exe - 0x00F2D36B->_
             inline - len(1) winlogon.exe - 0x00F2D37E->_
             inline - len(1) winlogon.exe - 0x00F2D39F->_
             inline - len(6) winlogon.exe - 0x00F2D3BD->_
             inline - len(5) winlogon.exe - 0x00F2D3CE->_
             inline - len(6) winlogon.exe - 0x00F2D3D8->_
             inline - len(1) winlogon.exe - 0x00F2D3E8->_
             inline - len(1) winlogon.exe - 0x00F2D3FD->_
             inline - len(1) winlogon.exe - 0x00F2D415->_
             inline - len(1) winlogon.exe - 0x00F2D430->_
             inline - len(1) winlogon.exe - 0x00F2D44A->_
             inline - len(1) winlogon.exe - 0x00F2D45D->_
             inline - len(1) winlogon.exe - 0x00F2D477->_
             inline - len(1) winlogon.exe - 0x00F2D491->_
             inline - len(1) winlogon.exe - 0x00F2D4A0->_
             inline - len(1) winlogon.exe - 0x00F2D4A9->_
             inline - len(1) winlogon.exe - 0x00F2D4BF->_
             inline - len(1) winlogon.exe - 0x00F2D4C8->_
             inline - len(6) winlogon.exe - 0x00F2D4D6->_
             inline - len(1) winlogon.exe - 0x00F2D4E1->_
             inline - len(1) winlogon.exe - 0x00F2D4EB->_
             inline - len(1) winlogon.exe - 0x00F2D4F1->_
             inline - len(1) winlogon.exe - 0x00F2D4FF->_
             inline - len(1) winlogon.exe - 0x00F2D515->_
             inline - len(1) winlogon.exe - 0x00F2D521->_
             inline - len(1) winlogon.exe - 0x00F2D548->_
             inline - len(1) winlogon.exe - 0x00F2D55E->_
             inline - len(1) winlogon.exe - 0x00F2D567->_
             inline - len(1) winlogon.exe - 0x00F2D571->_
             inline - len(1) winlogon.exe - 0x00F2D57A->_
             inline - len(1) winlogon.exe - 0x00F2D586->_
             inline - len(1) winlogon.exe - 0x00F2D593->_
             inline - len(1) winlogon.exe - 0x00F2D5A7->_
             inline - len(1) winlogon.exe - 0x00F2D5C7->_
             inline - len(1) winlogon.exe - 0x00F2D5D3->_
             inline - len(1) winlogon.exe - 0x00F2D5D9->_
             inline - len(1) winlogon.exe - 0x00F2D5E4->_
             inline - len(1) winlogon.exe - 0x00F2D5ED->_
             inline - len(1) winlogon.exe - 0x00F2D5FC->_
             inline - len(1) winlogon.exe - 0x00F2D611->_
             inline - len(1) winlogon.exe - 0x00F2D631->_
             inline - len(1) winlogon.exe - 0x00F2D640->_
             inline - len(1) winlogon.exe - 0x00F2D647->_
             inline - len(1) winlogon.exe - 0x00F2D656->_
             inline - len(1) winlogon.exe - 0x00F2D66D->_
             inline - len(1) winlogon.exe - 0x00F2D677->_
             inline - len(1) winlogon.exe - 0x00F2D68D->_
             inline - len(1) winlogon.exe - 0x00F2D696->_
             inline - len(1) winlogon.exe - 0x00F2D6AC->_
             inline - len(1) winlogon.exe - 0x00F2D6B5->_
             inline - len(1) winlogon.exe - 0x00F2D6BF->_
             inline - len(1) winlogon.exe - 0x00F2D6CC->_
             inline - len(1) winlogon.exe - 0x00F2D6E0->_
             inline - len(1) winlogon.exe - 0x00F2D6FA->_
             inline - len(1) winlogon.exe - 0x00F2D704->_
             inline - len(1) winlogon.exe - 0x00F2D71A->_
             inline - len(1) winlogon.exe - 0x00F2D723->_
             inline - len(1) winlogon.exe - 0x00F2D74D->_
             inline - len(1) winlogon.exe - 0x00F2D767->_
             inline - len(1) winlogon.exe - 0x00F2D770->_
             inline - len(1) winlogon.exe - 0x00F2D79A->_
             inline - len(1) winlogon.exe - 0x00F2D7A7->_
             inline - len(1) winlogon.exe - 0x00F2D7BB->_
             inline - len(1) winlogon.exe - 0x00F2D7C5->_
             inline - len(1) winlogon.exe - 0x00F2D7DC->_
             inline - len(1) winlogon.exe - 0x00F2D8BA->_
             inline - len(1) winlogon.exe - 0x00F2D8C4->_
             inline - len(1) winlogon.exe - 0x00F2D8D6->_
             inline - len(1) winlogon.exe - 0x00F2D954->_
             inline - len(13) winlogon.exe - 0x00F2DA1E->_
             inline - len(1) winlogon.exe - 0x00F2DA46->_
             inline - len(1) winlogon.exe - 0x00F2DA82->_
             inline - len(1) winlogon.exe - 0x00F2DA8C->_
             inline - len(1) winlogon.exe - 0x00F2DA92->_
             inline - len(1) winlogon.exe - 0x00F2DAA0->_
             inline - len(1) winlogon.exe - 0x00F2DAA6->_
             inline - len(1) winlogon.exe - 0x00F2DAC2->_
             inline - len(1) winlogon.exe - 0x00F2DAEC->_
             inline - len(1) winlogon.exe - 0x00F2DAF3->_
             inline - len(1) winlogon.exe - 0x00F2DAFA->_
             inline - len(1) winlogon.exe - 0x00F2DB01->_
             inline - len(1) winlogon.exe - 0x00F2DB08->_
             inline - len(1) winlogon.exe - 0x00F2DB5A->_
             inline - len(1) winlogon.exe - 0x00F2DBDD->_
             inline - len(1) winlogon.exe - 0x00F2DBE6->_
             inline - len(1) winlogon.exe - 0x00F2DBF6->_
             inline - len(1) winlogon.exe - 0x00F2DC07->_
             inline - len(6) winlogon.exe - 0x00F2E95D->_
             inline - len(1) winlogon.exe - 0x00F2E978->_
             inline - len(1) winlogon.exe - 0x00F2E9C3->_
             inline - len(1) winlogon.exe - 0x00F2E9CA->_
             inline - len(1) winlogon.exe - 0x00F2E9D9->_
             inline - len(1) winlogon.exe - 0x00F2E9DF->_
             inline - len(1) winlogon.exe - 0x00F2E9ED->_
             inline - len(1) winlogon.exe - 0x00F2E9FF->_
             inline - len(1) winlogon.exe - 0x00F2EA14->_
             inline - len(1) winlogon.exe - 0x00F2EA1A->_
             inline - len(1) winlogon.exe - 0x00F2EA34->_
             inline - len(1) winlogon.exe - 0x00F2EA3A->_
             inline - len(1) winlogon.exe - 0x00F2EA5A->_
             inline - len(6) winlogon.exe - 0x00F2EAB6->_
             inline - len(1) winlogon.exe - 0x00F2EB52->_
             inline - len(1) winlogon.exe - 0x00F2EB58->_
             inline - len(1) winlogon.exe - 0x00F2EB7D->_
             inline - len(1) winlogon.exe - 0x00F2EBAB->_
             inline - len(1) winlogon.exe - 0x00F2EBC6->_
             inline - len(1) winlogon.exe - 0x00F2EBD6->_
             inline - len(1) winlogon.exe - 0x00F2EBEE->_
             inline - len(1) winlogon.exe - 0x00F2EBFA->_
             inline - len(1) winlogon.exe - 0x00F2EC26->_
             inline - len(1) winlogon.exe - 0x00F2EC32->_
             inline - len(1) winlogon.exe - 0x00F2EC46->_
             inline - len(1) winlogon.exe - 0x00F2EC55->_
             inline - len(1) winlogon.exe - 0x00F2EC86->_
             inline - len(1) winlogon.exe - 0x00F2EC92->_
             inline - len(1) winlogon.exe - 0x00F2ECAB->_
             inline - len(1) winlogon.exe - 0x00F2ECB7->_
             inline - len(1) winlogon.exe - 0x00F2ECCE->_
             inline - len(1) winlogon.exe - 0x00F2ECD4->_
             inline - len(1) winlogon.exe - 0x00F2ECE8->_
             inline - len(1) winlogon.exe - 0x00F2ECF2->_
             inline - len(6) winlogon.exe - 0x00F2ED17->_
             inline - len(1) winlogon.exe - 0x00F2ED32->_
             inline - len(1) winlogon.exe - 0x00F2ED70->_
             inline - len(1) winlogon.exe - 0x00F2EDE4->_
             inline - len(1) winlogon.exe - 0x00F2EE25->_
             inline - len(1) winlogon.exe - 0x00F2EE2E->_
             inline - len(1) winlogon.exe - 0x00F2EEF0->_
             inline - len(6) winlogon.exe - 0x00F2EF76->_
             inline - len(6) winlogon.exe - 0x00F2EFAB->_
             inline - len(1) winlogon.exe - 0x00F2EFFC->_
             inline - len(1) winlogon.exe - 0x00F2F004->_
             inline - len(1) winlogon.exe - 0x00F2F037->_
             inline - len(1) winlogon.exe - 0x00F2F042->_
             inline - len(1) winlogon.exe - 0x00F2F056->_
             inline - len(1) winlogon.exe - 0x00F2F06F->_
             inline - len(1) winlogon.exe - 0x00F2F08F->_
             inline - len(1) winlogon.exe - 0x00F2F0F2->_
             inline - len(1) winlogon.exe - 0x00F2F13A->_
             inline - len(1) winlogon.exe - 0x00F2F1A2->_
             inline - len(1) winlogon.exe - 0x00F2F1B6->_
             inline - len(1) winlogon.exe - 0x00F2F1EA->_
             inline - len(1) winlogon.exe - 0x00F2F205->_
             inline - len(1) winlogon.exe - 0x00F2F256->0x3BC93300
             inline - len(1) winlogon.exe - 0x00F2F28D->_
             inline - len(1) winlogon.exe - 0x00F2F294->_
             inline - len(1) winlogon.exe - 0x00F2F2A1->_
             inline - len(1) winlogon.exe - 0x00F2F2B1->_
             inline - len(1) winlogon.exe - 0x00F2F2BD->_
             inline - len(1) winlogon.exe - 0x00F2F2DB->_
             inline - len(1) winlogon.exe - 0x00F2F2E8->_
             inline - len(1) winlogon.exe - 0x00F2F2FB->_
             inline - len(1) winlogon.exe - 0x00F2F315->_
             inline - len(6) winlogon.exe - 0x00F2F320->_
             inline - len(1) winlogon.exe - 0x00F2F35C->_
             inline - len(1) winlogon.exe - 0x00F2F370->_
             inline - len(1) winlogon.exe - 0x00F2F389->_
             inline - len(1) winlogon.exe - 0x00F2F3AC->_
             inline - len(1) winlogon.exe - 0x00F2F3DD->_
             inline - len(1) winlogon.exe - 0x00F2F3FD->_
             inline - len(1) winlogon.exe - 0x00F2F434->_
             inline - len(1) winlogon.exe - 0x00F2F466->_
             inline - len(6) winlogon.exe - 0x00F2F479->_
             inline - len(1) winlogon.exe - 0x00F2F4A7->_
             inline - len(1) winlogon.exe - 0x00F2F4B3->_
             inline - len(1) winlogon.exe - 0x00F2F4EC->_
             inline - len(1) winlogon.exe - 0x00F2F53A->_
             inline - len(1) winlogon.exe - 0x00F2F541->_
             inline - len(1) winlogon.exe - 0x00F2F552->_
             inline - len(1) winlogon.exe - 0x00F2F569->_
             inline - len(1) winlogon.exe - 0x00F2F592->_
             inline - len(1) winlogon.exe - 0x00F2F59E->_
             inline - len(1) winlogon.exe - 0x00F2F5D7->_
             inline - len(1) winlogon.exe - 0x00F2F616->_
             inline - len(1) winlogon.exe - 0x00F2F73A->_
             inline - len(1) winlogon.exe - 0x00F2F765->_
             inline - len(1) winlogon.exe - 0x00F2F7B2->_
             inline - len(1) winlogon.exe - 0x00F2F812->_
             inline - len(1) winlogon.exe - 0x00F2F82C->_
             inline - len(1) winlogon.exe - 0x00F2F867->_
             inline - len(1) winlogon.exe - 0x00F2F86E->_
             inline - len(1) winlogon.exe - 0x00F2F884->_
             inline - len(1) winlogon.exe - 0x00F2F8BA->_
             inline - len(1) winlogon.exe - 0x00F2F8EC->_
             inline - len(1) winlogon.exe - 0x00F2F912->_
             inline - len(1) winlogon.exe - 0x00F2F928->_
             inline - len(1) winlogon.exe - 0x00F2F93A->_
             inline - len(1) winlogon.exe - 0x00F2F9DA->_
             inline - len(1) winlogon.exe - 0x00F2FA49->_
             inline - len(1) winlogon.exe - 0x00F2FA53->_
             inline - len(1) winlogon.exe - 0x00F2FA61->_
             inline - len(1) winlogon.exe - 0x00F2FA6B->_
             inline - len(1) winlogon.exe - 0x00F2FA79->_
             inline - len(1) winlogon.exe - 0x00F2FA83->_
             inline - len(1) winlogon.exe - 0x00F2FAA7->_
             inline - len(1) winlogon.exe - 0x00F2FABD->_
             inline - len(1) winlogon.exe - 0x00F2FACD->_
             inline - len(1) winlogon.exe - 0x00F2FAD3->_
             inline - len(6) winlogon.exe - 0x00F2FAE7->_
             inline - len(1) winlogon.exe - 0x00F2FAF2->_
             inline - len(1) winlogon.exe - 0x00F2FB11->_
             inline - len(1) winlogon.exe - 0x00F2FB24->_
             inline - len(1) winlogon.exe - 0x00F2FB2F->_
             inline - len(1) winlogon.exe - 0x00F2FB40->_
             inline - len(1) winlogon.exe - 0x00F2FB46->_
             inline - len(1) winlogon.exe - 0x00F2FB61->_
             inline - len(1) winlogon.exe - 0x00F2FB67->_
             inline - len(1) winlogon.exe - 0x00F2FB6D->_
             inline - len(1) winlogon.exe - 0x00F2FB73->_
             inline - len(1) winlogon.exe - 0x00F2FB84->_
             inline - len(1) winlogon.exe - 0x00F2FB8D->_
             inline - len(1) winlogon.exe - 0x00F2FBDA->_
             inline - len(1) winlogon.exe - 0x00F2FBF6->_
             inline - len(6) winlogon.exe - 0x00F2FC08->_
             inline - len(6) winlogon.exe - 0x00F2FC13->_
             inline - len(1) winlogon.exe - 0x00F2FC1E->_
             inline - len(1) winlogon.exe - 0x00F2FC62->_
             inline - len(1) winlogon.exe - 0x00F2FC76->_
             inline - len(6) winlogon.exe - 0x00F2FC91->_
             inline - len(1) winlogon.exe - 0x00F2FCAE->_
             inline - len(1) winlogon.exe - 0x00F2FD42->_
             inline - len(1) winlogon.exe - 0x00F2FD69->_
             inline - len(1) winlogon.exe - 0x00F2FD8A->_
             inline - len(6) winlogon.exe - 0x00F2FDC8->_
             inline - len(1) winlogon.exe - 0x00F2FDD3->_
             inline - len(1) winlogon.exe - 0x00F2FDDA->_
             inline - len(1) winlogon.exe - 0x00F2FDE2->_
             inline - len(1) winlogon.exe - 0x00F2FDF9->_
             inline - len(1) winlogon.exe - 0x00F2FE0F->_
             inline - len(1) winlogon.exe - 0x00F2FE29->_
             inline - len(1) winlogon.exe - 0x00F2FEA2->_
             inline - len(1) winlogon.exe - 0x00F2FEB6->_
             inline - len(1) winlogon.exe - 0x00F2FEC5->_
             inline - len(1) winlogon.exe - 0x00F2FED2->_
             inline - len(1) winlogon.exe - 0x00F2FEFB->_
             inline - len(1) winlogon.exe - 0x00F2FFA2->_
             inline - len(1) winlogon.exe - 0x00F2FFD9->_
             inline - len(1) winlogon.exe - 0x00F2FFE6->_
             inline - len(1) winlogon.exe - 0x00F30044->_
             inline - len(1) winlogon.exe - 0x00F30055->_
             inline - len(6) winlogon.exe - 0x00F30072->_
             inline - len(1) winlogon.exe - 0x00F3008C->_
             inline - len(1) winlogon.exe - 0x00F3009E->_
             inline - len(1) winlogon.exe - 0x00F300B5->_
             inline - len(1) winlogon.exe - 0x00F3011A->_
             inline - len(1) winlogon.exe - 0x00F30126->_
             inline - len(1) winlogon.exe - 0x00F3015F->_
             inline - len(1) winlogon.exe - 0x00F30174->_
             inline - len(1) winlogon.exe - 0x00F3017A->_
             inline - len(1) winlogon.exe - 0x00F3018E->_
             inline - len(1) winlogon.exe - 0x00F301C2->_
             inline - len(1) winlogon.exe - 0x00F301C8->_
             inline - len(1) winlogon.exe - 0x00F301E1->_
             inline - len(6) winlogon.exe - 0x00F301F5->_
             inline - len(1) winlogon.exe - 0x00F30281->_
             inline - len(1) winlogon.exe - 0x00F3028E->_
             inline - len(1) winlogon.exe - 0x00F302A3->_
             inline - len(1) winlogon.exe - 0x00F302EA->_
             inline - len(1) winlogon.exe - 0x00F30324->_
             inline - len(1) winlogon.exe - 0x00F3032C->_
             inline - len(1) winlogon.exe - 0x00F30351->_
             inline - len(1) winlogon.exe - 0x00F30368->_
             inline - len(1) winlogon.exe - 0x00F30375->_
             inline - len(1) winlogon.exe - 0x00F30386->_
             inline - len(1) winlogon.exe - 0x00F303A1->_
             inline - len(1) winlogon.exe - 0x00F303C9->_
             inline - len(1) winlogon.exe - 0x00F30493->_
             inline - len(1) winlogon.exe - 0x00F304EE->_
             inline - len(1) winlogon.exe - 0x00F304FA->_
             inline - len(1) winlogon.exe - 0x00F305AA->_
             inline - len(1) winlogon.exe - 0x00F305BF->_
             inline - len(1) winlogon.exe - 0x00F305FA->_
             inline - len(1) winlogon.exe - 0x00F3060E->_
             inline - len(1) winlogon.exe - 0x00F3061B->_
             inline - len(1) winlogon.exe - 0x00F30634->_
             inline - len(1) winlogon.exe - 0x00F3064C->_
             inline - len(1) winlogon.exe - 0x00F3067B->_
             inline - len(1) winlogon.exe - 0x00F306C2->_
             inline - len(1) winlogon.exe - 0x00F306F8->_
             inline - len(1) winlogon.exe - 0x00F30714->_
             inline - len(1) winlogon.exe - 0x00F30739->_
             inline - len(1) winlogon.exe - 0x00F3080E->_
             inline - len(1) winlogon.exe - 0x00F30836->_
             inline - len(1) winlogon.exe - 0x00F30855->_
             inline - len(1) winlogon.exe - 0x00F30881->_
             inline - len(1) winlogon.exe - 0x00F3088C->_
             inline - len(1) winlogon.exe - 0x00F308B0->_
             inline - len(1) winlogon.exe - 0x00F308BA->_
             inline - len(6) winlogon.exe - 0x00F308CE->_
             inline - len(1) winlogon.exe - 0x00F308E9->_
             inline - len(1) winlogon.exe - 0x00F308FB->_
             inline - len(1) winlogon.exe - 0x00F30910->_
             inline - len(1) winlogon.exe - 0x00F30929->_
             inline - len(1) winlogon.exe - 0x00F30962->_
             inline - len(6) winlogon.exe - 0x00F30989->_
             inline - len(1) winlogon.exe - 0x00F3099E->_
             inline - len(1) winlogon.exe - 0x00F30A03->_
             inline - len(1) winlogon.exe - 0x00F30A11->_
             inline - len(1) winlogon.exe - 0x00F30A1F->_
             inline - len(1) winlogon.exe - 0x00F30A32->_
             inline - len(1) winlogon.exe - 0x00F30A45->_
             inline - len(1) winlogon.exe - 0x00F30A5D->_
             inline - len(1) winlogon.exe - 0x00F30A7F->_
             inline - len(1) winlogon.exe - 0x00F30AAA->_
             inline - len(1) winlogon.exe - 0x00F30AF2->_
             inline - len(1) winlogon.exe - 0x00F30B15->_
             inline - len(1) winlogon.exe - 0x00F30B37->_
             inline - len(1) winlogon.exe - 0x00F30B59->_
             inline - len(1) winlogon.exe - 0x00F30B77->_
             inline - len(1) winlogon.exe - 0x00F30B95->_
             inline - len(6) winlogon.exe - 0x00F30C61->_
             inline - len(1) winlogon.exe - 0x00F30C82->_
             inline - len(1) winlogon.exe - 0x00F30C89->_
             inline - len(1) winlogon.exe - 0x00F30C99->_
             inline - len(1) winlogon.exe - 0x00F30CA0->_
             inline - len(1) winlogon.exe - 0x00F30CBE->_
             inline - len(1) winlogon.exe - 0x00F30CF0->_
             inline - len(1) winlogon.exe - 0x00F30D36->_
             inline - len(1) winlogon.exe - 0x00F30D4F->0x00F2177B[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F30D9E->_
             inline - len(1) winlogon.exe - 0x00F30DA9->_
             inline - len(1) winlogon.exe - 0x00F30DB6->_
             inline - len(1) winlogon.exe - 0x00F30DD5->_
             inline - len(1) winlogon.exe - 0x00F30DE2->_
             inline - len(1) winlogon.exe - 0x00F30E13->0x5EC68B00
             inline - len(1) winlogon.exe - 0x00F30E42->_
             inline - len(1) winlogon.exe - 0x00F30EC5->_
             inline - len(1) winlogon.exe - 0x00F30EF0->_
             inline - len(1) winlogon.exe - 0x00F30F03->_
             inline - len(1) winlogon.exe - 0x00F30F96->_
             inline - len(1) winlogon.exe - 0x00F30F9C->_
             inline - len(11) winlogon.exe - 0x00F30FAB->_
             inline - len(1) winlogon.exe - 0x00F30FBB->_
             inline - len(6) winlogon.exe - 0x00F30FC4->_
             inline - len(1) winlogon.exe - 0x00F30FDF->_
             inline - len(6) winlogon.exe - 0x00F30FFE->_
             inline - len(21) winlogon.exe - 0x00F31009->_
             inline - len(1) winlogon.exe - 0x00F31023->_
             inline - len(1) winlogon.exe - 0x00F3102B->_
             inline - len(1) winlogon.exe - 0x00F31036->_
             inline - len(1) winlogon.exe - 0x00F3103C->_
             inline - len(1) winlogon.exe - 0x00F3104A->_
             inline - len(1) winlogon.exe - 0x00F3105C->_
             inline - len(1) winlogon.exe - 0x00F31083->_
             inline - len(1) winlogon.exe - 0x00F3108F->_
             inline - len(1) winlogon.exe - 0x00F31097->_
             inline - len(1) winlogon.exe - 0x00F3109F->_
             inline - len(1) winlogon.exe - 0x00F310AB->_
             inline - len(1) winlogon.exe - 0x00F310BD->_
             inline - len(1) winlogon.exe - 0x00F310C5->_
             inline - len(1) winlogon.exe - 0x00F310CD->_
             inline - len(1) winlogon.exe - 0x00F310DE->_
             inline - len(1) winlogon.exe - 0x00F310E8->_
             inline - len(1) winlogon.exe - 0x00F310F2->_
             inline - len(1) winlogon.exe - 0x00F31102->_
             inline - len(6) winlogon.exe - 0x00F31113->_
             inline - len(1) winlogon.exe - 0x00F31138->_
             inline - len(1) winlogon.exe - 0x00F3113E->_
             inline - len(1) winlogon.exe - 0x00F31153->_
             inline - len(1) winlogon.exe - 0x00F3115C->_
             inline - len(1) winlogon.exe - 0x00F3116D->_
             inline - len(1) winlogon.exe - 0x00F3117D->_
             inline - len(1) winlogon.exe - 0x00F31183->_
             inline - len(1) winlogon.exe - 0x00F31194->_
             inline - len(1) winlogon.exe - 0x00F3119E->_
             inline - len(1) winlogon.exe - 0x00F311A7->_
             inline - len(1) winlogon.exe - 0x00F311B1->_
             inline - len(1) winlogon.exe - 0x00F311BB->_
             inline - len(1) winlogon.exe - 0x00F311F9->_
             inline - len(1) winlogon.exe - 0x00F311FF->_
             inline - len(1) winlogon.exe - 0x00F3121E->_
             inline - len(1) winlogon.exe - 0x00F3122A->_
             inline - len(1) winlogon.exe - 0x00F31245->_
             inline - len(1) winlogon.exe - 0x00F3125C->_
             inline - len(1) winlogon.exe - 0x00F31278->_
             inline - len(1) winlogon.exe - 0x00F31282->_
             inline - len(1) winlogon.exe - 0x00F31292->_
             inline - len(1) winlogon.exe - 0x00F3129F->_
             inline - len(11) winlogon.exe - 0x00F312AD->_
             inline - len(1) winlogon.exe - 0x00F312CB->_
             inline - len(6) winlogon.exe - 0x00F312D4->_
             inline - len(1) winlogon.exe - 0x00F312E6->_
             inline - len(1) winlogon.exe - 0x00F312F6->_
             inline - len(1) winlogon.exe - 0x00F312FC->_
             inline - len(1) winlogon.exe - 0x00F31308->_
             inline - len(1) winlogon.exe - 0x00F31329->_
             inline - len(1) winlogon.exe - 0x00F3133E->_
             inline - len(5) winlogon.exe - 0x00F3134A->_
             inline - len(5) winlogon.exe - 0x00F3136E->_
             inline - len(5) winlogon.exe - 0x00F3137A->_
             inline - len(1) winlogon.exe - 0x00F3138F->_
             inline - len(1) winlogon.exe - 0x00F3139A->_
             inline - len(1) winlogon.exe - 0x00F313A0->_
             inline - len(1) winlogon.exe - 0x00F313D2->_
             inline - len(1) winlogon.exe - 0x00F313DE->_
             inline - len(1) winlogon.exe - 0x00F313E4->_
             inline - len(1) winlogon.exe - 0x00F313EB->_
             inline - len(1) winlogon.exe - 0x00F313F4->_
             inline - len(1) winlogon.exe - 0x00F313FA->_
             inline - len(1) winlogon.exe - 0x00F31402->_
             inline - len(1) winlogon.exe - 0x00F31408->_
             inline - len(1) winlogon.exe - 0x00F31415->_
             inline - len(1) winlogon.exe - 0x00F3143D->_
             inline - len(1) winlogon.exe - 0x00F31445->_
             inline - len(1) winlogon.exe - 0x00F3144F->_
             inline - len(1) winlogon.exe - 0x00F31464->_
             inline - len(1) winlogon.exe - 0x00F3155A->_
             inline - len(1) winlogon.exe - 0x00F31590->_
             inline - len(1) winlogon.exe - 0x00F315B3->_
             inline - len(1) winlogon.exe - 0x00F315C7->_
             inline - len(1) winlogon.exe - 0x00F315EA->_
             inline - len(1) winlogon.exe - 0x00F3160D->_
             inline - len(1) winlogon.exe - 0x00F3161B->_
             inline - len(1) winlogon.exe - 0x00F31699->_
             inline - len(1) winlogon.exe - 0x00F316A5->_
             inline - len(1) winlogon.exe - 0x00F316E4->_
             inline - len(1) winlogon.exe - 0x00F31742->_
             inline - len(1) winlogon.exe - 0x00F31756->_
             inline - len(1) winlogon.exe - 0x00F3175D->_
             inline - len(1) winlogon.exe - 0x00F31788->_
             inline - len(1) winlogon.exe - 0x00F31794->_
             inline - len(1) winlogon.exe - 0x00F317A1->_
             inline - len(1) winlogon.exe - 0x00F317A9->_
             inline - len(1) winlogon.exe - 0x00F317B0->_
             inline - len(1) winlogon.exe - 0x00F317B6->_
             inline - len(1) winlogon.exe - 0x00F317C1->_
             inline - len(1) winlogon.exe - 0x00F31848->_
             inline - len(1) winlogon.exe - 0x00F31873->_
             inline - len(1) winlogon.exe - 0x00F31885->_
             inline - len(1) winlogon.exe - 0x00F3188C->_
             inline - len(1) winlogon.exe - 0x00F31894->_
             inline - len(1) winlogon.exe - 0x00F3189C->_
             inline - len(1) winlogon.exe - 0x00F318AB->_
             inline - len(1) winlogon.exe - 0x00F318B1->_
             inline - len(1) winlogon.exe - 0x00F318B7->_
             inline - len(1) winlogon.exe - 0x00F318BF->_
             inline - len(1) winlogon.exe - 0x00F318CA->_
             inline - len(6) winlogon.exe - 0x00F318D0->_
             inline - len(1) winlogon.exe - 0x00F318DB->_
             inline - len(1) winlogon.exe - 0x00F318E1->_
             inline - len(1) winlogon.exe - 0x00F318EE->_
             inline - len(6) winlogon.exe - 0x00F318F4->_
             inline - len(1) winlogon.exe - 0x00F318FF->_
             inline - len(1) winlogon.exe - 0x00F31905->_
             inline - len(1) winlogon.exe - 0x00F3191A->_
             inline - len(1) winlogon.exe - 0x00F31994->_
             inline - len(1) winlogon.exe - 0x00F319DA->_
             inline - len(1) winlogon.exe - 0x00F319EE->_
             inline - len(6) winlogon.exe - 0x00F31A54->_
             inline - len(1) winlogon.exe - 0x00F31A66->_
             inline - len(1) winlogon.exe - 0x00F31A7C->_
             inline - len(1) winlogon.exe - 0x00F31A8E->_
             inline - len(1) winlogon.exe - 0x00F31AB3->_
             inline - len(1) winlogon.exe - 0x00F31AD8->_
             inline - len(1) winlogon.exe - 0x00F31AF8->_
             inline - len(1) winlogon.exe - 0x00F31B18->_
             inline - len(1) winlogon.exe - 0x00F31B37->_
             inline - len(1) winlogon.exe - 0x00F31B57->_
             inline - len(1) winlogon.exe - 0x00F31B76->_
             inline - len(1) winlogon.exe - 0x00F31B96->_
             inline - len(1) winlogon.exe - 0x00F31BEA->_
             inline - len(1) winlogon.exe - 0x00F31C07->_
             inline - len(1) winlogon.exe - 0x00F31C38->_
             inline - len(1) winlogon.exe - 0x00F31CDD->_
             inline - len(1) winlogon.exe - 0x00F31E15->_
             inline - len(1) winlogon.exe - 0x00F31E33->_
             inline - len(1) winlogon.exe - 0x00F31E3D->_
             inline - len(1) winlogon.exe - 0x00F31E4E->_
             inline - len(1) winlogon.exe - 0x00F31E6A->_
             inline - len(1) winlogon.exe - 0x00F31F02->_
             inline - len(1) winlogon.exe - 0x00F31F14->_
             inline - len(1) winlogon.exe - 0x00F31F21->_
             inline - len(1) winlogon.exe - 0x00F31F33->_
             inline - len(1) winlogon.exe - 0x00F31F3A->_
             inline - len(1) winlogon.exe - 0x00F31F48->_
             inline - len(1) winlogon.exe - 0x00F31F54->_
             inline - len(1) winlogon.exe - 0x00F31F65->_
             inline - len(1) winlogon.exe - 0x00F31F7E->_
             inline - len(1) winlogon.exe - 0x00F31FB2->_
             inline - len(1) winlogon.exe - 0x00F31FCD->_
             inline - len(1) winlogon.exe - 0x00F32016->_
             inline - len(1) winlogon.exe - 0x00F3205A->_
             inline - len(1) winlogon.exe - 0x00F32074->_
             inline - len(1) winlogon.exe - 0x00F3207A->_
             inline - len(1) winlogon.exe - 0x00F320C3->_
             inline - len(1) winlogon.exe - 0x00F320D0->_
             inline - len(1) winlogon.exe - 0x00F320E4->_
             inline - len(1) winlogon.exe - 0x00F32104->_
             inline - len(1) winlogon.exe - 0x00F32136->_
             inline - len(5) winlogon.exe - 0x00F3219E->_
             inline - len(1) winlogon.exe - 0x00F321C5->_
             inline - len(1) winlogon.exe - 0x00F321D4->_
             inline - len(1) winlogon.exe - 0x00F321DA->_
             inline - len(1) winlogon.exe - 0x00F321E9->_
             inline - len(1) winlogon.exe - 0x00F321F7->_
             inline - len(1) winlogon.exe - 0x00F32210->_
             inline - len(1) winlogon.exe - 0x00F3221C->_
             inline - len(1) winlogon.exe - 0x00F3222D->_
             inline - len(1) winlogon.exe - 0x00F3223E->_
             inline - len(6) winlogon.exe - 0x00F32245->_
             inline - len(1) winlogon.exe - 0x00F32277->_
             inline - len(1) winlogon.exe - 0x00F322AD->_
             inline - len(1) winlogon.exe - 0x00F322CB->_
             inline - len(1) winlogon.exe - 0x00F322EC->_
             inline - len(1) winlogon.exe - 0x00F32313->_
             inline - len(1) winlogon.exe - 0x00F32319->_
             inline - len(1) winlogon.exe - 0x00F3232C->_
             inline - len(1) winlogon.exe - 0x00F3233C->_
             inline - len(1) winlogon.exe - 0x00F32342->_
             inline - len(1) winlogon.exe - 0x00F32359->_
             inline - len(1) winlogon.exe - 0x00F32362->_
             inline - len(1) winlogon.exe - 0x00F323DA->_
             inline - len(6) winlogon.exe - 0x00F3240D->_
             inline - len(1) winlogon.exe - 0x00F32427->_
             inline - len(1) winlogon.exe - 0x00F3243D->_
             inline - len(1) winlogon.exe - 0x00F3245F->_
             inline - len(1) winlogon.exe - 0x00F3246C->_
             inline - len(1) winlogon.exe - 0x00F32477->_
             inline - len(1) winlogon.exe - 0x00F32488->_
             inline - len(1) winlogon.exe - 0x00F3248E->_
             inline - len(1) winlogon.exe - 0x00F324EB->_
             inline - len(1) winlogon.exe - 0x00F324F5->_
             inline - len(1) winlogon.exe - 0x00F32501->_
             inline - len(1) winlogon.exe - 0x00F3251C->_
             inline - len(1) winlogon.exe - 0x00F3252B->_
             inline - len(1) winlogon.exe - 0x00F32535->_
             inline - len(6) winlogon.exe - 0x00F3253B->_
             inline - len(1) winlogon.exe - 0x00F32563->_
             inline - len(1) winlogon.exe - 0x00F3256A->_
             inline - len(6) winlogon.exe - 0x00F32570->_
             inline - len(1) winlogon.exe - 0x00F3257C->_
             inline - len(1) winlogon.exe - 0x00F32583->_
             inline - len(1) winlogon.exe - 0x00F32589->_
             inline - len(1) winlogon.exe - 0x00F325CF->_
             inline - len(1) winlogon.exe - 0x00F32658->_
             inline - len(1) winlogon.exe - 0x00F32663->_
             inline - len(1) winlogon.exe - 0x00F3267A->_
             inline - len(1) winlogon.exe - 0x00F3268A->_
             inline - len(1) winlogon.exe - 0x00F32693->_
             inline - len(1) winlogon.exe - 0x00F326C1->_
             inline - len(1) winlogon.exe - 0x00F326CA->_
             inline - len(1) winlogon.exe - 0x00F326ED->_
             inline - len(1) winlogon.exe - 0x00F32704->_
             inline - len(1) winlogon.exe - 0x00F3270F->_
             inline - len(1) winlogon.exe - 0x00F32737->_
             inline - len(1) winlogon.exe - 0x00F32745->_
             inline - len(1) winlogon.exe - 0x00F32761->_
             inline - len(1) winlogon.exe - 0x00F32771->_
             inline - len(1) winlogon.exe - 0x00F3278E->_
             inline - len(1) winlogon.exe - 0x00F3280D->_
             inline - len(1) winlogon.exe - 0x00F32826->_
             inline - len(11) winlogon.exe - 0x00F32880->_
             inline - len(1) winlogon.exe - 0x00F328CB->_
             inline - len(1) winlogon.exe - 0x00F328D8->_
             inline - len(1) winlogon.exe - 0x00F328EA->_
             inline - len(1) winlogon.exe - 0x00F3292B->_
             inline - len(1) winlogon.exe - 0x00F32944->_
             inline - len(1) winlogon.exe - 0x00F3294A->_
             inline - len(1) winlogon.exe - 0x00F32960->_
             inline - len(1) winlogon.exe - 0x00F329A2->_
             inline - len(1) winlogon.exe - 0x00F329AC->_
             inline - len(1) winlogon.exe - 0x00F329BB->_
             inline - len(1) winlogon.exe - 0x00F329C7->_
             inline - len(1) winlogon.exe - 0x00F32A23->_
             inline - len(1) winlogon.exe - 0x00F32A29->_
             inline - len(1) winlogon.exe - 0x00F32A48->_
             inline - len(1) winlogon.exe - 0x00F32A55->_
             inline - len(1) winlogon.exe - 0x00F32AC4->_
             inline - len(1) winlogon.exe - 0x00F32B3D->_
             inline - len(1) winlogon.exe - 0x00F32B67->_
             inline - len(1) winlogon.exe - 0x00F32BA9->_
             inline - len(1) winlogon.exe - 0x00F32BBD->_
             inline - len(1) winlogon.exe - 0x00F32C5B->_
             inline - len(1) winlogon.exe - 0x00F32C7D->_
             inline - len(1) winlogon.exe - 0x00F32C94->_
             inline - len(13) winlogon.exe - 0x00F32CB2->_
             inline - len(1) winlogon.exe - 0x00F32CD2->_
             inline - len(13) winlogon.exe - 0x00F32DAA->_
             inline - len(1) winlogon.exe - 0x00F32DCA->_
             inline - len(1) winlogon.exe - 0x00F32EC0->_
             inline - len(1) winlogon.exe - 0x00F32EC7->_
             inline - len(1) winlogon.exe - 0x00F32EDA->_
             inline - len(1) winlogon.exe - 0x00F33007->_
             inline - len(1) winlogon.exe - 0x00F33089->_
             inline - len(1) winlogon.exe - 0x00F3309E->_
             inline - len(1) winlogon.exe - 0x00F330D9->_
             inline - len(11) winlogon.exe - 0x00F330E6->_
             inline - len(1) winlogon.exe - 0x00F33108->_
             inline - len(1) winlogon.exe - 0x00F3316C->_
             inline - len(1) winlogon.exe - 0x00F33184->_
             inline - len(1) winlogon.exe - 0x00F33196->_
             inline - len(1) winlogon.exe - 0x00F331EA->_
             inline - len(1) winlogon.exe - 0x00F331FF->_
             inline - len(1) winlogon.exe - 0x00F33206->_
             inline - len(1) winlogon.exe - 0x00F33215->_
             inline - len(1) winlogon.exe - 0x00F33244->_
             inline - len(1) winlogon.exe - 0x00F33253->_
             inline - len(1) winlogon.exe - 0x00F332D5->_
             inline - len(5) winlogon.exe - 0x00F3330E->_
             inline - len(6) winlogon.exe - 0x00F33326->_
             inline - len(1) winlogon.exe - 0x00F33349->_
             inline - len(1) winlogon.exe - 0x00F333A2->_
             inline - len(1) winlogon.exe - 0x00F3343C->_
             inline - len(1) winlogon.exe - 0x00F33447->_
             inline - len(1) winlogon.exe - 0x00F33452->_
             inline - len(1) winlogon.exe - 0x00F3345E->_
             inline - len(1) winlogon.exe - 0x00F334E2->_
             inline - len(1) winlogon.exe - 0x00F33506->_
             inline - len(1) winlogon.exe - 0x00F33548->_
             inline - len(1) winlogon.exe - 0x00F33562->_
             inline - len(1) winlogon.exe - 0x00F33568->_
             inline - len(1) winlogon.exe - 0x00F33583->_
             inline - len(1) winlogon.exe - 0x00F335E2->_
             inline - len(1) winlogon.exe - 0x00F335FE->_
             inline - len(1) winlogon.exe - 0x00F3365A->_
             inline - len(1) winlogon.exe - 0x00F336A4->_
             inline - len(1) winlogon.exe - 0x00F336B4->_
             inline - len(1) winlogon.exe - 0x00F336C1->_
             inline - len(1) winlogon.exe - 0x00F33727->_
             inline - len(1) winlogon.exe - 0x00F3373D->_
             inline - len(1) winlogon.exe - 0x00F337A0->_
             inline - len(1) winlogon.exe - 0x00F337AE->_
             inline - len(1) winlogon.exe - 0x00F337B5->_
             inline - len(1) winlogon.exe - 0x00F337F1->_
             inline - len(1) winlogon.exe - 0x00F337F7->_
             inline - len(1) winlogon.exe - 0x00F337FD->_
             inline - len(6) winlogon.exe - 0x00F33816->_
             inline - len(1) winlogon.exe - 0x00F33840->_
             inline - len(1) winlogon.exe - 0x00F33870->_
             inline - len(1) winlogon.exe - 0x00F3387F->_
             inline - len(1) winlogon.exe - 0x00F338A2->_
             inline - len(1) winlogon.exe - 0x00F338D4->_
             inline - len(1) winlogon.exe - 0x00F338E5->_
             inline - len(1) winlogon.exe - 0x00F338EF->_
             inline - len(1) winlogon.exe - 0x00F33913->_
             inline - len(1) winlogon.exe - 0x00F33971->_
             inline - len(1) winlogon.exe - 0x00F3397E->_
             inline - len(1) winlogon.exe - 0x00F3398B->_
             inline - len(11) winlogon.exe - 0x00F339CE->_
             inline - len(1) winlogon.exe - 0x00F339FB->_
             inline - len(1) winlogon.exe - 0x00F33A31->_
             inline - len(1) winlogon.exe - 0x00F33A3E->_
             inline - len(1) winlogon.exe - 0x00F33A68->_
             inline - len(1) winlogon.exe - 0x00F33A92->_
             inline - len(1) winlogon.exe - 0x00F33ACC->_
             inline - len(1) winlogon.exe - 0x00F33AFE->_
             inline - len(11) winlogon.exe - 0x00F33B0B->_
             inline - len(1) winlogon.exe - 0x00F33B81->_
             inline - len(1) winlogon.exe - 0x00F33B87->_
             inline - len(1) winlogon.exe - 0x00F33C83->_
             inline - len(11) winlogon.exe - 0x00F33C9F->_
             inline - len(1) winlogon.exe - 0x00F33CD2->_
             inline - len(1) winlogon.exe - 0x00F33D20->_
             inline - len(1) winlogon.exe - 0x00F33D6D->_
             inline - len(6) winlogon.exe - 0x00F33DF8->_
             inline - len(1) winlogon.exe - 0x00F33E2D->_
             inline - len(11) winlogon.exe - 0x00F33E43->_
             inline - len(1) winlogon.exe - 0x00F33EBC->_
             inline - len(1) winlogon.exe - 0x00F33EDF->_
             inline - len(1) winlogon.exe - 0x00F33EF9->_
             inline - len(1) winlogon.exe - 0x00F33F06->_
             inline - len(5) winlogon.exe - 0x00F33F6E->_
             inline - len(6) winlogon.exe - 0x00F33F86->_
             inline - len(1) winlogon.exe - 0x00F33FB9->_
             inline - len(6) winlogon.exe - 0x00F33FC5->_
             inline - len(1) winlogon.exe - 0x00F33FE0->_
             inline - len(1) winlogon.exe - 0x00F34052->_
             inline - len(6) winlogon.exe - 0x00F3405A->_
             inline - len(1) winlogon.exe - 0x00F340C1->_
             inline - len(1) winlogon.exe - 0x00F340FB->_
             inline - len(1) winlogon.exe - 0x00F34120->_
             inline - len(1) winlogon.exe - 0x00F34139->_
             inline - len(1) winlogon.exe - 0x00F341C9->_
             inline - len(1) winlogon.exe - 0x00F341E7->_
             inline - len(1) winlogon.exe - 0x00F341FF->_
             inline - len(1) winlogon.exe - 0x00F34216->_
             inline - len(1) winlogon.exe - 0x00F3421D->_
             inline - len(6) winlogon.exe - 0x00F3422A->_
             inline - len(1) winlogon.exe - 0x00F34244->_
             inline - len(1) winlogon.exe - 0x00F34250->_
             inline - len(1) winlogon.exe - 0x00F342A2->_
             inline - len(1) winlogon.exe - 0x00F342B2->_
             inline - len(1) winlogon.exe - 0x00F342F0->_
             inline - len(6) winlogon.exe - 0x00F3433F->_
             inline - len(1) winlogon.exe - 0x00F34357->_
             inline - len(1) winlogon.exe - 0x00F343D0->_
             inline - len(6) winlogon.exe - 0x00F343FC->_
             inline - len(1) winlogon.exe - 0x00F34417->_
             inline - len(1) winlogon.exe - 0x00F34429->_
             inline - len(1) winlogon.exe - 0x00F3443A->_
             inline - len(1) winlogon.exe - 0x00F34453->_
             inline - len(1) winlogon.exe - 0x00F3448A->_
             inline - len(1) winlogon.exe - 0x00F344A2->_
             inline - len(1) winlogon.exe - 0x00F344A9->_
             inline - len(1) winlogon.exe - 0x00F344B2->_
             inline - len(1) winlogon.exe - 0x00F344B8->_
             inline - len(1) winlogon.exe - 0x00F344C9->_
             inline - len(1) winlogon.exe - 0x00F34510->_
             inline - len(1) winlogon.exe - 0x00F3451D->_
             inline - len(1) winlogon.exe - 0x00F34562->_
             inline - len(1) winlogon.exe - 0x00F345F3->_
             inline - len(1) winlogon.exe - 0x00F34600->_
             inline - len(1) winlogon.exe - 0x00F34635->_
             inline - len(6) winlogon.exe - 0x00F34659->_
             inline - len(1) winlogon.exe - 0x00F34679->_
             inline - len(1) winlogon.exe - 0x00F3468B->_
             inline - len(1) winlogon.exe - 0x00F34694->_
             inline - len(1) winlogon.exe - 0x00F346A5->_
             inline - len(1) winlogon.exe - 0x00F346B9->_
             inline - len(1) winlogon.exe - 0x00F34700->_
             inline - len(6) winlogon.exe - 0x00F3471C->_
             inline - len(1) winlogon.exe - 0x00F34739->_
             inline - len(1) winlogon.exe - 0x00F34758->_
             inline - len(1) winlogon.exe - 0x00F34776->_
             inline - len(1) winlogon.exe - 0x00F3477E->_
             inline - len(1) winlogon.exe - 0x00F34789->_
             inline - len(1) winlogon.exe - 0x00F3479E->_
             inline - len(1) winlogon.exe - 0x00F347B4->_
             inline - len(1) winlogon.exe - 0x00F347CB->_
             inline - len(1) winlogon.exe - 0x00F347EB->_
             inline - len(1) winlogon.exe - 0x00F34832->_
             inline - len(1) winlogon.exe - 0x00F34854->_
             inline - len(1) winlogon.exe - 0x00F3485A->_
             inline - len(1) winlogon.exe - 0x00F34874->_
             inline - len(1) winlogon.exe - 0x00F34895->_
             inline - len(1) winlogon.exe - 0x00F3489D->_
             inline - len(11) winlogon.exe - 0x00F348E6->_
             inline - len(1) winlogon.exe - 0x00F34932->_
             inline - len(1) winlogon.exe - 0x00F3496D->_
             inline - len(1) winlogon.exe - 0x00F34988->_
             inline - len(1) winlogon.exe - 0x00F349AF->_
             inline - len(1) winlogon.exe - 0x00F349B7->_
             inline - len(6) winlogon.exe - 0x00F34A12->_
             inline - len(1) winlogon.exe - 0x00F34A73->_
             inline - len(1) winlogon.exe - 0x00F34AB2->_
             inline - len(1) winlogon.exe - 0x00F34ABA->_
             inline - len(1) winlogon.exe - 0x00F34AE9->_
             inline - len(1) winlogon.exe - 0x00F34AFF->_
             inline - len(1) winlogon.exe - 0x00F34B0E->_
             inline - len(6) winlogon.exe - 0x00F34B2F->_
             inline - len(1) winlogon.exe - 0x00F34B4C->_
             inline - len(1) winlogon.exe - 0x00F34BBF->_
             inline - len(6) winlogon.exe - 0x00F34BFC->_
             inline - len(1) winlogon.exe - 0x00F34C19->_
             inline - len(1) winlogon.exe - 0x00F34C2B->_
             inline - len(1) winlogon.exe - 0x00F34C43->_
             inline - len(1) winlogon.exe - 0x00F34CA4->_
             inline - len(1) winlogon.exe - 0x00F34CF2->_
             inline - len(1) winlogon.exe - 0x00F34D0B->_
             inline - len(1) winlogon.exe - 0x00F34DBA->_
             inline - len(1) winlogon.exe - 0x00F34DE3->_
             inline - len(1) winlogon.exe - 0x00F34DFA->_
             inline - len(6) winlogon.exe - 0x00F34E15->_
             inline - len(1) winlogon.exe - 0x00F34E30->_
             inline - len(1) winlogon.exe - 0x00F34F1A->_
             inline - len(6) winlogon.exe - 0x00F34F31->_
             inline - len(1) winlogon.exe - 0x00F34F4C->_
             inline - len(6) winlogon.exe - 0x00F34F74->_
             inline - len(1) winlogon.exe - 0x00F34F8F->_
             inline - len(1) winlogon.exe - 0x00F34FAB->_
             inline - len(6) winlogon.exe - 0x00F34FD0->_
             inline - len(1) winlogon.exe - 0x00F34FED->_
             inline - len(1) winlogon.exe - 0x00F35025->_
             inline - len(1) winlogon.exe - 0x00F35122->_
             inline - len(1) winlogon.exe - 0x00F3512E->_
             inline - len(1) winlogon.exe - 0x00F3515B->_
             inline - len(5) winlogon.exe - 0x00F3518E->_
             inline - len(6) winlogon.exe - 0x00F351A6->_
             inline - len(6) winlogon.exe - 0x00F351DC->_
             inline - len(1) winlogon.exe - 0x00F351F7->_
             inline - len(1) winlogon.exe - 0x00F35248->_
             inline - len(1) winlogon.exe - 0x00F3525D->0x00F331A6[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F35277->_
             inline - len(1) winlogon.exe - 0x00F35285->_
             inline - len(1) winlogon.exe - 0x00F3528D->_
             inline - len(1) winlogon.exe - 0x00F3529F->_
             inline - len(1) winlogon.exe - 0x00F352A5->_
             inline - len(1) winlogon.exe - 0x00F352C1->_
             inline - len(1) winlogon.exe - 0x00F352CF->_
             inline - len(1) winlogon.exe - 0x00F352E2->_
             inline - len(11) winlogon.exe - 0x00F3531E->_
             inline - len(1) winlogon.exe - 0x00F3535E->_
             inline - len(6) winlogon.exe - 0x00F353DD->_
             inline - len(1) winlogon.exe - 0x00F353F8->_
             inline - len(6) winlogon.exe - 0x00F35423->_
             inline - len(1) winlogon.exe - 0x00F3543E->_
             inline - len(1) winlogon.exe - 0x00F3545D->_
             inline - len(6) winlogon.exe - 0x00F35475->_
             inline - len(1) winlogon.exe - 0x00F3549E->_
             inline - len(1) winlogon.exe - 0x00F354CD->_
             inline - len(1) winlogon.exe - 0x00F35509->_
             inline - len(1) winlogon.exe - 0x00F35562->_
             inline - len(1) winlogon.exe - 0x00F3557C->_
             inline - len(1) winlogon.exe - 0x00F35599->_
             inline - len(1) winlogon.exe - 0x00F355B3->_
             inline - len(1) winlogon.exe - 0x00F355C3->_
             inline - len(1) winlogon.exe - 0x00F355DF->_
             inline - len(1) winlogon.exe - 0x00F355EB->_
             inline - len(1) winlogon.exe - 0x00F35653->_
             inline - len(6) winlogon.exe - 0x00F356DD->_
             inline - len(1) winlogon.exe - 0x00F356FA->_
             inline - len(1) winlogon.exe - 0x00F35713->_
             inline - len(1) winlogon.exe - 0x00F3572B->_
             inline - len(1) winlogon.exe - 0x00F3576A->_
             inline - len(6) winlogon.exe - 0x00F35797->_
             inline - len(1) winlogon.exe - 0x00F357B3->_
             inline - len(1) winlogon.exe - 0x00F357CD->_
             inline - len(1) winlogon.exe - 0x00F357E1->_
             inline - len(1) winlogon.exe - 0x00F3583F->_
             inline - len(1) winlogon.exe - 0x00F3584D->_
             inline - len(1) winlogon.exe - 0x00F3585C->_
             inline - len(1) winlogon.exe - 0x00F35866->_
             inline - len(1) winlogon.exe - 0x00F35878->_
             inline - len(1) winlogon.exe - 0x00F35896->_
             inline - len(1) winlogon.exe - 0x00F358B6->_
             inline - len(6) winlogon.exe - 0x00F358C9->_
             inline - len(1) winlogon.exe - 0x00F358F0->_
             inline - len(1) winlogon.exe - 0x00F358F7->_
             inline - len(1) winlogon.exe - 0x00F3593D->_
             inline - len(1) winlogon.exe - 0x00F3594A->_
             inline - len(6) winlogon.exe - 0x00F35971->_
             inline - len(1) winlogon.exe - 0x00F35995->_
             inline - len(1) winlogon.exe - 0x00F359A8->_
             inline - len(1) winlogon.exe - 0x00F359CE->_
             inline - len(1) winlogon.exe - 0x00F359EA->_
             inline - len(1) winlogon.exe - 0x00F35A2A->_
             inline - len(1) winlogon.exe - 0x00F35A3D->_
             inline - len(1) winlogon.exe - 0x00F35A4F->_
             inline - len(1) winlogon.exe - 0x00F35A73->_
             inline - len(1) winlogon.exe - 0x00F35A79->_
             inline - len(1) winlogon.exe - 0x00F35AAF->_
             inline - len(6) winlogon.exe - 0x00F35AD7->_
             inline - len(1) winlogon.exe - 0x00F35B00->_
             inline - len(1) winlogon.exe - 0x00F35B48->_
             inline - len(1) winlogon.exe - 0x00F35B60->_
             inline - len(1) winlogon.exe - 0x00F35B66->_
             inline - len(1) winlogon.exe - 0x00F35B77->_
             inline - len(1) winlogon.exe - 0x00F35B95->_
             inline - len(1) winlogon.exe - 0x00F35C22->_
             inline - len(6) winlogon.exe - 0x00F35C43->_
             inline - len(1) winlogon.exe - 0x00F35C60->_
             inline - len(1) winlogon.exe - 0x00F35CB8->_
             inline - len(1) winlogon.exe - 0x00F35CD0->_
             inline - len(1) winlogon.exe - 0x00F35D07->_
             inline - len(1) winlogon.exe - 0x00F35D2F->_
             inline - len(1) winlogon.exe - 0x00F35D46->_
             inline - len(6) winlogon.exe - 0x00F35D9A->_
             inline - len(1) winlogon.exe - 0x00F35E15->_
             inline - len(6) winlogon.exe - 0x00F35E25->_
             inline - len(1) winlogon.exe - 0x00F35E4C->_
             inline - len(1) winlogon.exe - 0x00F35E55->_
             inline - len(1) winlogon.exe - 0x00F35E65->_
             inline - len(1) winlogon.exe - 0x00F35ECE->_
             inline - len(6) winlogon.exe - 0x00F35EE3->_
             inline - len(1) winlogon.exe - 0x00F35EFE->_
             inline - len(1) winlogon.exe - 0x00F35FDA->_
             inline - len(1) winlogon.exe - 0x00F35FF5->_
             inline - len(1) winlogon.exe - 0x00F36019->_
             inline - len(5) winlogon.exe - 0x00F3604E->_
             inline - len(6) winlogon.exe - 0x00F36066->_
             inline - len(6) winlogon.exe - 0x00F360A2->_
             inline - len(1) winlogon.exe - 0x00F360CF->_
             inline - len(6) winlogon.exe - 0x00F360D7->_
             inline - len(1) winlogon.exe - 0x00F3612F->_
             inline - len(1) winlogon.exe - 0x00F36190->_
             inline - len(1) winlogon.exe - 0x00F361AC->_
             inline - len(11) winlogon.exe - 0x00F361CD->_
             inline - len(1) winlogon.exe - 0x00F36257->_
             inline - len(1) winlogon.exe - 0x00F36271->_
             inline - len(1) winlogon.exe - 0x00F36281->_
             inline - len(1) winlogon.exe - 0x00F362B1->_
             inline - len(1) winlogon.exe - 0x00F362CC->_
             inline - len(1) winlogon.exe - 0x00F362E5->_
             inline - len(1) winlogon.exe - 0x00F362F1->_
             inline - len(1) winlogon.exe - 0x00F362FF->_
             inline - len(1) winlogon.exe - 0x00F36333->_
             inline - len(1) winlogon.exe - 0x00F36341->_
             inline - len(1) winlogon.exe - 0x00F36378->_
             inline - len(1) winlogon.exe - 0x00F363C2->_
             inline - len(1) winlogon.exe - 0x00F363E3->_
             inline - len(1) winlogon.exe - 0x00F363F3->_
             inline - len(1) winlogon.exe - 0x00F363FF->_
             inline - len(11) winlogon.exe - 0x00F36416->_
             inline - len(1) winlogon.exe - 0x00F36479->_
             inline - len(1) winlogon.exe - 0x00F364A8->_
             inline - len(1) winlogon.exe - 0x00F364D0->_
             inline - len(1) winlogon.exe - 0x00F36532->_
             inline - len(1) winlogon.exe - 0x00F3653E->_
             inline - len(1) winlogon.exe - 0x00F3656D->_
             inline - len(1) winlogon.exe - 0x00F3657E->_
             inline - len(1) winlogon.exe - 0x00F36597->_
             inline - len(1) winlogon.exe - 0x00F365D2->_
             inline - len(6) winlogon.exe - 0x00F365FF->_
             inline - len(1) winlogon.exe - 0x00F36622->_
             inline - len(11) winlogon.exe - 0x00F36639->_
             inline - len(1) winlogon.exe - 0x00F3669E->_
             inline - len(1) winlogon.exe - 0x00F366CC->_
             inline - len(1) winlogon.exe - 0x00F366F6->_
             inline - len(1) winlogon.exe - 0x00F36762->_
             inline - len(1) winlogon.exe - 0x00F36778->_
             inline - len(6) winlogon.exe - 0x00F36797->_
             inline - len(1) winlogon.exe - 0x00F367D0->_
             inline - len(6) winlogon.exe - 0x00F367FD->_
             inline - len(1) winlogon.exe - 0x00F36818->_
             inline - len(1) winlogon.exe - 0x00F3683E->_
             inline - len(1) winlogon.exe - 0x00F36857->_
             inline - len(1) winlogon.exe - 0x00F36870->_
             inline - len(1) winlogon.exe - 0x00F36879->_
             inline - len(1) winlogon.exe - 0x00F36889->_
             inline - len(6) winlogon.exe - 0x00F36898->_
             inline - len(1) winlogon.exe - 0x00F368B8->_
             inline - len(1) winlogon.exe - 0x00F36919->_
             inline - len(6) winlogon.exe - 0x00F3693D->_
             inline - len(1) winlogon.exe - 0x00F36955->_
             inline - len(1) winlogon.exe - 0x00F36971->_
             inline - len(6) winlogon.exe - 0x00F36981->_
             inline - len(1) winlogon.exe - 0x00F369AA->_
             inline - len(1) winlogon.exe - 0x00F36A02->0x00F24C65[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F36A5A->_
             inline - len(1) winlogon.exe - 0x00F36A67->_
             inline - len(11) winlogon.exe - 0x00F36AF5->_
             inline - len(1) winlogon.exe - 0x00F36B29->_
             inline - len(1) winlogon.exe - 0x00F36B62->_
             inline - len(1) winlogon.exe - 0x00F36BAF->_
             inline - len(1) winlogon.exe - 0x00F36BC0->_
             inline - len(1) winlogon.exe - 0x00F36BD9->_
             inline - len(1) winlogon.exe - 0x00F36C12->_
             inline - len(1) winlogon.exe - 0x00F36C3D->_
             inline - len(1) winlogon.exe - 0x00F36C47->_
             inline - len(1) winlogon.exe - 0x00F36C4F->_
             inline - len(1) winlogon.exe - 0x00F36C9A->_
             inline - len(1) winlogon.exe - 0x00F36D14->_
             inline - len(1) winlogon.exe - 0x00F36D3C->_
             inline - len(1) winlogon.exe - 0x00F36D47->_
             inline - len(1) winlogon.exe - 0x00F36D5B->_
             inline - len(1) winlogon.exe - 0x00F36D68->_
             inline - len(1) winlogon.exe - 0x00F36DC6->_
             inline - len(1) winlogon.exe - 0x00F36DFC->_
             inline - len(1) winlogon.exe - 0x00F36E82->_
             inline - len(1) winlogon.exe - 0x00F36EC0->_
             inline - len(1) winlogon.exe - 0x00F36F35->_
             inline - len(11) winlogon.exe - 0x00F36F82->_
             inline - len(1) winlogon.exe - 0x00F36FB7->_
             inline - len(1) winlogon.exe - 0x00F36FDD->_
             inline - len(11) winlogon.exe - 0x00F36FE7->_
             inline - len(1) winlogon.exe - 0x00F37068->_
             inline - len(1) winlogon.exe - 0x00F370D2->_
             inline - len(1) winlogon.exe - 0x00F370FE->_
             inline - len(1) winlogon.exe - 0x00F3714A->_
             inline - len(1) winlogon.exe - 0x00F37161->_
             inline - len(11) winlogon.exe - 0x00F3716B->_
             inline - len(1) winlogon.exe - 0x00F37198->_
             inline - len(1) winlogon.exe - 0x00F371A6->_
             inline - len(6) winlogon.exe - 0x00F371F4->_
             inline - len(1) winlogon.exe - 0x00F37200->_
             inline - len(1) winlogon.exe - 0x00F37210->_
             inline - len(6) winlogon.exe - 0x00F37219->_
             inline - len(11) winlogon.exe - 0x00F37226->_
             inline - len(1) winlogon.exe - 0x00F37243->_
             inline - len(1) winlogon.exe - 0x00F3725D->_
             inline - len(6) winlogon.exe - 0x00F37264->_
             inline - len(1) winlogon.exe - 0x00F3727C->_
             inline - len(6) winlogon.exe - 0x00F372A4->_
             inline - len(1) winlogon.exe - 0x00F372BC->_
             inline - len(1) winlogon.exe - 0x00F372EB->_
             inline - len(1) winlogon.exe - 0x00F37314->_
             inline - len(1) winlogon.exe - 0x00F3734B->_
             inline - len(1) winlogon.exe - 0x00F37354->_
             inline - len(1) winlogon.exe - 0x00F37365->_
             inline - len(1) winlogon.exe - 0x00F37375->_
             inline - len(1) winlogon.exe - 0x00F373CA->_
             inline - len(1) winlogon.exe - 0x00F373DD->_
             inline - len(1) winlogon.exe - 0x00F373F9->_
             inline - len(1) winlogon.exe - 0x00F37416->_
             inline - len(1) winlogon.exe - 0x00F3745A->_
             inline - len(1) winlogon.exe - 0x00F3746D->_
             inline - len(1) winlogon.exe - 0x00F3747C->_
             inline - len(1) winlogon.exe - 0x00F37482->_
             inline - len(1) winlogon.exe - 0x00F374C2->_
             inline - len(1) winlogon.exe - 0x00F374D6->_
             inline - len(11) winlogon.exe - 0x00F374F6->_
             inline - len(1) winlogon.exe - 0x00F37524->_
             inline - len(1) winlogon.exe - 0x00F3752A->_
             inline - len(1) winlogon.exe - 0x00F37530->_
             inline - len(1) winlogon.exe - 0x00F3753C->_
             inline - len(1) winlogon.exe - 0x00F37542->_
             inline - len(1) winlogon.exe - 0x00F3754E->_
             inline - len(1) winlogon.exe - 0x00F3755D->_
             inline - len(1) winlogon.exe - 0x00F37574->_
             inline - len(1) winlogon.exe - 0x00F37580->_
             inline - len(1) winlogon.exe - 0x00F3758B->_
             inline - len(1) winlogon.exe - 0x00F37591->_
             inline - len(1) winlogon.exe - 0x00F3759E->_
             inline - len(6) winlogon.exe - 0x00F375A8->_
             inline - len(1) winlogon.exe - 0x00F375B3->_
             inline - len(6) winlogon.exe - 0x00F375C1->_
             inline - len(1) winlogon.exe - 0x00F375FA->_
             inline - len(1) winlogon.exe - 0x00F3761B->_
             inline - len(6) winlogon.exe - 0x00F3762D->_
             inline - len(1) winlogon.exe - 0x00F3767A->_
             inline - len(1) winlogon.exe - 0x00F3768B->_
             inline - len(1) winlogon.exe - 0x00F3769C->_
             inline - len(1) winlogon.exe - 0x00F376A2->_
             inline - len(1) winlogon.exe - 0x00F376AF->_
             inline - len(1) winlogon.exe - 0x00F376B5->_
             inline - len(1) winlogon.exe - 0x00F376D1->_
             inline - len(1) winlogon.exe - 0x00F376D7->_
             inline - len(1) winlogon.exe - 0x00F376E0->_
             inline - len(1) winlogon.exe - 0x00F376E6->_
             inline - len(6) winlogon.exe - 0x00F37710->_
             inline - len(1) winlogon.exe - 0x00F37728->_
             inline - len(1) winlogon.exe - 0x00F3775A->_
             inline - len(1) winlogon.exe - 0x00F37764->_
             inline - len(1) winlogon.exe - 0x00F3776C->_
             inline - len(6) winlogon.exe - 0x00F37799->_
             inline - len(1) winlogon.exe - 0x00F377BC->_
             inline - len(6) winlogon.exe - 0x00F377DA->_
             inline - len(1) winlogon.exe - 0x00F377F7->_
             inline - len(1) winlogon.exe - 0x00F37865->_
             inline - len(1) winlogon.exe - 0x00F3787E->_
             inline - len(1) winlogon.exe - 0x00F3789B->_
             inline - len(1) winlogon.exe - 0x00F378BE->_
             inline - len(1) winlogon.exe - 0x00F378CD->_
             inline - len(1) winlogon.exe - 0x00F378D7->_
             inline - len(1) winlogon.exe - 0x00F37908->_
             inline - len(1) winlogon.exe - 0x00F37982->_
             inline - len(1) winlogon.exe - 0x00F379D3->_
             inline - len(1) winlogon.exe - 0x00F379FA->_
             inline - len(1) winlogon.exe - 0x00F37A03->_
             inline - len(1) winlogon.exe - 0x00F37A14->_
             inline - len(1) winlogon.exe - 0x00F37A20->_
             inline - len(1) winlogon.exe - 0x00F37A3D->_
             inline - len(5) winlogon.exe - 0x00F37A6E->_
             inline - len(6) winlogon.exe - 0x00F37A86->_
             inline - len(6) winlogon.exe - 0x00F37AC4->_
             inline - len(1) winlogon.exe - 0x00F37ADF->_
             inline - len(1) winlogon.exe - 0x00F37B00->_
             inline - len(11) winlogon.exe - 0x00F37B0A->_
             inline - len(1) winlogon.exe - 0x00F37B65->_
             inline - len(1) winlogon.exe - 0x00F37BBE->_
             inline - len(1) winlogon.exe - 0x00F37C13->_
             inline - len(1) winlogon.exe - 0x00F37C39->_
             inline - len(1) winlogon.exe - 0x00F37C48->_
             inline - len(1) winlogon.exe - 0x00F37C52->_
             inline - len(1) winlogon.exe - 0x00F37C7E->_
             inline - len(1) winlogon.exe - 0x00F37CDF->_
             inline - len(1) winlogon.exe - 0x00F37D06->_
             inline - len(1) winlogon.exe - 0x00F37D24->_
             inline - len(1) winlogon.exe - 0x00F37D92->_
             inline - len(1) winlogon.exe - 0x00F37D9F->_
             inline - len(1) winlogon.exe - 0x00F37DB3->_
             inline - len(1) winlogon.exe - 0x00F37DC1->_
             inline - len(1) winlogon.exe - 0x00F37DCB->_
             inline - len(1) winlogon.exe - 0x00F37DD5->_
             inline - len(1) winlogon.exe - 0x00F37DDF->_
             inline - len(1) winlogon.exe - 0x00F37DE9->_
             inline - len(1) winlogon.exe - 0x00F37DF3->_
             inline - len(1) winlogon.exe - 0x00F37DFD->_
             inline - len(1) winlogon.exe - 0x00F37E0D->_
             inline - len(1) winlogon.exe - 0x00F37E1E->_
             inline - len(1) winlogon.exe - 0x00F37E24->_
             inline - len(1) winlogon.exe - 0x00F37E2C->_
             inline - len(1) winlogon.exe - 0x00F37E32->_
             inline - len(1) winlogon.exe - 0x00F37E38->_
             inline - len(1) winlogon.exe - 0x00F37E3E->_
             inline - len(1) winlogon.exe - 0x00F37E44->_
             inline - len(1) winlogon.exe - 0x00F37E4B->_
             inline - len(1) winlogon.exe - 0x00F37E5B->_
             inline - len(1) winlogon.exe - 0x00F37E6B->_
             inline - len(6) winlogon.exe - 0x00F37E73->_
             inline - len(1) winlogon.exe - 0x00F37E90->_
             inline - len(1) winlogon.exe - 0x00F37E9B->_
             inline - len(1) winlogon.exe - 0x00F37EAB->_
             inline - len(1) winlogon.exe - 0x00F37EBA->_
             inline - len(1) winlogon.exe - 0x00F37EF7->_
             inline - len(1) winlogon.exe - 0x00F37F1C->_
             inline - len(1) winlogon.exe - 0x00F37F3B->_
             inline - len(1) winlogon.exe - 0x00F37F4B->_
             inline - len(1) winlogon.exe - 0x00F37F67->_
             inline - len(1) winlogon.exe - 0x00F37F7D->_
             inline - len(1) winlogon.exe - 0x00F37F8F->_
             inline - len(1) winlogon.exe - 0x00F37FE2->_
             inline - len(1) winlogon.exe - 0x00F37FFE->_
             inline - len(1) winlogon.exe - 0x00F3800C->_
             inline - len(1) winlogon.exe - 0x00F3801A->_
             inline - len(1) winlogon.exe - 0x00F38027->_
             inline - len(1) winlogon.exe - 0x00F38056->_
             inline - len(1) winlogon.exe - 0x00F38067->_
             inline - len(1) winlogon.exe - 0x00F38080->_
             inline - len(1) winlogon.exe - 0x00F380BA->_
             inline - len(1) winlogon.exe - 0x00F380D0->_
             inline - len(6) winlogon.exe - 0x00F380F5->_
             inline - len(1) winlogon.exe - 0x00F38117->_
             inline - len(1) winlogon.exe - 0x00F38125->_
             inline - len(6) winlogon.exe - 0x00F3812C->_
             inline - len(1) winlogon.exe - 0x00F38137->_
             inline - len(1) winlogon.exe - 0x00F38147->_
             inline - len(1) winlogon.exe - 0x00F38158->_
             inline - len(1) winlogon.exe - 0x00F38161->_
             inline - len(1) winlogon.exe - 0x00F3816A->_
             inline - len(1) winlogon.exe - 0x00F38174->_
             inline - len(1) winlogon.exe - 0x00F3817A->_
             inline - len(1) winlogon.exe - 0x00F38192->_
             inline - len(1) winlogon.exe - 0x00F38199->_
             inline - len(1) winlogon.exe - 0x00F3819F->_
             inline - len(1) winlogon.exe - 0x00F381A5->_
             inline - len(1) winlogon.exe - 0x00F381AB->_
             inline - len(1) winlogon.exe - 0x00F381B5->_
             inline - len(1) winlogon.exe - 0x00F381BB->_
             inline - len(1) winlogon.exe - 0x00F381C2->_
             inline - len(1) winlogon.exe - 0x00F381C8->_
             inline - len(1) winlogon.exe - 0x00F381D2->_
             inline - len(1) winlogon.exe - 0x00F381D8->_
             inline - len(1) winlogon.exe - 0x00F381E3->_
             inline - len(1) winlogon.exe - 0x00F381E9->_
             inline - len(1) winlogon.exe - 0x00F381F3->_
             inline - len(1) winlogon.exe - 0x00F381FF->_
             inline - len(1) winlogon.exe - 0x00F3820A->_
             inline - len(1) winlogon.exe - 0x00F38210->_
             inline - len(1) winlogon.exe - 0x00F38261->_
             inline - len(1) winlogon.exe - 0x00F38267->_
             inline - len(1) winlogon.exe - 0x00F38279->_
             inline - len(1) winlogon.exe - 0x00F3827F->_
             inline - len(1) winlogon.exe - 0x00F38286->_
             inline - len(1) winlogon.exe - 0x00F382A1->_
             inline - len(1) winlogon.exe - 0x00F382AC->_
             inline - len(1) winlogon.exe - 0x00F382B4->_
             inline - len(1) winlogon.exe - 0x00F382BA->_
             inline - len(1) winlogon.exe - 0x00F382C5->_
             inline - len(1) winlogon.exe - 0x00F382CC->_
             inline - len(6) winlogon.exe - 0x00F382DB->_
             inline - len(1) winlogon.exe - 0x00F382F4->_
             inline - len(1) winlogon.exe - 0x00F3830F->_
             inline - len(1) winlogon.exe - 0x00F38315->_
             inline - len(1) winlogon.exe - 0x00F3831C->_
             inline - len(1) winlogon.exe - 0x00F3834D->_
             inline - len(1) winlogon.exe - 0x00F3837E->_
             inline - len(1) winlogon.exe - 0x00F38394->_
             inline - len(1) winlogon.exe - 0x00F3839A->0x5EC68B00
             inline - len(1) winlogon.exe - 0x00F383A3->_
             inline - len(1) winlogon.exe - 0x00F383B3->_
             inline - len(1) winlogon.exe - 0x00F383BD->_
             inline - len(1) winlogon.exe - 0x00F383CA->_
             inline - len(1) winlogon.exe - 0x00F383D5->_
             inline - len(1) winlogon.exe - 0x00F383DB->_
             inline - len(1) winlogon.exe - 0x00F383E4->_
             inline - len(1) winlogon.exe - 0x00F383EA->_
             inline - len(1) winlogon.exe - 0x00F38404->_
             inline - len(1) winlogon.exe - 0x00F3840B->_
             inline - len(1) winlogon.exe - 0x00F38411->_
             inline - len(1) winlogon.exe - 0x00F38417->_
             inline - len(1) winlogon.exe - 0x00F3841D->_
             inline - len(1) winlogon.exe - 0x00F3842B->_
             inline - len(1) winlogon.exe - 0x00F38431->_
             inline - len(1) winlogon.exe - 0x00F38438->_
             inline - len(1) winlogon.exe - 0x00F3843E->_
             inline - len(1) winlogon.exe - 0x00F3844C->_
             inline - len(1) winlogon.exe - 0x00F38452->_
             inline - len(1) winlogon.exe - 0x00F38458->_
             inline - len(1) winlogon.exe - 0x00F38463->_
             inline - len(1) winlogon.exe - 0x00F38473->_
             inline - len(1) winlogon.exe - 0x00F38479->_
             inline - len(1) winlogon.exe - 0x00F38484->_
             inline - len(1) winlogon.exe - 0x00F38494->_
             inline - len(1) winlogon.exe - 0x00F3849A->_
             inline - len(1) winlogon.exe - 0x00F384A0->_
             inline - len(1) winlogon.exe - 0x00F384A6->_
             inline - len(1) winlogon.exe - 0x00F384AC->_
             inline - len(1) winlogon.exe - 0x00F384B2->_
             inline - len(1) winlogon.exe - 0x00F384B8->_
             inline - len(1) winlogon.exe - 0x00F384BE->_
             inline - len(1) winlogon.exe - 0x00F384C9->_
             inline - len(1) winlogon.exe - 0x00F384D9->_
             inline - len(1) winlogon.exe - 0x00F38513->_
             inline - len(1) winlogon.exe - 0x00F3851E->_
             inline - len(1) winlogon.exe - 0x00F38541->_
             inline - len(1) winlogon.exe - 0x00F38568->_
             inline - len(1) winlogon.exe - 0x00F3864D->_
             inline - len(1) winlogon.exe - 0x00F3868C->_
             inline - len(1) winlogon.exe - 0x00F38693->_
             inline - len(1) winlogon.exe - 0x00F386A6->_
             inline - len(1) winlogon.exe - 0x00F386AC->_
             inline - len(1) winlogon.exe - 0x00F386C8->_
             inline - len(1) winlogon.exe - 0x00F386DA->_
             inline - len(1) winlogon.exe - 0x00F386E9->_
             inline - len(1) winlogon.exe - 0x00F38732->_
             inline - len(1) winlogon.exe - 0x00F3874D->_
             inline - len(1) winlogon.exe - 0x00F38785->_
             inline - len(1) winlogon.exe - 0x00F38793->_
             inline - len(1) winlogon.exe - 0x00F387A1->_
             inline - len(1) winlogon.exe - 0x00F387A9->_
             inline - len(1) winlogon.exe - 0x00F387BF->_
             inline - len(1) winlogon.exe - 0x00F387CE->_
             inline - len(1) winlogon.exe - 0x00F387D4->_
             inline - len(1) winlogon.exe - 0x00F387E1->_
             inline - len(1) winlogon.exe - 0x00F387EF->_
             inline - len(1) winlogon.exe - 0x00F387F7->_
             inline - len(1) winlogon.exe - 0x00F38802->_
             inline - len(1) winlogon.exe - 0x00F3881A->_
             inline - len(1) winlogon.exe - 0x00F38828->_
             inline - len(1) winlogon.exe - 0x00F38836->_
             inline - len(1) winlogon.exe - 0x00F38862->_
             inline - len(1) winlogon.exe - 0x00F388A1->_
             inline - len(1) winlogon.exe - 0x00F388B1->_
             inline - len(11) winlogon.exe - 0x00F388BC->_
             inline - len(1) winlogon.exe - 0x00F388D3->_
             inline - len(1) winlogon.exe - 0x00F388DA->_
             inline - len(1) winlogon.exe - 0x00F388E6->_
             inline - len(1) winlogon.exe - 0x00F38900->_
             inline - len(1) winlogon.exe - 0x00F38919->_
             inline - len(1) winlogon.exe - 0x00F3891F->_
             inline - len(1) winlogon.exe - 0x00F38926->_
             inline - len(1) winlogon.exe - 0x00F38932->_
             inline - len(1) winlogon.exe - 0x00F3893A->_
             inline - len(1) winlogon.exe - 0x00F3895F->_
             inline - len(1) winlogon.exe - 0x00F389BE->_
             inline - len(1) winlogon.exe - 0x00F389C7->_
             inline - len(1) winlogon.exe - 0x00F389D9->_
             inline - len(1) winlogon.exe - 0x00F38A5F->_
             inline - len(1) winlogon.exe - 0x00F38AA7->_
             inline - len(1) winlogon.exe - 0x00F38AB8->_
             inline - len(1) winlogon.exe - 0x00F38AD1->_
             inline - len(1) winlogon.exe - 0x00F38B0A->_
             inline - len(1) winlogon.exe - 0x00F38B4E->0x00F23510[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F38B64->0x00F36D30[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F38BA8->_
             inline - len(1) winlogon.exe - 0x00F38BBC->_
             inline - len(1) winlogon.exe - 0x00F38BD4->_
             inline - len(1) winlogon.exe - 0x00F38BDF->_
             inline - len(1) winlogon.exe - 0x00F38BE8->_
             inline - len(1) winlogon.exe - 0x00F38BF6->_
             inline - len(1) winlogon.exe - 0x00F38C5D->_
             inline - len(1) winlogon.exe - 0x00F38C6E->_
             inline - len(6) winlogon.exe - 0x00F38CA3->_
             inline - len(1) winlogon.exe - 0x00F38CBF->_
             inline - len(1) winlogon.exe - 0x00F38DFC->_
             inline - len(6) winlogon.exe - 0x00F38E50->_
             inline - len(1) winlogon.exe - 0x00F38E6B->_
             inline - len(1) winlogon.exe - 0x00F38F45->_
             inline - len(6) winlogon.exe - 0x00F38FBC->_
             inline - len(1) winlogon.exe - 0x00F38FE9->_
             inline - len(6) winlogon.exe - 0x00F390B8->_
             inline - len(1) winlogon.exe - 0x00F390D3->_
             inline - len(11) winlogon.exe - 0x00F390E5->_
             inline - len(1) winlogon.exe - 0x00F39158->_
             inline - len(1) winlogon.exe - 0x00F39163->_
             inline - len(1) winlogon.exe - 0x00F3917A->_
             inline - len(1) winlogon.exe - 0x00F391B5->_
             inline - len(1) winlogon.exe - 0x00F391BF->_
             inline - len(1) winlogon.exe - 0x00F3921A->_
             inline - len(1) winlogon.exe - 0x00F3924A->_
             inline - len(1) winlogon.exe - 0x00F3925A->_
             inline - len(1) winlogon.exe - 0x00F39266->_
             inline - len(1) winlogon.exe - 0x00F39277->_
             inline - len(1) winlogon.exe - 0x00F3928B->_
             inline - len(1) winlogon.exe - 0x00F392DF->_
             inline - len(1) winlogon.exe - 0x00F39302->_
             inline - len(1) winlogon.exe - 0x00F3930C->_
             inline - len(5) winlogon.exe - 0x00F39336->_
             inline - len(6) winlogon.exe - 0x00F3934D->_
             inline - len(1) winlogon.exe - 0x00F39369->_
             inline - len(1) winlogon.exe - 0x00F39375->_
             inline - len(1) winlogon.exe - 0x00F393A5->_
             inline - len(1) winlogon.exe - 0x00F393C1->_
             inline - len(1) winlogon.exe - 0x00F393CE->_
             inline - len(1) winlogon.exe - 0x00F393DA->_
             inline - len(11) winlogon.exe - 0x00F393E4->_
             inline - len(1) winlogon.exe - 0x00F393F4->_
             inline - len(1) winlogon.exe - 0x00F39401->_
             inline - len(1) winlogon.exe - 0x00F3940A->_
             inline - len(1) winlogon.exe - 0x00F39442->_
             inline - len(1) winlogon.exe - 0x00F39B57->0x00F22101[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F39B6D->0x00F2D336[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F39B83->0x00F244BB[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F39B99->0x00F244F7[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F39BA4->_
             inline - len(6) winlogon.exe - 0x00F39BB0->_
             inline - len(1) winlogon.exe - 0x00F39BCB->_
             inline - len(6) winlogon.exe - 0x00F39BEC->_
             inline - len(1) winlogon.exe - 0x00F39C10->_
             inline - len(6) winlogon.exe - 0x00F39C27->_
             inline - len(1) winlogon.exe - 0x00F39C4E->_
             inline - len(6) winlogon.exe - 0x00F39C6C->_
             inline - len(1) winlogon.exe - 0x00F39C90->_
             inline - len(6) winlogon.exe - 0x00F39C9C->_
             inline - len(1) winlogon.exe - 0x00F39CC3->_
             inline - len(6) winlogon.exe - 0x00F39CD3->_
             inline - len(1) winlogon.exe - 0x00F39CF7->_
             inline - len(6) winlogon.exe - 0x00F39D03->_
             inline - len(1) winlogon.exe - 0x00F39D2A->_
             inline - len(6) winlogon.exe - 0x00F39D77->_
             inline - len(1) winlogon.exe - 0x00F39D8F->_
             inline - len(6) winlogon.exe - 0x00F39DA4->_
             inline - len(1) winlogon.exe - 0x00F39DBC->_
             inline - len(1) winlogon.exe - 0x00F39DC6->_
             inline - len(1) winlogon.exe - 0x00F39DCC->_
             inline - len(1) winlogon.exe - 0x00F39DEC->_
             inline - len(6) winlogon.exe - 0x00F39E03->_
             inline - len(1) winlogon.exe - 0x00F39E2B->_
             inline - len(6) winlogon.exe - 0x00F39E42->_
             inline - len(1) winlogon.exe - 0x00F39E5A->_
             inline - len(1) winlogon.exe - 0x00F39E79->_
             inline - len(6) winlogon.exe - 0x00F39E81->_
             inline - len(1) winlogon.exe - 0x00F39EA8->_
             inline - len(1) winlogon.exe - 0x00F3A2BD->_
             inline - len(1) winlogon.exe - 0x00F3A2CA->_
             inline - len(1) winlogon.exe - 0x00F3A36C->_
             inline - len(6) winlogon.exe - 0x00F3A374->_
             inline - len(1) winlogon.exe - 0x00F3A38F->_
             inline - len(1) winlogon.exe - 0x00F3A3C3->_
             inline - len(6) winlogon.exe - 0x00F3A3CB->_
             inline - len(1) winlogon.exe - 0x00F3A3F2->_
             inline - len(6) winlogon.exe - 0x00F3A40E->_
             inline - len(1) winlogon.exe - 0x00F3A435->_
             inline - len(1) winlogon.exe - 0x00F3A443->_
             inline - len(1) winlogon.exe - 0x00F3A467->_
             inline - len(1) winlogon.exe - 0x00F3A479->_
             inline - len(6) winlogon.exe - 0x00F3A49C->_
             inline - len(1) winlogon.exe - 0x00F3A4F0->_
             inline - len(1) winlogon.exe - 0x00F3A4F7->_
             inline - len(6) winlogon.exe - 0x00F3A56D->_
             inline - len(6) winlogon.exe - 0x00F3A594->_
             inline - len(6) winlogon.exe - 0x00F3A5B0->_
             inline - len(1) winlogon.exe - 0x00F3A5D5->_
             inline - len(1) winlogon.exe - 0x00F3A5EC->_
             inline - len(1) winlogon.exe - 0x00F3A60B->_
             inline - len(1) winlogon.exe - 0x00F3A62C->_
             inline - len(1) winlogon.exe - 0x00F3A63A->_
             inline - len(1) winlogon.exe - 0x00F3A650->_
             inline - len(1) winlogon.exe - 0x00F3A68B->_
             inline - len(1) winlogon.exe - 0x00F3A69C->_
             inline - len(1) winlogon.exe - 0x00F3A6B6->_
             inline - len(1) winlogon.exe - 0x00F3A6EB->_
             inline - len(6) winlogon.exe - 0x00F3A6F8->_
             inline - len(1) winlogon.exe - 0x00F3A703->_
             inline - len(1) winlogon.exe - 0x00F3A70A->_
             inline - len(1) winlogon.exe - 0x00F3A710->_
             inline - len(1) winlogon.exe - 0x00F3A733->_
             inline - len(1) winlogon.exe - 0x00F3A744->_
             inline - len(1) winlogon.exe - 0x00F3A7B0->_
             inline - len(1) winlogon.exe - 0x00F3A7B6->_
             inline - len(1) winlogon.exe - 0x00F3A7D6->_
             inline - len(1) winlogon.exe - 0x00F3A7EE->_
             inline - len(1) winlogon.exe - 0x00F3A7F4->_
             inline - len(1) winlogon.exe - 0x00F3A814->_
             inline - len(1) winlogon.exe - 0x00F3A81E->_
             inline - len(1) winlogon.exe - 0x00F3A824->_
             inline - len(1) winlogon.exe - 0x00F3A838->_
             inline - len(1) winlogon.exe - 0x00F3A83E->_
             inline - len(1) winlogon.exe - 0x00F3A845->_
             inline - len(1) winlogon.exe - 0x00F3A856->_
             inline - len(1) winlogon.exe - 0x00F3A868->_
             inline - len(1) winlogon.exe - 0x00F3A86E->_
             inline - len(1) winlogon.exe - 0x00F3A882->_
             inline - len(1) winlogon.exe - 0x00F3A895->_
             inline - len(1) winlogon.exe - 0x00F3A8A7->_
             inline - len(1) winlogon.exe - 0x00F3A8AD->_
             inline - len(1) winlogon.exe - 0x00F3A8C1->_
             inline - len(1) winlogon.exe - 0x00F3A8CB->_
             inline - len(1) winlogon.exe - 0x00F3A8D1->_
             inline - len(1) winlogon.exe - 0x00F3A8F1->_
             inline - len(1) winlogon.exe - 0x00F3A8FD->_
             inline - len(1) winlogon.exe - 0x00F3A92C->_
             inline - len(1) winlogon.exe - 0x00F3A962->_
             inline - len(1) winlogon.exe - 0x00F3A98D->_
             inline - len(1) winlogon.exe - 0x00F3A9B9->_
             inline - len(1) winlogon.exe - 0x00F3A9BF->_
             inline - len(1) winlogon.exe - 0x00F3A9CF->_
             inline - len(1) winlogon.exe - 0x00F3A9D6->_
             inline - len(1) winlogon.exe - 0x00F3A9E4->_
             inline - len(1) winlogon.exe - 0x00F3A9F6->_
             inline - len(1) winlogon.exe - 0x00F3AA0A->_
             inline - len(1) winlogon.exe - 0x00F3AA1B->_
             inline - len(1) winlogon.exe - 0x00F3AA40->_
             inline - len(1) winlogon.exe - 0x00F3AA52->_
             inline - len(1) winlogon.exe - 0x00F3AA5B->_
             inline - len(1) winlogon.exe - 0x00F3AA8D->_
             inline - len(1) winlogon.exe - 0x00F3AA9A->_
             inline - len(1) winlogon.exe - 0x00F3AABF->_
             inline - len(1) winlogon.exe - 0x00F3AAD2->_
             inline - len(1) winlogon.exe - 0x00F3AAFE->_
             inline - len(1) winlogon.exe - 0x00F3AB0B->_
             inline - len(1) winlogon.exe - 0x00F3AB28->_
             inline - len(1) winlogon.exe - 0x00F3AB30->_
             inline - len(1) winlogon.exe - 0x00F3AB3C->_
             inline - len(1) winlogon.exe - 0x00F3AB5C->_
             inline - len(1) winlogon.exe - 0x00F3AB79->_
             inline - len(1) winlogon.exe - 0x00F3AB85->_
             inline - len(1) winlogon.exe - 0x00F3AB95->_
             inline - len(6) winlogon.exe - 0x00F3ABDB->_
             inline - len(1) winlogon.exe - 0x00F3ABF3->_
             inline - len(1) winlogon.exe - 0x00F3AC08->_
             inline - len(1) winlogon.exe - 0x00F3AC1F->_
             inline - len(1) winlogon.exe - 0x00F3AC31->_
             inline - len(1) winlogon.exe - 0x00F3AC56->_
             inline - len(1) winlogon.exe - 0x00F3AC79->_
             inline - len(1) winlogon.exe - 0x00F3AC9E->_
             inline - len(1) winlogon.exe - 0x00F3ACB0->_
             inline - len(1) winlogon.exe - 0x00F3ACDA->_
             inline - len(1) winlogon.exe - 0x00F3AD15->_
             inline - len(1) winlogon.exe - 0x00F3AD42->_
             inline - len(1) winlogon.exe - 0x00F3AD6D->_
             inline - len(1) winlogon.exe - 0x00F3ADAA->_
             inline - len(1) winlogon.exe - 0x00F3ADE2->_
             inline - len(1) winlogon.exe - 0x00F3AE10->_
             inline - len(1) winlogon.exe - 0x00F3AE3D->_
             inline - len(1) winlogon.exe - 0x00F3AE49->_
             inline - len(1) winlogon.exe - 0x00F3AE6A->_
             inline - len(1) winlogon.exe - 0x00F3AE79->_
             inline - len(1) winlogon.exe - 0x00F3AE86->_
             inline - len(1) winlogon.exe - 0x00F3AE96->_
             inline - len(1) winlogon.exe - 0x00F3AEDC->_
             inline - len(1) winlogon.exe - 0x00F3AEFE->_
             inline - len(1) winlogon.exe - 0x00F3AF08->_
             inline - len(1) winlogon.exe - 0x00F3AF3B->_
             inline - len(1) winlogon.exe - 0x00F3AF4E->_
             inline - len(1) winlogon.exe - 0x00F3AF5D->_
             inline - len(1) winlogon.exe - 0x00F3AF84->_
             inline - len(1) winlogon.exe - 0x00F3AF9F->_
             inline - len(1) winlogon.exe - 0x00F3AFAB->_
             inline - len(1) winlogon.exe - 0x00F3B003->_
             inline - len(1) winlogon.exe - 0x00F3B013->_
             inline - len(1) winlogon.exe - 0x00F3B029->_
             inline - len(1) winlogon.exe - 0x00F3B0A0->_
             inline - len(1) winlogon.exe - 0x00F3B0B9->_
             inline - len(1) winlogon.exe - 0x00F3B185->_
             inline - len(1) winlogon.exe - 0x00F3B19C->_
             inline - len(1) winlogon.exe - 0x00F3B1C1->_
             inline - len(1) winlogon.exe - 0x00F3B1FF->_
             inline - len(1) winlogon.exe - 0x00F3B216->_
             inline - len(1) winlogon.exe - 0x00F3B249->_
             inline - len(1) winlogon.exe - 0x00F3B2A1->_
             inline - len(1) winlogon.exe - 0x00F3B2A7->_
             inline - len(1) winlogon.exe - 0x00F3B2C6->_
             inline - len(1) winlogon.exe - 0x00F3B2DE->_
             inline - len(1) winlogon.exe - 0x00F3B2E4->_
             inline - len(1) winlogon.exe - 0x00F3B303->_
             inline - len(6) winlogon.exe - 0x00F3B31A->_
             inline - len(1) winlogon.exe - 0x00F3B33D->_
             inline - len(1) winlogon.exe - 0x00F3B355->_
             inline - len(1) winlogon.exe - 0x00F3B35B->_
             inline - len(1) winlogon.exe - 0x00F3B37B->_
             inline - len(1) winlogon.exe - 0x00F3B3AE->_
             inline - len(1) winlogon.exe - 0x00F3B3D7->_
             inline - len(1) winlogon.exe - 0x00F3B408->_
             inline - len(1) winlogon.exe - 0x00F3B431->_
             inline - len(6) winlogon.exe - 0x00F3B46F->_
             inline - len(1) winlogon.exe - 0x00F3B485->_
             inline - len(1) winlogon.exe - 0x00F3B4B1->_
             inline - len(1) winlogon.exe - 0x00F3B4E6->_
             inline - len(1) winlogon.exe - 0x00F3B548->_
             inline - len(1) winlogon.exe - 0x00F3B601->_
             inline - len(1) winlogon.exe - 0x00F3B638->_
             inline - len(1) winlogon.exe - 0x00F3B66C->_
             inline - len(1) winlogon.exe - 0x00F3B693->_
             inline - len(1) winlogon.exe - 0x00F3B6A7->_
             inline - len(1) winlogon.exe - 0x00F3B6C0->_
             inline - len(1) winlogon.exe - 0x00F3B6D3->_
             inline - len(1) winlogon.exe - 0x00F3B6FE->_
             inline - len(1) winlogon.exe - 0x00F3B724->_
             inline - len(1) winlogon.exe - 0x00F3B736->_
             inline - len(1) winlogon.exe - 0x00F3B788->_
             inline - len(1) winlogon.exe - 0x00F3B7BD->_
             inline - len(1) winlogon.exe - 0x00F3B7E9->_
             inline - len(1) winlogon.exe - 0x00F3B813->_
             inline - len(1) winlogon.exe - 0x00F3B83D->_
             inline - len(1) winlogon.exe - 0x00F3B867->_
             inline - len(6) winlogon.exe - 0x00F3B8A4->_
             inline - len(1) winlogon.exe - 0x00F3B8BC->_
             inline - len(6) winlogon.exe - 0x00F3B8D5->_
             inline - len(1) winlogon.exe - 0x00F3B8ED->_
             inline - len(6) winlogon.exe - 0x00F3B920->_
             inline - len(1) winlogon.exe - 0x00F3B938->_
             inline - len(6) winlogon.exe - 0x00F3B958->_
             inline - len(1) winlogon.exe - 0x00F3B97C->_
             inline - len(1) winlogon.exe - 0x00F3BB67->_
             inline - len(6) winlogon.exe - 0x00F3BB7D->_
             inline - len(1) winlogon.exe - 0x00F3BBA1->_
             inline - len(6) winlogon.exe - 0x00F3BBC3->_
             inline - len(1) winlogon.exe - 0x00F3BBEA->_
             inline - len(6) winlogon.exe - 0x00F3BC28->_
             inline - len(1) winlogon.exe - 0x00F3BC52->_
             inline - len(6) winlogon.exe - 0x00F3BC76->_
             inline - len(1) winlogon.exe - 0x00F3BCA0->_
             inline - len(1) winlogon.exe - 0x00F3BCBE->_
             inline - len(1) winlogon.exe - 0x00F3BCCF->_
             inline - len(1) winlogon.exe - 0x00F3BCE7->_
             inline - len(1) winlogon.exe - 0x00F3BD00->_
             inline - len(1) winlogon.exe - 0x00F3BD18->_
             inline - len(1) winlogon.exe - 0x00F3BD33->_
             inline - len(1) winlogon.exe - 0x00F3BD39->_
             inline - len(1) winlogon.exe - 0x00F3BD4A->_
             inline - len(1) winlogon.exe - 0x00F3BD62->_
             inline - len(1) winlogon.exe - 0x00F3BD80->_
             inline - len(1) winlogon.exe - 0x00F3BD99->_
             inline - len(1) winlogon.exe - 0x00F3BDEA->_
             inline - len(1) winlogon.exe - 0x00F3BE10->_
             inline - len(1) winlogon.exe - 0x00F3BE24->_
             inline - len(1) winlogon.exe - 0x00F3BE89->_
             inline - len(1) winlogon.exe - 0x00F3BE91->_
             inline - len(1) winlogon.exe - 0x00F3BEFF->_
             inline - len(1) winlogon.exe - 0x00F3BF25->_
             inline - len(1) winlogon.exe - 0x00F3BF55->_
             inline - len(1) winlogon.exe - 0x00F3BF77->_
             inline - len(1) winlogon.exe - 0x00F3BF7D->_
             inline - len(1) winlogon.exe - 0x00F3BF84->_
             inline - len(1) winlogon.exe - 0x00F3BF99->_
             inline - len(1) winlogon.exe - 0x00F3BFB1->_
             inline - len(1) winlogon.exe - 0x00F3BFE5->_
             inline - len(1) winlogon.exe - 0x00F3BFFC->_
             inline - len(6) winlogon.exe - 0x00F3C031->_
             inline - len(1) winlogon.exe - 0x00F3C04B->_
             inline - len(6) winlogon.exe - 0x00F3C073->_
             inline - len(1) winlogon.exe - 0x00F3C08E->_
             inline - len(1) winlogon.exe - 0x00F3C0A0->_
             inline - len(1) winlogon.exe - 0x00F3C0D6->_
             inline - len(1) winlogon.exe - 0x00F3C0DE->_
             inline - len(1) winlogon.exe - 0x00F3C10E->_
             inline - len(1) winlogon.exe - 0x00F3C125->_
             inline - len(1) winlogon.exe - 0x00F3C13F->_
             inline - len(6) winlogon.exe - 0x00F3C149->_
             inline - len(1) winlogon.exe - 0x00F3C172->_
             inline - len(6) winlogon.exe - 0x00F3C17B->_
             inline - len(1) winlogon.exe - 0x00F3C1A4->_
             inline - len(1) winlogon.exe - 0x00F3C1AD->_
             inline - len(1) winlogon.exe - 0x00F3C1BF->_
             inline - len(1) winlogon.exe - 0x00F3C1DF->_
             inline - len(1) winlogon.exe - 0x00F3C1F1->_
             inline - len(1) winlogon.exe - 0x00F3C20C->_
             inline - len(1) winlogon.exe - 0x00F3C244->_
             inline - len(1) winlogon.exe - 0x00F3C25C->_
             inline - len(6) winlogon.exe - 0x00F3C27F->_
             inline - len(1) winlogon.exe - 0x00F3C2AA->_
             inline - len(1) winlogon.exe - 0x00F3C2C1->_
             inline - len(1) winlogon.exe - 0x00F3C309->_
             inline - len(1) winlogon.exe - 0x00F3C350->_
             inline - len(1) winlogon.exe - 0x00F3C397->_
             inline - len(1) winlogon.exe - 0x00F3C3D2->_
             inline - len(1) winlogon.exe - 0x00F3C42D->_
             inline - len(6) winlogon.exe - 0x00F3C468->_
             inline - len(1) winlogon.exe - 0x00F3C477->_
             inline - len(1) winlogon.exe - 0x00F3C4B2->_
             inline - len(1) winlogon.exe - 0x00F3C51A->_
             inline - len(6) winlogon.exe - 0x00F3C557->_
             inline - len(1) winlogon.exe - 0x00F3C56A->_
             inline - len(1) winlogon.exe - 0x00F3C5A6->_
             inline - len(1) winlogon.exe - 0x00F3C5F5->_
             inline - len(1) winlogon.exe - 0x00F3C644->_
             inline - len(1) winlogon.exe - 0x00F3C67F->_
             inline - len(1) winlogon.exe - 0x00F3C689->_
             inline - len(1) winlogon.exe - 0x00F3C6B8->_
             inline - len(1) winlogon.exe - 0x00F3C6E7->_
             inline - len(1) winlogon.exe - 0x00F3C729->_
             inline - len(1) winlogon.exe - 0x00F3C758->_
             inline - len(1) winlogon.exe - 0x00F3C794->_
             inline - len(1) winlogon.exe - 0x00F3C84E->_
             inline - len(1) winlogon.exe - 0x00F3C879->_
             inline - len(1) winlogon.exe - 0x00F3C8BF->_
             inline - len(1) winlogon.exe - 0x00F3C8E9->0x00F29EBF[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3C901->_
             inline - len(1) winlogon.exe - 0x00F3C9FC->_
             inline - len(6) winlogon.exe - 0x00F3CA37->_
             inline - len(1) winlogon.exe - 0x00F3CA61->_
             inline - len(1) winlogon.exe - 0x00F3CA98->_
             inline - len(1) winlogon.exe - 0x00F3CAC8->_
             inline - len(1) winlogon.exe - 0x00F3CB00->_
             inline - len(1) winlogon.exe - 0x00F3CB42->_
             inline - len(1) winlogon.exe - 0x00F3CB8F->_
             inline - len(1) winlogon.exe - 0x00F3CBD3->_
             inline - len(1) winlogon.exe - 0x00F3CC05->_
             inline - len(1) winlogon.exe - 0x00F3CC76->_
             inline - len(6) winlogon.exe - 0x00F3CCCB->_
             inline - len(1) winlogon.exe - 0x00F3CCE8->_
             inline - len(1) winlogon.exe - 0x00F3CD00->_
             inline - len(6) winlogon.exe - 0x00F3CD11->_
             inline - len(1) winlogon.exe - 0x00F3CD3A->_
             inline - len(6) winlogon.exe - 0x00F3CD74->_
             inline - len(1) winlogon.exe - 0x00F3CDC6->_
             inline - len(1) winlogon.exe - 0x00F3CDDA->_
             inline - len(1) winlogon.exe - 0x00F3CE11->_
             inline - len(1) winlogon.exe - 0x00F3CE26->_
             inline - len(1) winlogon.exe - 0x00F3CE30->_
             inline - len(6) winlogon.exe - 0x00F3CE3B->_
             inline - len(6) winlogon.exe - 0x00F3CEDC->_
             inline - len(1) winlogon.exe - 0x00F3CF70->_
             inline - len(1) winlogon.exe - 0x00F3CFA3->_
             inline - len(1) winlogon.exe - 0x00F3CFA9->_
             inline - len(1) winlogon.exe - 0x00F3CFD3->0x00F33CF1[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F3CFE0->_
             inline - len(1) winlogon.exe - 0x00F3D00A->_
             inline - len(6) winlogon.exe - 0x00F3D028->_
             inline - len(1) winlogon.exe - 0x00F3D050->_
             inline - len(6) winlogon.exe - 0x00F3D07B->_
             inline - len(1) winlogon.exe - 0x00F3D0A2->_
             inline - len(6) winlogon.exe - 0x00F3D0BA->_
             inline - len(1) winlogon.exe - 0x00F3D0E2->_
             inline - len(6) winlogon.exe - 0x00F3D101->_
             inline - len(1) winlogon.exe - 0x00F3D11C->_
             inline - len(6) winlogon.exe - 0x00F3D141->_
             inline - len(1) winlogon.exe - 0x00F3D168->_
             inline - len(6) winlogon.exe - 0x00F3D186->_
             inline - len(1) winlogon.exe - 0x00F3D1AE->_
             inline - len(6) winlogon.exe - 0x00F3D1E0->_
             inline - len(1) winlogon.exe - 0x00F3D207->_
             inline - len(6) winlogon.exe - 0x00F3D21F->_
             inline - len(1) winlogon.exe - 0x00F3D247->_
             inline - len(6) winlogon.exe - 0x00F3D266->_
             inline - len(1) winlogon.exe - 0x00F3D28D->_
             inline - len(6) winlogon.exe - 0x00F3D2A6->_
             inline - len(1) winlogon.exe - 0x00F3D2CD->_
             inline - len(6) winlogon.exe - 0x00F3D2E5->_
             inline - len(1) winlogon.exe - 0x00F3D30D->_
             inline - len(6) winlogon.exe - 0x00F3D33D->_
             inline - len(1) winlogon.exe - 0x00F3D364->_
             inline - len(6) winlogon.exe - 0x00F3D43E->_
             inline - len(1) winlogon.exe - 0x00F3D468->_
             inline - len(1) winlogon.exe - 0x00F3D476->_
             inline - len(6) winlogon.exe - 0x00F3D47E->_
             inline - len(1) winlogon.exe - 0x00F3D4A8->_
             inline - len(1) winlogon.exe - 0x00F3D4C0->_
             inline - len(1) winlogon.exe - 0x00F3D4E9->_
             inline - len(1) winlogon.exe - 0x00F3D536->_
             inline - len(1) winlogon.exe - 0x00F3D583->_
             inline - len(1) winlogon.exe - 0x00F3D5AC->_
             inline - len(1) winlogon.exe - 0x00F3D5CA->_
             inline - len(1) winlogon.exe - 0x00F3D5F3->_
             inline - len(1) winlogon.exe - 0x00F3D657->_
             inline - len(1) winlogon.exe - 0x00F3D6A1->_
             inline - len(1) winlogon.exe - 0x00F3D6E5->_
             inline - len(1) winlogon.exe - 0x00F3D765->_
             inline - len(1) winlogon.exe - 0x00F3D7AD->_
             inline - len(6) winlogon.exe - 0x00F3D7DC->_
             inline - len(6) winlogon.exe - 0x00F3D80B->_
             inline - len(6) winlogon.exe - 0x00F3D83A->_
             inline - len(1) winlogon.exe - 0x00F3D862->_
             inline - len(1) winlogon.exe - 0x00F3D86B->_
             inline - len(6) winlogon.exe - 0x00F3D880->_
             inline - len(1) winlogon.exe - 0x00F3D8A8->_
             inline - len(1) winlogon.exe - 0x00F3D8B1->_
             inline - len(1) winlogon.exe - 0x00F3D8C7->_
             inline - len(1) winlogon.exe - 0x00F3D8CD->_
             inline - len(1) winlogon.exe - 0x00F3D908->0x00F390AB[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F3D915->_
             inline - len(1) winlogon.exe - 0x00F3D93F->_
             inline - len(1) winlogon.exe - 0x00F3D9C0->_
             inline - len(1) winlogon.exe - 0x00F3DA8F->_
             inline - len(1) winlogon.exe - 0x00F3DAA7->_
             inline - len(1) winlogon.exe - 0x00F3DAD1->_
             inline - len(1) winlogon.exe - 0x00F3DAF8->_
             inline - len(1) winlogon.exe - 0x00F3DB16->_
             inline - len(1) winlogon.exe - 0x00F3DB3A->_
             inline - len(1) winlogon.exe - 0x00F3DB51->_
             inline - len(1) winlogon.exe - 0x00F3DB78->_
             inline - len(1) winlogon.exe - 0x00F3DB84->_
             inline - len(1) winlogon.exe - 0x00F3DBAB->_
             inline - len(1) winlogon.exe - 0x00F3DBB8->_
             inline - len(1) winlogon.exe - 0x00F3DBEB->_
             inline - len(1) winlogon.exe - 0x00F3DC0F->_
             inline - len(1) winlogon.exe - 0x00F3DC39->_
             inline - len(1) winlogon.exe - 0x00F3DC5D->_
             inline - len(1) winlogon.exe - 0x00F3DC69->_
             inline - len(1) winlogon.exe - 0x00F3DC90->_
             inline - len(1) winlogon.exe - 0x00F3DCA5->_
             inline - len(1) winlogon.exe - 0x00F3DCCA->_
             inline - len(1) winlogon.exe - 0x00F3DCD0->_
             inline - len(1) winlogon.exe - 0x00F3DCD7->_
             inline - len(1) winlogon.exe - 0x00F3DCF0->_
             inline - len(1) winlogon.exe - 0x00F3DCF8->_
             inline - len(1) winlogon.exe - 0x00F3DD1F->_
             inline - len(1) winlogon.exe - 0x00F3DD2D->0x00F2AD70[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3DD3C->0x00F2ADD6[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3DD49->_
             inline - len(1) winlogon.exe - 0x00F3DD70->_
             inline - len(1) winlogon.exe - 0x00F3DD7C->_
             inline - len(1) winlogon.exe - 0x00F3DDA3->_
             inline - len(1) winlogon.exe - 0x00F3DDD3->_
             inline - len(1) winlogon.exe - 0x00F3DDF7->_
             inline - len(1) winlogon.exe - 0x00F3DE03->_
             inline - len(1) winlogon.exe - 0x00F3DE2A->_
             inline - len(1) winlogon.exe - 0x00F3DE36->_
             inline - len(1) winlogon.exe - 0x00F3DE8F->_
             inline - len(1) winlogon.exe - 0x00F3DED9->_
             inline - len(1) winlogon.exe - 0x00F3DF13->_
             inline - len(1) winlogon.exe - 0x00F3DF4D->_
             inline - len(1) winlogon.exe - 0x00F3DF8F->_
             inline - len(1) winlogon.exe - 0x00F3DFBB->_
             inline - len(1) winlogon.exe - 0x00F3DFF7->_
             inline - len(1) winlogon.exe - 0x00F3E031->_
             inline - len(6) winlogon.exe - 0x00F3E07A->_
             inline - len(11) winlogon.exe - 0x00F3E0BC->_
             inline - len(1) winlogon.exe - 0x00F3E0FD->_
             inline - len(6) winlogon.exe - 0x00F3E105->_
             inline - len(6) winlogon.exe - 0x00F3E13D->_
             inline - len(6) winlogon.exe - 0x00F3E171->_
             inline - len(1) winlogon.exe - 0x00F3E19C->_
             inline - len(1) winlogon.exe - 0x00F3E1A7->_
             inline - len(6) winlogon.exe - 0x00F3E1B1->_
             inline - len(1) winlogon.exe - 0x00F3E1DC->_
             inline - len(1) winlogon.exe - 0x00F3E1EB->_
             inline - len(1) winlogon.exe - 0x00F3E211->_
             inline - len(6) winlogon.exe - 0x00F3E21A->_
             inline - len(6) winlogon.exe - 0x00F3E248->_
             inline - len(1) winlogon.exe - 0x00F3E279->_
             inline - len(1) winlogon.exe - 0x00F3E27F->_
             inline - len(1) winlogon.exe - 0x00F3E287->_
             inline - len(1) winlogon.exe - 0x00F3E2AD->_
             inline - len(1) winlogon.exe - 0x00F3E2BA->_
             inline - len(1) winlogon.exe - 0x00F3E2F1->_
             inline - len(1) winlogon.exe - 0x00F3E31B->_
             inline - len(1) winlogon.exe - 0x00F3E356->_
             inline - len(6) winlogon.exe - 0x00F3E36A->_
             inline - len(1) winlogon.exe - 0x00F3E385->_
             inline - len(1) winlogon.exe - 0x00F3E3A5->_
             inline - len(6) winlogon.exe - 0x00F3E3AD->_
             inline - len(1) winlogon.exe - 0x00F3E3D5->_
             inline - len(1) winlogon.exe - 0x00F3E3EE->_
             inline - len(6) winlogon.exe - 0x00F3E3F6->_
             inline - len(1) winlogon.exe - 0x00F3E420->_
             inline - len(6) winlogon.exe - 0x00F3E439->_
             inline - len(1) winlogon.exe - 0x00F3E449->_
             inline - len(1) winlogon.exe - 0x00F3E456->_
             inline - len(6) winlogon.exe - 0x00F3E463->_
             inline - len(1) winlogon.exe - 0x00F3E472->_
             inline - len(1) winlogon.exe - 0x00F3E486->_
             inline - len(1) winlogon.exe - 0x00F3E49E->_
             inline - len(1) winlogon.exe - 0x00F3E4A8->_
             inline - len(1) winlogon.exe - 0x00F3E4E0->_
             inline - len(1) winlogon.exe - 0x00F3E55F->_
             inline - len(1) winlogon.exe - 0x00F3E598->_
             inline - len(1) winlogon.exe - 0x00F3E5D1->_
             inline - len(1) winlogon.exe - 0x00F3E60A->_
             inline - len(6) winlogon.exe - 0x00F3E689->_
             inline - len(1) winlogon.exe - 0x00F3E6FB->0x00F32020[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F3E74D->_
             inline - len(1) winlogon.exe - 0x00F3E772->_
             inline - len(6) winlogon.exe - 0x00F3E778->_
             inline - len(6) winlogon.exe - 0x00F3E794->_
             inline - len(1) winlogon.exe - 0x00F3E7B9->_
             inline - len(6) winlogon.exe - 0x00F3E7BF->_
             inline - len(1) winlogon.exe - 0x00F3E7DC->_
             inline - len(1) winlogon.exe - 0x00F3E7E2->_
             inline - len(1) winlogon.exe - 0x00F3E7F6->_
             inline - len(1) winlogon.exe - 0x00F3E815->_
             inline - len(1) winlogon.exe - 0x00F3E845->0x00F345CC[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3E856->_
             inline - len(1) winlogon.exe - 0x00F3E86B->_
             inline - len(1) winlogon.exe - 0x00F3E874->0x00F38C09[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3E883->_
             inline - len(6) winlogon.exe - 0x00F3E88D->_
             inline - len(1) winlogon.exe - 0x00F3E8B4->_
             inline - len(1) winlogon.exe - 0x00F3E8CC->_
             inline - len(6) winlogon.exe - 0x00F3E8D4->_
             inline - len(1) winlogon.exe - 0x00F3E8FB->_
             inline - len(1) winlogon.exe - 0x00F3E908->_
             inline - len(1) winlogon.exe - 0x00F3E911->_
             inline - len(1) winlogon.exe - 0x00F3E91E->_
             inline - len(1) winlogon.exe - 0x00F3E941->_
             inline - len(1) winlogon.exe - 0x00F3E95D->_
             inline - len(6) winlogon.exe - 0x00F3E967->_
             inline - len(1) winlogon.exe - 0x00F3E980->_
             inline - len(1) winlogon.exe - 0x00F3E986->_
             inline - len(1) winlogon.exe - 0x00F3E98D->_
             inline - len(6) winlogon.exe - 0x00F3E9F2->_
             inline - len(1) winlogon.exe - 0x00F3EA17->_
             inline - len(1) winlogon.exe - 0x00F3EA1D->_
             inline - len(1) winlogon.exe - 0x00F3EA23->_
             inline - len(6) winlogon.exe - 0x00F3EA3A->_
             inline - len(1) winlogon.exe - 0x00F3EA5F->_
             inline - len(6) winlogon.exe - 0x00F3EA65->_
             inline - len(1) winlogon.exe - 0x00F3EA89->_
             inline - len(1) winlogon.exe - 0x00F3EAAA->_
             inline - len(1) winlogon.exe - 0x00F3EAC2->_
             inline - len(1) winlogon.exe - 0x00F3EAD1->_
             inline - len(1) winlogon.exe - 0x00F3EAF3->_
             inline - len(1) winlogon.exe - 0x00F3EAFD->_
             inline - len(1) winlogon.exe - 0x00F3EB2C->_
             inline - len(6) winlogon.exe - 0x00F3EB63->_
             inline - len(1) winlogon.exe - 0x00F3EB88->_
             inline - len(1) winlogon.exe - 0x00F3EB8E->_
             inline - len(1) winlogon.exe - 0x00F3EB95->_
             inline - len(6) winlogon.exe - 0x00F3EBAA->_
             inline - len(1) winlogon.exe - 0x00F3EBCF->_
             inline - len(1) winlogon.exe - 0x00F3EBD5->_
             inline - len(1) winlogon.exe - 0x00F3EBDE->_
             inline - len(1) winlogon.exe - 0x00F3EBE5->_
             inline - len(1) winlogon.exe - 0x00F3EBEE->_
             inline - len(1) winlogon.exe - 0x00F3EC0B->_
             inline - len(1) winlogon.exe - 0x00F3EC9C->_
             inline - len(1) winlogon.exe - 0x00F3ECA2->_
             inline - len(1) winlogon.exe - 0x00F3ECB6->_
             inline - len(1) winlogon.exe - 0x00F3ECE8->_
             inline - len(6) winlogon.exe - 0x00F3ECF1->_
             inline - len(1) winlogon.exe - 0x00F3ED16->_
             inline - len(6) winlogon.exe - 0x00F3ED1C->_
             inline - len(11) winlogon.exe - 0x00F3ED44->_
             inline - len(1) winlogon.exe - 0x00F3ED7D->_
             inline - len(1) winlogon.exe - 0x00F3ED87->_
             inline - len(1) winlogon.exe - 0x00F3ED8F->_
             inline - len(1) winlogon.exe - 0x00F3EDCB->_
             inline - len(1) winlogon.exe - 0x00F3EDE4->_
             inline - len(1) winlogon.exe - 0x00F3EDFB->_
             inline - len(1) winlogon.exe - 0x00F3EE04->_
             inline - len(1) winlogon.exe - 0x00F3EE1D->0x00F239EB[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3EED6->_
             inline - len(1) winlogon.exe - 0x00F3EEDE->_
             inline - len(1) winlogon.exe - 0x00F3EEF6->_
             inline - len(1) winlogon.exe - 0x00F3EF08->_
             inline - len(1) winlogon.exe - 0x00F3EF17->_
             inline - len(1) winlogon.exe - 0x00F3EF3B->_
             inline - len(1) winlogon.exe - 0x00F3EF53->_
             inline - len(6) winlogon.exe - 0x00F3EF8B->_
             inline - len(1) winlogon.exe - 0x00F3EFB2->_
             inline - len(6) winlogon.exe - 0x00F3EFC9->_
             inline - len(1) winlogon.exe - 0x00F3EFF3->_
             inline - len(1) winlogon.exe - 0x00F3F00B->_
             inline - len(6) winlogon.exe - 0x00F3F013->_
             inline - len(1) winlogon.exe - 0x00F3F03D->_
             inline - len(6) winlogon.exe - 0x00F3F046->_
             inline - len(1) winlogon.exe - 0x00F3F062->_
             inline - len(1) winlogon.exe - 0x00F3F076->0x00F28875[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F3F08E->_
             inline - len(1) winlogon.exe - 0x00F3F0AB->_
             inline - len(1) winlogon.exe - 0x00F3F0C4->_
             inline - len(1) winlogon.exe - 0x00F3F0CA->_
             inline - len(1) winlogon.exe - 0x00F3F0E3->_
             inline - len(1) winlogon.exe - 0x00F3F0F7->_
             inline - len(1) winlogon.exe - 0x00F3F11C->_
             inline - len(1) winlogon.exe - 0x00F3F12C->0x00F30F0D[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3F135->_
             inline - len(1) winlogon.exe - 0x00F3F159->_
             inline - len(6) winlogon.exe - 0x00F3F161->_
             inline - len(1) winlogon.exe - 0x00F3F188->_
             inline - len(1) winlogon.exe - 0x00F3F191->_
             inline - len(1) winlogon.exe - 0x00F3F1AA->_
             inline - len(1) winlogon.exe - 0x00F3F1B2->_
             inline - len(1) winlogon.exe - 0x00F3F1D6->_
             inline - len(6) winlogon.exe - 0x00F3F1F5->_
             inline - len(1) winlogon.exe - 0x00F3F21C->_
             inline - len(1) winlogon.exe - 0x00F3F227->_
             inline - len(6) winlogon.exe - 0x00F3F22F->_
             inline - len(1) winlogon.exe - 0x00F3F256->_
             inline - len(1) winlogon.exe - 0x00F3F277->_
             inline - len(1) winlogon.exe - 0x00F3F283->_
             inline - len(1) winlogon.exe - 0x00F3F292->_
             inline - len(6) winlogon.exe - 0x00F3F29A->_
             inline - len(1) winlogon.exe - 0x00F3F2C1->_
             inline - len(6) winlogon.exe - 0x00F3F2D8->_
             inline - len(1) winlogon.exe - 0x00F3F302->_
             inline - len(6) winlogon.exe - 0x00F3F319->_
             inline - len(1) winlogon.exe - 0x00F3F340->0x00F3F3D0[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3F34E->_
             inline - len(6) winlogon.exe - 0x00F3F356->_
             inline - len(1) winlogon.exe - 0x00F3F37D->_
             inline - len(1) winlogon.exe - 0x00F3F39D->_
             inline - len(6) winlogon.exe - 0x00F3F3A5->_
             inline - len(1) winlogon.exe - 0x00F3F3CC->_
             inline - len(1) winlogon.exe - 0x00F3F3EF->_
             inline - len(1) winlogon.exe - 0x00F3F40A->_
             inline - len(1) winlogon.exe - 0x00F3F422->_
             inline - len(1) winlogon.exe - 0x00F3F44A->_
             inline - len(1) winlogon.exe - 0x00F3F451->_
             inline - len(1) winlogon.exe - 0x00F3F45F->_
             inline - len(1) winlogon.exe - 0x00F3F483->_
             inline - len(1) winlogon.exe - 0x00F3F4B9->_
             inline - len(1) winlogon.exe - 0x00F3F4C0->_
             inline - len(1) winlogon.exe - 0x00F3F4CE->_
             inline - len(1) winlogon.exe - 0x00F3F4F2->_
             inline - len(6) winlogon.exe - 0x00F3F510->_
             inline - len(1) winlogon.exe - 0x00F3F537->_
             inline - len(1) winlogon.exe - 0x00F3F550->_
             inline - len(6) winlogon.exe - 0x00F3F558->_
             inline - len(1) winlogon.exe - 0x00F3F57F->_
             inline - len(1) winlogon.exe - 0x00F3F642->0x00F29954[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3F658->0x00F29993[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3F669->0x00F299D3[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3F6A0->_
             inline - len(6) winlogon.exe - 0x00F3F6A7->_
             inline - len(1) winlogon.exe - 0x00F3F6CC->_
             inline - len(1) winlogon.exe - 0x00F3F6E4->_
             inline - len(6) winlogon.exe - 0x00F3F6EB->_
             inline - len(1) winlogon.exe - 0x00F3F710->_
             inline - len(6) winlogon.exe - 0x00F3F727->_
             inline - len(1) winlogon.exe - 0x00F3F74E->_
             inline - len(6) winlogon.exe - 0x00F3F765->_
             inline - len(1) winlogon.exe - 0x00F3F78C->_
             inline - len(6) winlogon.exe - 0x00F3F795->_
             inline - len(1) winlogon.exe - 0x00F3F7BC->_
             inline - len(6) winlogon.exe - 0x00F3F7C5->_
             inline - len(1) winlogon.exe - 0x00F3F7EC->_
             inline - len(1) winlogon.exe - 0x00F3F7FC->_
             inline - len(6) winlogon.exe - 0x00F3F812->_
             inline - len(1) winlogon.exe - 0x00F3F839->_
             inline - len(1) winlogon.exe - 0x00F3F849->_
             inline - len(6) winlogon.exe - 0x00F3F85F->_
             inline - len(1) winlogon.exe - 0x00F3F886->_
             inline - len(1) winlogon.exe - 0x00F3F8AF->_
             inline - len(6) winlogon.exe - 0x00F3F8C5->_
             inline - len(1) winlogon.exe - 0x00F3F8EC->_
             inline - len(1) winlogon.exe - 0x00F3F939->_
             inline - len(6) winlogon.exe - 0x00F3F9A6->_
             inline - len(1) winlogon.exe - 0x00F3F9D1->_
             inline - len(6) winlogon.exe - 0x00F3F9F2->_
             inline - len(1) winlogon.exe - 0x00F3FA16->_
             inline - len(1) winlogon.exe - 0x00F3FA78->_
             inline - len(6) winlogon.exe - 0x00F3FA8F->_
             inline - len(1) winlogon.exe - 0x00F3FAAE->_
             inline - len(6) winlogon.exe - 0x00F3FAE5->_
             inline - len(1) winlogon.exe - 0x00F3FB0A->_
             inline - len(6) winlogon.exe - 0x00F3FB1C->_
             inline - len(1) winlogon.exe - 0x00F3FB41->_
             inline - len(6) winlogon.exe - 0x00F3FB4A->_
             inline - len(1) winlogon.exe - 0x00F3FB65->_
             inline - len(1) winlogon.exe - 0x00F3FB7F->_
             inline - len(1) winlogon.exe - 0x00F3FB9A->_
             inline - len(1) winlogon.exe - 0x00F3FBBC->_
             inline - len(1) winlogon.exe - 0x00F3FC09->0x00F2BA81[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F3FC17->_
             inline - len(6) winlogon.exe - 0x00F3FC1F->_
             inline - len(1) winlogon.exe - 0x00F3FC49->_
             inline - len(1) winlogon.exe - 0x00F3FC62->_
             inline - len(6) winlogon.exe - 0x00F3FC6A->_
             inline - len(1) winlogon.exe - 0x00F3FC92->_
             inline - len(6) winlogon.exe - 0x00F3FCB5->_
             inline - len(1) winlogon.exe - 0x00F3FCDC->_
             inline - len(1) winlogon.exe - 0x00F3FD43->_
             inline - len(1) winlogon.exe - 0x00F3FD88->_
             inline - len(1) winlogon.exe - 0x00F3FDC5->_
             inline - len(1) winlogon.exe - 0x00F3FDD6->_
             inline - len(1) winlogon.exe - 0x00F3FE2C->_
             inline - len(1) winlogon.exe - 0x00F3FE32->_
             inline - len(1) winlogon.exe - 0x00F3FE52->_
             inline - len(1) winlogon.exe - 0x00F3FE90->_
             inline - len(1) winlogon.exe - 0x00F3FEB2->_
             inline - len(1) winlogon.exe - 0x00F3FEB8->_
             inline - len(1) winlogon.exe - 0x00F3FEBF->_
             inline - len(1) winlogon.exe - 0x00F3FECF->_
             inline - len(1) winlogon.exe - 0x00F3FEF1->_
             inline - len(1) winlogon.exe - 0x00F3FEF7->_
             inline - len(1) winlogon.exe - 0x00F3FF01->_
             inline - len(1) winlogon.exe - 0x00F3FF29->_
             inline - len(1) winlogon.exe - 0x00F3FF5F->_
             inline - len(1) winlogon.exe - 0x00F3FF81->_
             inline - len(6) winlogon.exe - 0x00F3FF98->_
             inline - len(1) winlogon.exe - 0x00F3FFB0->_
             inline - len(1) winlogon.exe - 0x00F3FFDE->_
             inline - len(6) winlogon.exe - 0x00F3FFEF->_
             inline - len(1) winlogon.exe - 0x00F40016->_
             inline - len(6) winlogon.exe - 0x00F40034->_
             inline - len(1) winlogon.exe - 0x00F40058->_
             inline - len(1) winlogon.exe - 0x00F40071->_
             inline - len(6) winlogon.exe - 0x00F40079->_
             inline - len(1) winlogon.exe - 0x00F400A0->_
             inline - len(6) winlogon.exe - 0x00F400AC->_
             inline - len(1) winlogon.exe - 0x00F400D3->_
             inline - len(6) winlogon.exe - 0x00F400FB->_
             inline - len(1) winlogon.exe - 0x00F40125->_
             inline - len(6) winlogon.exe - 0x00F4013C->_
             inline - len(1) winlogon.exe - 0x00F40166->_
             inline - len(6) winlogon.exe - 0x00F4016F->_
             inline - len(1) winlogon.exe - 0x00F40199->_
             inline - len(6) winlogon.exe - 0x00F401A2->_
             inline - len(1) winlogon.exe - 0x00F401CC->_
             inline - len(6) winlogon.exe - 0x00F401D8->_
             inline - len(1) winlogon.exe - 0x00F40202->_
             inline - len(6) winlogon.exe - 0x00F4020E->_
             inline - len(1) winlogon.exe - 0x00F40238->_
             inline - len(6) winlogon.exe - 0x00F40244->_
             inline - len(1) winlogon.exe - 0x00F4026E->_
             inline - len(6) winlogon.exe - 0x00F4027A->_
             inline - len(1) winlogon.exe - 0x00F402A4->_
             inline - len(6) winlogon.exe - 0x00F402BB->_
             inline - len(1) winlogon.exe - 0x00F402E5->_
             inline - len(6) winlogon.exe - 0x00F402FC->_
             inline - len(1) winlogon.exe - 0x00F40326->_
             inline - len(1) winlogon.exe - 0x00F40346->_
             inline - len(1) winlogon.exe - 0x00F4035D->_
             inline - len(6) winlogon.exe - 0x00F4037E->_
             inline - len(1) winlogon.exe - 0x00F403A5->_
             inline - len(1) winlogon.exe - 0x00F403FE->_
             inline - len(6) winlogon.exe - 0x00F40415->_
             inline - len(1) winlogon.exe - 0x00F4043C->_
             inline - len(6) winlogon.exe - 0x00F40448->_
             inline - len(1) winlogon.exe - 0x00F40465->_
             inline - len(1) winlogon.exe - 0x00F40477->_
             inline - len(1) winlogon.exe - 0x00F40490->_
             inline - len(1) winlogon.exe - 0x00F40498->_
             inline - len(1) winlogon.exe - 0x00F404BC->_
             inline - len(1) winlogon.exe - 0x00F404FB->_
             inline - len(1) winlogon.exe - 0x00F40507->_
             inline - len(1) winlogon.exe - 0x00F4054D->0x00F37FF2[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4057A->_
             inline - len(1) winlogon.exe - 0x00F40589->_
             inline - len(6) winlogon.exe - 0x00F4059B->_
             inline - len(6) winlogon.exe - 0x00F405BD->_
             inline - len(1) winlogon.exe - 0x00F405D8->_
             inline - len(1) winlogon.exe - 0x00F405F2->_
             inline - len(1) winlogon.exe - 0x00F405FC->_
             inline - len(1) winlogon.exe - 0x00F4061C->_
             inline - len(1) winlogon.exe - 0x00F4062C->_
             inline - len(1) winlogon.exe - 0x00F4064D->_
             inline - len(1) winlogon.exe - 0x00F40705->_
             inline - len(1) winlogon.exe - 0x00F4070C->_
             inline - len(1) winlogon.exe - 0x00F40716->_
             inline - len(1) winlogon.exe - 0x00F4072C->_
             inline - len(6) winlogon.exe - 0x00F4074E->_
             inline - len(1) winlogon.exe - 0x00F40768->_
             inline - len(1) winlogon.exe - 0x00F40771->_
             inline - len(1) winlogon.exe - 0x00F40786->_
             inline - len(1) winlogon.exe - 0x00F407A6->_
             inline - len(1) winlogon.exe - 0x00F407AD->_
             inline - len(1) winlogon.exe - 0x00F407B8->_
             inline - len(1) winlogon.exe - 0x00F407C0->_
             inline - len(1) winlogon.exe - 0x00F407E4->_
             inline - len(6) winlogon.exe - 0x00F4080C->_
             inline - len(1) winlogon.exe - 0x00F40826->_
             inline - len(1) winlogon.exe - 0x00F4083D->_
             inline - len(1) winlogon.exe - 0x00F4084B->_
             inline - len(1) winlogon.exe - 0x00F4085B->_
             inline - len(1) winlogon.exe - 0x00F4087C->_
             inline - len(6) winlogon.exe - 0x00F40894->_
             inline - len(1) winlogon.exe - 0x00F408B8->_
             inline - len(6) winlogon.exe - 0x00F40929->_
             inline - len(1) winlogon.exe - 0x00F40945->_
             inline - len(1) winlogon.exe - 0x00F40959->_
             inline - len(1) winlogon.exe - 0x00F40962->_
             inline - len(1) winlogon.exe - 0x00F4096B->_
             inline - len(1) winlogon.exe - 0x00F40992->_
             inline - len(1) winlogon.exe - 0x00F409B3->_
             inline - len(1) winlogon.exe - 0x00F409CA->_
             inline - len(1) winlogon.exe - 0x00F409F5->_
             inline - len(1) winlogon.exe - 0x00F40A22->_
             inline - len(1) winlogon.exe - 0x00F40A29->_
             inline - len(1) winlogon.exe - 0x00F40A87->_
             inline - len(1) winlogon.exe - 0x00F40A9C->_
             inline - len(1) winlogon.exe - 0x00F40AAE->_
             inline - len(1) winlogon.exe - 0x00F40AB4->_
             inline - len(1) winlogon.exe - 0x00F40ABA->_
             inline - len(1) winlogon.exe - 0x00F40AF1->_
             inline - len(1) winlogon.exe - 0x00F40B1B->_
             inline - len(1) winlogon.exe - 0x00F40B52->_
             inline - len(1) winlogon.exe - 0x00F40B76->_
             inline - len(1) winlogon.exe - 0x00F40B8E->_
             inline - len(1) winlogon.exe - 0x00F40BB3->_
             inline - len(1) winlogon.exe - 0x00F40BCB->_
             inline - len(1) winlogon.exe - 0x00F40BF0->_
             inline - len(1) winlogon.exe - 0x00F40C08->_
             inline - len(1) winlogon.exe - 0x00F40C2A->_
             inline - len(1) winlogon.exe - 0x00F40C42->_
             inline - len(1) winlogon.exe - 0x00F40C67->_
             inline - len(1) winlogon.exe - 0x00F40C7E->_
             inline - len(1) winlogon.exe - 0x00F40C87->_
             inline - len(6) winlogon.exe - 0x00F40CDC->_
             inline - len(1) winlogon.exe - 0x00F40CF8->_
             inline - len(1) winlogon.exe - 0x00F40D20->_
             inline - len(1) winlogon.exe - 0x00F40D6B->_
             inline - len(1) winlogon.exe - 0x00F40D82->_
             inline - len(1) winlogon.exe - 0x00F40DEE->_
             inline - len(1) winlogon.exe - 0x00F40E00->_
             inline - len(1) winlogon.exe - 0x00F40E39->_
             inline - len(1) winlogon.exe - 0x00F40E72->_
             inline - len(1) winlogon.exe - 0x00F40E97->_
             inline - len(1) winlogon.exe - 0x00F40EAE->0x00F355E7[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F40ECA->_
             inline - len(1) winlogon.exe - 0x00F40EEF->_
             inline - len(1) winlogon.exe - 0x00F40F21->_
             inline - len(1) winlogon.exe - 0x00F40F45->_
             inline - len(6) winlogon.exe - 0x00F40F75->_
             inline - len(1) winlogon.exe - 0x00F40F9F->_
             inline - len(1) winlogon.exe - 0x00F40FB6->_
             inline - len(6) winlogon.exe - 0x00F40FC2->_
             inline - len(1) winlogon.exe - 0x00F40FEC->_
             inline - len(1) winlogon.exe - 0x00F41003->_
             inline - len(1) winlogon.exe - 0x00F41066->_
             inline - len(6) winlogon.exe - 0x00F41070->_
             inline - len(1) winlogon.exe - 0x00F41098->_
             inline - len(6) winlogon.exe - 0x00F410AF->_
             inline - len(1) winlogon.exe - 0x00F410CA->_
             inline - len(1) winlogon.exe - 0x00F410DC->_
             inline - len(6) winlogon.exe - 0x00F410E9->_
             inline - len(1) winlogon.exe - 0x00F41110->_
             inline - len(6) winlogon.exe - 0x00F4112B->_
             inline - len(1) winlogon.exe - 0x00F41152->_
             inline - len(6) winlogon.exe - 0x00F4118E->_
             inline - len(1) winlogon.exe - 0x00F411B7->_
             inline - len(6) winlogon.exe - 0x00F411E6->_
             inline - len(1) winlogon.exe - 0x00F4120F->_
             inline - len(1) winlogon.exe - 0x00F4122B->_
             inline - len(6) winlogon.exe - 0x00F41239->_
             inline - len(1) winlogon.exe - 0x00F41262->_
             inline - len(1) winlogon.exe - 0x00F41272->_
             inline - len(6) winlogon.exe - 0x00F41284->_
             inline - len(1) winlogon.exe - 0x00F412AD->_
             inline - len(1) winlogon.exe - 0x00F412BC->_
             inline - len(1) winlogon.exe - 0x00F412C6->_
             inline - len(1) winlogon.exe - 0x00F412D9->_
             inline - len(6) winlogon.exe - 0x00F412E7->_
             inline - len(6) winlogon.exe - 0x00F412F6->_
             inline - len(1) winlogon.exe - 0x00F41320->_
             inline - len(6) winlogon.exe - 0x00F41337->_
             inline - len(1) winlogon.exe - 0x00F41361->_
             inline - len(1) winlogon.exe - 0x00F41378->_
             inline - len(6) winlogon.exe - 0x00F41382->_
             inline - len(1) winlogon.exe - 0x00F4139F->_
             inline - len(6) winlogon.exe - 0x00F413C4->_
             inline - len(1) winlogon.exe - 0x00F413F3->_
             inline - len(1) winlogon.exe - 0x00F413FC->0x00F29240[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4140F->_
             inline - len(1) winlogon.exe - 0x00F41449->_
             inline - len(6) winlogon.exe - 0x00F4145C->_
             inline - len(6) winlogon.exe - 0x00F414A4->_
             inline - len(1) winlogon.exe - 0x00F414CD->_
             inline - len(1) winlogon.exe - 0x00F414F6->_
             inline - len(6) winlogon.exe - 0x00F41525->_
             inline - len(1) winlogon.exe - 0x00F41551->_
             inline - len(1) winlogon.exe - 0x00F41574->_
             inline - len(1) winlogon.exe - 0x00F4159F->_
             inline - len(1) winlogon.exe - 0x00F415E6->_
             inline - len(1) winlogon.exe - 0x00F4162D->_
             inline - len(1) winlogon.exe - 0x00F4165E->_
             inline - len(1) winlogon.exe - 0x00F41670->_
             inline - len(6) winlogon.exe - 0x00F416A2->_
             inline - len(1) winlogon.exe - 0x00F416DA->_
             inline - len(6) winlogon.exe - 0x00F416E4->_
             inline - len(6) winlogon.exe - 0x00F416F7->_
             inline - len(6) winlogon.exe - 0x00F4170A->_
             inline - len(6) winlogon.exe - 0x00F4171D->_
             inline - len(6) winlogon.exe - 0x00F4173B->_
             inline - len(1) winlogon.exe - 0x00F41759->_
             inline - len(1) winlogon.exe - 0x00F41770->_
             inline - len(6) winlogon.exe - 0x00F41782->_
             inline - len(1) winlogon.exe - 0x00F417AC->_
             inline - len(1) winlogon.exe - 0x00F417CB->_
             inline - len(1) winlogon.exe - 0x00F417D8->_
             inline - len(6) winlogon.exe - 0x00F417EE->_
             inline - len(1) winlogon.exe - 0x00F41818->_
             inline - len(6) winlogon.exe - 0x00F4182F->_
             inline - len(1) winlogon.exe - 0x00F41857->_
             inline - len(1) winlogon.exe - 0x00F41862->_
             inline - len(6) winlogon.exe - 0x00F41870->_
             inline - len(1) winlogon.exe - 0x00F41880->_
             inline - len(1) winlogon.exe - 0x00F41886->_
             inline - len(1) winlogon.exe - 0x00F418A9->_
             inline - len(1) winlogon.exe - 0x00F418C5->_
             inline - len(6) winlogon.exe - 0x00F418CD->_
             inline - len(1) winlogon.exe - 0x00F418F7->_
             inline - len(1) winlogon.exe - 0x00F41909->_
             inline - len(1) winlogon.exe - 0x00F41913->_
             inline - len(1) winlogon.exe - 0x00F4192B->_
             inline - len(6) winlogon.exe - 0x00F41936->_
             inline - len(1) winlogon.exe - 0x00F41954->_
             inline - len(1) winlogon.exe - 0x00F41969->_
             inline - len(1) winlogon.exe - 0x00F41974->_
             inline - len(1) winlogon.exe - 0x00F4197F->_
             inline - len(1) winlogon.exe - 0x00F41987->_
             inline - len(1) winlogon.exe - 0x00F419C5->_
             inline - len(1) winlogon.exe - 0x00F419CF->_
             inline - len(1) winlogon.exe - 0x00F419E5->_
             inline - len(1) winlogon.exe - 0x00F419F2->0x00F36D20[C:\Windows\System32\winlogon.exe]
             inline - len(11) winlogon.exe - 0x00F41A01->_
             inline - len(1) winlogon.exe - 0x00F41A35->_
             inline - len(1) winlogon.exe - 0x00F41A46->_
             inline - len(1) winlogon.exe - 0x00F41A4C->_
             inline - len(1) winlogon.exe - 0x00F41A5E->_
             inline - len(1) winlogon.exe - 0x00F41A69->_
             inline - len(1) winlogon.exe - 0x00F41A95->_
             inline - len(1) winlogon.exe - 0x00F41A9F->_
             inline - len(1) winlogon.exe - 0x00F41AA7->_
             inline - len(1) winlogon.exe - 0x00F41AD2->_
             inline - len(1) winlogon.exe - 0x00F41B04->0x00F24F6F[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F41B11->_
             inline - len(1) winlogon.exe - 0x00F41B2B->_
             inline - len(1) winlogon.exe - 0x00F41B49->_
             inline - len(1) winlogon.exe - 0x00F41B51->_
             inline - len(1) winlogon.exe - 0x00F41B5C->_
             inline - len(1) winlogon.exe - 0x00F41B72->_
             inline - len(6) winlogon.exe - 0x00F41B78->_
             inline - len(1) winlogon.exe - 0x00F41B9F->_
             inline - len(1) winlogon.exe - 0x00F41BA6->_
             inline - len(1) winlogon.exe - 0x00F41BB1->_
             inline - len(1) winlogon.exe - 0x00F41BB7->_
             inline - len(1) winlogon.exe - 0x00F41BD7->_
             inline - len(1) winlogon.exe - 0x00F41BEF->_
             inline - len(1) winlogon.exe - 0x00F41BF5->_
             inline - len(1) winlogon.exe - 0x00F41C15->_
             inline - len(6) winlogon.exe - 0x00F41C2C->_
             inline - len(1) winlogon.exe - 0x00F41C56->_
             inline - len(1) winlogon.exe - 0x00F41C83->_
             inline - len(1) winlogon.exe - 0x00F41C89->_
             inline - len(1) winlogon.exe - 0x00F41CAB->_
             inline - len(1) winlogon.exe - 0x00F41CBD->_
             inline - len(6) winlogon.exe - 0x00F41CD3->_
             inline - len(1) winlogon.exe - 0x00F41CFC->_
             inline - len(6) winlogon.exe - 0x00F41D53->_
             inline - len(1) winlogon.exe - 0x00F41D70->_
             inline - len(6) winlogon.exe - 0x00F41D8A->_
             inline - len(1) winlogon.exe - 0x00F41DA7->_
             inline - len(1) winlogon.exe - 0x00F41DCC->_
             inline - len(1) winlogon.exe - 0x00F41DD7->_
             inline - len(1) winlogon.exe - 0x00F41DE6->_
             inline - len(1) winlogon.exe - 0x00F41DF4->_
             inline - len(1) winlogon.exe - 0x00F41E12->_
             inline - len(1) winlogon.exe - 0x00F41E61->_
             inline - len(6) winlogon.exe - 0x00F41E77->_
             inline - len(1) winlogon.exe - 0x00F41E90->_
             inline - len(6) winlogon.exe - 0x00F41EB1->_
             inline - len(1) winlogon.exe - 0x00F41ECA->_
             inline - len(1) winlogon.exe - 0x00F41EE0->_
             inline - len(1) winlogon.exe - 0x00F41EEB->_
             inline - len(1) winlogon.exe - 0x00F41EF2->_
             inline - len(1) winlogon.exe - 0x00F41F08->_
             inline - len(1) winlogon.exe - 0x00F41F1F->_
             inline - len(1) winlogon.exe - 0x00F41F2D->_
             inline - len(1) winlogon.exe - 0x00F41F4F->_
             inline - len(1) winlogon.exe - 0x00F41F67->_
             inline - len(1) winlogon.exe - 0x00F41F89->_
             inline - len(1) winlogon.exe - 0x00F41FA0->_
             inline - len(1) winlogon.exe - 0x00F41FC1->_
             inline - len(1) winlogon.exe - 0x00F41FD9->_
             inline - len(1) winlogon.exe - 0x00F41FFB->_
             inline - len(1) winlogon.exe - 0x00F42018->_
             inline - len(1) winlogon.exe - 0x00F4202E->_
             inline - len(1) winlogon.exe - 0x00F4203B->_
             inline - len(1) winlogon.exe - 0x00F4205D->_
             inline - len(1) winlogon.exe - 0x00F42063->_
             inline - len(1) winlogon.exe - 0x00F4207B->_
             inline - len(1) winlogon.exe - 0x00F4209D->_
             inline - len(1) winlogon.exe - 0x00F420A3->_
             inline - len(1) winlogon.exe - 0x00F420C2->0x00F285D8[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F420F2->_
             inline - len(1) winlogon.exe - 0x00F420FA->_
             inline - len(1) winlogon.exe - 0x00F4213E->_
             inline - len(1) winlogon.exe - 0x00F42176->_
             inline - len(6) winlogon.exe - 0x00F4217D->_
             inline - len(1) winlogon.exe - 0x00F421A5->_
             inline - len(1) winlogon.exe - 0x00F421BD->_
             inline - len(1) winlogon.exe - 0x00F421C3->_
             inline - len(1) winlogon.exe - 0x00F421E5->_
             inline - len(6) winlogon.exe - 0x00F421FD->_
             inline - len(1) winlogon.exe - 0x00F42224->_
             inline - len(6) winlogon.exe - 0x00F4223B->_
             inline - len(6) winlogon.exe - 0x00F42285->_
             inline - len(6) winlogon.exe - 0x00F422E8->_
             inline - len(1) winlogon.exe - 0x00F42346->_
             inline - len(6) winlogon.exe - 0x00F4237E->_
             inline - len(1) winlogon.exe - 0x00F4243D->_
             inline - len(1) winlogon.exe - 0x00F42454->_
             inline - len(1) winlogon.exe - 0x00F4246E->_
             inline - len(1) winlogon.exe - 0x00F424C5->_
             inline - len(1) winlogon.exe - 0x00F424CB->_
             inline - len(1) winlogon.exe - 0x00F424D5->_
             inline - len(1) winlogon.exe - 0x00F424DB->_
             inline - len(1) winlogon.exe - 0x00F424E4->_
             inline - len(1) winlogon.exe - 0x00F424F0->_
             inline - len(1) winlogon.exe - 0x00F42536->_
             inline - len(1) winlogon.exe - 0x00F4253C->_
             inline - len(1) winlogon.exe - 0x00F42571->_
             inline - len(1) winlogon.exe - 0x00F4258A->_
             inline - len(1) winlogon.exe - 0x00F425A8->_
             inline - len(1) winlogon.exe - 0x00F425CA->_
             inline - len(1) winlogon.exe - 0x00F425D0->_
             inline - len(11) winlogon.exe - 0x00F425EB->_
             inline - len(1) winlogon.exe - 0x00F42614->_
             inline - len(1) winlogon.exe - 0x00F4262D->_
             inline - len(6) winlogon.exe - 0x00F42635->_
             inline - len(1) winlogon.exe - 0x00F4265A->_
             inline - len(1) winlogon.exe - 0x00F42672->_
             inline - len(6) winlogon.exe - 0x00F4267A->_
             inline - len(1) winlogon.exe - 0x00F426A1->_
             inline - len(1) winlogon.exe - 0x00F426D0->_
             inline - len(1) winlogon.exe - 0x00F426E7->_
             inline - len(1) winlogon.exe - 0x00F426FE->_
             inline - len(1) winlogon.exe - 0x00F42714->_
             inline - len(1) winlogon.exe - 0x00F4272E->_
             inline - len(1) winlogon.exe - 0x00F42740->_
             inline - len(1) winlogon.exe - 0x00F4274A->_
             inline - len(1) winlogon.exe - 0x00F42762->_
             inline - len(1) winlogon.exe - 0x00F4277C->_
             inline - len(1) winlogon.exe - 0x00F4279E->_
             inline - len(6) winlogon.exe - 0x00F427A4->_
             inline - len(1) winlogon.exe - 0x00F427C0->_
             inline - len(1) winlogon.exe - 0x00F427D7->_
             inline - len(1) winlogon.exe - 0x00F427EE->_
             inline - len(1) winlogon.exe - 0x00F42801->_
             inline - len(1) winlogon.exe - 0x00F4280B->_
             inline - len(1) winlogon.exe - 0x00F42826->_
             inline - len(1) winlogon.exe - 0x00F42841->_
             inline - len(1) winlogon.exe - 0x00F42876->_
             inline - len(6) winlogon.exe - 0x00F42894->_
             inline - len(1) winlogon.exe - 0x00F428B8->_
             inline - len(6) winlogon.exe - 0x00F428D6->_
             inline - len(1) winlogon.exe - 0x00F428F9->_
             inline - len(1) winlogon.exe - 0x00F42918->_
             inline - len(1) winlogon.exe - 0x00F42935->_
             inline - len(1) winlogon.exe - 0x00F4294D->_
             inline - len(1) winlogon.exe - 0x00F42953->_
             inline - len(1) winlogon.exe - 0x00F42959->_
             inline - len(1) winlogon.exe - 0x00F4296D->_
             inline - len(1) winlogon.exe - 0x00F42985->_
             inline - len(1) winlogon.exe - 0x00F4298F->_
             inline - len(1) winlogon.exe - 0x00F429C4->_
             inline - len(1) winlogon.exe - 0x00F429CF->_
             inline - len(1) winlogon.exe - 0x00F429E7->_
             inline - len(1) winlogon.exe - 0x00F429EF->_
             inline - len(1) winlogon.exe - 0x00F42A13->_
             inline - len(1) winlogon.exe - 0x00F42A31->_
             inline - len(1) winlogon.exe - 0x00F42A68->_
             inline - len(1) winlogon.exe - 0x00F42A77->_
             inline - len(1) winlogon.exe - 0x00F42A99->0x00F42A17[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F42AC7->_
             inline - len(1) winlogon.exe - 0x00F42ADF->_
             inline - len(6) winlogon.exe - 0x00F42AFD->_
             inline - len(1) winlogon.exe - 0x00F42B1C->_
             inline - len(1) winlogon.exe - 0x00F42B66->_
             inline - len(1) winlogon.exe - 0x00F42B71->_
             inline - len(1) winlogon.exe - 0x00F42B8B->_
             inline - len(1) winlogon.exe - 0x00F42BA2->_
             inline - len(6) winlogon.exe - 0x00F42BB9->_
             inline - len(1) winlogon.exe - 0x00F42BD3->_
             inline - len(1) winlogon.exe - 0x00F42C21->_
             inline - len(1) winlogon.exe - 0x00F42C35->_
             inline - len(6) winlogon.exe - 0x00F42C4C->_
             inline - len(1) winlogon.exe - 0x00F42C70->_
             inline - len(6) winlogon.exe - 0x00F42C91->_
             inline - len(1) winlogon.exe - 0x00F42CAA->_
             inline - len(1) winlogon.exe - 0x00F42CCC->_
             inline - len(6) winlogon.exe - 0x00F42CE4->_
             inline - len(1) winlogon.exe - 0x00F42CFC->_
             inline - len(1) winlogon.exe - 0x00F42D1C->_
             inline - len(6) winlogon.exe - 0x00F42D24->_
             inline - len(1) winlogon.exe - 0x00F42D4B->_
             inline - len(1) winlogon.exe - 0x00F42D63->_
             inline - len(6) winlogon.exe - 0x00F42D6B->_
             inline - len(1) winlogon.exe - 0x00F42D92->_
             inline - len(6) winlogon.exe - 0x00F42D9B->_
             inline - len(1) winlogon.exe - 0x00F42DC1->_
             inline - len(6) winlogon.exe - 0x00F42DD8->_
             inline - len(1) winlogon.exe - 0x00F42DFD->_
             inline - len(6) winlogon.exe - 0x00F42E06->_
             inline - len(1) winlogon.exe - 0x00F42E2D->_
             inline - len(1) winlogon.exe - 0x00F42E4C->_
             inline - len(1) winlogon.exe - 0x00F42EC1->_
             inline - len(1) winlogon.exe - 0x00F42ECA->_
             inline - len(1) winlogon.exe - 0x00F42ED3->_
             inline - len(1) winlogon.exe - 0x00F42EDE->_
             inline - len(1) winlogon.exe - 0x00F42EE5->_
             inline - len(1) winlogon.exe - 0x00F42EEB->_
             inline - len(6) winlogon.exe - 0x00F42EF6->_
             inline - len(1) winlogon.exe - 0x00F42F10->_
             inline - len(6) winlogon.exe - 0x00F42F2E->_
             inline - len(1) winlogon.exe - 0x00F42F49->_
             inline - len(6) winlogon.exe - 0x00F42F67->_
             inline - len(1) winlogon.exe - 0x00F42F8D->_
             inline - len(6) winlogon.exe - 0x00F42FAE->_
             inline - len(1) winlogon.exe - 0x00F42FD4->_
             inline - len(1) winlogon.exe - 0x00F42FFA->_
             inline - len(1) winlogon.exe - 0x00F43002->_
             inline - len(1) winlogon.exe - 0x00F43018->_
             inline - len(1) winlogon.exe - 0x00F4302A->_
             inline - len(1) winlogon.exe - 0x00F43038->_
             inline - len(1) winlogon.exe - 0x00F43059->_
             inline - len(1) winlogon.exe - 0x00F43067->_
             inline - len(1) winlogon.exe - 0x00F4307A->_
             inline - len(6) winlogon.exe - 0x00F43082->_
             inline - len(1) winlogon.exe - 0x00F430A9->_
             inline - len(6) winlogon.exe - 0x00F430C0->_
             inline - len(1) winlogon.exe - 0x00F430EA->_
             inline - len(1) winlogon.exe - 0x00F43102->_
             inline - len(6) winlogon.exe - 0x00F43115->_
             inline - len(1) winlogon.exe - 0x00F43133->_
             inline - len(1) winlogon.exe - 0x00F4313B->_
             inline - len(1) winlogon.exe - 0x00F43150->_
             inline - len(1) winlogon.exe - 0x00F43169->_
             inline - len(1) winlogon.exe - 0x00F4319D->_
             inline - len(1) winlogon.exe - 0x00F431A9->_
             inline - len(6) winlogon.exe - 0x00F431B3->_
             inline - len(1) winlogon.exe - 0x00F431CC->_
             inline - len(1) winlogon.exe - 0x00F431EE->_
             inline - len(1) winlogon.exe - 0x00F431F4->_
             inline - len(1) winlogon.exe - 0x00F43209->_
             inline - len(6) winlogon.exe - 0x00F4322C->_
             inline - len(6) winlogon.exe - 0x00F43263->_
             inline - len(1) winlogon.exe - 0x00F43296->_
             inline - len(1) winlogon.exe - 0x00F432C0->_
             inline - len(6) winlogon.exe - 0x00F43313->_
             inline - len(6) winlogon.exe - 0x00F43336->_
             inline - len(1) winlogon.exe - 0x00F4336C->_
             inline - len(1) winlogon.exe - 0x00F43372->_
             inline - len(6) winlogon.exe - 0x00F433A5->_
             inline - len(1) winlogon.exe - 0x00F43422->_
             inline - len(1) winlogon.exe - 0x00F4342E->_
             inline - len(6) winlogon.exe - 0x00F43441->_
             inline - len(6) winlogon.exe - 0x00F43476->_
             inline - len(6) winlogon.exe - 0x00F434B1->_
             inline - len(6) winlogon.exe - 0x00F434EF->_
             inline - len(1) winlogon.exe - 0x00F43513->_
             inline - len(1) winlogon.exe - 0x00F4351A->_
             inline - len(1) winlogon.exe - 0x00F43521->_
             inline - len(1) winlogon.exe - 0x00F43571->_
             inline - len(6) winlogon.exe - 0x00F43581->_
             inline - len(1) winlogon.exe - 0x00F435AB->_
             inline - len(6) winlogon.exe - 0x00F435C2->_
             inline - len(1) winlogon.exe - 0x00F435E6->_
             inline - len(1) winlogon.exe - 0x00F435ED->_
             inline - len(1) winlogon.exe - 0x00F435FA->_
             inline - len(6) winlogon.exe - 0x00F43638->_
             inline - len(1) winlogon.exe - 0x00F43648->_
             inline - len(1) winlogon.exe - 0x00F4364E->_
             inline - len(1) winlogon.exe - 0x00F4366E->_
             inline - len(1) winlogon.exe - 0x00F43675->_
             inline - len(1) winlogon.exe - 0x00F4367D->_
             inline - len(6) winlogon.exe - 0x00F436B9->_
             inline - len(1) winlogon.exe - 0x00F436F3->_
             inline - len(6) winlogon.exe - 0x00F43711->_
             inline - len(1) winlogon.exe - 0x00F4373F->_
             inline - len(6) winlogon.exe - 0x00F43766->_
             inline - len(1) winlogon.exe - 0x00F43794->_
             inline - len(6) winlogon.exe - 0x00F437A8->_
             inline - len(1) winlogon.exe - 0x00F437C8->_
             inline - len(1) winlogon.exe - 0x00F437CE->_
             inline - len(6) winlogon.exe - 0x00F437F1->_
             inline - len(6) winlogon.exe - 0x00F4381D->_
             inline - len(1) winlogon.exe - 0x00F43847->_
             inline - len(1) winlogon.exe - 0x00F4386C->_
             inline - len(6) winlogon.exe - 0x00F43883->_
             inline - len(1) winlogon.exe - 0x00F438A8->_
             inline - len(6) winlogon.exe - 0x00F438BA->_
             inline - len(1) winlogon.exe - 0x00F438E5->_
             inline - len(1) winlogon.exe - 0x00F43933->_
             inline - len(1) winlogon.exe - 0x00F439BC->_
             inline - len(1) winlogon.exe - 0x00F439DD->_
             inline - len(6) winlogon.exe - 0x00F43A12->_
             inline - len(1) winlogon.exe - 0x00F43A43->_
             inline - len(1) winlogon.exe - 0x00F43A72->_
             inline - len(1) winlogon.exe - 0x00F43A7C->_
             inline - len(6) winlogon.exe - 0x00F43AC2->_
             inline - len(6) winlogon.exe - 0x00F43AEB->_
             inline - len(6) winlogon.exe - 0x00F43B09->_
             inline - len(1) winlogon.exe - 0x00F43B28->_
             inline - len(1) winlogon.exe - 0x00F43B2F->_
             inline - len(1) winlogon.exe - 0x00F43B47->_
             inline - len(1) winlogon.exe - 0x00F43B72->_
             inline - len(1) winlogon.exe - 0x00F43BA8->_
             inline - len(1) winlogon.exe - 0x00F43BDA->_
             inline - len(1) winlogon.exe - 0x00F43BFC->_
             inline - len(1) winlogon.exe - 0x00F43C09->_
             inline - len(1) winlogon.exe - 0x00F43C10->_
             inline - len(6) winlogon.exe - 0x00F43C25->_
             inline - len(1) winlogon.exe - 0x00F43C3D->_
             inline - len(1) winlogon.exe - 0x00F43C44->_
             inline - len(1) winlogon.exe - 0x00F43C4B->_
             inline - len(6) winlogon.exe - 0x00F43C63->_
             inline - len(1) winlogon.exe - 0x00F43C7C->_
             inline - len(1) winlogon.exe - 0x00F43C83->_
             inline - len(6) winlogon.exe - 0x00F43C8C->_
             inline - len(1) winlogon.exe - 0x00F43CA8->_
             inline - len(1) winlogon.exe - 0x00F43CAF->_
             inline - len(6) winlogon.exe - 0x00F43CCB->_
             inline - len(1) winlogon.exe - 0x00F43CE7->_
             inline - len(6) winlogon.exe - 0x00F43D07->_
             inline - len(1) winlogon.exe - 0x00F43D2C->_
             inline - len(11) winlogon.exe - 0x00F43D44->_
             inline - len(1) winlogon.exe - 0x00F43D6E->_
             inline - len(6) winlogon.exe - 0x00F43D74->_
             inline - len(6) winlogon.exe - 0x00F43D90->_
             inline - len(1) winlogon.exe - 0x00F43DAE->_
             inline - len(1) winlogon.exe - 0x00F43DC6->_
             inline - len(6) winlogon.exe - 0x00F43DD0->_
             inline - len(1) winlogon.exe - 0x00F43DF9->_
             inline - len(6) winlogon.exe - 0x00F43E4F->_
             inline - len(1) winlogon.exe - 0x00F43E7D->_
             inline - len(6) winlogon.exe - 0x00F43E94->_
             inline - len(1) winlogon.exe - 0x00F43EB6->_
             inline - len(6) winlogon.exe - 0x00F43F0C->_
             inline - len(1) winlogon.exe - 0x00F43F2E->_
             inline - len(6) winlogon.exe - 0x00F43FB4->_
             inline - len(1) winlogon.exe - 0x00F43FD7->_
             inline - len(1) winlogon.exe - 0x00F43FE6->_
             inline - len(1) winlogon.exe - 0x00F43FF8->_
             inline - len(1) winlogon.exe - 0x00F44016->_
             inline - len(1) winlogon.exe - 0x00F44035->_
             inline - len(6) winlogon.exe - 0x00F4405E->_
             inline - len(1) winlogon.exe - 0x00F4408D->_
             inline - len(1) winlogon.exe - 0x00F4409C->_
             inline - len(1) winlogon.exe - 0x00F440F6->_
             inline - len(1) winlogon.exe - 0x00F4414E->_
             inline - len(1) winlogon.exe - 0x00F4416C->_
             inline - len(1) winlogon.exe - 0x00F4417A->0x00F2BBC0[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F441B8->_
             inline - len(1) winlogon.exe - 0x00F441D0->_
             inline - len(1) winlogon.exe - 0x00F441D6->_
             inline - len(1) winlogon.exe - 0x00F441E1->_
             inline - len(11) winlogon.exe - 0x00F441F8->_
             inline - len(1) winlogon.exe - 0x00F44227->_
             inline - len(1) winlogon.exe - 0x00F44232->_
             inline - len(1) winlogon.exe - 0x00F44241->0x00F22083[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F44278->_
             inline - len(1) winlogon.exe - 0x00F442F5->_
             inline - len(1) winlogon.exe - 0x00F442FB->_
             inline - len(1) winlogon.exe - 0x00F44345->_
             inline - len(1) winlogon.exe - 0x00F44449->0x00F39316[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4445D->_
             inline - len(1) winlogon.exe - 0x00F44493->_
             inline - len(1) winlogon.exe - 0x00F444A0->_
             inline - len(1) winlogon.exe - 0x00F444A6->_
             inline - len(1) winlogon.exe - 0x00F444C6->_
             inline - len(6) winlogon.exe - 0x00F444DD->_
             inline - len(1) winlogon.exe - 0x00F44501->_
             inline - len(1) winlogon.exe - 0x00F44519->_
             inline - len(1) winlogon.exe - 0x00F4451F->_
             inline - len(1) winlogon.exe - 0x00F4453F->_
             inline - len(6) winlogon.exe - 0x00F4456A->_
             inline - len(1) winlogon.exe - 0x00F4458F->_
             inline - len(6) winlogon.exe - 0x00F445A6->_
             inline - len(1) winlogon.exe - 0x00F445CB->_
             inline - len(6) winlogon.exe - 0x00F445E2->_
             inline - len(1) winlogon.exe - 0x00F44607->_
             inline - len(6) winlogon.exe - 0x00F44610->_
             inline - len(1) winlogon.exe - 0x00F44635->_
             inline - len(6) winlogon.exe - 0x00F4463E->_
             inline - len(1) winlogon.exe - 0x00F44663->_
             inline - len(6) winlogon.exe - 0x00F44681->_
             inline - len(1) winlogon.exe - 0x00F446A3->0x00F445CF[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F446AF->_
             inline - len(1) winlogon.exe - 0x00F446C8->_
             inline - len(1) winlogon.exe - 0x00F446FA->_
             inline - len(1) winlogon.exe - 0x00F44701->_
             inline - len(1) winlogon.exe - 0x00F44712->_
             inline - len(1) winlogon.exe - 0x00F4471D->0x00F31BB5[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4472C->_
             inline - len(6) winlogon.exe - 0x00F44734->_
             inline - len(1) winlogon.exe - 0x00F4475B->_
             inline - len(1) winlogon.exe - 0x00F44774->_
             inline - len(6) winlogon.exe - 0x00F4477C->_
             inline - len(1) winlogon.exe - 0x00F447A3->_
             inline - len(1) winlogon.exe - 0x00F447AE->_
             inline - len(6) winlogon.exe - 0x00F447B6->_
             inline - len(1) winlogon.exe - 0x00F447DD->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F447EB->_
             inline - len(6) winlogon.exe - 0x00F447F3->_
             inline - len(1) winlogon.exe - 0x00F4481A->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F44828->_
             inline - len(6) winlogon.exe - 0x00F44830->_
             inline - len(1) winlogon.exe - 0x00F44857->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F44865->_
             inline - len(6) winlogon.exe - 0x00F4486D->_
             inline - len(1) winlogon.exe - 0x00F44894->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F448A2->_
             inline - len(6) winlogon.exe - 0x00F448AA->_
             inline - len(1) winlogon.exe - 0x00F448D1->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F448DF->_
             inline - len(6) winlogon.exe - 0x00F448E7->_
             inline - len(1) winlogon.exe - 0x00F4490E->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4491C->_
             inline - len(6) winlogon.exe - 0x00F44924->_
             inline - len(1) winlogon.exe - 0x00F4494B->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F44959->_
             inline - len(6) winlogon.exe - 0x00F44961->_
             inline - len(1) winlogon.exe - 0x00F44986->0x00F4475F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F449A4->0x00F28A54[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F449DF->_
             inline - len(6) winlogon.exe - 0x00F449F6->_
             inline - len(1) winlogon.exe - 0x00F44A1B->_
             inline - len(6) winlogon.exe - 0x00F44A21->_
             inline - len(1) winlogon.exe - 0x00F44A3F->_
             inline - len(6) winlogon.exe - 0x00F44A46->_
             inline - len(1) winlogon.exe - 0x00F44A6B->_
             inline - len(1) winlogon.exe - 0x00F44A83->_
             inline - len(1) winlogon.exe - 0x00F44A89->_
             inline - len(1) winlogon.exe - 0x00F44AA8->_
             inline - len(1) winlogon.exe - 0x00F44ACB->_
             inline - len(1) winlogon.exe - 0x00F44AFC->_
             inline - len(1) winlogon.exe - 0x00F44B28->_
             inline - len(1) winlogon.exe - 0x00F44B56->_
             inline - len(1) winlogon.exe - 0x00F44B65->_
             inline - len(1) winlogon.exe - 0x00F44B71->_
             inline - len(1) winlogon.exe - 0x00F44B9C->_
             inline - len(1) winlogon.exe - 0x00F44BC5->_
             inline - len(1) winlogon.exe - 0x00F44BD8->_
             inline - len(1) winlogon.exe - 0x00F44C0A->_
             inline - len(1) winlogon.exe - 0x00F44C3F->_
             inline - len(1) winlogon.exe - 0x00F44C76->_
             inline - len(1) winlogon.exe - 0x00F44CAD->_
             inline - len(1) winlogon.exe - 0x00F44CF4->_
             inline - len(1) winlogon.exe - 0x00F44D1B->0x00F2FDD5[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F44D2A->_
             inline - len(6) winlogon.exe - 0x00F44D31->_
             inline - len(1) winlogon.exe - 0x00F44D4A->_
             inline - len(1) winlogon.exe - 0x00F44D76->_
             inline - len(1) winlogon.exe - 0x00F44D81->_
             inline - len(6) winlogon.exe - 0x00F44D88->_
             inline - len(1) winlogon.exe - 0x00F44DA4->_
             inline - len(1) winlogon.exe - 0x00F44DCD->_
             inline - len(1) winlogon.exe - 0x00F44DD8->_
             inline - len(6) winlogon.exe - 0x00F44DE0->_
             inline - len(1) winlogon.exe - 0x00F44E07->_
             inline - len(1) winlogon.exe - 0x00F44E1F->_
             inline - len(6) winlogon.exe - 0x00F44E27->_
             inline - len(1) winlogon.exe - 0x00F44E4D->_
             inline - len(1) winlogon.exe - 0x00F44E65->_
             inline - len(6) winlogon.exe - 0x00F44E70->_
             inline - len(1) winlogon.exe - 0x00F44E9A->_
             inline - len(1) winlogon.exe - 0x00F44EB9->_
             inline - len(6) winlogon.exe - 0x00F44EC1->_
             inline - len(1) winlogon.exe - 0x00F44EE7->_
             inline - len(1) winlogon.exe - 0x00F44EFF->_
             inline - len(6) winlogon.exe - 0x00F44F07->_
             inline - len(1) winlogon.exe - 0x00F44F2D->_
             inline - len(1) winlogon.exe - 0x00F44F45->_
             inline - len(6) winlogon.exe - 0x00F44F4D->_
             inline - len(1) winlogon.exe - 0x00F44F73->_
             inline - len(1) winlogon.exe - 0x00F44F8B->_
             inline - len(6) winlogon.exe - 0x00F44F93->_
             inline - len(1) winlogon.exe - 0x00F44FB9->_
             inline - len(6) winlogon.exe - 0x00F45082->_
             inline - len(1) winlogon.exe - 0x00F4509A->_
             inline - len(1) winlogon.exe - 0x00F450B9->_
             inline - len(6) winlogon.exe - 0x00F450C1->_
             inline - len(1) winlogon.exe - 0x00F450DC->_
             inline - len(6) winlogon.exe - 0x00F45103->_
             inline - len(1) winlogon.exe - 0x00F4512A->_
             inline - len(6) winlogon.exe - 0x00F45141->_
             inline - len(1) winlogon.exe - 0x00F45168->_
             inline - len(1) winlogon.exe - 0x00F45172->_
             inline - len(6) winlogon.exe - 0x00F4517A->_
             inline - len(1) winlogon.exe - 0x00F451A1->_
             inline - len(1) winlogon.exe - 0x00F451AB->_
             inline - len(6) winlogon.exe - 0x00F451B3->_
             inline - len(1) winlogon.exe - 0x00F451DA->_
             inline - len(1) winlogon.exe - 0x00F451E6->_
             inline - len(1) winlogon.exe - 0x00F451FD->_
             inline - len(1) winlogon.exe - 0x00F45221->_
             inline - len(1) winlogon.exe - 0x00F4524B->_
             inline - len(1) winlogon.exe - 0x00F4525D->_
             inline - len(1) winlogon.exe - 0x00F45273->_
             inline - len(1) winlogon.exe - 0x00F45289->_
             inline - len(1) winlogon.exe - 0x00F452A1->_
             inline - len(1) winlogon.exe - 0x00F452DC->_
             inline - len(1) winlogon.exe - 0x00F45301->_
             inline - len(1) winlogon.exe - 0x00F45307->_
             inline - len(1) winlogon.exe - 0x00F45313->_
             inline - len(1) winlogon.exe - 0x00F45319->_
             inline - len(1) winlogon.exe - 0x00F45332->_
             inline - len(1) winlogon.exe - 0x00F45343->_
             inline - len(1) winlogon.exe - 0x00F4534E->_
             inline - len(1) winlogon.exe - 0x00F45354->_
             inline - len(1) winlogon.exe - 0x00F45374->_
             inline - len(6) winlogon.exe - 0x00F4538B->_
             inline - len(1) winlogon.exe - 0x00F453AF->_
             inline - len(1) winlogon.exe - 0x00F453C7->_
             inline - len(1) winlogon.exe - 0x00F453CD->_
             inline - len(1) winlogon.exe - 0x00F453ED->_
             inline - len(6) winlogon.exe - 0x00F453F6->_
             inline - len(1) winlogon.exe - 0x00F4540D->_
             inline - len(1) winlogon.exe - 0x00F45427->_
             inline - len(6) winlogon.exe - 0x00F45438->_
             inline - len(1) winlogon.exe - 0x00F4545C->_
             inline - len(1) winlogon.exe - 0x00F45483->_
             inline - len(5) winlogon.exe - 0x00F4548E->_
             inline - len(5) winlogon.exe - 0x00F4549D->_
             inline - len(1) winlogon.exe - 0x00F454AC->_
             inline - len(1) winlogon.exe - 0x00F454DA->_
             inline - len(1) winlogon.exe - 0x00F454EB->_
             inline - len(1) winlogon.exe - 0x00F45503->_
             inline - len(1) winlogon.exe - 0x00F4551B->_
             inline - len(1) winlogon.exe - 0x00F45538->_
             inline - len(1) winlogon.exe - 0x00F45549->_
             inline - len(1) winlogon.exe - 0x00F45555->_
             inline - len(6) winlogon.exe - 0x00F45565->_
             inline - len(1) winlogon.exe - 0x00F4558F->_
             inline - len(6) winlogon.exe - 0x00F45598->_
             inline - len(1) winlogon.exe - 0x00F455C2->_
             inline - len(6) winlogon.exe - 0x00F455D6->_
             inline - len(1) winlogon.exe - 0x00F455FF->_
             inline - len(6) winlogon.exe - 0x00F45627->_
             inline - len(1) winlogon.exe - 0x00F4564E->_
             inline - len(6) winlogon.exe - 0x00F4565A->_
             inline - len(1) winlogon.exe - 0x00F45680->_
             inline - len(6) winlogon.exe - 0x00F4568C->_
             inline - len(1) winlogon.exe - 0x00F456B2->_
             inline - len(6) winlogon.exe - 0x00F456BE->_
             inline - len(1) winlogon.exe - 0x00F456E4->_
             inline - len(6) winlogon.exe - 0x00F456ED->_
             inline - len(1) winlogon.exe - 0x00F45713->_
             inline - len(6) winlogon.exe - 0x00F4571C->_
             inline - len(1) winlogon.exe - 0x00F45742->_
             inline - len(1) winlogon.exe - 0x00F45765->_
             inline - len(1) winlogon.exe - 0x00F4576B->_
             inline - len(5) winlogon.exe - 0x00F45B1E->_
             inline - len(1) winlogon.exe - 0x00F45B75->_
             inline - len(1) winlogon.exe - 0x00F45B84->_
             inline - len(1) winlogon.exe - 0x00F45BC4->_
             inline - len(1) winlogon.exe - 0x00F45C21->_
             inline - len(6) winlogon.exe - 0x00F45C2A->_
             inline - len(1) winlogon.exe - 0x00F45C43->_
             inline - len(6) winlogon.exe - 0x00F45C4C->_
             inline - len(6) winlogon.exe - 0x00F45C8C->_
             inline - len(1) winlogon.exe - 0x00F45CAB->_
             inline - len(6) winlogon.exe - 0x00F45CBF->_
             inline - len(1) winlogon.exe - 0x00F45CDD->_
             inline - len(1) winlogon.exe - 0x00F45D5B->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F45D7F->_
             inline - len(1) winlogon.exe - 0x00F45D8C->_
             inline - len(1) winlogon.exe - 0x00F45DA2->0x3BD6FF00
             inline - len(1) winlogon.exe - 0x00F45DAE->_
             inline - len(1) winlogon.exe - 0x00F45E21->_
             inline - len(1) winlogon.exe - 0x00F45E42->_
             inline - len(1) winlogon.exe - 0x00F45E4E->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F45E7F->_
             inline - len(1) winlogon.exe - 0x00F45E97->_
             inline - len(1) winlogon.exe - 0x00F45EAB->_
             inline - len(1) winlogon.exe - 0x00F45EB7->_
             inline - len(6) winlogon.exe - 0x00F45EC2->_
             inline - len(1) winlogon.exe - 0x00F45EDA->_
             inline - len(6) winlogon.exe - 0x00F45EEE->_
             inline - len(1) winlogon.exe - 0x00F45F05->_
             inline - len(1) winlogon.exe - 0x00F45F52->_
             inline - len(1) winlogon.exe - 0x00F45F58->_
             inline - len(1) winlogon.exe - 0x00F45F6C->_
             inline - len(1) winlogon.exe - 0x00F45F9A->_
             inline - len(1) winlogon.exe - 0x00F46014->_
             inline - len(6) winlogon.exe - 0x00F4601D->_
             inline - len(1) winlogon.exe - 0x00F46035->_
             inline - len(1) winlogon.exe - 0x00F46053->_
             inline - len(1) winlogon.exe - 0x00F46071->_
             inline - len(1) winlogon.exe - 0x00F46077->_
             inline - len(1) winlogon.exe - 0x00F4608B->_
             inline - len(6) winlogon.exe - 0x00F460B2->_
             inline - len(1) winlogon.exe - 0x00F460CA->_
             inline - len(1) winlogon.exe - 0x00F460E4->_
             inline - len(1) winlogon.exe - 0x00F4610B->_
             inline - len(6) winlogon.exe - 0x00F46114->_
             inline - len(1) winlogon.exe - 0x00F4612C->_
             inline - len(1) winlogon.exe - 0x00F4618B->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F461A0->0x00F228C6[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F461C3->_
             inline - len(1) winlogon.exe - 0x00F461DC->_
             inline - len(1) winlogon.exe - 0x00F461F0->_
             inline - len(1) winlogon.exe - 0x00F46206->_
             inline - len(6) winlogon.exe - 0x00F46212->_
             inline - len(1) winlogon.exe - 0x00F4622F->_
             inline - len(1) winlogon.exe - 0x00F46241->_
             inline - len(1) winlogon.exe - 0x00F4625B->_
             inline - len(1) winlogon.exe - 0x00F46270->_
             inline - len(1) winlogon.exe - 0x00F46284->0x00F228C6[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F462B9->_
             inline - len(1) winlogon.exe - 0x00F462BF->_
             inline - len(1) winlogon.exe - 0x00F462D3->_
             inline - len(1) winlogon.exe - 0x00F46322->_
             inline - len(6) winlogon.exe - 0x00F463EE->_
             inline - len(1) winlogon.exe - 0x00F4640A->_
             inline - len(6) winlogon.exe - 0x00F4641E->_
             inline - len(1) winlogon.exe - 0x00F4643C->_
             inline - len(6) winlogon.exe - 0x00F46496->_
             inline - len(1) winlogon.exe - 0x00F464C8->_
             inline - len(1) winlogon.exe - 0x00F464FD->_
             inline - len(1) winlogon.exe - 0x00F4653D->_
             inline - len(1) winlogon.exe - 0x00F4659C->_
             inline - len(1) winlogon.exe - 0x00F465A2->_
             inline - len(1) winlogon.exe - 0x00F465BC->_
             inline - len(1) winlogon.exe - 0x00F46626->_
             inline - len(1) winlogon.exe - 0x00F46685->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F46707->_
             inline - len(1) winlogon.exe - 0x00F46726->_
             inline - len(1) winlogon.exe - 0x00F46766->_
             inline - len(1) winlogon.exe - 0x00F4678E->_
             inline - len(1) winlogon.exe - 0x00F46872->_
             inline - len(6) winlogon.exe - 0x00F46884->_
             inline - len(1) winlogon.exe - 0x00F4689F->_
             inline - len(6) winlogon.exe - 0x00F468A5->_
             inline - len(1) winlogon.exe - 0x00F468D9->_
             inline - len(1) winlogon.exe - 0x00F468EE->_
             inline - len(6) winlogon.exe - 0x00F46905->_
             inline - len(1) winlogon.exe - 0x00F46919->_
             inline - len(1) winlogon.exe - 0x00F46933->_
             inline - len(1) winlogon.exe - 0x00F4693E->_
             inline - len(1) winlogon.exe - 0x00F46947->_
             inline - len(1) winlogon.exe - 0x00F46950->_
             inline - len(1) winlogon.exe - 0x00F46959->_
             inline - len(1) winlogon.exe - 0x00F46963->_
             inline - len(6) winlogon.exe - 0x00F4697C->_
             inline - len(1) winlogon.exe - 0x00F46994->_
             inline - len(6) winlogon.exe - 0x00F469C7->_
             inline - len(1) winlogon.exe - 0x00F469DF->_
             inline - len(1) winlogon.exe - 0x00F46A52->_
             inline - len(6) winlogon.exe - 0x00F46A5A->_
             inline - len(1) winlogon.exe - 0x00F46A96->_
             inline - len(1) winlogon.exe - 0x00F46AC5->_
             inline - len(1) winlogon.exe - 0x00F46B13->_
             inline - len(1) winlogon.exe - 0x00F46B1E->_
             inline - len(1) winlogon.exe - 0x00F46B31->_
             inline - len(1) winlogon.exe - 0x00F46B3A->_
             inline - len(1) winlogon.exe - 0x00F46B45->_
             inline - len(1) winlogon.exe - 0x00F46B71->_
             inline - len(1) winlogon.exe - 0x00F46B81->_
             inline - len(1) winlogon.exe - 0x00F46B97->_
             inline - len(1) winlogon.exe - 0x00F46BA8->_
             inline - len(1) winlogon.exe - 0x00F46BCA->_
             inline - len(1) winlogon.exe - 0x00F46BD3->_
             inline - len(1) winlogon.exe - 0x00F46BFA->_
             inline - len(1) winlogon.exe - 0x00F46C08->_
             inline - len(1) winlogon.exe - 0x00F46C1E->_
             inline - len(1) winlogon.exe - 0x00F46C2E->_
             inline - len(1) winlogon.exe - 0x00F46C37->_
             inline - len(1) winlogon.exe - 0x00F46C94->_
             inline - len(1) winlogon.exe - 0x00F46C9A->_
             inline - len(1) winlogon.exe - 0x00F46CA5->_
             inline - len(1) winlogon.exe - 0x00F46CAC->_
             inline - len(1) winlogon.exe - 0x00F46CC8->_
             inline - len(1) winlogon.exe - 0x00F46D0F->_
             inline - len(1) winlogon.exe - 0x00F46D27->_
             inline - len(1) winlogon.exe - 0x00F46D44->_
             inline - len(1) winlogon.exe - 0x00F46D57->_
             inline - len(1) winlogon.exe - 0x00F46D60->_
             inline - len(1) winlogon.exe - 0x00F46D72->_
             inline - len(1) winlogon.exe - 0x00F46D88->_
             inline - len(1) winlogon.exe - 0x00F46D9B->_
             inline - len(1) winlogon.exe - 0x00F46DBD->_
             inline - len(1) winlogon.exe - 0x00F46E07->_
             inline - len(6) winlogon.exe - 0x00F46E14->_
             inline - len(1) winlogon.exe - 0x00F46E2D->_
             inline - len(6) winlogon.exe - 0x00F46E33->_
             inline - len(1) winlogon.exe - 0x00F46E59->_
             inline - len(1) winlogon.exe - 0x00F46E6B->_
             inline - len(1) winlogon.exe - 0x00F46E7D->_
             inline - len(1) winlogon.exe - 0x00F46E8E->_
             inline - len(1) winlogon.exe - 0x00F46EB1->_
             inline - len(6) winlogon.exe - 0x00F46EBD->_
             inline - len(1) winlogon.exe - 0x00F46EE2->_
             inline - len(1) winlogon.exe - 0x00F46EE8->0x00F470DE[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F46F34->_
             inline - len(1) winlogon.exe - 0x00F46F59->_
             inline - len(1) winlogon.exe - 0x00F46F5F->0x00F470DE[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F46F7F->_
             inline - len(1) winlogon.exe - 0x00F46FA4->_
             inline - len(1) winlogon.exe - 0x00F46FAA->0x00F470DE[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F46FCA->_
             inline - len(1) winlogon.exe - 0x00F46FEF->_
             inline - len(1) winlogon.exe - 0x00F46FF5->0x00F470DE[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F47015->_
             inline - len(1) winlogon.exe - 0x00F4703A->_
             inline - len(1) winlogon.exe - 0x00F47040->0x00F470DE[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4704D->_
             inline - len(6) winlogon.exe - 0x00F47068->_
             inline - len(1) winlogon.exe - 0x00F4708D->_
             inline - len(1) winlogon.exe - 0x00F47093->_
             inline - len(6) winlogon.exe - 0x00F470AF->_
             inline - len(1) winlogon.exe - 0x00F470D4->_
             inline - len(1) winlogon.exe - 0x00F470DA->_
             inline - len(1) winlogon.exe - 0x00F470E1->_
             inline - len(1) winlogon.exe - 0x00F47125->_
             inline - len(1) winlogon.exe - 0x00F4712F->_
             inline - len(1) winlogon.exe - 0x00F47135->_
             inline - len(1) winlogon.exe - 0x00F47155->_
             inline - len(1) winlogon.exe - 0x00F4719F->_
             inline - len(1) winlogon.exe - 0x00F471A9->_
             inline - len(1) winlogon.exe - 0x00F471AF->_
             inline - len(1) winlogon.exe - 0x00F471CF->_
             inline - len(1) winlogon.exe - 0x00F471E5->_
             inline - len(1) winlogon.exe - 0x00F471EF->_
             inline - len(1) winlogon.exe - 0x00F471F5->_
             inline - len(1) winlogon.exe - 0x00F47215->_
             inline - len(1) winlogon.exe - 0x00F47229->_
             inline - len(1) winlogon.exe - 0x00F47233->_
             inline - len(1) winlogon.exe - 0x00F47239->_
             inline - len(1) winlogon.exe - 0x00F4724D->_
             inline - len(6) winlogon.exe - 0x00F47271->_
             inline - len(1) winlogon.exe - 0x00F47289->_
             inline - len(1) winlogon.exe - 0x00F472A0->_
             inline - len(1) winlogon.exe - 0x00F472B0->_
             inline - len(1) winlogon.exe - 0x00F472C4->_
             inline - len(1) winlogon.exe - 0x00F472DA->_
             inline - len(1) winlogon.exe - 0x00F472FE->0x00F54E1D[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F47315->_
             inline - len(1) winlogon.exe - 0x00F4731C->_
             inline - len(1) winlogon.exe - 0x00F47349->_
             inline - len(1) winlogon.exe - 0x00F47352->_
             inline - len(1) winlogon.exe - 0x00F473F1->_
             inline - len(1) winlogon.exe - 0x00F47415->_
             inline - len(1) winlogon.exe - 0x00F47431->_
             inline - len(1) winlogon.exe - 0x00F47445->_
             inline - len(1) winlogon.exe - 0x00F4746B->_
             inline - len(1) winlogon.exe - 0x00F47488->_
             inline - len(1) winlogon.exe - 0x00F474DF->_
             inline - len(1) winlogon.exe - 0x00F474EA->_
             inline - len(1) winlogon.exe - 0x00F474F8->_
             inline - len(1) winlogon.exe - 0x00F47551->_
             inline - len(1) winlogon.exe - 0x00F475B7->_
             inline - len(1) winlogon.exe - 0x00F475D4->_
             inline - len(1) winlogon.exe - 0x00F4765D->_
             inline - len(1) winlogon.exe - 0x00F4769F->_
             inline - len(1) winlogon.exe - 0x00F47706->_
             inline - len(1) winlogon.exe - 0x00F4773B->_
             inline - len(1) winlogon.exe - 0x00F47761->_
             inline - len(1) winlogon.exe - 0x00F4778C->_
             inline - len(1) winlogon.exe - 0x00F477D9->_
             inline - len(1) winlogon.exe - 0x00F477F3->_
             inline - len(1) winlogon.exe - 0x00F47808->_
             inline - len(1) winlogon.exe - 0x00F4781D->_
             inline - len(1) winlogon.exe - 0x00F4783E->_
             inline - len(1) winlogon.exe - 0x00F47867->_
             inline - len(1) winlogon.exe - 0x00F47888->_
             inline - len(1) winlogon.exe - 0x00F4789C->_
             inline - len(1) winlogon.exe - 0x00F478C1->_
             inline - len(1) winlogon.exe - 0x00F478D7->_
             inline - len(6) winlogon.exe - 0x00F478E0->_
             inline - len(1) winlogon.exe - 0x00F478FF->_
             inline - len(1) winlogon.exe - 0x00F47914->_
             inline - len(1) winlogon.exe - 0x00F4791A->_
             inline - len(1) winlogon.exe - 0x00F4792E->_
             inline - len(1) winlogon.exe - 0x00F47947->_
             inline - len(1) winlogon.exe - 0x00F4794F->_
             inline - len(1) winlogon.exe - 0x00F47955->_
             inline - len(1) winlogon.exe - 0x00F47969->_
             inline - len(1) winlogon.exe - 0x00F47981->_
             inline - len(1) winlogon.exe - 0x00F4799D->_
             inline - len(1) winlogon.exe - 0x00F479AF->_
             inline - len(1) winlogon.exe - 0x00F479BB->_
             inline - len(1) winlogon.exe - 0x00F479C1->_
             inline - len(6) winlogon.exe - 0x00F479C8->_
             inline - len(1) winlogon.exe - 0x00F479F8->_
             inline - len(1) winlogon.exe - 0x00F47A1F->_
             inline - len(1) winlogon.exe - 0x00F47A32->_
             inline - len(1) winlogon.exe - 0x00F47A39->_
             inline - len(1) winlogon.exe - 0x00F47A46->_
             inline - len(1) winlogon.exe - 0x00F47AA0->_
             inline - len(1) winlogon.exe - 0x00F47ABA->_
             inline - len(6) winlogon.exe - 0x00F47ACF->_
             inline - len(1) winlogon.exe - 0x00F47AEA->_
             inline - len(1) winlogon.exe - 0x00F47AFD->_
             inline - len(1) winlogon.exe - 0x00F47B04->_
             inline - len(1) winlogon.exe - 0x00F47B31->_
             inline - len(1) winlogon.exe - 0x00F47B3D->_
             inline - len(1) winlogon.exe - 0x00F47B54->_
             inline - len(1) winlogon.exe - 0x00F47B5A->_
             inline - len(1) winlogon.exe - 0x00F47B7D->_
             inline - len(1) winlogon.exe - 0x00F47B9D->_
             inline - len(1) winlogon.exe - 0x00F47BAD->_
             inline - len(1) winlogon.exe - 0x00F47BC2->_
             inline - len(1) winlogon.exe - 0x00F47BD7->_
             inline - len(1) winlogon.exe - 0x00F47BE4->_
             inline - len(6) winlogon.exe - 0x00F47C03->_
             inline - len(1) winlogon.exe - 0x00F47C33->_
             inline - len(1) winlogon.exe - 0x00F47C49->_
             inline - len(1) winlogon.exe - 0x00F47C4F->_
             inline - len(1) winlogon.exe - 0x00F47C59->_
             inline - len(1) winlogon.exe - 0x00F47C84->_
             inline - len(6) winlogon.exe - 0x00F47D2D->_
             inline - len(1) winlogon.exe - 0x00F47D48->_
             inline - len(11) winlogon.exe - 0x00F47D8B->_
             inline - len(1) winlogon.exe - 0x00F47DCE->_
             inline - len(11) winlogon.exe - 0x00F47E04->_
             inline - len(1) winlogon.exe - 0x00F47E47->_
             inline - len(1) winlogon.exe - 0x00F47EAA->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F47ED9->_
             inline - len(1) winlogon.exe - 0x00F47EF6->_
             inline - len(1) winlogon.exe - 0x00F47F37->_
             inline - len(1) winlogon.exe - 0x00F47F4C->_
             inline - len(1) winlogon.exe - 0x00F48068->_
             inline - len(1) winlogon.exe - 0x00F480FA->_
             inline - len(6) winlogon.exe - 0x00F48109->_
             inline - len(1) winlogon.exe - 0x00F48124->_
             inline - len(6) winlogon.exe - 0x00F4814F->_
             inline - len(1) winlogon.exe - 0x00F4816A->_
             inline - len(6) winlogon.exe - 0x00F48188->_
             inline - len(1) winlogon.exe - 0x00F481A3->_
             inline - len(1) winlogon.exe - 0x00F481BF->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F481E1->_
             inline - len(1) winlogon.exe - 0x00F481FE->_
             inline - len(1) winlogon.exe - 0x00F48232->_
             inline - len(1) winlogon.exe - 0x00F4824D->_
             inline - len(1) winlogon.exe - 0x00F48270->_
             inline - len(1) winlogon.exe - 0x00F4828A->_
             inline - len(1) winlogon.exe - 0x00F482A3->_
             inline - len(1) winlogon.exe - 0x00F482A9->_
             inline - len(1) winlogon.exe - 0x00F482B0->_
             inline - len(1) winlogon.exe - 0x00F482E5->_
             inline - len(1) winlogon.exe - 0x00F48362->_
             inline - len(6) winlogon.exe - 0x00F48371->_
             inline - len(1) winlogon.exe - 0x00F4838C->_
             inline - len(1) winlogon.exe - 0x00F483F1->_
             inline - len(1) winlogon.exe - 0x00F48417->_
             inline - len(1) winlogon.exe - 0x00F48428->_
             inline - len(1) winlogon.exe - 0x00F48466->_
             inline - len(6) winlogon.exe - 0x00F4846D->_
             inline - len(1) winlogon.exe - 0x00F48485->_
             inline - len(1) winlogon.exe - 0x00F484A8->_
             inline - len(1) winlogon.exe - 0x00F484C5->_
             inline - len(1) winlogon.exe - 0x00F484D0->_
             inline - len(1) winlogon.exe - 0x00F484D7->_
             inline - len(1) winlogon.exe - 0x00F484EB->_
             inline - len(1) winlogon.exe - 0x00F484F2->_
             inline - len(1) winlogon.exe - 0x00F484FE->_
             inline - len(1) winlogon.exe - 0x00F48504->_
             inline - len(1) winlogon.exe - 0x00F48515->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F48542->_
             inline - len(1) winlogon.exe - 0x00F4854D->_
             inline - len(1) winlogon.exe - 0x00F4855C->_
             inline - len(1) winlogon.exe - 0x00F48562->_
             inline - len(1) winlogon.exe - 0x00F48585->_
             inline - len(1) winlogon.exe - 0x00F485A8->_
             inline - len(1) winlogon.exe - 0x00F485BA->_
             inline - len(1) winlogon.exe - 0x00F485C4->_
             inline - len(1) winlogon.exe - 0x00F485CA->_
             inline - len(1) winlogon.exe - 0x00F485ED->_
             inline - len(1) winlogon.exe - 0x00F485F6->_
             inline - len(1) winlogon.exe - 0x00F4860C->_
             inline - len(6) winlogon.exe - 0x00F48615->_
             inline - len(1) winlogon.exe - 0x00F4863E->_
             inline - len(1) winlogon.exe - 0x00F48659->_
             inline - len(1) winlogon.exe - 0x00F48688->_
             inline - len(1) winlogon.exe - 0x00F4869D->_
             inline - len(1) winlogon.exe - 0x00F486A3->_
             inline - len(1) winlogon.exe - 0x00F486C6->_
             inline - len(1) winlogon.exe - 0x00F486F2->_
             inline - len(1) winlogon.exe - 0x00F486FA->_
             inline - len(6) winlogon.exe - 0x00F48706->_
             inline - len(1) winlogon.exe - 0x00F48724->_
             inline - len(1) winlogon.exe - 0x00F48759->_
             inline - len(1) winlogon.exe - 0x00F4879D->_
             inline - len(1) winlogon.exe - 0x00F48832->_
             inline - len(1) winlogon.exe - 0x00F48847->_
             inline - len(1) winlogon.exe - 0x00F48859->_
             inline - len(1) winlogon.exe - 0x00F4887D->_
             inline - len(1) winlogon.exe - 0x00F48884->_
             inline - len(1) winlogon.exe - 0x00F4889A->_
             inline - len(1) winlogon.exe - 0x00F488A7->_
             inline - len(6) winlogon.exe - 0x00F488B5->_
             inline - len(1) winlogon.exe - 0x00F488D5->_
             inline - len(6) winlogon.exe - 0x00F488DB->_
             inline - len(1) winlogon.exe - 0x00F4890B->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4892B->_
             inline - len(1) winlogon.exe - 0x00F48932->_
             inline - len(1) winlogon.exe - 0x00F48940->_
             inline - len(1) winlogon.exe - 0x00F48946->_
             inline - len(1) winlogon.exe - 0x00F4894C->_
             inline - len(1) winlogon.exe - 0x00F48952->_
             inline - len(1) winlogon.exe - 0x00F48990->_
             inline - len(1) winlogon.exe - 0x00F489B8->_
             inline - len(1) winlogon.exe - 0x00F489C8->_
             inline - len(1) winlogon.exe - 0x00F489D9->_
             inline - len(1) winlogon.exe - 0x00F489DF->_
             inline - len(1) winlogon.exe - 0x00F489F6->_
             inline - len(1) winlogon.exe - 0x00F48A25->_
             inline - len(1) winlogon.exe - 0x00F48A35->_
             inline - len(6) winlogon.exe - 0x00F48A3E->_
             inline - len(1) winlogon.exe - 0x00F48A5A->_
             inline - len(1) winlogon.exe - 0x00F48A60->_
             inline - len(1) winlogon.exe - 0x00F48A67->_
             inline - len(1) winlogon.exe - 0x00F48A84->_
             inline - len(1) winlogon.exe - 0x00F48AFB->_
             inline - len(1) winlogon.exe - 0x00F48B08->_
             inline - len(1) winlogon.exe - 0x00F48B0E->_
             inline - len(1) winlogon.exe - 0x00F48B31->_
             inline - len(1) winlogon.exe - 0x00F48B57->_
             inline - len(1) winlogon.exe - 0x00F48B73->_
             inline - len(6) winlogon.exe - 0x00F48B7F->_
             inline - len(1) winlogon.exe - 0x00F48BA1->_
             inline - len(1) winlogon.exe - 0x00F48BA7->_
             inline - len(1) winlogon.exe - 0x00F48BAE->_
             inline - len(1) winlogon.exe - 0x00F48C00->_
             inline - len(1) winlogon.exe - 0x00F48C0D->_
             inline - len(1) winlogon.exe - 0x00F48C13->_
             inline - len(1) winlogon.exe - 0x00F48C2D->_
             inline - len(1) winlogon.exe - 0x00F48C44->_
             inline - len(1) winlogon.exe - 0x00F48C59->_
             inline - len(1) winlogon.exe - 0x00F48C6A->_
             inline - len(1) winlogon.exe - 0x00F48C70->_
             inline - len(1) winlogon.exe - 0x00F48C76->_
             inline - len(1) winlogon.exe - 0x00F48C9A->_
             inline - len(1) winlogon.exe - 0x00F48CA6->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F48CD7->_
             inline - len(6) winlogon.exe - 0x00F48CEB->_
             inline - len(1) winlogon.exe - 0x00F48D04->_
             inline - len(1) winlogon.exe - 0x00F48D1D->_
             inline - len(1) winlogon.exe - 0x00F48D2D->_
             inline - len(1) winlogon.exe - 0x00F48D42->_
             inline - len(1) winlogon.exe - 0x00F48D5D->_
             inline - len(6) winlogon.exe - 0x00F48D85->_
             inline - len(1) winlogon.exe - 0x00F48D94->_
             inline - len(1) winlogon.exe - 0x00F48D9F->_
             inline - len(1) winlogon.exe - 0x00F48DB4->_
             inline - len(1) winlogon.exe - 0x00F48DE4->_
             inline - len(1) winlogon.exe - 0x00F48DEA->_
             inline - len(1) winlogon.exe - 0x00F48E04->_
             inline - len(1) winlogon.exe - 0x00F48ECA->_
             inline - len(6) winlogon.exe - 0x00F48F34->_
             inline - len(1) winlogon.exe - 0x00F48F4F->_
             inline - len(6) winlogon.exe - 0x00F48F9C->_
             inline - len(1) winlogon.exe - 0x00F48FB7->_
             inline - len(6) winlogon.exe - 0x00F48FE8->_
             inline - len(1) winlogon.exe - 0x00F49003->_
             inline - len(6) winlogon.exe - 0x00F4904F->_
             inline - len(1) winlogon.exe - 0x00F4906C->_
             inline - len(1) winlogon.exe - 0x00F490A2->_
             inline - len(1) winlogon.exe - 0x00F490BB->_
             inline - len(1) winlogon.exe - 0x00F490D2->_
             inline - len(1) winlogon.exe - 0x00F490EA->_
             inline - len(1) winlogon.exe - 0x00F49175->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F49183->_
             inline - len(1) winlogon.exe - 0x00F491A0->_
             inline - len(1) winlogon.exe - 0x00F491B6->_
             inline - len(1) winlogon.exe - 0x00F491F2->_
             inline - len(1) winlogon.exe - 0x00F4920D->_
             inline - len(1) winlogon.exe - 0x00F49213->_
             inline - len(1) winlogon.exe - 0x00F4922B->_
             inline - len(1) winlogon.exe - 0x00F49241->_
             inline - len(1) winlogon.exe - 0x00F49262->_
             inline - len(1) winlogon.exe - 0x00F4927C->_
             inline - len(1) winlogon.exe - 0x00F49291->_
             inline - len(1) winlogon.exe - 0x00F492D4->_
             inline - len(1) winlogon.exe - 0x00F49303->_
             inline - len(1) winlogon.exe - 0x00F49318->_
             inline - len(1) winlogon.exe - 0x00F493A2->_
             inline - len(1) winlogon.exe - 0x00F493B7->_
             inline - len(1) winlogon.exe - 0x00F49403->_
             inline - len(1) winlogon.exe - 0x00F4952C->_
             inline - len(1) winlogon.exe - 0x00F49572->_
             inline - len(1) winlogon.exe - 0x00F4965F->_
             inline - len(1) winlogon.exe - 0x00F49666->_
             inline - len(1) winlogon.exe - 0x00F4966C->_
             inline - len(1) winlogon.exe - 0x00F49673->_
             inline - len(6) winlogon.exe - 0x00F49684->_
             inline - len(1) winlogon.exe - 0x00F4969F->_
             inline - len(11) winlogon.exe - 0x00F496C7->_
             inline - len(1) winlogon.exe - 0x00F49713->_
             inline - len(1) winlogon.exe - 0x00F49784->_
             inline - len(6) winlogon.exe - 0x00F49790->_
             inline - len(1) winlogon.exe - 0x00F497A9->_
             inline - len(6) winlogon.exe - 0x00F497AF->_
             inline - len(1) winlogon.exe - 0x00F49809->_
             inline - len(1) winlogon.exe - 0x00F4980F->_
             inline - len(1) winlogon.exe - 0x00F4981C->_
             inline - len(6) winlogon.exe - 0x00F49823->_
             inline - len(1) winlogon.exe - 0x00F4983F->_
             inline - len(1) winlogon.exe - 0x00F4987C->_
             inline - len(1) winlogon.exe - 0x00F498E2->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4993B->_
             inline - len(1) winlogon.exe - 0x00F4994D->_
             inline - len(1) winlogon.exe - 0x00F49A13->_
             inline - len(1) winlogon.exe - 0x00F49A6A->_
             inline - len(1) winlogon.exe - 0x00F49A8F->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F49AF1->_
             inline - len(1) winlogon.exe - 0x00F49B0A->_
             inline - len(1) winlogon.exe - 0x00F49BA2->_
             inline - len(6) winlogon.exe - 0x00F49BE3->_
             inline - len(1) winlogon.exe - 0x00F49C08->_
             inline - len(6) winlogon.exe - 0x00F49C25->_
             inline - len(1) winlogon.exe - 0x00F49C40->_
             inline - len(6) winlogon.exe - 0x00F49C46->_
             inline - len(1) winlogon.exe - 0x00F49C6A->_
             inline - len(1) winlogon.exe - 0x00F49C80->_
             inline - len(6) winlogon.exe - 0x00F49C97->_
             inline - len(1) winlogon.exe - 0x00F49CB0->_
             inline - len(11) winlogon.exe - 0x00F49D44->_
             inline - len(1) winlogon.exe - 0x00F49D81->_
             inline - len(11) winlogon.exe - 0x00F49DCD->_
             inline - len(1) winlogon.exe - 0x00F49E0A->_
             inline - len(11) winlogon.exe - 0x00F49E56->_
             inline - len(1) winlogon.exe - 0x00F49E93->_
             inline - len(1) winlogon.exe - 0x00F49EC7->_
             inline - len(1) winlogon.exe - 0x00F49ECD->_
             inline - len(1) winlogon.exe - 0x00F49EE1->_
             inline - len(1) winlogon.exe - 0x00F49F05->_
             inline - len(1) winlogon.exe - 0x00F49F0E->_
             inline - len(1) winlogon.exe - 0x00F49F23->_
             inline - len(1) winlogon.exe - 0x00F49F42->_
             inline - len(1) winlogon.exe - 0x00F49F4F->_
             inline - len(1) winlogon.exe - 0x00F49F74->_
             inline - len(1) winlogon.exe - 0x00F49F84->_
             inline - len(1) winlogon.exe - 0x00F49FAF->_
             inline - len(1) winlogon.exe - 0x00F49FBF->_
             inline - len(1) winlogon.exe - 0x00F49FE6->_
             inline - len(1) winlogon.exe - 0x00F4A00D->_
             inline - len(1) winlogon.exe - 0x00F4A046->_
             inline - len(6) winlogon.exe - 0x00F4A188->0x00F24BC9[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4A1A3->0x00F49EBF[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4A1AD->_
             inline - len(1) winlogon.exe - 0x00F4A1D4->_
             inline - len(1) winlogon.exe - 0x00F4A229->_
             inline - len(1) winlogon.exe - 0x00F4A22F->_
             inline - len(1) winlogon.exe - 0x00F4A246->_
             inline - len(6) winlogon.exe - 0x00F4A25A->_
             inline - len(1) winlogon.exe - 0x00F4A279->_
             inline - len(1) winlogon.exe - 0x00F4A2E6->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4A335->_
             inline - len(1) winlogon.exe - 0x00F4A359->_
             inline - len(1) winlogon.exe - 0x00F4A406->_
             inline - len(6) winlogon.exe - 0x00F4A415->_
             inline - len(1) winlogon.exe - 0x00F4A42D->_
             inline - len(6) winlogon.exe - 0x00F4A444->_
             inline - len(1) winlogon.exe - 0x00F4A45D->_
             inline - len(1) winlogon.exe - 0x00F4A474->_
             inline - len(1) winlogon.exe - 0x00F4A4C2->_
             inline - len(1) winlogon.exe - 0x00F4A4CE->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4A534->_
             inline - len(1) winlogon.exe - 0x00F4A54C->_
             inline - len(6) winlogon.exe - 0x00F4A582->_
             inline - len(1) winlogon.exe - 0x00F4A59A->_
             inline - len(6) winlogon.exe - 0x00F4A5BB->_
             inline - len(1) winlogon.exe - 0x00F4A5D3->_
             inline - len(6) winlogon.exe - 0x00F4A5F9->_
             inline - len(1) winlogon.exe - 0x00F4A611->_
             inline - len(6) winlogon.exe - 0x00F4A62F->_
             inline - len(1) winlogon.exe - 0x00F4A647->_
             inline - len(1) winlogon.exe - 0x00F4A68B->_
             inline - len(6) winlogon.exe - 0x00F4A694->_
             inline - len(1) winlogon.exe - 0x00F4A6B9->_
             inline - len(1) winlogon.exe - 0x00F4A6BF->_
             inline - len(1) winlogon.exe - 0x00F4A6C9->_
             inline - len(1) winlogon.exe - 0x00F4A6E8->_
             inline - len(6) winlogon.exe - 0x00F4A6F1->_
             inline - len(1) winlogon.exe - 0x00F4A716->_
             inline - len(1) winlogon.exe - 0x00F4A71C->_
             inline - len(1) winlogon.exe - 0x00F4A737->_
             inline - len(6) winlogon.exe - 0x00F4A744->_
             inline - len(1) winlogon.exe - 0x00F4A769->_
             inline - len(1) winlogon.exe - 0x00F4A76F->_
             inline - len(6) winlogon.exe - 0x00F4A7A3->_
             inline - len(1) winlogon.exe - 0x00F4A7C8->_
             inline - len(1) winlogon.exe - 0x00F4A7CE->_
             inline - len(1) winlogon.exe - 0x00F4A7EA->_
             inline - len(6) winlogon.exe - 0x00F4A7F7->_
             inline - len(1) winlogon.exe - 0x00F4A81C->_
             inline - len(1) winlogon.exe - 0x00F4A822->_
             inline - len(6) winlogon.exe - 0x00F4A856->_
             inline - len(1) winlogon.exe - 0x00F4A87B->_
             inline - len(1) winlogon.exe - 0x00F4A881->_
             inline - len(1) winlogon.exe - 0x00F4A8D8->_
             inline - len(1) winlogon.exe - 0x00F4A8EF->_
             inline - len(1) winlogon.exe - 0x00F4A925->_
             inline - len(6) winlogon.exe - 0x00F4A92E->_
             inline - len(1) winlogon.exe - 0x00F4A953->_
             inline - len(1) winlogon.exe - 0x00F4A959->_
             inline - len(1) winlogon.exe - 0x00F4A973->_
             inline - len(6) winlogon.exe - 0x00F4A97C->_
             inline - len(1) winlogon.exe - 0x00F4A9A1->_
             inline - len(1) winlogon.exe - 0x00F4A9A7->_
             inline - len(1) winlogon.exe - 0x00F4A9C2->_
             inline - len(6) winlogon.exe - 0x00F4A9CE->_
             inline - len(1) winlogon.exe - 0x00F4A9F3->_
             inline - len(1) winlogon.exe - 0x00F4A9F9->_
             inline - len(1) winlogon.exe - 0x00F4AA2C->_
             inline - len(6) winlogon.exe - 0x00F4AA35->_
             inline - len(1) winlogon.exe - 0x00F4AA5A->_
             inline - len(1) winlogon.exe - 0x00F4AA60->_
             inline - len(6) winlogon.exe - 0x00F4AA84->_
             inline - len(1) winlogon.exe - 0x00F4AAA9->_
             inline - len(1) winlogon.exe - 0x00F4AAAF->_
             inline - len(6) winlogon.exe - 0x00F4AAE7->_
             inline - len(1) winlogon.exe - 0x00F4AB0C->_
             inline - len(1) winlogon.exe - 0x00F4AB12->_
             inline - len(1) winlogon.exe - 0x00F4AB69->_
             inline - len(6) winlogon.exe - 0x00F4AC9C->_
             inline - len(1) winlogon.exe - 0x00F4ACB7->_
             inline - len(1) winlogon.exe - 0x00F4ADCA->_
             inline - len(1) winlogon.exe - 0x00F4ADEB->_
             inline - len(6) winlogon.exe - 0x00F4ADF1->_
             inline - len(6) winlogon.exe - 0x00F4AE0C->_
             inline - len(1) winlogon.exe - 0x00F4AE3A->_
             inline - len(1) winlogon.exe - 0x00F4AE55->_
             inline - len(1) winlogon.exe - 0x00F4AE8B->_
             inline - len(1) winlogon.exe - 0x00F4AEBE->_
             inline - len(1) winlogon.exe - 0x00F4AEC8->_
             inline - len(1) winlogon.exe - 0x00F4AECE->_
             inline - len(1) winlogon.exe - 0x00F4AEF1->_
             inline - len(1) winlogon.exe - 0x00F4AF19->_
             inline - len(1) winlogon.exe - 0x00F4AF30->_
             inline - len(1) winlogon.exe - 0x00F4AF3A->_
             inline - len(1) winlogon.exe - 0x00F4AF40->_
             inline - len(1) winlogon.exe - 0x00F4AF57->_
             inline - len(1) winlogon.exe - 0x00F4AF76->_
             inline - len(1) winlogon.exe - 0x00F4AF80->_
             inline - len(1) winlogon.exe - 0x00F4AF86->_
             inline - len(1) winlogon.exe - 0x00F4AF9D->_
             inline - len(1) winlogon.exe - 0x00F4AFB6->_
             inline - len(6) winlogon.exe - 0x00F4B08A->_
             inline - len(1) winlogon.exe - 0x00F4B0A2->_
             inline - len(1) winlogon.exe - 0x00F4B0EF->_
             inline - len(11) winlogon.exe - 0x00F4B16A->_
             inline - len(1) winlogon.exe - 0x00F4B18B->_
             inline - len(6) winlogon.exe - 0x00F4B19F->_
             inline - len(1) winlogon.exe - 0x00F4B1C0->_
             inline - len(6) winlogon.exe - 0x00F4B1EF->_
             inline - len(1) winlogon.exe - 0x00F4B209->_
             inline - len(1) winlogon.exe - 0x00F4B21E->_
             inline - len(1) winlogon.exe - 0x00F4B239->_
             inline - len(1) winlogon.exe - 0x00F4B265->_
             inline - len(6) winlogon.exe - 0x00F4B2D8->_
             inline - len(1) winlogon.exe - 0x00F4B2F5->_
             inline - len(1) winlogon.exe - 0x00F4B391->_
             inline - len(11) winlogon.exe - 0x00F4B3AF->_
             inline - len(1) winlogon.exe - 0x00F4B3E9->_
             inline - len(1) winlogon.exe - 0x00F4B3F3->_
             inline - len(1) winlogon.exe - 0x00F4B419->_
             inline - len(1) winlogon.exe - 0x00F4B465->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4B4AA->_
             inline - len(1) winlogon.exe - 0x00F4B4D1->_
             inline - len(1) winlogon.exe - 0x00F4B4D7->_
             inline - len(1) winlogon.exe - 0x00F4B4E4->_
             inline - len(6) winlogon.exe - 0x00F4B4EC->_
             inline - len(1) winlogon.exe - 0x00F4B508->_
             inline - len(1) winlogon.exe - 0x00F4B55A->_
             inline - len(6) winlogon.exe - 0x00F4B578->_
             inline - len(1) winlogon.exe - 0x00F4B593->_
             inline - len(6) winlogon.exe - 0x00F4B5E8->_
             inline - len(1) winlogon.exe - 0x00F4B603->_
             inline - len(1) winlogon.exe - 0x00F4B656->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4B660->_
             inline - len(1) winlogon.exe - 0x00F4B67B->_
             inline - len(1) winlogon.exe - 0x00F4B6CA->_
             inline - len(6) winlogon.exe - 0x00F4B6D6->_
             inline - len(1) winlogon.exe - 0x00F4B6F1->_
             inline - len(6) winlogon.exe - 0x00F4B70D->_
             inline - len(1) winlogon.exe - 0x00F4B728->_
             inline - len(6) winlogon.exe - 0x00F4B750->_
             inline - len(1) winlogon.exe - 0x00F4B76B->_
             inline - len(6) winlogon.exe - 0x00F4B79B->_
             inline - len(1) winlogon.exe - 0x00F4B7B6->_
             inline - len(6) winlogon.exe - 0x00F4B7D4->_
             inline - len(1) winlogon.exe - 0x00F4B7EF->_
             inline - len(1) winlogon.exe - 0x00F4B80B->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4B815->_
             inline - len(1) winlogon.exe - 0x00F4B830->_
             inline - len(1) winlogon.exe - 0x00F4B882->_
             inline - len(6) winlogon.exe - 0x00F4B88E->_
             inline - len(1) winlogon.exe - 0x00F4B8A9->_
             inline - len(6) winlogon.exe - 0x00F4B8D7->_
             inline - len(1) winlogon.exe - 0x00F4B8F2->_
             inline - len(1) winlogon.exe - 0x00F4B93C->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4B946->_
             inline - len(1) winlogon.exe - 0x00F4B961->_
             inline - len(1) winlogon.exe - 0x00F4B9B2->_
             inline - len(6) winlogon.exe - 0x00F4B9BE->_
             inline - len(1) winlogon.exe - 0x00F4B9D9->_
             inline - len(6) winlogon.exe - 0x00F4B9F8->_
             inline - len(1) winlogon.exe - 0x00F4BA13->_
             inline - len(6) winlogon.exe - 0x00F4BA44->_
             inline - len(1) winlogon.exe - 0x00F4BA5F->_
             inline - len(1) winlogon.exe - 0x00F4BB12->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4BB34->_
             inline - len(1) winlogon.exe - 0x00F4BB40->_
             inline - len(1) winlogon.exe - 0x00F4BB4D->_
             inline - len(1) winlogon.exe - 0x00F4BB53->_
             inline - len(1) winlogon.exe - 0x00F4BB76->_
             inline - len(6) winlogon.exe - 0x00F4BB8D->_
             inline - len(1) winlogon.exe - 0x00F4BBB0->_
             inline - len(1) winlogon.exe - 0x00F4BBF5->_
             inline - len(1) winlogon.exe - 0x00F4BC02->_
             inline - len(1) winlogon.exe - 0x00F4BC27->_
             inline - len(1) winlogon.exe - 0x00F4BC50->_
             inline - len(1) winlogon.exe - 0x00F4BC5D->_
             inline - len(1) winlogon.exe - 0x00F4BC63->_
             inline - len(1) winlogon.exe - 0x00F4BC7C->_
             inline - len(1) winlogon.exe - 0x00F4BC91->_
             inline - len(1) winlogon.exe - 0x00F4BCB3->_
             inline - len(1) winlogon.exe - 0x00F4BD0A->_
             inline - len(6) winlogon.exe - 0x00F4BD1E->_
             inline - len(1) winlogon.exe - 0x00F4BD44->_
             inline - len(1) winlogon.exe - 0x00F4BD5C->_
             inline - len(1) winlogon.exe - 0x00F4BD69->_
             inline - len(1) winlogon.exe - 0x00F4BD70->_
             inline - len(1) winlogon.exe - 0x00F4BD8F->_
             inline - len(1) winlogon.exe - 0x00F4BDB1->_
             inline - len(1) winlogon.exe - 0x00F4BDCE->_
             inline - len(1) winlogon.exe - 0x00F4BDDD->_
             inline - len(1) winlogon.exe - 0x00F4BE07->_
             inline - len(1) winlogon.exe - 0x00F4BE1D->_
             inline - len(1) winlogon.exe - 0x00F4BE3B->_
             inline - len(6) winlogon.exe - 0x00F4BE4F->_
             inline - len(1) winlogon.exe - 0x00F4BE70->_
             inline - len(1) winlogon.exe - 0x00F4BE9C->_
             inline - len(6) winlogon.exe - 0x00F4BEBC->_
             inline - len(1) winlogon.exe - 0x00F4BEE4->_
             inline - len(1) winlogon.exe - 0x00F4BF02->_
             inline - len(1) winlogon.exe - 0x00F4BF0F->_
             inline - len(1) winlogon.exe - 0x00F4BF15->_
             inline - len(1) winlogon.exe - 0x00F4BF38->_
             inline - len(6) winlogon.exe - 0x00F4BF4C->_
             inline - len(1) winlogon.exe - 0x00F4BF76->_
             inline - len(6) winlogon.exe - 0x00F4BF7C->_
             inline - len(1) winlogon.exe - 0x00F4BFB1->_
             inline - len(1) winlogon.exe - 0x00F4BFC8->_
             inline - len(1) winlogon.exe - 0x00F4BFE8->_
             inline - len(1) winlogon.exe - 0x00F4BFEE->_
             inline - len(1) winlogon.exe - 0x00F4C013->_
             inline - len(1) winlogon.exe - 0x00F4C03D->0x00F21F9C[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4C080->_
             inline - len(1) winlogon.exe - 0x00F4C0A2->_
             inline - len(1) winlogon.exe - 0x00F4C0BA->_
             inline - len(1) winlogon.exe - 0x00F4C0EA->_
             inline - len(1) winlogon.exe - 0x00F4C0FC->_
             inline - len(1) winlogon.exe - 0x00F4C118->_
             inline - len(1) winlogon.exe - 0x00F4C13F->_
             inline - len(1) winlogon.exe - 0x00F4C15D->_
             inline - len(1) winlogon.exe - 0x00F4C178->_
             inline - len(1) winlogon.exe - 0x00F4C18B->_
             inline - len(1) winlogon.exe - 0x00F4C19C->_
             inline - len(1) winlogon.exe - 0x00F4C1B0->_
             inline - len(1) winlogon.exe - 0x00F4C1BB->_
             inline - len(1) winlogon.exe - 0x00F4C1C5->_
             inline - len(1) winlogon.exe - 0x00F4C1CB->_
             inline - len(1) winlogon.exe - 0x00F4C1E4->_
             inline - len(1) winlogon.exe - 0x00F4C1FE->_
             inline - len(1) winlogon.exe - 0x00F4C21C->_
             inline - len(1) winlogon.exe - 0x00F4C225->_
             inline - len(1) winlogon.exe - 0x00F4C240->_
             inline - len(1) winlogon.exe - 0x00F4C271->_
             inline - len(1) winlogon.exe - 0x00F4C277->_
             inline - len(1) winlogon.exe - 0x00F4C290->_
             inline - len(1) winlogon.exe - 0x00F4C2BC->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4C300->_
             inline - len(1) winlogon.exe - 0x00F4C350->_
             inline - len(1) winlogon.exe - 0x00F4C361->_
             inline - len(1) winlogon.exe - 0x00F4C381->_
             inline - len(1) winlogon.exe - 0x00F4C39C->_
             inline - len(1) winlogon.exe - 0x00F4C3C9->_
             inline - len(1) winlogon.exe - 0x00F4C3E2->_
             inline - len(1) winlogon.exe - 0x00F4C3EE->_
             inline - len(1) winlogon.exe - 0x00F4C3F8->_
             inline - len(6) winlogon.exe - 0x00F4C403->_
             inline - len(1) winlogon.exe - 0x00F4C430->_
             inline - len(1) winlogon.exe - 0x00F4C453->_
             inline - len(1) winlogon.exe - 0x00F4C45D->_
             inline - len(6) winlogon.exe - 0x00F4C468->_
             inline - len(1) winlogon.exe - 0x00F4C489->_
             inline - len(1) winlogon.exe - 0x00F4C496->_
             inline - len(1) winlogon.exe - 0x00F4C50F->_
             inline - len(1) winlogon.exe - 0x00F4C524->_
             inline - len(1) winlogon.exe - 0x00F4C53A->_
             inline - len(1) winlogon.exe - 0x00F4C55E->_
             inline - len(1) winlogon.exe - 0x00F4C567->_
             inline - len(11) winlogon.exe - 0x00F4C56F->_
             inline - len(1) winlogon.exe - 0x00F4C5A4->_
             inline - len(1) winlogon.exe - 0x00F4C612->_
             inline - len(1) winlogon.exe - 0x00F4C61E->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4C6C4->_
             inline - len(1) winlogon.exe - 0x00F4C6D1->0x00F4C87B[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4C759->_
             inline - len(1) winlogon.exe - 0x00F4C783->_
             inline - len(1) winlogon.exe - 0x00F4C7D6->0x00F55063[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4C7E5->_
             inline - len(6) winlogon.exe - 0x00F4C808->_
             inline - len(1) winlogon.exe - 0x00F4C824->_
             inline - len(1) winlogon.exe - 0x00F4C8B1->_
             inline - len(1) winlogon.exe - 0x00F4C94A->_
             inline - len(6) winlogon.exe - 0x00F4C97A->_
             inline - len(1) winlogon.exe - 0x00F4C998->_
             inline - len(6) winlogon.exe - 0x00F4C9C5->_
             inline - len(1) winlogon.exe - 0x00F4C9E0->_
             inline - len(1) winlogon.exe - 0x00F4CA08->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4CA12->_
             inline - len(1) winlogon.exe - 0x00F4CA2F->_
             inline - len(1) winlogon.exe - 0x00F4CA7E->_
             inline - len(1) winlogon.exe - 0x00F4CAA3->_
             inline - len(6) winlogon.exe - 0x00F4CB4C->_
             inline - len(1) winlogon.exe - 0x00F4CB6A->_
             inline - len(1) winlogon.exe - 0x00F4CBE2->_
             inline - len(1) winlogon.exe - 0x00F4CBEE->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4CC0C->_
             inline - len(1) winlogon.exe - 0x00F4CC27->_
             inline - len(1) winlogon.exe - 0x00F4CD72->_
             inline - len(6) winlogon.exe - 0x00F4CD81->_
             inline - len(1) winlogon.exe - 0x00F4CD9C->_
             inline - len(1) winlogon.exe - 0x00F4CDC4->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4CDCE->_
             inline - len(1) winlogon.exe - 0x00F4CDE9->_
             inline - len(6) winlogon.exe - 0x00F4CEB0->_
             inline - len(1) winlogon.exe - 0x00F4CECC->_
             inline - len(1) winlogon.exe - 0x00F4CF2A->_
             inline - len(6) winlogon.exe - 0x00F4CF39->_
             inline - len(1) winlogon.exe - 0x00F4CF54->_
             inline - len(1) winlogon.exe - 0x00F4CF7C->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4CF86->_
             inline - len(1) winlogon.exe - 0x00F4CFA1->_
             inline - len(1) winlogon.exe - 0x00F4CFB6->_
             inline - len(1) winlogon.exe - 0x00F4CFF2->_
             inline - len(1) winlogon.exe - 0x00F4CFF8->_
             inline - len(6) winlogon.exe - 0x00F4D07B->_
             inline - len(1) winlogon.exe - 0x00F4D102->_
             inline - len(1) winlogon.exe - 0x00F4D10E->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4D12C->_
             inline - len(1) winlogon.exe - 0x00F4D147->_
             inline - len(1) winlogon.exe - 0x00F4D272->_
             inline - len(6) winlogon.exe - 0x00F4D281->_
             inline - len(1) winlogon.exe - 0x00F4D29C->_
             inline - len(6) winlogon.exe - 0x00F4D2CE->_
             inline - len(1) winlogon.exe - 0x00F4D2E9->_
             inline - len(1) winlogon.exe - 0x00F4D334->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4D33E->_
             inline - len(1) winlogon.exe - 0x00F4D359->_
             inline - len(6) winlogon.exe - 0x00F4D426->_
             inline - len(1) winlogon.exe - 0x00F4D442->_
             inline - len(1) winlogon.exe - 0x00F4D4BA->_
             inline - len(1) winlogon.exe - 0x00F4D4C6->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4D4EA->_
             inline - len(1) winlogon.exe - 0x00F4D4F5->_
             inline - len(1) winlogon.exe - 0x00F4D4FF->_
             inline - len(6) winlogon.exe - 0x00F4D507->_
             inline - len(1) winlogon.exe - 0x00F4D531->_
             inline - len(1) winlogon.exe - 0x00F4D555->_
             inline - len(1) winlogon.exe - 0x00F4D560->_
             inline - len(1) winlogon.exe - 0x00F4D56B->_
             inline - len(6) winlogon.exe - 0x00F4D573->_
             inline - len(1) winlogon.exe - 0x00F4D59D->_
             inline - len(1) winlogon.exe - 0x00F4D5B2->_
             inline - len(1) winlogon.exe - 0x00F4D5C2->_
             inline - len(6) winlogon.exe - 0x00F4D5CA->_
             inline - len(1) winlogon.exe - 0x00F4D5F4->0x00F4D535[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4D630->_
             inline - len(6) winlogon.exe - 0x00F4D638->_
             inline - len(1) winlogon.exe - 0x00F4D656->0x00F4D535[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4D668->_
             inline - len(6) winlogon.exe - 0x00F4D67F->_
             inline - len(1) winlogon.exe - 0x00F4D69D->0x00F4D535[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4D6EE->_
             inline - len(1) winlogon.exe - 0x00F4D74A->_
             inline - len(1) winlogon.exe - 0x00F4D759->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4D78C->_
             inline - len(1) winlogon.exe - 0x00F4D7A9->_
             inline - len(1) winlogon.exe - 0x00F4D7E7->_
             inline - len(1) winlogon.exe - 0x00F4D7FF->_
             inline - len(1) winlogon.exe - 0x00F4D85A->_
             inline - len(11) winlogon.exe - 0x00F4D87B->_
             inline - len(1) winlogon.exe - 0x00F4D8AB->_
             inline - len(1) winlogon.exe - 0x00F4D8DA->_
             inline - len(1) winlogon.exe - 0x00F4D8E4->_
             inline - len(11) winlogon.exe - 0x00F4D933->_
             inline - len(1) winlogon.exe - 0x00F4D963->_
             inline - len(1) winlogon.exe - 0x00F4D992->_
             inline - len(1) winlogon.exe - 0x00F4D99C->_
             inline - len(1) winlogon.exe - 0x00F4D9D6->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4DA3F->_
             inline - len(1) winlogon.exe - 0x00F4DA45->_
             inline - len(1) winlogon.exe - 0x00F4DA69->_
             inline - len(1) winlogon.exe - 0x00F4DA6F->_
             inline - len(1) winlogon.exe - 0x00F4DA86->_
             inline - len(1) winlogon.exe - 0x00F4DAAD->_
             inline - len(6) winlogon.exe - 0x00F4DAB9->_
             inline - len(1) winlogon.exe - 0x00F4DAD5->_
             inline - len(1) winlogon.exe - 0x00F4DADE->_
             inline - len(1) winlogon.exe - 0x00F4DAE5->_
             inline - len(1) winlogon.exe - 0x00F4DB4A->_
             inline - len(1) winlogon.exe - 0x00F4DB56->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4DB9C->_
             inline - len(1) winlogon.exe - 0x00F4DBC4->_
             inline - len(1) winlogon.exe - 0x00F4DBEE->_
             inline - len(6) winlogon.exe - 0x00F4DC03->_
             inline - len(1) winlogon.exe - 0x00F4DC2D->_
             inline - len(1) winlogon.exe - 0x00F4DC44->_
             inline - len(6) winlogon.exe - 0x00F4DC99->_
             inline - len(1) winlogon.exe - 0x00F4DCC3->0x00F4DBC8[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4DCE9->_
             inline - len(1) winlogon.exe - 0x00F4DCF3->_
             inline - len(1) winlogon.exe - 0x00F4DCFF->_
             inline - len(6) winlogon.exe - 0x00F4DD09->_
             inline - len(1) winlogon.exe - 0x00F4DD33->0x00F4DBC8[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4DD53->_
             inline - len(1) winlogon.exe - 0x00F4DD71->0x00F4DBC8[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4DD7D->_
             inline - len(1) winlogon.exe - 0x00F4DDA0->_
             inline - len(1) winlogon.exe - 0x00F4DDD9->_
             inline - len(1) winlogon.exe - 0x00F4DDE7->_
             inline - len(1) winlogon.exe - 0x00F4DE32->_
             inline - len(11) winlogon.exe - 0x00F4DE59->_
             inline - len(1) winlogon.exe - 0x00F4DE8C->_
             inline - len(1) winlogon.exe - 0x00F4DE96->_
             inline - len(6) winlogon.exe - 0x00F4DECA->_
             inline - len(1) winlogon.exe - 0x00F4DEE5->_
             inline - len(6) winlogon.exe - 0x00F4DF07->_
             inline - len(1) winlogon.exe - 0x00F4DF22->_
             inline - len(1) winlogon.exe - 0x00F4DF4D->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(11) winlogon.exe - 0x00F4DF64->_
             inline - len(1) winlogon.exe - 0x00F4DFA9->_
             inline - len(1) winlogon.exe - 0x00F4DFED->_
             inline - len(1) winlogon.exe - 0x00F4E02C->_
             inline - len(1) winlogon.exe - 0x00F4E058->_
             inline - len(1) winlogon.exe - 0x00F4E08A->_
             inline - len(1) winlogon.exe - 0x00F4E0AE->_
             inline - len(1) winlogon.exe - 0x00F4E0E0->_
             inline - len(1) winlogon.exe - 0x00F4E137->_
             inline - len(6) winlogon.exe - 0x00F4E17E->_
             inline - len(1) winlogon.exe - 0x00F4E1BA->_
             inline - len(1) winlogon.exe - 0x00F4E1C6->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(11) winlogon.exe - 0x00F4E1DD->_
             inline - len(1) winlogon.exe - 0x00F4E222->_
             inline - len(1) winlogon.exe - 0x00F4E266->_
             inline - len(1) winlogon.exe - 0x00F4E2A5->_
             inline - len(1) winlogon.exe - 0x00F4E2D1->_
             inline - len(1) winlogon.exe - 0x00F4E303->_
             inline - len(1) winlogon.exe - 0x00F4E342->_
             inline - len(6) winlogon.exe - 0x00F4E37E->_
             inline - len(1) winlogon.exe - 0x00F4E3BA->_
             inline - len(6) winlogon.exe - 0x00F4E3C6->_
             inline - len(1) winlogon.exe - 0x00F4E3E1->_
             inline - len(6) winlogon.exe - 0x00F4E404->_
             inline - len(1) winlogon.exe - 0x00F4E422->_
             inline - len(1) winlogon.exe - 0x00F4E448->_
             inline - len(1) winlogon.exe - 0x00F4E452->_
             inline - len(1) winlogon.exe - 0x00F4E469->_
             inline - len(1) winlogon.exe - 0x00F4E47B->_
             inline - len(1) winlogon.exe - 0x00F4E483->_
             inline - len(1) winlogon.exe - 0x00F4E4A8->_
             inline - len(1) winlogon.exe - 0x00F4E4AF->_
             inline - len(6) winlogon.exe - 0x00F4E4CA->_
             inline - len(1) winlogon.exe - 0x00F4E4E3->_
             inline - len(1) winlogon.exe - 0x00F4E4F7->_
             inline - len(11) winlogon.exe - 0x00F4E51A->_
             inline - len(1) winlogon.exe - 0x00F4E54E->_
             inline - len(1) winlogon.exe - 0x00F4E554->_
             inline - len(6) winlogon.exe - 0x00F4E561->_
             inline - len(11) winlogon.exe - 0x00F4E5B8->_
             inline - len(1) winlogon.exe - 0x00F4E5E8->_
             inline - len(1) winlogon.exe - 0x00F4E617->_
             inline - len(1) winlogon.exe - 0x00F4E621->_
             inline - len(1) winlogon.exe - 0x00F4E68F->_
             inline - len(1) winlogon.exe - 0x00F4E696->_
             inline - len(1) winlogon.exe - 0x00F4E6BC->_
             inline - len(1) winlogon.exe - 0x00F4E6EB->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4E719->_
             inline - len(1) winlogon.exe - 0x00F4E72A->_
             inline - len(6) winlogon.exe - 0x00F4E762->_
             inline - len(1) winlogon.exe - 0x00F4E77E->_
             inline - len(1) winlogon.exe - 0x00F4E799->_
             inline - len(6) winlogon.exe - 0x00F4E7A5->_
             inline - len(1) winlogon.exe - 0x00F4E7C3->_
             inline - len(1) winlogon.exe - 0x00F4E812->_
             inline - len(1) winlogon.exe - 0x00F4E81E->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4E844->_
             inline - len(1) winlogon.exe - 0x00F4E84E->_
             inline - len(6) winlogon.exe - 0x00F4E85C->_
             inline - len(1) winlogon.exe - 0x00F4E886->_
             inline - len(6) winlogon.exe - 0x00F4E8CF->_
             inline - len(1) winlogon.exe - 0x00F4E8ED->_
             inline - len(1) winlogon.exe - 0x00F4E905->_
             inline - len(6) winlogon.exe - 0x00F4E911->_
             inline - len(1) winlogon.exe - 0x00F4E92F->_
             inline - len(1) winlogon.exe - 0x00F4E982->_
             inline - len(1) winlogon.exe - 0x00F4E98E->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4E9BD->_
             inline - len(1) winlogon.exe - 0x00F4E9C7->_
             inline - len(6) winlogon.exe - 0x00F4E9D5->_
             inline - len(1) winlogon.exe - 0x00F4E9FF->_
             inline - len(6) winlogon.exe - 0x00F4EA48->_
             inline - len(1) winlogon.exe - 0x00F4EA72->_
             inline - len(6) winlogon.exe - 0x00F4EA8F->_
             inline - len(1) winlogon.exe - 0x00F4EAB9->_
             inline - len(6) winlogon.exe - 0x00F4EAEF->_
             inline - len(1) winlogon.exe - 0x00F4EB0D->_
             inline - len(1) winlogon.exe - 0x00F4EB92->_
             inline - len(1) winlogon.exe - 0x00F4EBA5->_
             inline - len(1) winlogon.exe - 0x00F4EBAE->_
             inline - len(1) winlogon.exe - 0x00F4EBC8->_
             inline - len(1) winlogon.exe - 0x00F4EBD8->_
             inline - len(1) winlogon.exe - 0x00F4EBDE->_
             inline - len(1) winlogon.exe - 0x00F4EBF5->_
             inline - len(1) winlogon.exe - 0x00F4EC15->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4ECA8->_
             inline - len(1) winlogon.exe - 0x00F4ECCF->_
             inline - len(1) winlogon.exe - 0x00F4ECE1->_
             inline - len(1) winlogon.exe - 0x00F4ED00->_
             inline - len(6) winlogon.exe - 0x00F4ED0B->_
             inline - len(1) winlogon.exe - 0x00F4ED38->_
             inline - len(1) winlogon.exe - 0x00F4ED77->_
             inline - len(1) winlogon.exe - 0x00F4EDA1->_
             inline - len(1) winlogon.exe - 0x00F4EDAF->_
             inline - len(6) winlogon.exe - 0x00F4EDBA->_
             inline - len(1) winlogon.exe - 0x00F4EDE7->_
             inline - len(6) winlogon.exe - 0x00F4EE23->_
             inline - len(1) winlogon.exe - 0x00F4EE50->_
             inline - len(1) winlogon.exe - 0x00F4EE64->_
             inline - len(1) winlogon.exe - 0x00F4EE6E->_
             inline - len(6) winlogon.exe - 0x00F4EE79->_
             inline - len(1) winlogon.exe - 0x00F4EE9A->_
             inline - len(1) winlogon.exe - 0x00F4EEB3->_
             inline - len(1) winlogon.exe - 0x00F4EEBE->_
             inline - len(6) winlogon.exe - 0x00F4EEC9->_
             inline - len(1) winlogon.exe - 0x00F4EEF2->_
             inline - len(6) winlogon.exe - 0x00F4EF18->_
             inline - len(1) winlogon.exe - 0x00F4EF36->_
             inline - len(1) winlogon.exe - 0x00F4EF3D->_
             inline - len(1) winlogon.exe - 0x00F4EF49->_
             inline - len(1) winlogon.exe - 0x00F4EF5B->_
             inline - len(1) winlogon.exe - 0x00F4EF72->_
             inline - len(1) winlogon.exe - 0x00F4EF8E->_
             inline - len(1) winlogon.exe - 0x00F4EFAE->_
             inline - len(6) winlogon.exe - 0x00F4EFC8->_
             inline - len(6) winlogon.exe - 0x00F4EFE2->_
             inline - len(1) winlogon.exe - 0x00F4F01A->_
             inline - len(1) winlogon.exe - 0x00F4F026->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4F062->_
             inline - len(1) winlogon.exe - 0x00F4F08C->_
             inline - len(6) winlogon.exe - 0x00F4F0BF->_
             inline - len(1) winlogon.exe - 0x00F4F0DD->_
             inline - len(1) winlogon.exe - 0x00F4F0EB->_
             inline - len(6) winlogon.exe - 0x00F4F0FD->_
             inline - len(1) winlogon.exe - 0x00F4F11B->_
             inline - len(1) winlogon.exe - 0x00F4F12A->_
             inline - len(1) winlogon.exe - 0x00F4F13B->_
             inline - len(1) winlogon.exe - 0x00F4F154->_
             inline - len(1) winlogon.exe - 0x00F4F173->_
             inline - len(6) winlogon.exe - 0x00F4F186->_
             inline - len(1) winlogon.exe - 0x00F4F1AA->_
             inline - len(1) winlogon.exe - 0x00F4F1B6->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4F1F2->_
             inline - len(1) winlogon.exe - 0x00F4F21C->_
             inline - len(6) winlogon.exe - 0x00F4F24F->_
             inline - len(1) winlogon.exe - 0x00F4F26D->_
             inline - len(1) winlogon.exe - 0x00F4F27B->_
             inline - len(6) winlogon.exe - 0x00F4F28D->_
             inline - len(1) winlogon.exe - 0x00F4F2AB->_
             inline - len(1) winlogon.exe - 0x00F4F2BA->_
             inline - len(1) winlogon.exe - 0x00F4F2CB->_
             inline - len(1) winlogon.exe - 0x00F4F2E4->_
             inline - len(1) winlogon.exe - 0x00F4F303->_
             inline - len(6) winlogon.exe - 0x00F4F316->_
             inline - len(1) winlogon.exe - 0x00F4F33A->_
             inline - len(1) winlogon.exe - 0x00F4F35C->_
             inline - len(1) winlogon.exe - 0x00F4F36D->_
             inline - len(1) winlogon.exe - 0x00F4F380->_
             inline - len(1) winlogon.exe - 0x00F4F393->_
             inline - len(6) winlogon.exe - 0x00F4F3A4->_
             inline - len(6) winlogon.exe - 0x00F4F3D1->_
             inline - len(1) winlogon.exe - 0x00F4F485->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4F4F8->_
             inline - len(1) winlogon.exe - 0x00F4F514->_
             inline - len(6) winlogon.exe - 0x00F4F53F->_
             inline - len(1) winlogon.exe - 0x00F4F55B->_
             inline - len(6) winlogon.exe - 0x00F4F573->_
             inline - len(1) winlogon.exe - 0x00F4F58F->_
             inline - len(1) winlogon.exe - 0x00F4F5BB->_
             inline - len(1) winlogon.exe - 0x00F4F5D6->_
             inline - len(1) winlogon.exe - 0x00F4F5DF->_
             inline - len(1) winlogon.exe - 0x00F4F5F6->_
             inline - len(1) winlogon.exe - 0x00F4F5FF->_
             inline - len(1) winlogon.exe - 0x00F4F608->_
             inline - len(1) winlogon.exe - 0x00F4F611->_
             inline - len(6) winlogon.exe - 0x00F4F61D->_
             inline - len(1) winlogon.exe - 0x00F4F637->_
             inline - len(6) winlogon.exe - 0x00F4F64E->_
             inline - len(1) winlogon.exe - 0x00F4F669->_
             inline - len(1) winlogon.exe - 0x00F4F6AC->_
             inline - len(1) winlogon.exe - 0x00F4F6C7->_
             inline - len(1) winlogon.exe - 0x00F4F6D5->_
             inline - len(1) winlogon.exe - 0x00F4F6E3->_
             inline - len(6) winlogon.exe - 0x00F4F6ED->_
             inline - len(1) winlogon.exe - 0x00F4F715->_
             inline - len(1) winlogon.exe - 0x00F4F741->_
             inline - len(6) winlogon.exe - 0x00F4F757->_
             inline - len(1) winlogon.exe - 0x00F4F773->_
             inline - len(6) winlogon.exe - 0x00F4F79A->_
             inline - len(1) winlogon.exe - 0x00F4F7B6->_
             inline - len(1) winlogon.exe - 0x00F4F7EB->_
             inline - len(1) winlogon.exe - 0x00F4F7F9->_
             inline - len(1) winlogon.exe - 0x00F4F82A->_
             inline - len(1) winlogon.exe - 0x00F4F839->0x00F227B0[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F4F885->_
             inline - len(1) winlogon.exe - 0x00F4F89D->_
             inline - len(1) winlogon.exe - 0x00F4F8BB->_
             inline - len(1) winlogon.exe - 0x00F4F8EB->_
             inline - len(1) winlogon.exe - 0x00F4F906->_
             inline - len(1) winlogon.exe - 0x00F4F90F->_
             inline - len(1) winlogon.exe - 0x00F4F926->_
             inline - len(1) winlogon.exe - 0x00F4F92F->_
             inline - len(1) winlogon.exe - 0x00F4F938->_
             inline - len(1) winlogon.exe - 0x00F4F941->_
             inline - len(1) winlogon.exe - 0x00F4F952->_
             inline - len(1) winlogon.exe - 0x00F4F96D->_
             inline - len(1) winlogon.exe - 0x00F4F986->_
             inline - len(1) winlogon.exe - 0x00F4F99D->_
             inline - len(1) winlogon.exe - 0x00F4F9CB->_
             inline - len(1) winlogon.exe - 0x00F4F9E2->_
             inline - len(6) winlogon.exe - 0x00F4FA18->_
             inline - len(1) winlogon.exe - 0x00F4FA24->_
             inline - len(1) winlogon.exe - 0x00F4FA4A->_
             inline - len(1) winlogon.exe - 0x00F4FA54->_
             inline - len(1) winlogon.exe - 0x00F4FA5C->_
             inline - len(1) winlogon.exe - 0x00F4FAA7->_
             inline - len(1) winlogon.exe - 0x00F4FAAF->_
             inline - len(1) winlogon.exe - 0x00F4FADC->_
             inline - len(1) winlogon.exe - 0x00F4FAE6->_
             inline - len(1) winlogon.exe - 0x00F4FAEE->_
             inline - len(1) winlogon.exe - 0x00F4FB1D->_
             inline - len(1) winlogon.exe - 0x00F4FB28->_
             inline - len(1) winlogon.exe - 0x00F4FB30->_
             inline - len(1) winlogon.exe - 0x00F4FB50->_
             inline - len(1) winlogon.exe - 0x00F4FB61->_
             inline - len(1) winlogon.exe - 0x00F4FB68->_
             inline - len(1) winlogon.exe - 0x00F4FBB8->_
             inline - len(1) winlogon.exe - 0x00F4FBC7->_
             inline - len(1) winlogon.exe - 0x00F4FBEA->_
             inline - len(1) winlogon.exe - 0x00F4FC1D->_
             inline - len(1) winlogon.exe - 0x00F4FC6F->_
             inline - len(53) winlogon.exe - 0x00F4FC8F->_
             inline - len(1) winlogon.exe - 0x00F4FCDB->_
             inline - len(1) winlogon.exe - 0x00F4FCE1->_
             inline - len(1) winlogon.exe - 0x00F4FCF8->_
             inline - len(1) winlogon.exe - 0x00F4FD12->0x00F21590[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F4FD1D->_
             inline - len(1) winlogon.exe - 0x00F4FD2C->_
             inline - len(1) winlogon.exe - 0x00F4FD38->_
             inline - len(1) winlogon.exe - 0x00F4FD3E->_
             inline - len(1) winlogon.exe - 0x00F4FD49->_
             inline - len(1) winlogon.exe - 0x00F4FD61->_
             inline - len(6) winlogon.exe - 0x00F4FD6E->_
             inline - len(1) winlogon.exe - 0x00F4FD8D->_
             inline - len(1) winlogon.exe - 0x00F4FD95->_
             inline - len(1) winlogon.exe - 0x00F4FDA7->_
             inline - len(1) winlogon.exe - 0x00F4FDC3->_
             inline - len(1) winlogon.exe - 0x00F4FDD5->_
             inline - len(1) winlogon.exe - 0x00F4FDDB->_
             inline - len(11) winlogon.exe - 0x00F4FDFB->_
             inline - len(1) winlogon.exe - 0x00F4FE0B->_
             inline - len(1) winlogon.exe - 0x00F4FE2D->_
             inline - len(1) winlogon.exe - 0x00F4FE43->_
             inline - len(1) winlogon.exe - 0x00F4FE49->_
             inline - len(1) winlogon.exe - 0x00F4FE4F->_
             inline - len(1) winlogon.exe - 0x00F4FE59->_
             inline - len(1) winlogon.exe - 0x00F4FE63->_
             inline - len(1) winlogon.exe - 0x00F4FE6B->_
             inline - len(1) winlogon.exe - 0x00F4FE87->_
             inline - len(1) winlogon.exe - 0x00F4FE99->_
             inline - len(1) winlogon.exe - 0x00F4FEA8->_
             inline - len(1) winlogon.exe - 0x00F4FEB3->_
             inline - len(1) winlogon.exe - 0x00F4FEBB->_
             inline - len(1) winlogon.exe - 0x00F4FEDA->_
             inline - len(1) winlogon.exe - 0x00F4FEE0->_
             inline - len(1) winlogon.exe - 0x00F4FF02->_
             inline - len(1) winlogon.exe - 0x00F4FF4A->_
             inline - len(1) winlogon.exe - 0x00F4FF51->_
             inline - len(1) winlogon.exe - 0x00F4FFA8->_
             inline - len(1) winlogon.exe - 0x00F4FFAE->_
             inline - len(1) winlogon.exe - 0x00F4FFC9->_
             inline - len(1) winlogon.exe - 0x00F50003->_
             inline - len(1) winlogon.exe - 0x00F50009->_
             inline - len(1) winlogon.exe - 0x00F50021->_
             inline - len(1) winlogon.exe - 0x00F5006C->_
             inline - len(1) winlogon.exe - 0x00F50072->_
             inline - len(1) winlogon.exe - 0x00F5008D->_
             inline - len(1) winlogon.exe - 0x00F500C7->_
             inline - len(1) winlogon.exe - 0x00F500CD->_
             inline - len(1) winlogon.exe - 0x00F500E5->_
             inline - len(6) winlogon.exe - 0x00F50120->_
             inline - len(1) winlogon.exe - 0x00F50151->_
             inline - len(1) winlogon.exe - 0x00F50199->_
             inline - len(1) winlogon.exe - 0x00F501B2->_
             inline - len(1) winlogon.exe - 0x00F501CB->_
             inline - len(1) winlogon.exe - 0x00F501D1->_
             inline - len(6) winlogon.exe - 0x00F50204->_
             inline - len(1) winlogon.exe - 0x00F5021F->_
             inline - len(6) winlogon.exe - 0x00F50263->_
             inline - len(1) winlogon.exe - 0x00F5027E->_
             inline - len(6) winlogon.exe - 0x00F502A0->_
             inline - len(1) winlogon.exe - 0x00F502BB->_
             inline - len(1) winlogon.exe - 0x00F502DD->_
             inline - len(1) winlogon.exe - 0x00F5033F->_
             inline - len(1) winlogon.exe - 0x00F5034A->_
             inline - len(1) winlogon.exe - 0x00F50356->_
             inline - len(1) winlogon.exe - 0x00F5035C->_
             inline - len(1) winlogon.exe - 0x00F5037F->_
             inline - len(1) winlogon.exe - 0x00F503AC->_
             inline - len(1) winlogon.exe - 0x00F503BE->_
             inline - len(1) winlogon.exe - 0x00F503F5->_
             inline - len(1) winlogon.exe - 0x00F50401->_
             inline - len(1) winlogon.exe - 0x00F50435->_
             inline - len(1) winlogon.exe - 0x00F5046F->_
             inline - len(1) winlogon.exe - 0x00F504A9->_
             inline - len(1) winlogon.exe - 0x00F504E3->_
             inline - len(1) winlogon.exe - 0x00F50532->_
             inline - len(1) winlogon.exe - 0x00F5053A->_
             inline - len(1) winlogon.exe - 0x00F5054D->_
             inline - len(1) winlogon.exe - 0x00F5057F->_
             inline - len(1) winlogon.exe - 0x00F505B9->_
             inline - len(1) winlogon.exe - 0x00F505F3->_
             inline - len(1) winlogon.exe - 0x00F5062D->_
             inline - len(1) winlogon.exe - 0x00F50667->_
             inline - len(1) winlogon.exe - 0x00F506B6->_
             inline - len(1) winlogon.exe - 0x00F506C9->_
             inline - len(1) winlogon.exe - 0x00F50707->_
             inline - len(1) winlogon.exe - 0x00F50741->_
             inline - len(6) winlogon.exe - 0x00F50765->_
             inline - len(1) winlogon.exe - 0x00F50782->_
             inline - len(1) winlogon.exe - 0x00F5079E->_
             inline - len(1) winlogon.exe - 0x00F507C0->_
             inline - len(1) winlogon.exe - 0x00F507C7->_
             inline - len(1) winlogon.exe - 0x00F507E1->_
             inline - len(1) winlogon.exe - 0x00F507FF->_
             inline - len(6) winlogon.exe - 0x00F50812->_
             inline - len(1) winlogon.exe - 0x00F5082D->_
             inline - len(6) winlogon.exe - 0x00F5083B->_
             inline - len(1) winlogon.exe - 0x00F50856->_
             inline - len(1) winlogon.exe - 0x00F508B5->_
             inline - len(6) winlogon.exe - 0x00F50900->_
             inline - len(1) winlogon.exe - 0x00F5091B->_
             inline - len(1) winlogon.exe - 0x00F5092D->_
             inline - len(6) winlogon.exe - 0x00F50946->_
             inline - len(1) winlogon.exe - 0x00F50967->_
             inline - len(1) winlogon.exe - 0x00F50B02->_
             inline - len(1) winlogon.exe - 0x00F50B11->_
             inline - len(11) winlogon.exe - 0x00F50B78->_
             inline - len(1) winlogon.exe - 0x00F50BDD->_
             inline - len(1) winlogon.exe - 0x00F50C50->_
             inline - len(1) winlogon.exe - 0x00F50C85->_
             inline - len(1) winlogon.exe - 0x00F50CAB->_
             inline - len(1) winlogon.exe - 0x00F50CB9->_
             inline - len(1) winlogon.exe - 0x00F50DAA->_
             inline - len(1) winlogon.exe - 0x00F50E04->_
             inline - len(1) winlogon.exe - 0x00F50E3C->_
             inline - len(1) winlogon.exe - 0x00F50E61->_
             inline - len(1) winlogon.exe - 0x00F50EBD->_
             inline - len(1) winlogon.exe - 0x00F50EF0->_
             inline - len(1) winlogon.exe - 0x00F50F09->_
             inline - len(1) winlogon.exe - 0x00F50F4F->_
             inline - len(1) winlogon.exe - 0x00F50F67->_
             inline - len(1) winlogon.exe - 0x00F50FA0->_
             inline - len(1) winlogon.exe - 0x00F50FB9->_
             inline - len(1) winlogon.exe - 0x00F510B2->_
             inline - len(1) winlogon.exe - 0x00F510C1->_
             inline - len(11) winlogon.exe - 0x00F51106->_
             inline - len(1) winlogon.exe - 0x00F5115D->_
             inline - len(1) winlogon.exe - 0x00F5119A->_
             inline - len(1) winlogon.exe - 0x00F511C6->_
             inline - len(1) winlogon.exe - 0x00F51265->_
             inline - len(1) winlogon.exe - 0x00F512C3->_
             inline - len(1) winlogon.exe - 0x00F51303->_
             inline - len(1) winlogon.exe - 0x00F5133E->_
             inline - len(1) winlogon.exe - 0x00F513DA->_
             inline - len(1) winlogon.exe - 0x00F513E9->_
             inline - len(11) winlogon.exe - 0x00F51428->_
             inline - len(1) winlogon.exe - 0x00F51476->_
             inline - len(1) winlogon.exe - 0x00F514B3->_
             inline - len(1) winlogon.exe - 0x00F514E0->_
             inline - len(1) winlogon.exe - 0x00F5156B->_
             inline - len(1) winlogon.exe - 0x00F515BB->_
             inline - len(1) winlogon.exe - 0x00F51642->_
             inline - len(1) winlogon.exe - 0x00F51657->_
             inline - len(11) winlogon.exe - 0x00F51687->_
             inline - len(1) winlogon.exe - 0x00F516C4->_
             inline - len(1) winlogon.exe - 0x00F516F0->_
             inline - len(1) winlogon.exe - 0x00F517AF->_
             inline - len(1) winlogon.exe - 0x00F517B6->_
             inline - len(1) winlogon.exe - 0x00F5182B->_
             inline - len(1) winlogon.exe - 0x00F5183A->_
             inline - len(1) winlogon.exe - 0x00F5187A->_
             inline - len(1) winlogon.exe - 0x00F51936->_
             inline - len(1) winlogon.exe - 0x00F51945->_
             inline - len(1) winlogon.exe - 0x00F51985->_
             inline - len(1) winlogon.exe - 0x00F519C4->_
             inline - len(1) winlogon.exe - 0x00F519DC->_
             inline - len(1) winlogon.exe - 0x00F519F2->_
             inline - len(1) winlogon.exe - 0x00F519FA->_
             inline - len(6) winlogon.exe - 0x00F51A08->_
             inline - len(1) winlogon.exe - 0x00F51A30->_
             inline - len(6) winlogon.exe - 0x00F51A67->_
             inline - len(1) winlogon.exe - 0x00F51A91->_
             inline - len(1) winlogon.exe - 0x00F51ABD->_
             inline - len(1) winlogon.exe - 0x00F51AC6->_
             inline - len(1) winlogon.exe - 0x00F51AD0->_
             inline - len(1) winlogon.exe - 0x00F51AFC->_
             inline - len(1) winlogon.exe - 0x00F51B2D->_
             inline - len(1) winlogon.exe - 0x00F51B5E->_
             inline - len(1) winlogon.exe - 0x00F51B8F->_
             inline - len(1) winlogon.exe - 0x00F51BA2->_
             inline - len(1) winlogon.exe - 0x00F51BB5->_
             inline - len(1) winlogon.exe - 0x00F51BC8->_
             inline - len(1) winlogon.exe - 0x00F51BDB->_
             inline - len(6) winlogon.exe - 0x00F51BE5->_
             inline - len(1) winlogon.exe - 0x00F51C03->_
             inline - len(1) winlogon.exe - 0x00F51C3C->_
             inline - len(1) winlogon.exe - 0x00F51C4A->_
             inline - len(1) winlogon.exe - 0x00F51DBA->_
             inline - len(1) winlogon.exe - 0x00F51DCF->_
             inline - len(11) winlogon.exe - 0x00F51E44->_
             inline - len(1) winlogon.exe - 0x00F51E88->_
             inline - len(1) winlogon.exe - 0x00F51E99->_
             inline - len(1) winlogon.exe - 0x00F51EC2->_
             inline - len(1) winlogon.exe - 0x00F51ED6->_
             inline - len(1) winlogon.exe - 0x00F51EF1->_
             inline - len(1) winlogon.exe - 0x00F51F16->_
             inline - len(6) winlogon.exe - 0x00F51F47->_
             inline - len(1) winlogon.exe - 0x00F51F63->_
             inline - len(1) winlogon.exe - 0x00F51FEA->_
             inline - len(1) winlogon.exe - 0x00F5201D->_
             inline - len(1) winlogon.exe - 0x00F52038->_
             inline - len(1) winlogon.exe - 0x00F52086->_
             inline - len(1) winlogon.exe - 0x00F52091->_
             inline - len(1) winlogon.exe - 0x00F520B4->_
             inline - len(1) winlogon.exe - 0x00F520BA->_
             inline - len(1) winlogon.exe - 0x00F520D1->_
             inline - len(6) winlogon.exe - 0x00F52173->_
             inline - len(1) winlogon.exe - 0x00F52197->_
             inline - len(1) winlogon.exe - 0x00F521DD->_
             inline - len(1) winlogon.exe - 0x00F521E3->_
             inline - len(1) winlogon.exe - 0x00F521FA->_
             inline - len(1) winlogon.exe - 0x00F52254->_
             inline - len(1) winlogon.exe - 0x00F5226B->_
             inline - len(1) winlogon.exe - 0x00F52282->_
             inline - len(1) winlogon.exe - 0x00F52297->_
             inline - len(1) winlogon.exe - 0x00F522AA->_
             inline - len(1) winlogon.exe - 0x00F522C1->_
             inline - len(1) winlogon.exe - 0x00F522D8->_
             inline - len(1) winlogon.exe - 0x00F52306->_
             inline - len(1) winlogon.exe - 0x00F5232B->_
             inline - len(1) winlogon.exe - 0x00F52332->_
             inline - len(1) winlogon.exe - 0x00F52363->_
             inline - len(1) winlogon.exe - 0x00F5237A->_
             inline - len(1) winlogon.exe - 0x00F52390->_
             inline - len(1) winlogon.exe - 0x00F523B3->_
             inline - len(1) winlogon.exe - 0x00F523CA->_
             inline - len(1) winlogon.exe - 0x00F523DF->_
             inline - len(1) winlogon.exe - 0x00F523F6->_
             inline - len(1) winlogon.exe - 0x00F5240B->_
             inline - len(1) winlogon.exe - 0x00F52422->_
             inline - len(1) winlogon.exe - 0x00F52445->_
             inline - len(1) winlogon.exe - 0x00F52478->_
             inline - len(1) winlogon.exe - 0x00F52486->_
             inline - len(6) winlogon.exe - 0x00F52495->_
             inline - len(1) winlogon.exe - 0x00F524B5->_
             inline - len(1) winlogon.exe - 0x00F524D1->_
             inline - len(1) winlogon.exe - 0x00F524E6->_
             inline - len(1) winlogon.exe - 0x00F524F0->_
             inline - len(1) winlogon.exe - 0x00F5250F->_
             inline - len(6) winlogon.exe - 0x00F52529->_
             inline - len(1) winlogon.exe - 0x00F52542->_
             inline - len(37) winlogon.exe - 0x00F525AA->_
             inline - len(1) winlogon.exe - 0x00F528EA->_
             inline - len(1) winlogon.exe - 0x00F528FF->_
             inline - len(1) winlogon.exe - 0x00F52929->_
             inline - len(6) winlogon.exe - 0x00F5292F->_
             inline - len(6) winlogon.exe - 0x00F5293D->_
             inline - len(1) winlogon.exe - 0x00F5296C->_
             inline - len(1) winlogon.exe - 0x00F52985->_
             inline - len(1) winlogon.exe - 0x00F529AD->_
             inline - len(6) winlogon.exe - 0x00F529BC->_
             inline - len(1) winlogon.exe - 0x00F529F2->_
             inline - len(1) winlogon.exe - 0x00F52A0C->_
             inline - len(6) winlogon.exe - 0x00F52A15->_
             inline - len(1) winlogon.exe - 0x00F52A4B->_
             inline - len(1) winlogon.exe - 0x00F52A67->_
             inline - len(6) winlogon.exe - 0x00F52A70->_
             inline - len(6) winlogon.exe - 0x00F52AA3->_
             inline - len(1) winlogon.exe - 0x00F52ADF->_
             inline - len(1) winlogon.exe - 0x00F52AF9->_
             inline - len(1) winlogon.exe - 0x00F52B02->_
             inline - len(1) winlogon.exe - 0x00F52B20->_
             inline - len(1) winlogon.exe - 0x00F52B35->_
             inline - len(1) winlogon.exe - 0x00F52B65->_
             inline - len(1) winlogon.exe - 0x00F52BCD->_
             inline - len(1) winlogon.exe - 0x00F52BF1->_
             inline - len(1) winlogon.exe - 0x00F52BFE->_
             inline - len(1) winlogon.exe - 0x00F52C15->_
             inline - len(1) winlogon.exe - 0x00F52C1F->_
             inline - len(1) winlogon.exe - 0x00F52C62->_
             inline - len(1) winlogon.exe - 0x00F52C6B->_
             inline - len(1) winlogon.exe - 0x00F52C87->_
             inline - len(1) winlogon.exe - 0x00F52C97->_
             inline - len(1) winlogon.exe - 0x00F52CB8->_
             inline - len(1) winlogon.exe - 0x00F52CEA->_
             inline - len(1) winlogon.exe - 0x00F52D0E->_
             inline - len(1) winlogon.exe - 0x00F52D2D->_
             inline - len(1) winlogon.exe - 0x00F52D36->_
             inline - len(1) winlogon.exe - 0x00F52D56->_
             inline - len(1) winlogon.exe - 0x00F52D5D->_
             inline - len(1) winlogon.exe - 0x00F52D70->_
             inline - len(1) winlogon.exe - 0x00F52D7D->_
             inline - len(1) winlogon.exe - 0x00F52D8D->_
             inline - len(1) winlogon.exe - 0x00F52DE9->_
             inline - len(1) winlogon.exe - 0x00F52E13->_
             inline - len(1) winlogon.exe - 0x00F52E2A->_
             inline - len(6) winlogon.exe - 0x00F52E31->_
             inline - len(1) winlogon.exe - 0x00F52E4C->_
             inline - len(1) winlogon.exe - 0x00F52E53->0x00F52BBF[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F52E71->_
             inline - len(1) winlogon.exe - 0x00F52E89->_
             inline - len(1) winlogon.exe - 0x00F52E9E->_
             inline - len(1) winlogon.exe - 0x00F52EAF->_
             inline - len(6) winlogon.exe - 0x00F52EB6->_
             inline - len(1) winlogon.exe - 0x00F52EC4->_
             inline - len(6) winlogon.exe - 0x00F52EF4->_
             inline - len(6) winlogon.exe - 0x00F52F32->_
             inline - len(1) winlogon.exe - 0x00F52F4A->_
             inline - len(1) winlogon.exe - 0x00F52F72->_
             inline - len(1) winlogon.exe - 0x00F52FAE->0x00F53096[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F52FCE->_
             inline - len(1) winlogon.exe - 0x00F53009->_
             inline - len(1) winlogon.exe - 0x00F5301D->_
             inline - len(1) winlogon.exe - 0x00F53023->_
             inline - len(1) winlogon.exe - 0x00F5304B->_
             inline - len(1) winlogon.exe - 0x00F53066->_
             inline - len(6) winlogon.exe - 0x00F5306D->_
             inline - len(1) winlogon.exe - 0x00F53085->_
             inline - len(1) winlogon.exe - 0x00F5308C->_
             inline - len(1) winlogon.exe - 0x00F530B8->_
             inline - len(11) winlogon.exe - 0x00F530CA->_
             inline - len(1) winlogon.exe - 0x00F530F7->_
             inline - len(11) winlogon.exe - 0x00F5310A->_
             inline - len(1) winlogon.exe - 0x00F53137->_
             inline - len(1) winlogon.exe - 0x00F53144->_
             inline - len(1) winlogon.exe - 0x00F5314B->_
             inline - len(6) winlogon.exe - 0x00F53155->_
             inline - len(1) winlogon.exe - 0x00F53183->_
             inline - len(6) winlogon.exe - 0x00F5319D->_
             inline - len(1) winlogon.exe - 0x00F531B7->_
             inline - len(1) winlogon.exe - 0x00F531CA->_
             inline - len(1) winlogon.exe - 0x00F531E6->_
             inline - len(1) winlogon.exe - 0x00F53202->_
             inline - len(1) winlogon.exe - 0x00F5320C->_
             inline - len(1) winlogon.exe - 0x00F53224->_
             inline - len(1) winlogon.exe - 0x00F53243->_
             inline - len(1) winlogon.exe - 0x00F53275->_
             inline - len(1) winlogon.exe - 0x00F53280->_
             inline - len(1) winlogon.exe - 0x00F5329D->_
             inline - len(1) winlogon.exe - 0x00F532A6->_
             inline - len(1) winlogon.exe - 0x00F534D0->_
             inline - len(1) winlogon.exe - 0x00F5359A->_
             inline - len(1) winlogon.exe - 0x00F535A6->_
             inline - len(6) winlogon.exe - 0x00F535F0->_
             inline - len(1) winlogon.exe - 0x00F5361A->_
             inline - len(6) winlogon.exe - 0x00F53664->_
             inline - len(1) winlogon.exe - 0x00F53681->_
             inline - len(1) winlogon.exe - 0x00F536A3->_
             inline - len(1) winlogon.exe - 0x00F536A9->_
             inline - len(1) winlogon.exe - 0x00F536C0->_
             inline - len(1) winlogon.exe - 0x00F536DA->_
             inline - len(6) winlogon.exe - 0x00F536F0->_
             inline - len(1) winlogon.exe - 0x00F5370E->_
             inline - len(6) winlogon.exe - 0x00F53785->_
             inline - len(1) winlogon.exe - 0x00F537A3->_
             inline - len(1) winlogon.exe - 0x00F537D1->_
             inline - len(1) winlogon.exe - 0x00F537E7->_
             inline - len(1) winlogon.exe - 0x00F537F2->_
             inline - len(1) winlogon.exe - 0x00F53800->_
             inline - len(1) winlogon.exe - 0x00F5380E->_
             inline - len(1) winlogon.exe - 0x00F53832->_
             inline - len(6) winlogon.exe - 0x00F53848->_
             inline - len(1) winlogon.exe - 0x00F53863->_
             inline - len(6) winlogon.exe - 0x00F53899->_
             inline - len(1) winlogon.exe - 0x00F538B4->_
             inline - len(6) winlogon.exe - 0x00F538DF->_
             inline - len(1) winlogon.exe - 0x00F538FA->_
             inline - len(6) winlogon.exe - 0x00F53930->_
             inline - len(1) winlogon.exe - 0x00F5394B->_
             inline - len(1) winlogon.exe - 0x00F5396C->_
             inline - len(1) winlogon.exe - 0x00F53994->_
             inline - len(1) winlogon.exe - 0x00F5399E->_
             inline - len(6) winlogon.exe - 0x00F539A6->_
             inline - len(1) winlogon.exe - 0x00F539C1->_
             inline - len(1) winlogon.exe - 0x00F53A12->_
             inline - len(1) winlogon.exe - 0x00F53A1E->_
             inline - len(1) winlogon.exe - 0x00F53B22->_
             inline - len(11) winlogon.exe - 0x00F53B35->_
             inline - len(1) winlogon.exe - 0x00F53B88->_
             inline - len(6) winlogon.exe - 0x00F53BB2->_
             inline - len(1) winlogon.exe - 0x00F53BEF->_
             inline - len(1) winlogon.exe - 0x00F53C26->_
             inline - len(1) winlogon.exe - 0x00F53C2C->_
             inline - len(1) winlogon.exe - 0x00F53C47->_
             inline - len(1) winlogon.exe - 0x00F53C7A->_
             inline - len(1) winlogon.exe - 0x00F53CC0->_
             inline - len(11) winlogon.exe - 0x00F53CF5->_
             inline - len(1) winlogon.exe - 0x00F53D25->_
             inline - len(1) winlogon.exe - 0x00F53D8C->_
             inline - len(1) winlogon.exe - 0x00F53D93->_
             inline - len(1) winlogon.exe - 0x00F53D9F->_
             inline - len(1) winlogon.exe - 0x00F53DC8->_
             inline - len(1) winlogon.exe - 0x00F53DDC->_
             inline - len(1) winlogon.exe - 0x00F53DE6->_
             inline - len(11) winlogon.exe - 0x00F53E2D->_
             inline - len(1) winlogon.exe - 0x00F53E6C->_
             inline - len(1) winlogon.exe - 0x00F53E76->_
             inline - len(6) winlogon.exe - 0x00F53EC3->_
             inline - len(1) winlogon.exe - 0x00F53EE0->_
             inline - len(1) winlogon.exe - 0x00F53EF2->_
             inline - len(1) winlogon.exe - 0x00F53F04->_
             inline - len(1) winlogon.exe - 0x00F53F0E->_
             inline - len(1) winlogon.exe - 0x00F53F28->_
             inline - len(1) winlogon.exe - 0x00F53F3C->_
             inline - len(1) winlogon.exe - 0x00F53F51->_
             inline - len(1) winlogon.exe - 0x00F53F75->_
             inline - len(1) winlogon.exe - 0x00F53F8D->_
             inline - len(1) winlogon.exe - 0x00F53FAE->_
             inline - len(6) winlogon.exe - 0x00F54036->_
             inline - len(1) winlogon.exe - 0x00F5404E->_
             inline - len(1) winlogon.exe - 0x00F54074->_
             inline - len(1) winlogon.exe - 0x00F5408E->_
             inline - len(6) winlogon.exe - 0x00F54099->_
             inline - len(1) winlogon.exe - 0x00F540C3->_
             inline - len(1) winlogon.exe - 0x00F540EA->_
             inline - len(6) winlogon.exe - 0x00F540F6->_
             inline - len(6) winlogon.exe - 0x00F54121->_
             inline - len(1) winlogon.exe - 0x00F54146->_
             inline - len(1) winlogon.exe - 0x00F54177->_
             inline - len(1) winlogon.exe - 0x00F5419A->_
             inline - len(1) winlogon.exe - 0x00F541A4->_
             inline - len(6) winlogon.exe - 0x00F541AF->_
             inline - len(1) winlogon.exe - 0x00F541CC->_
             inline - len(6) winlogon.exe - 0x00F541F5->_
             inline - len(1) winlogon.exe - 0x00F54212->_
             inline - len(1) winlogon.exe - 0x00F5427E->_
             inline - len(1) winlogon.exe - 0x00F5429E->_
             inline - len(1) winlogon.exe - 0x00F542B2->_
             inline - len(1) winlogon.exe - 0x00F54362->_
             inline - len(1) winlogon.exe - 0x00F5436E->_
             inline - len(6) winlogon.exe - 0x00F54383->_
             inline - len(1) winlogon.exe - 0x00F5439D->_
             inline - len(1) winlogon.exe - 0x00F543C8->_
             inline - len(1) winlogon.exe - 0x00F543E8->_
             inline - len(1) winlogon.exe - 0x00F543FC->_
             inline - len(1) winlogon.exe - 0x00F54411->_
             inline - len(1) winlogon.exe - 0x00F5442E->_
             inline - len(1) winlogon.exe - 0x00F54443->_
             inline - len(1) winlogon.exe - 0x00F5449A->_
             inline - len(1) winlogon.exe - 0x00F544A6->_
             inline - len(6) winlogon.exe - 0x00F544BD->_
             inline - len(1) winlogon.exe - 0x00F544DA->_
             inline - len(1) winlogon.exe - 0x00F544EF->_
             inline - len(1) winlogon.exe - 0x00F5450E->_
             inline - len(1) winlogon.exe - 0x00F5455E->_
             inline - len(1) winlogon.exe - 0x00F5458E->_
             inline - len(1) winlogon.exe - 0x00F545B5->_
             inline - len(1) winlogon.exe - 0x00F545EF->_
             inline - len(1) winlogon.exe - 0x00F5465F->_
             inline - len(1) winlogon.exe - 0x00F5476A->_
             inline - len(1) winlogon.exe - 0x00F547A7->_
             inline - len(1) winlogon.exe - 0x00F547BF->_
             inline - len(1) winlogon.exe - 0x00F547D4->_
             inline - len(1) winlogon.exe - 0x00F547EC->_
             inline - len(1) winlogon.exe - 0x00F547FA->_
             inline - len(1) winlogon.exe - 0x00F5482D->_
             inline - len(1) winlogon.exe - 0x00F548B0->_
             inline - len(1) winlogon.exe - 0x00F548B7->_
             inline - len(6) winlogon.exe - 0x00F548C3->_
             inline - len(1) winlogon.exe - 0x00F548DE->_
             inline - len(1) winlogon.exe - 0x00F5490C->_
             inline - len(1) winlogon.exe - 0x00F54919->_
             inline - len(1) winlogon.exe - 0x00F54955->_
             inline - len(1) winlogon.exe - 0x00F5498B->_
             inline - len(1) winlogon.exe - 0x00F549BF->_
             inline - len(1) winlogon.exe - 0x00F54A20->_
             inline - len(1) winlogon.exe - 0x00F54A36->_
             inline - len(1) winlogon.exe - 0x00F54A46->_
             inline - len(1) winlogon.exe - 0x00F54A82->_
             inline - len(1) winlogon.exe - 0x00F54A95->_
             inline - len(6) winlogon.exe - 0x00F54A9E->_
             inline - len(1) winlogon.exe - 0x00F54AB9->_
             inline - len(1) winlogon.exe - 0x00F54ACC->_
             inline - len(1) winlogon.exe - 0x00F54AD2->_
             inline - len(1) winlogon.exe - 0x00F54AD8->_
             inline - len(1) winlogon.exe - 0x00F54AEC->_
             inline - len(1) winlogon.exe - 0x00F54B00->_
             inline - len(1) winlogon.exe - 0x00F54B17->_
             inline - len(6) winlogon.exe - 0x00F54B81->_
             inline - len(1) winlogon.exe - 0x00F54B9B->_
             inline - len(1) winlogon.exe - 0x00F54BDD->_
             inline - len(1) winlogon.exe - 0x00F54BEE->_
             inline - len(1) winlogon.exe - 0x00F54C7D->_
             inline - len(1) winlogon.exe - 0x00F54C8B->_
             inline - len(5) winlogon.exe - 0x00F54CFE->_
             inline - len(1) winlogon.exe - 0x00F54D0D->_
             inline - len(1) winlogon.exe - 0x00F54D18->_
             inline - len(1) winlogon.exe - 0x00F54D28->_
             inline - len(1) winlogon.exe - 0x00F54D2E->_
             inline - len(1) winlogon.exe - 0x00F54D34->_
             inline - len(1) winlogon.exe - 0x00F54D3A->_
             inline - len(1) winlogon.exe - 0x00F54D40->_
             inline - len(1) winlogon.exe - 0x00F54D46->_
             inline - len(1) winlogon.exe - 0x00F54D4C->_
             inline - len(1) winlogon.exe - 0x00F54D52->_
             inline - len(1) winlogon.exe - 0x00F54D58->_
             inline - len(1) winlogon.exe - 0x00F54D5E->_
             inline - len(1) winlogon.exe - 0x00F54D64->_
             inline - len(1) winlogon.exe - 0x00F54D6A->_
             inline - len(1) winlogon.exe - 0x00F54D71->_
             inline - len(1) winlogon.exe - 0x00F54D79->_
             inline - len(1) winlogon.exe - 0x00F54D81->_
             inline - len(1) winlogon.exe - 0x00F54D89->_
             inline - len(1) winlogon.exe - 0x00F54D95->_
             inline - len(6) winlogon.exe - 0x00F54D9E->_
             inline - len(1) winlogon.exe - 0x00F54DA9->_
             inline - len(1) winlogon.exe - 0x00F54DB3->_
             inline - len(1) winlogon.exe - 0x00F54DBC->_
             inline - len(1) winlogon.exe - 0x00F54DC7->_
             inline - len(6) winlogon.exe - 0x00F54DD5->_
             inline - len(1) winlogon.exe - 0x00F54DE0->_
             inline - len(1) winlogon.exe - 0x00F54DEB->_
             inline - len(1) winlogon.exe - 0x00F54DF2->_
             inline - len(10) winlogon.exe - 0x00F54DFA->_
             inline - len(1) winlogon.exe - 0x00F54E0D->_
             inline - len(6) winlogon.exe - 0x00F54E21->_
             inline - len(1) winlogon.exe - 0x00F54E33->_
             inline - len(1) winlogon.exe - 0x00F5501A->_
             inline - len(1) winlogon.exe - 0x00F55024->_
             inline - len(1) winlogon.exe - 0x00F5502E->_
             inline - len(1) winlogon.exe - 0x00F55038->_
             inline - len(1) winlogon.exe - 0x00F55042->_
             inline - len(6) winlogon.exe - 0x00F55052->_
             inline - len(1) winlogon.exe - 0x00F55067->_
             inline - len(1) winlogon.exe - 0x00F55072->_
             inline - len(1) winlogon.exe - 0x00F5507D->_
             inline - len(1) winlogon.exe - 0x00F55088->_
             inline - len(1) winlogon.exe - 0x00F550F3->_
             inline - len(1) winlogon.exe - 0x00F55102->_
             inline - len(1) winlogon.exe - 0x00F55142->_
             inline - len(1) winlogon.exe - 0x00F551AC->_
             inline - len(1) winlogon.exe - 0x00F551E8->_
             inline - len(1) winlogon.exe - 0x00F551EF->_
             inline - len(1) winlogon.exe - 0x00F55250->_
             inline - len(1) winlogon.exe - 0x00F5528C->_
             inline - len(1) winlogon.exe - 0x00F55293->_
             inline - len(1) winlogon.exe - 0x00F552EE->_
             inline - len(1) winlogon.exe - 0x00F5532A->_
             inline - len(1) winlogon.exe - 0x00F55331->_
             inline - len(1) winlogon.exe - 0x00F55367->_
             inline - len(1) winlogon.exe - 0x00F553A1->_
             inline - len(1) winlogon.exe - 0x00F553B5->_
             inline - len(6) winlogon.exe - 0x00F553C6->_
             inline - len(1) winlogon.exe - 0x00F553F0->_
             inline - len(1) winlogon.exe - 0x00F55408->_
             inline - len(1) winlogon.exe - 0x00F5540E->_
             inline - len(1) winlogon.exe - 0x00F55434->_
             inline - len(1) winlogon.exe - 0x00F5544D->_
             inline - len(1) winlogon.exe - 0x00F55455->_
             inline - len(6) winlogon.exe - 0x00F55461->_
             inline - len(1) winlogon.exe - 0x00F5548E->_
             inline - len(1) winlogon.exe - 0x00F55495->_
             inline - len(6) winlogon.exe - 0x00F554CC->_
             inline - len(1) winlogon.exe - 0x00F554F9->_
             inline - len(6) winlogon.exe - 0x00F5550B->_
             inline - len(1) winlogon.exe - 0x00F55529->_
             inline - len(1) winlogon.exe - 0x00F55545->_
             inline - len(1) winlogon.exe - 0x00F5555B->_
             inline - len(6) winlogon.exe - 0x00F5557C->_
             inline - len(1) winlogon.exe - 0x00F5559C->_
             inline - len(6) winlogon.exe - 0x00F555C8->_
             inline - len(1) winlogon.exe - 0x00F555EA->_
             inline - len(6) winlogon.exe - 0x00F55601->_
             inline - len(1) winlogon.exe - 0x00F55623->_
             inline - len(1) winlogon.exe - 0x00F55644->_
             inline - len(1) winlogon.exe - 0x00F5564A->_
             inline - len(1) winlogon.exe - 0x00F55664->_
             inline - len(1) winlogon.exe - 0x00F556B2->_
             inline - len(1) winlogon.exe - 0x00F5571D->_
             inline - len(6) winlogon.exe - 0x00F5572D->_
             inline - len(1) winlogon.exe - 0x00F55740->_
             inline - len(1) winlogon.exe - 0x00F5575B->_
             inline - len(1) winlogon.exe - 0x00F55777->_
             inline - len(1) winlogon.exe - 0x00F55793->_
             inline - len(6) winlogon.exe - 0x00F557C7->_
             inline - len(6) winlogon.exe - 0x00F557F2->_
             inline - len(6) winlogon.exe - 0x00F5581D->_
             inline - len(6) winlogon.exe - 0x00F55848->_
             inline - len(1) winlogon.exe - 0x00F5586B->_
             inline - len(1) winlogon.exe - 0x00F558A1->_
             inline - len(1) winlogon.exe - 0x00F558BD->_
             inline - len(1) winlogon.exe - 0x00F558CA->_
             inline - len(1) winlogon.exe - 0x00F558D6->_
             inline - len(11) winlogon.exe - 0x00F558E0->_
             inline - len(1) winlogon.exe - 0x00F558F0->_
             inline - len(1) winlogon.exe - 0x00F55902->_
             inline - len(1) winlogon.exe - 0x00F5590C->_
             inline - len(1) winlogon.exe - 0x00F55929->_
             inline - len(1) winlogon.exe - 0x00F5594E->_
             inline - len(1) winlogon.exe - 0x00F559C2->_
             inline - len(1) winlogon.exe - 0x00F559CE->_
             inline - len(1) winlogon.exe - 0x00F559F6->_
             inline - len(1) winlogon.exe - 0x00F55A01->_
             inline - len(1) winlogon.exe - 0x00F55A17->_
             inline - len(1) winlogon.exe - 0x00F55A21->_
             inline - len(1) winlogon.exe - 0x00F55AB4->_
             inline - len(1) winlogon.exe - 0x00F55ACA->_
             inline - len(1) winlogon.exe - 0x00F55B1A->_
             inline - len(1) winlogon.exe - 0x00F55B26->_
             inline - len(1) winlogon.exe - 0x00F55B8E->_
             inline - len(1) winlogon.exe - 0x00F55B97->0x00F21570[C:\Windows\System32\winlogon.exe]
             inline - len(5) winlogon.exe - 0x00F55BBE->_
             inline - len(1) winlogon.exe - 0x00F55BCE->_
             inline - len(1) winlogon.exe - 0x00F55C34->_
             inline - len(1) winlogon.exe - 0x00F55C3D->0x00F21570[C:\Windows\System32\winlogon.exe]
             inline - len(5) winlogon.exe - 0x00F55C66->_
             inline - len(6) winlogon.exe - 0x00F55C7E->0x00F21F91[C:\Windows\System32\winlogon.exe]
             inline - len(6) winlogon.exe - 0x00F55CA9->0x00F21F91[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F55CEB->_
             inline - len(1) winlogon.exe - 0x00F55D12->_
             inline - len(5) winlogon.exe - 0x00F55D5E->_
             inline - len(1) winlogon.exe - 0x00F55D6E->_
             inline - len(1) winlogon.exe - 0x00F55D98->_
             inline - len(5) winlogon.exe - 0x00F55DE6->_
             inline - len(1) winlogon.exe - 0x00F55DF6->_
             inline - len(1) winlogon.exe - 0x00F55E1A->_
             inline - len(5) winlogon.exe - 0x00F55E66->_
             inline - len(1) winlogon.exe - 0x00F55E76->_
             inline - len(1) winlogon.exe - 0x00F55E97->_
             inline - len(5) winlogon.exe - 0x00F55EE6->_
             inline - len(1) winlogon.exe - 0x00F55F81->_
             inline - len(1) winlogon.exe - 0x00F55FAB->_
             inline - len(5) winlogon.exe - 0x00F55FFE->_
             inline - len(1) winlogon.exe - 0x00F5609C->_
             inline - len(1) winlogon.exe - 0x00F560F5->_
             inline - len(5) winlogon.exe - 0x00F56146->_
             inline - len(6) winlogon.exe - 0x00F5615E->_
             inline - len(6) winlogon.exe - 0x00F56189->_
             inline - len(6) winlogon.exe - 0x00F561B4->_
             inline - len(6) winlogon.exe - 0x00F561DF->_
             inline - len(6) winlogon.exe - 0x00F5620A->_
             inline - len(6) winlogon.exe - 0x00F56235->_
             inline - len(1) winlogon.exe - 0x00F56258->_
             inline - len(1) winlogon.exe - 0x00F56269->_
             inline - len(1) winlogon.exe - 0x00F5627D->_
             inline - len(1) winlogon.exe - 0x00F562EE->_
             inline - len(1) winlogon.exe - 0x00F562FC->_
             inline - len(1) winlogon.exe - 0x00F56314->_
             inline - len(1) winlogon.exe - 0x00F56335->_
             inline - len(1) winlogon.exe - 0x00F5633F->_
             inline - len(5) winlogon.exe - 0x00F5636E->_
             inline - len(6) winlogon.exe - 0x00F563CA->_
             inline - len(1) winlogon.exe - 0x00F563ED->_
             inline - len(1) winlogon.exe - 0x00F56412->_
             inline - len(1) winlogon.exe - 0x00F5641E->_
             inline - len(1) winlogon.exe - 0x00F56457->_
             inline - len(1) winlogon.exe - 0x00F56462->_
             inline - len(1) winlogon.exe - 0x00F564A4->_
             inline - len(1) winlogon.exe - 0x00F564B0->_
             inline - len(1) winlogon.exe - 0x00F564F7->_
             inline - len(1) winlogon.exe - 0x00F56512->_
             inline - len(1) winlogon.exe - 0x00F5651F->_
             inline - len(1) winlogon.exe - 0x00F56525->_
             inline - len(1) winlogon.exe - 0x00F5652B->_
             inline - len(1) winlogon.exe - 0x00F56534->_
             inline - len(1) winlogon.exe - 0x00F5653B->_
             inline - len(1) winlogon.exe - 0x00F56559->_
             inline - len(1) winlogon.exe - 0x00F56568->_
             inline - len(1) winlogon.exe - 0x00F5656F->_
             inline - len(1) winlogon.exe - 0x00F565B1->_
             inline - len(1) winlogon.exe - 0x00F565FA->_
             inline - len(1) winlogon.exe - 0x00F56605->_
             inline - len(1) winlogon.exe - 0x00F56632->_
             inline - len(1) winlogon.exe - 0x00F5663E->_
             inline - len(1) winlogon.exe - 0x00F56669->_
             inline - len(1) winlogon.exe - 0x00F56676->_
             inline - len(1) winlogon.exe - 0x00F5668F->_
             inline - len(1) winlogon.exe - 0x00F566AB->_
             inline - len(1) winlogon.exe - 0x00F566B1->_
             inline - len(1) winlogon.exe - 0x00F566B7->_
             inline - len(1) winlogon.exe - 0x00F566D8->_
             inline - len(6) winlogon.exe - 0x00F566EF->_
             inline - len(1) winlogon.exe - 0x00F56714->0x00F567C6[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F56721->_
             inline - len(1) winlogon.exe - 0x00F56727->_
             inline - len(1) winlogon.exe - 0x00F5672D->_
             inline - len(1) winlogon.exe - 0x00F5674D->_
             inline - len(1) winlogon.exe - 0x00F56761->_
             inline - len(1) winlogon.exe - 0x00F56788->_
             inline - len(6) winlogon.exe - 0x00F567A3->_
             inline - len(1) winlogon.exe - 0x00F567C2->_
             inline - len(1) winlogon.exe - 0x00F567DB->_
             inline - len(1) winlogon.exe - 0x00F567E1->_
             inline - len(1) winlogon.exe - 0x00F567E7->_
             inline - len(1) winlogon.exe - 0x00F5680C->_
             inline - len(1) winlogon.exe - 0x00F56812->_
             inline - len(1) winlogon.exe - 0x00F56835->_
             inline - len(1) winlogon.exe - 0x00F56858->_
             inline - len(1) winlogon.exe - 0x00F5685E->_
             inline - len(1) winlogon.exe - 0x00F568AA->_
             inline - len(1) winlogon.exe - 0x00F56A5A->_
             inline - len(1) winlogon.exe - 0x00F56A6F->_
             inline - len(6) winlogon.exe - 0x00F56A90->_
             inline - len(1) winlogon.exe - 0x00F56AB7->_
             inline - len(1) winlogon.exe - 0x00F56ADD->_
             inline - len(1) winlogon.exe - 0x00F56B0A->_
             inline - len(1) winlogon.exe - 0x00F56B2A->_
             inline - len(1) winlogon.exe - 0x00F56B5E->_
             inline - len(6) winlogon.exe - 0x00F56B7B->_
             inline - len(1) winlogon.exe - 0x00F56B8D->_
             inline - len(1) winlogon.exe - 0x00F56BB3->_
             inline - len(1) winlogon.exe - 0x00F56BEA->_
             inline - len(1) winlogon.exe - 0x00F56BF3->_
             inline - len(1) winlogon.exe - 0x00F56C1D->_
             inline - len(1) winlogon.exe - 0x00F56C2F->_
             inline - len(1) winlogon.exe - 0x00F56C35->_
             inline - len(1) winlogon.exe - 0x00F56C67->_
             inline - len(1) winlogon.exe - 0x00F56C6F->_
             inline - len(1) winlogon.exe - 0x00F56C75->_
             inline - len(1) winlogon.exe - 0x00F56C7B->_
             inline - len(1) winlogon.exe - 0x00F56C90->_
             inline - len(1) winlogon.exe - 0x00F56C9B->_
             inline - len(1) winlogon.exe - 0x00F56CA1->_
             inline - len(1) winlogon.exe - 0x00F56CA7->_
             inline - len(1) winlogon.exe - 0x00F56CBC->_
             inline - len(1) winlogon.exe - 0x00F56CD5->_
             inline - len(1) winlogon.exe - 0x00F56CDD->_
             inline - len(1) winlogon.exe - 0x00F56CE3->_
             inline - len(1) winlogon.exe - 0x00F56CE9->_
             inline - len(1) winlogon.exe - 0x00F56CFE->_
             inline - len(6) winlogon.exe - 0x00F56D4E->_
             inline - len(1) winlogon.exe - 0x00F56D66->_
             inline - len(1) winlogon.exe - 0x00F56D81->_
             inline - len(1) winlogon.exe - 0x00F56D8C->_
             inline - len(1) winlogon.exe - 0x00F56D97->_
             inline - len(1) winlogon.exe - 0x00F56DA2->_
             inline - len(1) winlogon.exe - 0x00F56E16->_
             inline - len(1) winlogon.exe - 0x00F56E2D->_
             inline - len(1) winlogon.exe - 0x00F56E39->_
             inline - len(1) winlogon.exe - 0x00F56E48->_
             inline - len(1) winlogon.exe - 0x00F56E75->_
             inline - len(1) winlogon.exe - 0x00F56E92->_
             inline - len(1) winlogon.exe - 0x00F56EA4->_
             inline - len(1) winlogon.exe - 0x00F56EEB->_
             inline - len(1) winlogon.exe - 0x00F56F06->_
             inline - len(1) winlogon.exe - 0x00F56F26->_
             inline - len(1) winlogon.exe - 0x00F57007->_
             inline - len(1) winlogon.exe - 0x00F5700E->_
             inline - len(1) winlogon.exe - 0x00F57016->_
             inline - len(1) winlogon.exe - 0x00F57045->_
             inline - len(1) winlogon.exe - 0x00F57064->_
             inline - len(1) winlogon.exe - 0x00F570AC->_
             inline - len(1) winlogon.exe - 0x00F570B2->_
             inline - len(1) winlogon.exe - 0x00F570C8->_
             inline - len(1) winlogon.exe - 0x00F570F7->_
             inline - len(1) winlogon.exe - 0x00F57126->_
             inline - len(1) winlogon.exe - 0x00F5712D->0x00F5706F[C:\Windows\System32\winlogon.exe]
             inline - len(1) winlogon.exe - 0x00F5715B->_
             inline - len(1) winlogon.exe - 0x00F57168->_
             inline - len(1) winlogon.exe - 0x00F5717A->_
             inline - len(1) winlogon.exe - 0x00F57180->_
             inline - len(1) winlogon.exe - 0x00F571A2->_
             inline - len(1) winlogon.exe - 0x00F571AE->_
             inline - len(1) winlogon.exe - 0x00F571C2->_
             inline - len(1) winlogon.exe - 0x00F571CC->_
             inline - len(1) winlogon.exe - 0x00F571D2->_
             inline - len(1) winlogon.exe - 0x00F571DE->_
             inline - len(1) winlogon.exe - 0x00F571E8->_
             inline - len(1) winlogon.exe - 0x00F57209->_
             inline - len(1) winlogon.exe - 0x00F5721B->_
             inline - len(1) winlogon.exe - 0x00F57226->_
             inline - len(1) winlogon.exe - 0x00F57231->_
             inline - len(1) winlogon.exe - 0x00F5725B->_
             inline - len(1) winlogon.exe - 0x00F57261->_
             inline - len(1) winlogon.exe - 0x00F57282->_
             inline - len(1) winlogon.exe - 0x00F572B1->_
             inline - len(1) winlogon.exe - 0x00F572D1->_
             inline - len(1) winlogon.exe - 0x00F572F9->_
             inline - len(1) winlogon.exe - 0x00F57334->_
             inline - len(1) winlogon.exe - 0x00F5733B->_
             inline - len(1) winlogon.exe - 0x00F57341->_
             inline - len(1) winlogon.exe - 0x00F57362->_
             inline - len(1) winlogon.exe - 0x00F57387->_
             inline - len(1) winlogon.exe - 0x00F57392->_
             inline - len(1) winlogon.exe - 0x00F5739A->_
             inline - len(1) winlogon.exe - 0x00F573B0->_
             inline - len(1) winlogon.exe - 0x00F573B9->_
             inline - len(1) winlogon.exe - 0x00F573C4->_
             inline - len(1) winlogon.exe - 0x00F573CC->_
             inline - len(1) winlogon.exe - 0x00F573E5->_
             inline - len(1) winlogon.exe - 0x00F573F0->_
             inline - len(1) winlogon.exe - 0x00F573F7->_
             inline - len(1) winlogon.exe - 0x00F57407->_
             inline - len(1) winlogon.exe - 0x00F57445->_
             inline - len(1) winlogon.exe - 0x00F5746F->_
             inline - len(1) winlogon.exe - 0x00F5747A->_
             inline - len(1) winlogon.exe - 0x00F574A5->_
             inline - len(1) winlogon.exe - 0x00F574D7->_
             inline - len(1) winlogon.exe - 0x00F574E2->_
             inline - len(1) winlogon.exe - 0x00F5761A->_
             inline - len(1) winlogon.exe - 0x00F57620->_
             inline - len(1) winlogon.exe - 0x00F577F7->_
             inline - len(1) winlogon.exe - 0x00F5780E->_
             inline - len(1) winlogon.exe - 0x00F57814->_
             inline - len(1) winlogon.exe - 0x00F578A9->_
             inline - len(1) winlogon.exe - 0x00F578C2->_
             inline - len(1) winlogon.exe - 0x00F578DA->_
             inline - len(1) winlogon.exe - 0x00F578E0->_
             inline - len(1) winlogon.exe - 0x00F57981->_
             inline - len(1) winlogon.exe - 0x00F5799A->_
             inline - len(1) winlogon.exe - 0x00F579B2->_
             inline - len(1) winlogon.exe - 0x00F579BB->_
             inline - len(1) winlogon.exe - 0x00F57B4D->_
             inline - len(1) winlogon.exe - 0x00F57B54->_
             inline - len(1) winlogon.exe - 0x00F57B5A->_
             inline - len(1) winlogon.exe - 0x00F57B80->_
             inline - len(1) winlogon.exe - 0x00F57B95->_
             inline - len(1) winlogon.exe - 0x00F57BAB->_
             inline - len(1) winlogon.exe - 0x00F57BB9->_
             inline - len(1) winlogon.exe - 0x00F57D04->_
             inline - len(1) winlogon.exe - 0x00F57D3E->_
             inline - len(1) winlogon.exe - 0x00F57D44->_
             inline - len(1) winlogon.exe - 0x00F57D4A->_
             inline - len(1) winlogon.exe - 0x00F57D65->_
             inline - len(1) winlogon.exe - 0x00F57D7C->_
             inline - len(1) winlogon.exe - 0x00F57DCD->_
             inline - len(1) winlogon.exe - 0x00F57DD8->_
             inline - len(1) winlogon.exe - 0x00F57DDF->_
             inline - len(1) winlogon.exe - 0x00F57DE5->_
             inline - len(1) winlogon.exe - 0x00F57E11->_
             inline - len(1) winlogon.exe - 0x00F57E28->_
             inline - len(1) winlogon.exe - 0x00F57E43->_
             inline - len(1) winlogon.exe - 0x00F57E5C->_
             inline - len(1) winlogon.exe - 0x00F57E66->_
             inline - len(1) winlogon.exe - 0x00F57E8C->_
             inline - len(1) winlogon.exe - 0x00F57E96->_
             inline - len(1) winlogon.exe - 0x00F57EB4->_
             inline - len(1) winlogon.exe - 0x00F57EBA->_
             inline - len(1) winlogon.exe - 0x00F57ED3->_
             inline - len(1) winlogon.exe - 0x00F57ED9->_
             inline - len(1) winlogon.exe - 0x00F57EFC->_
             inline - len(1) winlogon.exe - 0x00F57F0F->_
             inline - len(1) winlogon.exe - 0x00F57F31->_
             inline - len(1) winlogon.exe - 0x00F57F37->_
             inline - len(1) winlogon.exe - 0x00F57F61->_
             inline - len(1) winlogon.exe - 0x00F57F67->_
             inline - len(1) winlogon.exe - 0x00F57F82->_
             inline - len(1) winlogon.exe - 0x00F57F88->_
             inline - len(1) winlogon.exe - 0x00F57FC2->_
             inline - len(1) winlogon.exe - 0x00F57FDD->_
             inline - len(1) winlogon.exe - 0x00F58005->_
             inline - len(1) winlogon.exe - 0x00F58022->_
             inline - len(1) winlogon.exe - 0x00F5805A->_
             inline - len(1) winlogon.exe - 0x00F5808A->_
             inline - len(1) winlogon.exe - 0x00F580A4->_
             inline - len(1) winlogon.exe - 0x00F580D1->_
             inline - len(1) winlogon.exe - 0x00F580E5->_
             inline - len(1) winlogon.exe - 0x00F580F0->_
             inline - len(1) winlogon.exe - 0x00F58100->_
             inline - len(6) winlogon.exe - 0x00F582E4->_
             inline - len(1) winlogon.exe - 0x00F582FB->_
             inline - len(1) winlogon.exe - 0x00F58312->_
             inline - len(1) winlogon.exe - 0x00F5832D->_
             inline - len(1) winlogon.exe - 0x00F58335->_
             inline - len(1) winlogon.exe - 0x00F58342->_
             inline - len(1) winlogon.exe - 0x00F58370->_
             inline - len(1) winlogon.exe - 0x00F583DE->_
             inline - len(1) winlogon.exe - 0x00F583E5->_
             inline - len(6) winlogon.exe - 0x00F583F0->_
             inline - len(1) winlogon.exe - 0x00F58408->_
             inline - len(1) winlogon.exe - 0x00F58431->_
             inline - len(1) winlogon.exe - 0x00F58438->_
             inline - len(6) winlogon.exe - 0x00F58441->_
             inline - len(1) winlogon.exe - 0x00F58459->_
             inline - len(1) winlogon.exe - 0x00F584CB->_
             inline - len(1) winlogon.exe - 0x00F584F2->_
             inline - len(1) winlogon.exe - 0x00F584FA->_
             inline - len(1) winlogon.exe - 0x00F5850F->_
             inline - len(1) winlogon.exe - 0x00F5851D->_
             inline - len(1) winlogon.exe - 0x00F58526->_
             inline - len(1) winlogon.exe - 0x00F58536->_
             inline - len(6) winlogon.exe - 0x00F58541->_
             inline - len(1) winlogon.exe - 0x00F58550->_
             inline - len(1) winlogon.exe - 0x00F5855A->_
             inline - len(1) winlogon.exe - 0x00F58568->_
             inline - len(1) winlogon.exe - 0x00F58572->_
             inline - len(1) winlogon.exe - 0x00F58582->_
             inline - len(1) winlogon.exe - 0x00F5858D->_
             Iat - tquery.dll->msvcrt.dll:towupper - 0x75ADF670->0x6FF5F670
             Iat - tquery.dll->msvcrt.dll:??0exception@@QAE@XZ - 0x75AE14F9->0x6FF614F9
             Iat - tquery.dll->msvcrt.dll:_wcsnicmp - 0x75ADAAE3->0x6FF5AAE3
             Iat - tquery.dll->msvcrt.dll:wcschr - 0x75ADAA61->0x6FF5AA61
             Iat - tquery.dll->msvcrt.dll:strerror - 0x75AF7A18->0x6FF77A18
             Iat - tquery.dll->msvcrt.dll:wcsncmp - 0x75ADB05E->0x6FF5B05E
             Iat - tquery.dll->msvcrt.dll:iswspace - 0x75ADAACB->0x6FF5AACB
             Iat - tquery.dll->msvcrt.dll:_wtol - 0x75ADC7C8->0x6FF5C7C8
             Iat - tquery.dll->msvcrt.dll:strncmp - 0x75ADB443->0x6FF5B443
             Iat - tquery.dll->msvcrt.dll:_iob - 0x75B72900->0x6FFF2900
             Iat - tquery.dll->msvcrt.dll:wcsspn - 0x75AE0014->0x6FF60014
             Iat - tquery.dll->msvcrt.dll:calloc - 0x75ADC456->0x6FF5C456
             Iat - tquery.dll->msvcrt.dll:_XcptFilter - 0x75AFDC75->0x6FF7DC75
             Iat - tquery.dll->msvcrt.dll:_initterm - 0x75ADC151->0x6FF5C151
             Iat - tquery.dll->msvcrt.dll:_amsg_exit - 0x75B3B2EF->0x6FFBB2EF
             Iat - tquery.dll->msvcrt.dll:?terminate@@YAXXZ - 0x75B261CF->0x6FFA61CF
             Iat - tquery.dll->msvcrt.dll:??1type_info@@UAE@XZ - 0x75B292B3->0x6FFA92B3
             Iat - tquery.dll->msvcrt.dll:_except_handler4_common - 0x75AF3E27->0x6FF73E27
             Iat - tquery.dll->msvcrt.dll:_unlock - 0x75ADA42D->0x6FF5A42D
             Iat - tquery.dll->msvcrt.dll:__dllonexit - 0x75ADF509->0x6FF5F509
             Iat - tquery.dll->msvcrt.dll:_lock - 0x75ADA449->0x6FF5A449
             Iat - tquery.dll->msvcrt.dll:_onexit - 0x75AE112D->0x6FF6112D
             Iat - tquery.dll->msvcrt.dll:realloc - 0x75ADB10D->0x6FF5B10D
             Iat - tquery.dll->msvcrt.dll:_wcsupr - 0x75ADDAC1->0x6FF5DAC1
             Iat - tquery.dll->msvcrt.dll:wcscspn - 0x75ADD9DA->0x6FF5D9DA
             Iat - tquery.dll->msvcrt.dll:iswdigit - 0x75ADC02C->0x6FF5C02C
             Iat - tquery.dll->msvcrt.dll:swscanf - 0x75AEBB89->0x6FF6BB89
             Iat - tquery.dll->msvcrt.dll:_errno - 0x75ADA5B8->0x6FF5A5B8
             Iat - tquery.dll->msvcrt.dll:wcsrchr - 0x75ADA73F->0x6FF5A73F
             Iat - tquery.dll->msvcrt.dll:fprintf - 0x75AE3E00->0x6FF63E00
             Iat - tquery.dll->msvcrt.dll:_vsnprintf - 0x75ADD1A8->0x6FF5D1A8
             Iat - tquery.dll->msvcrt.dll:_ultow_s - 0x75ADF8E9->0x6FF5F8E9
             Iat - tquery.dll->msvcrt.dll:_itow_s - 0x75AE123B->0x6FF6123B
             Iat - tquery.dll->msvcrt.dll:_wcsicmp - 0x75ADA9E9->0x6FF5A9E9
             Iat - tquery.dll->msvcrt.dll:wcstoul - 0x75ADB319->0x6FF5B319
             Iat - tquery.dll->msvcrt.dll:memmove - 0x75AD9E5A->0x6FF59E5A
             Iat - tquery.dll->msvcrt.dll:??0exception@@QAE@ABV0@@Z - 0x75B256C5->0x6FFA56C5
             Iat - tquery.dll->msvcrt.dll:??1exception@@UAE@XZ - 0x75AE14E3->0x6FF614E3
             Iat - tquery.dll->msvcrt.dll:?what@exception@@UBEPBDXZ - 0x75B2579D->0x6FFA579D
             Iat - tquery.dll->msvcrt.dll:??0exception@@QAE@ABQBD@Z - 0x75AF6AFD->0x6FF76AFD
             Iat - tquery.dll->msvcrt.dll:memmove_s - 0x75ADC487->0x6FF5C487
             Iat - tquery.dll->msvcrt.dll:iswalpha - 0x75ADC136->0x6FF5C136
             Iat - tquery.dll->msvcrt.dll:_CIlog - 0x75AE11E5->0x6FF611E5
             Iat - tquery.dll->msvcrt.dll:div - 0x75ADF908->0x6FF5F908
             Iat - tquery.dll->msvcrt.dll:_HUGE - 0x75B73300->0x6FFF3300
             Iat - tquery.dll->msvcrt.dll:_CIsqrt - 0x75ADEEC0->0x6FF5EEC0
             Iat - tquery.dll->msvcrt.dll:_ftol2 - 0x75AD9BA1->0x6FF59BA1
             Iat - tquery.dll->msvcrt.dll:strcspn - 0x75AED099->0x6FF6D099
             Iat - tquery.dll->msvcrt.dll:wcstok - 0x75AE076E->0x6FF6076E
             Iat - tquery.dll->msvcrt.dll:bsearch - 0x75ADB34A->0x6FF5B34A
             Iat - tquery.dll->msvcrt.dll:_ultow - 0x75ADFAB0->0x6FF5FAB0
             Iat - tquery.dll->msvcrt.dll:swprintf - 0x75AFE87C->0x6FF7E87C
             Iat - tquery.dll->msvcrt.dll:_ftol2_sse - 0x75AD9E3A->0x6FF59E3A
             Iat - tquery.dll->msvcrt.dll:wcstol - 0x75ADFF45->0x6FF5FF45
             Iat - tquery.dll->msvcrt.dll:_vsnwprintf - 0x75ADBBCE->0x6FF5BBCE
             Iat - tquery.dll->msvcrt.dll:memcpy - 0x75AD9910->0x6FF59910
             Iat - tquery.dll->msvcrt.dll:memcpy_s - 0x75ADAFBF->0x6FF5AFBF
             Iat - tquery.dll->msvcrt.dll:malloc - 0x75AD9CEE->0x6FF59CEE
             Iat - tquery.dll->msvcrt.dll:__CxxFrameHandler3 - 0x75AF3495->0x6FF73495
             Iat - tquery.dll->msvcrt.dll:wcscat_s - 0x75ADFD66->0x6FF5FD66
             Iat - tquery.dll->msvcrt.dll:wcsncpy_s - 0x75ADC24B->0x6FF5C24B
             Iat - tquery.dll->msvcrt.dll:wcscpy_s - 0x75ADBFD9->0x6FF5BFD9
             Iat - tquery.dll->msvcrt.dll:_CxxThrowException - 0x75AF3557->0x6FF73557
             Iat - tquery.dll->msvcrt.dll:free - 0x75AD9894->0x6FF59894
             Iat - tquery.dll->msvcrt.dll:memset - 0x75AD9790->0x6FF59790
             Iat - tquery.dll->msvcrt.dll:qsort - 0x75ADD3E6->0x6FF5D3E6
             Iat - tquery.dll->ntdll.dll:NtQuerySystemInformation - 0x773D61F8->0x77F06238
             Iat - tquery.dll->ntdll.dll:VerSetConditionMask - 0x773B3050->0x77EE3070
             Iat - tquery.dll->ntdll.dll:EtwEventRegister - 0x773F5ADC->0x77F25B5C
             Iat - tquery.dll->ntdll.dll:EtwEventUnregister - 0x773ED96D->0x77F1DA2D
             Iat - tquery.dll->ntdll.dll:EtwEventWrite - 0x773BD5BA->0x77EED5DA
             Iat - tquery.dll->ntdll.dll:RtlNtStatusToDosError - 0x773E3BF5->0x77F13CB5
             Iat - tquery.dll->ntdll.dll:RtlUpcaseUnicodeChar - 0x773E7497->0x77F17557
             Iat - tquery.dll->ntdll.dll:NtClose - 0x773D54C8->0x77F05508
             Iat - tquery.dll->ntdll.dll:WinSqmIncrementDWORD - 0x773BB1D1->0x77EEB1F1
             Iat - tquery.dll->ntdll.dll:WinSqmAddToStream - 0x773B04C5->0x77EE04E5
             Iat - tquery.dll->ntdll.dll:EtwEventEnabled - 0x773C2083->0x77EF20CF
             Iat - tquery.dll->KERNEL32.dll:SetEndOfFile - 0x764E2BA5->0x77E22BA5
             Iat - tquery.dll->KERNEL32.dll:SetFilePointer - 0x764F060D->0x77E3068D
             Iat - tquery.dll->KERNEL32.dll:FlushFileBuffers - 0x764D84E7->0x77E184E7
             Iat - tquery.dll->KERNEL32.dll:SearchPathW - 0x764E43A5->0x77E243A5
             Iat - tquery.dll->KERNEL32.dll:GetSystemDefaultUILanguage - 0x764D7573->0x77E17573
             Iat - tquery.dll->KERNEL32.dll:GetLocaleInfoW - 0x764EF7C9->0x77E2F849
             Iat - tquery.dll->KERNEL32.dll:FindResourceExW - 0x764E43B2->0x77E243B2
             Iat - tquery.dll->KERNEL32.dll:GetSystemPreferredUILanguages - 0x764D560C->0x77E1560C
             Iat - tquery.dll->KERNEL32.dll:ResolveLocaleName - 0x764D5624->0x77E15624
             Iat - tquery.dll->KERNEL32.dll:LocaleNameToLCID - 0x764E2B4B->0x77E22B4B
             Iat - tquery.dll->KERNEL32.dll:GetUserDefaultUILanguage - 0x764E2B7B->0x77E22B7B
             Iat - tquery.dll->KERNEL32.dll:InitializeCriticalSectionAndSpinCount - 0x764EEA21->0x77E2EA99
             Iat - tquery.dll->KERNEL32.dll:LockResource - 0x764E02D9->0x77E202D9
             Iat - tquery.dll->KERNEL32.dll:ResumeThread - 0x764E16D7->0x77E216D7
             Iat - tquery.dll->KERNEL32.dll:SleepEx - 0x764E0846->0x77E20846
             Iat - tquery.dll->KERNEL32.dll:GetThreadTimes - 0x764D5E8B->0x77E15E8B
             Iat - tquery.dll->KERNEL32.dll:WriteFileEx - 0x7650552D->0x77E455CD
             Iat - tquery.dll->KERNEL32.dll:ReadFileEx - 0x76505515->0x77E455B5
             Iat - tquery.dll->KERNEL32.dll:QueueUserAPC - 0x764D8EB9->0x77E18EB9
             Iat - tquery.dll->KERNEL32.dll:WaitForMultipleObjectsEx - 0x764EBC90->0x77E2BD30
             Iat - tquery.dll->KERNEL32.dll:GlobalFree - 0x764EA13D->0x77E2A1DD
             Iat - tquery.dll->KERNEL32.dll:GlobalUnlock - 0x764EA183->0x77E2A223
             Iat - tquery.dll->KERNEL32.dll:GlobalLock - 0x764EA235->0x77E2A2D5
             Iat - tquery.dll->KERNEL32.dll:GlobalAlloc - 0x764EA125->0x77E2A1C5
             Iat - tquery.dll->KERNEL32.dll:GlobalMemoryStatusEx - 0x764D91F8->0x77E191F8
             Iat - tquery.dll->KERNEL32.dll:GetCalendarInfoA - 0x7650688D->0x77E4692D
             Iat - tquery.dll->KERNEL32.dll:HeapReAlloc - 0x773FFF2F->0x77F2FFAF
             Iat - tquery.dll->KERNEL32.dll:GetProcessHeap - 0x764EFCDD->0x77E2FD5D
             Iat - tquery.dll->KERNEL32.dll:FoldStringW - 0x7650709D->0x77E4713D
             Iat - tquery.dll->KERNEL32.dll:GetCPInfo - 0x764F8E7F->0x77E38EFF
             Iat - tquery.dll->KERNEL32.dll:IsDBCSLeadByteEx - 0x7650683E->0x77E468DE
             Iat - tquery.dll->KERNEL32.dll:GetSystemInfo - 0x764EDCB2->0x77E2DD32
             Iat - tquery.dll->KERNEL32.dll:CreateDirectoryW - 0x764E9989->0x77E29A29
             Iat - tquery.dll->KERNEL32.dll:GetStringTypeW - 0x764F532E->0x77E353AE
             Iat - tquery.dll->KERNEL32.dll:GetProcessAffinityMask - 0x764E2BDD->0x77E22BDD
             Iat - tquery.dll->KERNEL32.dll:CreateTimerQueueTimer - 0x764DBC15->0x77E1BC15
             Iat - tquery.dll->KERNEL32.dll:GetSystemPowerStatus - 0x764DE257->0x77E1E257
             Iat - tquery.dll->KERNEL32.dll:DeleteTimerQueueTimer - 0x764DBC2D->0x77E1BC2D
             Iat - tquery.dll->KERNEL32.dll:TryEnterCriticalSection - 0x773E324C->0x77F1330C
             Iat - tquery.dll->KERNEL32.dll:SetErrorMode - 0x764F0178->0x77E301F8
             Iat - tquery.dll->KERNEL32.dll:QueueUserWorkItem - 0x764E9961->0x77E29A01
             Iat - tquery.dll->KERNEL32.dll:InterlockedExchangeAdd - 0x764E9AA0->0x77E29B40
             Iat - tquery.dll->KERNEL32.dll:SystemTimeToFileTime - 0x764EEA44->0x77E2EABC
             Iat - tquery.dll->KERNEL32.dll:CreateWaitableTimerW - 0x764D6D86->0x77E16D86
             Iat - tquery.dll->KERNEL32.dll:CreateThreadpoolWork - 0x764D8F02->0x77E18F02
             Iat - tquery.dll->KERNEL32.dll:SubmitThreadpoolWork - 0x773A26B9->0x77ED26C9
             Iat - tquery.dll->KERNEL32.dll:CloseThreadpoolWork - 0x773A2121->0x77ED2131
             Iat - tquery.dll->KERNEL32.dll:FreeLibraryWhenCallbackReturns - 0x773A2261->0x77ED2271
             Iat - tquery.dll->KERNEL32.dll:CompareStringOrdinal - 0x764E53CA->0x77E253CA
             Iat - tquery.dll->KERNEL32.dll:SystemTimeToTzSpecificLocalTime - 0x764DB72E->0x77E1B72E
             Iat - tquery.dll->KERNEL32.dll:GetTimeFormatW - 0x764EAFC0->0x77E2B060
             Iat - tquery.dll->KERNEL32.dll:ExpandEnvironmentStringsW - 0x764E43D7->0x77E243D7
             Iat - tquery.dll->KERNEL32.dll:SetUnhandledExceptionFilter - 0x764EF4FB->0x77E2F573
             Iat - tquery.dll->KERNEL32.dll:UnhandledExceptionFilter - 0x76500651->0x77E406F1
             Iat - tquery.dll->KERNEL32.dll:TerminateProcess - 0x764E2BBD->0x77E22BBD
             Iat - tquery.dll->KERNEL32.dll:QueryPerformanceCounter - 0x764EC422->0x77E2C4A2
             Iat - tquery.dll->KERNEL32.dll:GetFileTime - 0x764E16FC->0x77E216FC
             Iat - tquery.dll->KERNEL32.dll:SetThreadPriority - 0x764E44C6->0x77E244C6
             Iat - tquery.dll->KERNEL32.dll:DeleteFileA - 0x764E4382->0x77E24382
             Iat - tquery.dll->KERNEL32.dll:VerifyVersionInfoW - 0x764E14B5->0x77E214B5
             Iat - tquery.dll->KERNEL32.dll:GetVersionExW - 0x764E99A1->0x77E29A41
             Iat - tquery.dll->KERNEL32.dll:lstrlenW - 0x764EBDA0->0x77E2BE40
             Iat - tquery.dll->KERNEL32.dll:RaiseException - 0x764DF11A->0x77E1F11A
             Iat - tquery.dll->KERNEL32.dll:EnterCriticalSection - 0x773D7720->0x77F077E0
             Iat - tquery.dll->KERNEL32.dll:LeaveCriticalSection - 0x773D76E0->0x77F077A0
             Iat - tquery.dll->KERNEL32.dll:InitializeCriticalSection - 0x773EA0D9->0x77F1A199
             Iat - tquery.dll->KERNEL32.dll:DeleteCriticalSection - 0x773E9A55->0x77F19B15
             Iat - tquery.dll->KERNEL32.dll:GetLastError - 0x764ECDE0->0x77E2CE60
             Iat - tquery.dll->KERNEL32.dll:LoadLibraryW - 0x764EEF42->0x77E2EFBA
             Iat - tquery.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x77E2CD14
             Iat - tquery.dll->KERNEL32.dll:GetModuleHandleW - 0x764ECCAC->0x77E2CD2C
             Iat - tquery.dll->KERNEL32.dll:FreeLibrary - 0x764EEF67->0x77E2EFDF
             Iat - tquery.dll->KERNEL32.dll:WideCharToMultiByte - 0x764EEEFA->0x77E2EF72
             Iat - tquery.dll->KERNEL32.dll:InterlockedIncrement - 0x764EC3B0->0x77E2C430
             Iat - tquery.dll->KERNEL32.dll:InterlockedDecrement - 0x764EC3E0->0x77E2C460
             Iat - tquery.dll->KERNEL32.dll:GetModuleFileNameW - 0x764EEF35->0x77E2EFAD
             Iat - tquery.dll->KERNEL32.dll:LoadLibraryExW - 0x764E5079->0x77E25079
             Iat - tquery.dll->KERNEL32.dll:DisableThreadLibraryCalls - 0x764EDA8C->0x77E2DB0C
             Iat - tquery.dll->KERNEL32.dll:lstrcmpiW - 0x764EAAD7->0x77E2AB77
             Iat - tquery.dll->KERNEL32.dll:MultiByteToWideChar - 0x764EEF07->0x77E2EF7F
             Iat - tquery.dll->KERNEL32.dll:SizeofResource - 0x764E54ED->0x77E254ED
             Iat - tquery.dll->KERNEL32.dll:LoadResource - 0x764E9C72->0x77E29D12
             Iat - tquery.dll->KERNEL32.dll:FindResourceW - 0x764E54CF->0x77E254CF
             Iat - tquery.dll->KERNEL32.dll:CloseHandle - 0x764EE868->0x77E2E8E0
             Iat - tquery.dll->KERNEL32.dll:MapViewOfFile - 0x764E93DB->0x77E2947B
             Iat - tquery.dll->KERNEL32.dll:OpenFileMappingW - 0x764F50EA->0x77E3516A
             Iat - tquery.dll->KERNEL32.dll:UnmapViewOfFile - 0x764EF73C->0x77E2F7B4
             Iat - tquery.dll->KERNEL32.dll:DelayLoadFailureHook - 0x764C01FC->0x77E001FC
             Iat - tquery.dll->KERNEL32.dll:InterlockedCompareExchange - 0x764EC3FB->0x77E2C47B
             Iat - tquery.dll->KERNEL32.dll:LoadLibraryExA - 0x764E4466->0x77E24466
             Iat - tquery.dll->KERNEL32.dll:DeviceIoControl - 0x764EB925->0x77E2B9C5
             Iat - tquery.dll->KERNEL32.dll:CreateFileW - 0x764EE8A5->0x77E2E91D
             Iat - tquery.dll->KERNEL32.dll:GetDiskFreeSpaceW - 0x764D3C3C->0x77E13C3C
             Iat - tquery.dll->KERNEL32.dll:GetDiskFreeSpaceExW - 0x764E9949->0x77E299E9
             Iat - tquery.dll->KERNEL32.dll:LCMapStringW - 0x764F528C->0x77E3530C
             Iat - tquery.dll->KERNEL32.dll:WaitForSingleObjectEx - 0x764EC2B0->0x77E2C330
             Iat - tquery.dll->KERNEL32.dll:SetEvent - 0x764EBD5C->0x77E2BDFC
             Iat - tquery.dll->KERNEL32.dll:ResetEvent - 0x764EBD44->0x77E2BDE4
             Iat - tquery.dll->KERNEL32.dll:CreateEventW - 0x764ED7BC->0x77E2D83C
             Iat - tquery.dll->KERNEL32.dll:FindFirstFileW - 0x764F404C->0x77E340CC
             Iat - tquery.dll->KERNEL32.dll:FindClose - 0x764F4C24->0x77E34CA4
             Iat - tquery.dll->KERNEL32.dll:GetCurrentThreadId - 0x764EC410->0x77E2C490
             Iat - tquery.dll->KERNEL32.dll:GetFileAttributesW - 0x764F4C14->0x77E34C94
             Iat - tquery.dll->KERNEL32.dll:SetLastError - 0x764EC3F0->0x77E2C470
             Iat - tquery.dll->KERNEL32.dll:DeleteFileW - 0x764E16EF->0x77E216EF
             Iat - tquery.dll->KERNEL32.dll:CreateThread - 0x764EDCC2->0x77E2DD42
             Iat - tquery.dll->KERNEL32.dll:FindNextFileW - 0x764E9B4E->0x77E29BEE
             Iat - tquery.dll->KERNEL32.dll:CopyFileExW - 0x764DB238->0x77E1B238
             Iat - tquery.dll->KERNEL32.dll:VirtualFree - 0x764F6B15->0x77E36B95
             Iat - tquery.dll->KERNEL32.dll:VirtualAlloc - 0x764EC43A->0x77E2C4BA
             Iat - tquery.dll->KERNEL32.dll:WriteFile - 0x764F53EE->0x77E3546E
             Iat - tquery.dll->KERNEL32.dll:ReadFile - 0x764E9B66->0x77E29C06
             Iat - tquery.dll->KERNEL32.dll:GetFileInformationByHandle - 0x764EBDAD->0x77E2BE4D
             Iat - tquery.dll->KERNEL32.dll:CompareStringW - 0x764EA01A->0x77E2A0BA
             Iat - tquery.dll->KERNEL32.dll:GetSystemDefaultLCID - 0x764E78AA->0x77E278AA
             Iat - tquery.dll->KERNEL32.dll:GetUserDefaultLCID - 0x764EF7B7->0x77E2F837
             Iat - tquery.dll->KERNEL32.dll:GetNLSVersion - 0x764D477E->0x77E1477E
             Iat - tquery.dll->KERNEL32.dll:GetModuleHandleExW - 0x764E54B7->0x77E254B7
             Iat - tquery.dll->KERNEL32.dll:OutputDebugStringW - 0x764D6DF2->0x77E16DF2
             Iat - tquery.dll->KERNEL32.dll:GetTickCount - 0x764EC260->0x77E2C2E0
             Iat - tquery.dll->KERNEL32.dll:IsValidLocale - 0x764E44EB->0x77E244EB
             Iat - tquery.dll->KERNEL32.dll:SetCurrentDirectoryW - 0x764F6BEE->0x77E36C6E
             Iat - tquery.dll->KERNEL32.dll:HeapCreate - 0x764EEF74->0x77E2EFEC
             Iat - tquery.dll->KERNEL32.dll:HeapDestroy - 0x764E2B8D->0x77E22B8D
             Iat - tquery.dll->KERNEL32.dll:GetCurrentProcess - 0x764ED7A0->0x77E2D820
             Iat - tquery.dll->KERNEL32.dll:GetOverlappedResult - 0x764E3629->0x77E23629
             Iat - tquery.dll->KERNEL32.dll:CancelIo - 0x765012BE->0x77E4135E
             Iat - tquery.dll->KERNEL32.dll:GetTickCount64 - 0x764DF108->0x77E1F108
             Iat - tquery.dll->KERNEL32.dll:WaitForMultipleObjects - 0x764EBD74->0x77E2BE14
             Iat - tquery.dll->KERNEL32.dll:WaitForSingleObject - 0x764EC290->0x77E2C310
             Iat - tquery.dll->KERNEL32.dll:GetComputerNameW - 0x764E09C7->0x77E209C7
             Iat - tquery.dll->KERNEL32.dll:HeapAlloc - 0x773E2D66->0x77F12E26
             Iat - tquery.dll->KERNEL32.dll:HeapFree - 0x764EC3C0->0x77E2C440
             Iat - tquery.dll->KERNEL32.dll:HeapSize - 0x773E9B7C->0x77F19C3C
             Iat - tquery.dll->KERNEL32.dll:FormatMessageW - 0x764E8DD0->0x77E28E70
             Iat - tquery.dll->KERNEL32.dll:InterlockedExchange - 0x764EC452->0x77E2C4D2
             Iat - tquery.dll->KERNEL32.dll:CreateFileMappingW - 0x764E120C->0x77E2120C
             Iat - tquery.dll->KERNEL32.dll:Sleep - 0x764EC246->0x77E2C2C6
             Iat - tquery.dll->KERNEL32.dll:CompareFileTime - 0x764F617E->0x77E361FE
             Iat - tquery.dll->KERNEL32.dll:lstrcmpW - 0x764F5321->0x77E353A1
             Iat - tquery.dll->KERNEL32.dll:GetSystemTimeAsFileTime - 0x764ED816->0x77E2D896
             Iat - tquery.dll->KERNEL32.dll:GetCurrentThread - 0x764ED799->0x77E2D819
             Iat - tquery.dll->KERNEL32.dll:FileTimeToSystemTime - 0x764EBDC5->0x77E2BE65
             Iat - tquery.dll->KERNEL32.dll:FileTimeToLocalFileTime - 0x764EBDDD->0x77E2BE7D
             Iat - tquery.dll->KERNEL32.dll:GetSystemDirectoryW - 0x764EEE37->0x77E2EEAF
             Iat - tquery.dll->KERNEL32.dll:LocalFree - 0x764ECBFC->0x77E2CC7C
             Iat - tquery.dll->KERNEL32.dll:GetVersionExA - 0x764EDD80->0x77E2DE00
             Iat - tquery.dll->KERNEL32.dll:OutputDebugStringA - 0x764DF0F0->0x77E1F0F0
             Iat - tquery.dll->KERNEL32.dll:CreateFileA - 0x764EEA61->0x77E2EAD9
             Iat - tquery.dll->KERNEL32.dll:GetCurrentProcessId - 0x764ED7B5->0x77E2D835
             Iat - tquery.dll->KERNEL32.dll:GetLocalTime - 0x764EAAEF->0x77E2AB8F
             Iat - tquery.dll->KERNEL32.dll:FlushViewOfFile - 0x764D8893->0x77E18893
             Iat - tquery.dll->KERNEL32.dll:GetStringTypeExW - 0x764DC438->0x77E1C438
             Iat - tquery.dll->KERNEL32.dll:CopyFileA - 0x76506D5A->0x77E46DFA
             Iat - tquery.dll->KERNEL32.dll:lstrlenA - 0x764EA032->0x77E2A0D2
             Iat - tquery.dll->KERNEL32.dll:ReleaseMutex - 0x764EC272->0x77E2C2F2
             Iat - tquery.dll->KERNEL32.dll:CreateMutexA - 0x764ED7D4->0x77E2D854
             Iat - tquery.dll->KERNEL32.dll:CompareStringA - 0x764E16B4->0x77E216B4
             Iat - tquery.dll->KERNEL32.dll:GetFileSize - 0x764E0823->0x77E20823
             Iat - tquery.dll->USER32.dll:LoadStringW - 0x75B8DFBA->0x77D1DFBA
             Iat - tquery.dll->USER32.dll:UnregisterClassA - 0x75B88D70->0x77D18D70
             Iat - tquery.dll->USER32.dll:CharLowerW - 0x75B8BA8A->0x77D1BA8A
             Iat - tquery.dll->USER32.dll:CharUpperW - 0x75B9E981->0x77D2E981
             Iat - tquery.dll->USER32.dll:CharLowerBuffW - 0x75B93AFE->0x77D23AFE
             Iat - tquery.dll->USER32.dll:LoadImageW - 0x75B912EB->0x77D212EB
             Iat - tquery.dll->USER32.dll:CharNextW - 0x75B90BE6->0x77D20BE6
             Iat - tquery.dll->USER32.dll:LoadMenuW - 0x75B8F214->0x77D1F214
             Iat - tquery.dll->ole32.dll:StringFromGUID2 - 0x762222EC->0x7258234C
             Iat - tquery.dll->ole32.dll:CoCreateInstance - 0x76229D0B->0x72589D8F
             Iat - tquery.dll->ole32.dll:CoTaskMemAlloc - 0x7622EA4C->0x7258EACC
             Iat - tquery.dll->ole32.dll:CoTaskMemRealloc - 0x7621EE39->0x7257EE8D
             Iat - tquery.dll->ole32.dll:CoTaskMemFree - 0x76236F41->0x72596FB1
             Iat - tquery.dll->ole32.dll:CreateStreamOnHGlobal - 0x7620363B->0x7256362B
             Iat - tquery.dll->ole32.dll:CoCreateFreeThreadedMarshaler - 0x761FE452->0x7255E46A
             Iat - tquery.dll->ole32.dll:CoFileTimeNow - 0x76254284->0x725B4324
             Iat - tquery.dll->ole32.dll:PropVariantClear - 0x76223D79->0x72583DD9
             Iat - tquery.dll->ole32.dll:CoGetMalloc - 0x76226265->0x725862C5
             Iat - tquery.dll->ole32.dll:CoGetClassObject - 0x762154AD->0x7257548D
             Iat - tquery.dll->ole32.dll:PropVariantCopy - 0x7621B9C5->0x7257BA05
             Iat - tquery.dll->ole32.dll:CLSIDFromString - 0x761FE599->0x7255E5B1
             Iat - tquery.dll->ole32.dll:StringFromCLSID - 0x761FEB17->0x7255EB2F
             Iat - tquery.dll->ole32.dll:CLSIDFromProgID - 0x7620503C->0x72565030
             Iat - tquery.dll->SHLWAPI.dll:PathRemoveFileSpecW - 0x77573248->0x6DE33260
             Iat - tquery.dll->SHLWAPI.dll:PathAppendW - 0x775781EF->0x6DE3821B
             Iat - tquery.dll->SHLWAPI.dll:PathIsDirectoryW - 0x7756FF07->0x6DE2FF1F
             Iat - tquery.dll->SHLWAPI.dll:SHRegGetValueW - 0x7757B8BA->0x6DE3B8D6
             Iat - tquery.dll->SHLWAPI.dll:SHSetValueW - 0x7757170C->0x6DE31724
             Iat - tquery.dll->SHLWAPI.dll:PathFindExtensionW - 0x7757A1B9->0x6DE3A1D5
             Iat - tquery.dll->SHLWAPI.dll:SHGetValueW - 0x7757A955->0x6DE3A971
             Iat - tquery.dll->SHLWAPI.dll:PathIsSameRootW - 0x7758FC97->0x6DE4FCAF
             Iat - tquery.dll->SHLWAPI.dll:PathIsRootW - 0x77575BFC->0x6DE35C24
             Iat - tquery.dll->SHLWAPI.dll:PathFindFileNameW - 0x7757BB71->0x6DE3BB8D
             Iat - wevtapi.dll->ntdll.dll:NtWriteFile - 0x773D6A68->0x77F05EB0
             Iat - wevtapi.dll->ntdll.dll:NtReadFile - 0x773D62B8->0x77F05700
             Iat - wevtapi.dll->ntdll.dll:RtlSetLastWin32ErrorAndNtStatusFromNtStatus - 0x7740339D->0x77F2E980
             Iat - wevtapi.dll->ntdll.dll:RtlSetLastWin32Error - 0x773E308B->0x77F123C2
             Iat - wevtapi.dll->ntdll.dll:RtlNtStatusToDosError - 0x773E3BF5->0x77F13AF5
             Iat - wevtapi.dll->ntdll.dll:EtwGetTraceEnableFlags - 0x773B8B55->0x77EEA4CA
             Iat - wevtapi.dll->ntdll.dll:EtwGetTraceEnableLevel - 0x773B8B1F->0x77EEA494
             Iat - wevtapi.dll->ntdll.dll:EtwGetTraceLoggerHandle - 0x773B8AB6->0x77EEA42B
             Iat - wevtapi.dll->ntdll.dll:EtwRegisterTraceGuidsW - 0x773B867A->0x77EE9627
             Iat - wevtapi.dll->ntdll.dll:EtwUnregisterTraceGuids - 0x773BB085->0x77EF17AD
             Iat - wevtapi.dll->ntdll.dll:EtwTraceMessage - 0x773BE41F->0x77EF18F3
             Iat - wevtapi.dll->msvcrt.dll:_except_handler4_common - 0x75AF3E27->0x6FF73E27
             Iat - wevtapi.dll->msvcrt.dll:?terminate@@YAXXZ - 0x75B261CF->0x6FFA61CF
             Iat - wevtapi.dll->msvcrt.dll:_onexit - 0x75AE112D->0x6FF6112D
             Iat - wevtapi.dll->msvcrt.dll:_lock - 0x75ADA449->0x6FF5A449
             Iat - wevtapi.dll->msvcrt.dll:__dllonexit - 0x75ADF509->0x6FF5F509
             Iat - wevtapi.dll->msvcrt.dll:_unlock - 0x75ADA42D->0x6FF5A42D
             Iat - wevtapi.dll->msvcrt.dll:??1type_info@@UAE@XZ - 0x75B292B3->0x6FFA92B3
             Iat - wevtapi.dll->msvcrt.dll:_amsg_exit - 0x75B3B2EF->0x6FFBB2EF
             Iat - wevtapi.dll->msvcrt.dll:_initterm - 0x75ADC151->0x6FF5C151
             Iat - wevtapi.dll->msvcrt.dll:free - 0x75AD9894->0x6FF59894
             Iat - wevtapi.dll->msvcrt.dll:malloc - 0x75AD9CEE->0x6FF59CEE
             Iat - wevtapi.dll->msvcrt.dll:_XcptFilter - 0x75AFDC75->0x6FF7DC75
             Iat - wevtapi.dll->msvcrt.dll:_wtoi - 0x75ADC823->0x6FF5C823
             Iat - wevtapi.dll->msvcrt.dll:iswspace - 0x75ADAACB->0x6FF5AACB
             Iat - wevtapi.dll->msvcrt.dll:wcsncpy_s - 0x75ADC24B->0x6FF5C24B
             Iat - wevtapi.dll->msvcrt.dll:_wcsnicmp - 0x75ADAAE3->0x6FF5AAE3
             Iat - wevtapi.dll->msvcrt.dll:??0exception@@QAE@XZ - 0x75AE14F9->0x6FF614F9
             Iat - wevtapi.dll->msvcrt.dll:memset - 0x75AD9790->0x6FF59790
             Iat - wevtapi.dll->msvcrt.dll:memcpy_s - 0x75ADAFBF->0x6FF5AFBF
             Iat - wevtapi.dll->msvcrt.dll:memmove_s - 0x75ADC487->0x6FF5C487
             Iat - wevtapi.dll->msvcrt.dll:??0exception@@QAE@ABV0@@Z - 0x75B256C5->0x6FFA56C5
             Iat - wevtapi.dll->msvcrt.dll:??1exception@@UAE@XZ - 0x75AE14E3->0x6FF614E3
             Iat - wevtapi.dll->msvcrt.dll:?what@exception@@UBEPBDXZ - 0x75B2579D->0x6FFA579D
             Iat - wevtapi.dll->msvcrt.dll:??0exception@@QAE@ABQBD@Z - 0x75AF6AFD->0x6FF76AFD
             Iat - wevtapi.dll->msvcrt.dll:memcpy - 0x75AD9910->0x6FF59910
             Iat - wevtapi.dll->msvcrt.dll:_CxxThrowException - 0x75AF3557->0x6FF73557
             Iat - wevtapi.dll->msvcrt.dll:_purecall - 0x75B36EA9->0x6FFB6EA9
             Iat - wevtapi.dll->msvcrt.dll:__CxxFrameHandler3 - 0x75AF3495->0x6FF73495
             Iat - wevtapi.dll->msvcrt.dll:_wcstoi64 - 0x75AE05FD->0x6FF605FD
             Iat - wevtapi.dll->msvcrt.dll:_wsplitpath_s - 0x75AE473A->0x6FF6473A
             Iat - wevtapi.dll->msvcrt.dll:_wcsicmp - 0x75ADA9E9->0x6FF5A9E9
             Iat - wevtapi.dll->msvcrt.dll:swscanf_s - 0x75AF3031->0x6FF73031
             Iat - wevtapi.dll->msvcrt.dll:wcsrchr - 0x75ADA73F->0x6FF5A73F
             Iat - wevtapi.dll->msvcrt.dll:swprintf_s - 0x75ADECF8->0x6FF5ECF8
             Iat - wevtapi.dll->msvcrt.dll:abort - 0x75B38E53->0x6FFB8E53
             Iat - wevtapi.dll->msvcrt.dll:_itow - 0x75AE019C->0x6FF6019C
             Iat - wevtapi.dll->msvcrt.dll:_ultow - 0x75ADFAB0->0x6FF5FAB0
             Iat - wevtapi.dll->msvcrt.dll:_i64tow - 0x75AEC065->0x6FF6C065
             Iat - wevtapi.dll->msvcrt.dll:_ui64tow - 0x75AE0885->0x6FF60885
             Iat - wevtapi.dll->msvcrt.dll:iswdigit - 0x75ADC02C->0x6FF5C02C
             Iat - wevtapi.dll->msvcrt.dll:_wtol - 0x75ADC7C8->0x6FF5C7C8
             Iat - wevtapi.dll->msvcrt.dll:_wtoi64 - 0x75AE062E->0x6FF6062E
             Iat - wevtapi.dll->msvcrt.dll:wcschr - 0x75ADAA61->0x6FF5AA61
             Iat - wevtapi.dll->msvcrt.dll:iswalnum - 0x75ADF949->0x6FF5F949
             Iat - wevtapi.dll->msvcrt.dll:iswalpha - 0x75ADC136->0x6FF5C136
             Iat - wevtapi.dll->msvcrt.dll:_vsnwprintf - 0x75ADBBCE->0x6FF5BBCE
             Iat - wevtapi.dll->msvcrt.dll:_wtof - 0x75AEF70A->0x6FF6F70A
             Iat - wevtapi.dll->msvcrt.dll:_wcstoui64 - 0x75ADD836->0x6FF5D836
             Iat - wevtapi.dll->KERNEL32.dll:SetEndOfFile - 0x764E2BA5->0x77E24502
             Iat - wevtapi.dll->KERNEL32.dll:InitializeConditionVariable - 0x773E9911->0x77F19B8E
             Iat - wevtapi.dll->KERNEL32.dll:GetTempFileNameW - 0x764D7039->0x77E191F5
             Iat - wevtapi.dll->KERNEL32.dll:MoveFileW - 0x76506ED6->0x77E1A173
             Iat - wevtapi.dll->KERNEL32.dll:GetDiskFreeSpaceExW - 0x764E9949->0x77E21FC3
             Iat - wevtapi.dll->KERNEL32.dll:WaitForThreadpoolTimerCallbacks - 0x773AC04A->0x77ECF583
             Iat - wevtapi.dll->KERNEL32.dll:CloseThreadpoolTimer - 0x773AC0F2->0x77ED7B3C
             Iat - wevtapi.dll->KERNEL32.dll:CreateThreadpoolTimer - 0x764DB5EE->0x77E1E295
             Iat - wevtapi.dll->KERNEL32.dll:SleepConditionVariableCS - 0x764D2EAC->0x77E11E70
             Iat - wevtapi.dll->KERNEL32.dll:WakeAllConditionVariable - 0x773B45C5->0x77EF0E3E
             Iat - wevtapi.dll->KERNEL32.dll:GetTickCount64 - 0x764DF108->0x77E1E0CB
             Iat - wevtapi.dll->KERNEL32.dll:DeleteFileW - 0x764E16EF->0x77E2656B
             Iat - wevtapi.dll->KERNEL32.dll:SetThreadpoolTimer - 0x773B89DE->0x77EE8AC6
             Iat - wevtapi.dll->KERNEL32.dll:GetFileAttributesW - 0x764F4C14->0x77E313CE
             Iat - wevtapi.dll->KERNEL32.dll:CreateFileW - 0x764EE8A5->0x77E30B5D
             Iat - wevtapi.dll->KERNEL32.dll:WriteFile - 0x764F53EE->0x77E311CC
             Iat - wevtapi.dll->KERNEL32.dll:ReadFile - 0x764E9B66->0x77E2DAA9
             Iat - wevtapi.dll->KERNEL32.dll:GetFileInformationByHandle - 0x764EBDAD->0x77E30CFE
             Iat - wevtapi.dll->KERNEL32.dll:GetFileSizeEx - 0x764E99B1->0x77E2CA51
             Iat - wevtapi.dll->KERNEL32.dll:SetFilePointerEx - 0x764DFB6A->0x77E22A2A
             Iat - wevtapi.dll->KERNEL32.dll:FlushFileBuffers - 0x764D84E7->0x77E1C112
             Iat - wevtapi.dll->KERNEL32.dll:SystemTimeToFileTime - 0x764EEA44->0x77E32997
             Iat - wevtapi.dll->KERNEL32.dll:FileTimeToSystemTime - 0x764EBDC5->0x77E31239
             Iat - wevtapi.dll->KERNEL32.dll:InterlockedIncrement - 0x764EC3B0->0x77E2F188
             Iat - wevtapi.dll->KERNEL32.dll:InterlockedDecrement - 0x764EC3E0->0x77E2F15B
             Iat - wevtapi.dll->KERNEL32.dll:DeleteCriticalSection - 0x773E9A55->0x77F17B5B
             Iat - wevtapi.dll->KERNEL32.dll:LeaveCriticalSection - 0x773D76E0->0x77F06B40
             Iat - wevtapi.dll->KERNEL32.dll:HeapFree - 0x764EC3C0->0x77E2F198
             Iat - wevtapi.dll->KERNEL32.dll:HeapAlloc - 0x773E2D66->0x77F1209D
             Iat - wevtapi.dll->KERNEL32.dll:InterlockedExchange - 0x764EC452->0x77E2F25E
             Iat - wevtapi.dll->KERNEL32.dll:GetLocaleInfoW - 0x764EF7C9->0x77E3354A
             Iat - wevtapi.dll->KERNEL32.dll:GetThreadLocale - 0x764E1CE3->0x77E26452
             Iat - wevtapi.dll->KERNEL32.dll:lstrcmpiW - 0x764EAAD7->0x77E2DB75
             Iat - wevtapi.dll->KERNEL32.dll:GetThreadUILanguage - 0x764DB3B7->0x77E17C49
             Iat - wevtapi.dll->KERNEL32.dll:TlsAlloc - 0x764ED804->0x77E32962
             Iat - wevtapi.dll->KERNEL32.dll:TlsFree - 0x764F5259->0x77E32A9F
             Iat - wevtapi.dll->KERNEL32.dll:SetLastError - 0x764EC3F0->0x77E2F17D
             Iat - wevtapi.dll->KERNEL32.dll:GetProcessHeap - 0x764EFCDD->0x77E2F24C
             Iat - wevtapi.dll->KERNEL32.dll:GetLastError - 0x764ECDE0->0x77E2F176
             Iat - wevtapi.dll->KERNEL32.dll:ExpandEnvironmentStringsW - 0x764E43D7->0x77E2B606
             Iat - wevtapi.dll->KERNEL32.dll:GetFullPathNameW - 0x764EF6D7->0x77E319D1
             Iat - wevtapi.dll->KERNEL32.dll:Sleep - 0x764EC246->0x77E2EF66
             Iat - wevtapi.dll->KERNEL32.dll:TlsGetValue - 0x764EF760->0x77E2F084
             Iat - wevtapi.dll->KERNEL32.dll:TlsSetValue - 0x764EF783->0x77E2F551
             Iat - wevtapi.dll->KERNEL32.dll:LocalFree - 0x764ECBFC->0x77E3057C
             Iat - wevtapi.dll->KERNEL32.dll:FormatMessageW - 0x764E8DD0->0x77E2B65C
             Iat - wevtapi.dll->KERNEL32.dll:CloseHandle - 0x764EE868->0x77E305B7
             Iat - wevtapi.dll->KERNEL32.dll:SubmitThreadpoolWork - 0x773A26B9->0x77ED6D3D
             Iat - wevtapi.dll->KERNEL32.dll:UnregisterWaitEx - 0x764D5B02->0x77E18052
             Iat - wevtapi.dll->KERNEL32.dll:WaitForSingleObject - 0x764EC290->0x77E2EFA0
             Iat - wevtapi.dll->KERNEL32.dll:GetCurrentThreadId - 0x764EC410->0x77E2F212
             Iat - wevtapi.dll->KERNEL32.dll:SetEvent - 0x764EBD5C->0x77E2F26E
             Iat - wevtapi.dll->KERNEL32.dll:ResetEvent - 0x764EBD44->0x77E2F224
             Iat - wevtapi.dll->KERNEL32.dll:RegisterWaitForSingleObject - 0x764DB93C->0x77E1E105
             Iat - wevtapi.dll->KERNEL32.dll:CreateEventW - 0x764ED7BC->0x77E30613
             Iat - wevtapi.dll->KERNEL32.dll:DuplicateHandle - 0x764ED888->0x77E30636
             Iat - wevtapi.dll->KERNEL32.dll:GetCurrentProcess - 0x764ED7A0->0x77E3060C
             Iat - wevtapi.dll->KERNEL32.dll:DelayLoadFailureHook - 0x764C01FC->0x77E001A4
             Iat - wevtapi.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x77E31837
             Iat - wevtapi.dll->KERNEL32.dll:FreeLibrary - 0x764EEF67->0x77E319E9
             Iat - wevtapi.dll->KERNEL32.dll:InterlockedCompareExchange - 0x764EC3FB->0x77E2F23C
             Iat - wevtapi.dll->KERNEL32.dll:LoadLibraryExA - 0x764E4466->0x77E2BC8B
             Iat - wevtapi.dll->KERNEL32.dll:OutputDebugStringA - 0x764DF0F0->0x77E216A2
             Iat - wevtapi.dll->KERNEL32.dll:QueryPerformanceCounter - 0x764EC422->0x77E2F2A7
             Iat - wevtapi.dll->KERNEL32.dll:GetTickCount - 0x764EC260->0x77E2EF76
             Iat - wevtapi.dll->KERNEL32.dll:GetCurrentProcessId - 0x764ED7B5->0x77E30D23
             Iat - wevtapi.dll->KERNEL32.dll:GetSystemTimeAsFileTime - 0x764ED816->0x77E2FE44
             Iat - wevtapi.dll->KERNEL32.dll:TerminateProcess - 0x764E2BBD->0x77E2509B
             Iat - wevtapi.dll->KERNEL32.dll:UnhandledExceptionFilter - 0x76500651->0x77E42B35
             Iat - wevtapi.dll->KERNEL32.dll:SetUnhandledExceptionFilter - 0x764EF4FB->0x77E33142
             Iat - wevtapi.dll->KERNEL32.dll:DebugBreak - 0x7652FB1D->0x77E6F42D
             Iat - wevtapi.dll->KERNEL32.dll:InitializeCriticalSectionAndSpinCount - 0x764EEA21->0x77E30D0B
             Iat - wevtapi.dll->KERNEL32.dll:EnterCriticalSection - 0x773D7720->0x77F06B7E
             Iat - wevtapi.dll->KERNEL32.dll:LocalAlloc - 0x764ECC66->0x77E30594
             Iat - wevtapi.dll->KERNEL32.dll:WideCharToMultiByte - 0x764EEEFA->0x77E30F86
             Iat - wevtapi.dll->KERNEL32.dll:MultiByteToWideChar - 0x764EEF07->0x77E30E69
             Iat - wevtapi.dll->KERNEL32.dll:CloseThreadpoolWork - 0x773A2121->0x77ED6F39
             Iat - wevtapi.dll->KERNEL32.dll:FreeLibraryWhenCallbackReturns - 0x773A2261->0x77ED7077
             Iat - wevtapi.dll->KERNEL32.dll:CreateThreadpoolCleanupGroup - 0x764D8ED1->0x77E1E2CE
             Iat - wevtapi.dll->KERNEL32.dll:CloseThreadpoolCleanupGroup - 0x77399939->0x77ECC29D
             Iat - wevtapi.dll->KERNEL32.dll:CreateThreadpoolWork - 0x764D8F02->0x77E1E425
             Iat - wevtapi.dll->KERNEL32.dll:GetModuleHandleExW - 0x764E54B7->0x77E28B60

------------------------------------------------------------------------------------------

      Image File Name[976 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x005E01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x005E0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x005E0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x005E03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x005E0A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1520 wmpnetwk.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00130C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00130E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00130804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00130A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001301F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001303FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00130600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00131014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001401F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00140600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00140804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001403FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00140A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[2228 taskhost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000501F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000503FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000701F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00070600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00070804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000703FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00070A08

------------------------------------------------------------------------------------------

      Image File Name[3452 chrome.exe]Process Hook
             Iat - chrome.exe->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000901F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000903FC
             inline - len(6) ntdll.dll->NtCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->NtMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->NtOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->NtOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->NtOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->NtOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->NtOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->NtOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->NtOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->NtQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->NtQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->NtSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->NtSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->NtUnmapViewOfSection - 0x773D69BE->_
             inline - len(6) ntdll.dll->ZwCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->ZwMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->ZwOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->ZwOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->ZwOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->ZwOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->ZwOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->ZwOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->ZwOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->ZwQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->ZwQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->ZwSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->ZwSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->ZwUnmapViewOfSection - 0x773D69BE->_
             Eat - kernel32.dll->CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(4) kernel32.dll - 0x76555474->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x002301F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00230600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00230804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x002303FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00230A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00240C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00240E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00240804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00240A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x002401F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x002403FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00240600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00241014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - chrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             Iat - pdf.dll->GDI32.dll:GetFontData - 0x75FEBCC4->0x5D94791E[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]
             Iat - ppGoogleNaClPluginChrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(4) avcodec-53.dll->avcodec_get_chroma_sub_sample - 0x60D9E61D->_
             inline - len(4) avcodec-53.dll->ff_is_hwaccel_pix_fmt - 0x60D9E65A->_
             inline - len(4) avcodec-53.dll - 0x60CF9D90->_
             inline - len(4) avcodec-53.dll - 0x60D04E7C->_
             inline - len(4) avcodec-53.dll - 0x60D04E8B->_
             inline - len(4) avcodec-53.dll - 0x60D04EA2->_
             inline - len(4) avcodec-53.dll - 0x60D04EB3->_
             inline - len(4) avcodec-53.dll - 0x60D05060->_
             inline - len(4) avcodec-53.dll - 0x60D05071->_
             inline - len(4) avcodec-53.dll - 0x60D0507D->_
             inline - len(4) avcodec-53.dll - 0x60D05099->_
             inline - len(4) avcodec-53.dll - 0x60D05531->_
             inline - len(4) avcodec-53.dll - 0x60D0553B->_
             inline - len(4) avcodec-53.dll - 0x60D05547->_
             inline - len(4) avcodec-53.dll - 0x60D0555E->_
             inline - len(4) avcodec-53.dll - 0x60D0572C->_
             inline - len(4) avcodec-53.dll - 0x60D05740->_
             inline - len(4) avcodec-53.dll - 0x60D0574E->_
             inline - len(4) avcodec-53.dll - 0x60D05767->_
             inline - len(4) avcodec-53.dll - 0x60D9E825->_
             inline - len(4) avcodec-53.dll - 0x60D9E843->_
             inline - len(4) avcodec-53.dll - 0x60D9E90A->_
             inline - len(4) avcodec-53.dll - 0x60D9E91C->_
             inline - len(10) avcodec-53.dll - 0x60D9E9DC->_
             inline - len(4) avcodec-53.dll - 0x60D9EB8A->_
             inline - len(4) avcodec-53.dll - 0x60D9EB9B->_
             inline - len(4) avcodec-53.dll - 0x60D9EBA9->_
             inline - len(4) avcodec-53.dll - 0x60D9F153->_
             inline - len(4) avcodec-53.dll - 0x60D9F52E->_
             inline - len(4) avcodec-53.dll - 0x60DAC60D->_
             inline - len(4) avcodec-53.dll - 0x60DAC71C->_
             inline - len(4) avcodec-53.dll - 0x60DAC788->_
             inline - len(4) avcodec-53.dll - 0x60DAC7B0->_
             inline - len(4) avcodec-53.dll - 0x60DAC7F7->_
             inline - len(4) avcodec-53.dll - 0x60DB8FA5->_
             inline - len(4) avcodec-53.dll - 0x60DBD37B->_
             inline - len(11) avcodec-53.dll - 0x60DBEE40->_
             inline - len(4) avcodec-53.dll - 0x60DC0B41->_
             inline - len(4) avcodec-53.dll - 0x60DC44DE->_
             inline - len(4) avcodec-53.dll - 0x60DC687C->_
             inline - len(4) avformat-53.dll - 0x71825CF1->_
             inline - len(3) avformat-53.dll - 0x71826034->_
             inline - len(4) avformat-53.dll - 0x7182A02D->_
             inline - len(4) avformat-53.dll - 0x7182A044->_
             inline - len(4) avformat-53.dll - 0x7182A0F0->_
             inline - len(4) avformat-53.dll - 0x7182A105->_
             inline - len(4) avformat-53.dll - 0x7183EC9B->_

------------------------------------------------------------------------------------------

      Image File Name[1176 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x006901F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00690600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00690804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x006903FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00690A08

------------------------------------------------------------------------------------------

      Image File Name[1204 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00130C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00130E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00130804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00130A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001301F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001303FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00130600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00131014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x018101F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x01810600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x01810804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x018103FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x01810A08

------------------------------------------------------------------------------------------

      Image File Name[1224 nvtray.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001101F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00110600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00110804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001103FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00110A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[3844 PDAgentS1.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014

------------------------------------------------------------------------------------------

      Image File Name[1468 taskmgr.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00100600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00100804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00100A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[2220 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x002101F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00210600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00210804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x002103FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00210A08

------------------------------------------------------------------------------------------

      Image File Name[3820 SearchIndexer.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00100600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00100804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00100A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1984 soffice.bin]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x03C001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x03C00600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x03C00804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x03C003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x03C00A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x03C10C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x03C10E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x03C10804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x03C10A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x03C101F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x03C103FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x03C10600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x03C11014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1588 dwm.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014

------------------------------------------------------------------------------------------

      Image File Name[2532 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014

------------------------------------------------------------------------------------------

      Image File Name[4732 XueTr.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(5) kernel32.dll->LoadLibraryExW - 0x764E5079->0x00408A80[C:\Nov sloka\XueTr.exe]
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001801F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00180600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00180804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001803FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00180A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00190C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00190E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00190804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00190A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001901F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001903FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00190600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00191014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[5268 chrome.exe]Process Hook
             Iat - chrome.exe->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000901F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000903FC
             inline - len(6) ntdll.dll->NtCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->NtMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->NtOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->NtOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->NtOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->NtOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->NtOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->NtOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->NtOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->NtQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->NtQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->NtSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->NtSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->NtUnmapViewOfSection - 0x773D69BE->_
             inline - len(6) ntdll.dll->ZwCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->ZwMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->ZwOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->ZwOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->ZwOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->ZwOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->ZwOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->ZwOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->ZwOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->ZwQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->ZwQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->ZwSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->ZwSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->ZwUnmapViewOfSection - 0x773D69BE->_
             Eat - kernel32.dll->CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(4) kernel32.dll - 0x76555474->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001C01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001C0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001C0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001C03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001C0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001D0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001D0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001D0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001D0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001D01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001D03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001D0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001D1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - chrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             Iat - pdf.dll->GDI32.dll:GetFontData - 0x75FEBCC4->0x5D94791E[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]
             Iat - ppGoogleNaClPluginChrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(4) avcodec-53.dll->avcodec_get_chroma_sub_sample - 0x60D9E61D->_
             inline - len(4) avcodec-53.dll->ff_is_hwaccel_pix_fmt - 0x60D9E65A->_
             inline - len(4) avcodec-53.dll - 0x60CF9D90->_
             inline - len(4) avcodec-53.dll - 0x60D04E7C->_
             inline - len(4) avcodec-53.dll - 0x60D04E8B->_
             inline - len(4) avcodec-53.dll - 0x60D04EA2->_
             inline - len(4) avcodec-53.dll - 0x60D04EB3->_
             inline - len(4) avcodec-53.dll - 0x60D05060->_
             inline - len(4) avcodec-53.dll - 0x60D05071->_
             inline - len(4) avcodec-53.dll - 0x60D0507D->_
             inline - len(4) avcodec-53.dll - 0x60D05099->_
             inline - len(4) avcodec-53.dll - 0x60D05531->_
             inline - len(4) avcodec-53.dll - 0x60D0553B->_
             inline - len(4) avcodec-53.dll - 0x60D05547->_
             inline - len(4) avcodec-53.dll - 0x60D0555E->_
             inline - len(4) avcodec-53.dll - 0x60D0572C->_
             inline - len(4) avcodec-53.dll - 0x60D05740->_
             inline - len(4) avcodec-53.dll - 0x60D0574E->_
             inline - len(4) avcodec-53.dll - 0x60D05767->_
             inline - len(4) avcodec-53.dll - 0x60D9E825->_
             inline - len(4) avcodec-53.dll - 0x60D9E843->_
             inline - len(4) avcodec-53.dll - 0x60D9E90A->_
             inline - len(4) avcodec-53.dll - 0x60D9E91C->_
             inline - len(10) avcodec-53.dll - 0x60D9E9DC->_
             inline - len(4) avcodec-53.dll - 0x60D9EB8A->_
             inline - len(4) avcodec-53.dll - 0x60D9EB9B->_
             inline - len(4) avcodec-53.dll - 0x60D9EBA9->_
             inline - len(4) avcodec-53.dll - 0x60D9F153->_
             inline - len(4) avcodec-53.dll - 0x60D9F52E->_
             inline - len(4) avcodec-53.dll - 0x60DAC60D->_
             inline - len(4) avcodec-53.dll - 0x60DAC71C->_
             inline - len(4) avcodec-53.dll - 0x60DAC788->_
             inline - len(4) avcodec-53.dll - 0x60DAC7B0->_
             inline - len(4) avcodec-53.dll - 0x60DAC7F7->_
             inline - len(4) avcodec-53.dll - 0x60DB8FA5->_
             inline - len(4) avcodec-53.dll - 0x60DBD37B->_
             inline - len(11) avcodec-53.dll - 0x60DBEE40->_
             inline - len(4) avcodec-53.dll - 0x60DC0B41->_
             inline - len(4) avcodec-53.dll - 0x60DC44DE->_
             inline - len(4) avcodec-53.dll - 0x60DC687C->_
             inline - len(4) avformat-53.dll - 0x71825CF1->_
             inline - len(3) avformat-53.dll - 0x71826034->_
             inline - len(4) avformat-53.dll - 0x7182A02D->_
             inline - len(4) avformat-53.dll - 0x7182A044->_
             inline - len(4) avformat-53.dll - 0x7182A0F0->_
             inline - len(4) avformat-53.dll - 0x7182A105->_
             inline - len(4) avformat-53.dll - 0x7183EC9B->_

------------------------------------------------------------------------------------------

      Image File Name[2352 AppleMobileDeviceService.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00100600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00100804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00100A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1920 VM305_STI.EXE]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001501F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001503FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001E01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001E0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001E0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001E03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001E0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001F1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[1968 soffice.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001701F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001703FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001901F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00190600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00190804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001903FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00190A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001A0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001A0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001A0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001A0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001A01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001A03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001A0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001A1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[3584 vmnetdhcp.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x000F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x000F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x000F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014

------------------------------------------------------------------------------------------

      Image File Name[2188 spoolsv.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00100600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00100804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00100A08

------------------------------------------------------------------------------------------

      Image File Name[2404 mDNSResponder.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00180C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00180E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00180804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00180A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001801F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001803FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00180600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00181014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001901F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00190600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00190804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001903FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00190A08

------------------------------------------------------------------------------------------

      Image File Name[2640 sqlservr.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001A0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001A0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001A0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001A0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001A01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001A03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001A0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001A1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001B01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001B0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001B0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001B03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001B0A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[2440 CepstralLicSrv.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001501F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001503FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001E01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001E0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001E0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001E03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001E0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001F1014

------------------------------------------------------------------------------------------

      Image File Name[4064 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00100C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00100E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00100804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00100A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00100600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00101014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x002001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00200600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00200804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x002003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00200A08

------------------------------------------------------------------------------------------

      Image File Name[3032 TeamViewer_Service.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001801F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00180600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00180804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001803FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00180A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00190C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00190E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00190804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00190A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001901F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001903FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00190600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00191014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[2500 launcherd.exe]Process Hook
             Iat - launcherd.exe->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             Iat - snxhk.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - snxhk.dll->KERNEL32.dll:CreateProcessW - 0x764A204D->0x6AF0258F[C:\Windows\AppPatch\AcLayers.DLL]
             Iat - WTSAPI32.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - USER32.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001F0A08
             Iat - GDI32.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - USP10.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - ADVAPI32.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00200C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00200E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00200804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00200A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x002001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x002003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00200600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00201014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHLWAPI.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - OLEAUT32.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - WINSPOOL.DRV->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - MPR.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - IMM32.DLL->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]
             Iat - MSCTF.dll->KERNEL32.dll:GetProcAddress - 0x764ECC94->0x753EFFF6[C:\Windows\system32\apphelp.dll]

------------------------------------------------------------------------------------------

      Image File Name[3780 PDEngine.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001801F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00180600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00180804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001803FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00180A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00190C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00190E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00190804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00190A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001901F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001903FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00190600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00191014
             Iat - oledb32.dll->OLEAUT32.dll:[Ordinal:416] - 0x75CB93EC->0x75C701A0[C:\Windows\system32\OLEAUT32.dll]

------------------------------------------------------------------------------------------

      Image File Name[2820 PnkBstrA.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001501F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001503FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001E01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001E0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001E0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001E03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001E0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001F1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[2904 PnkBstrB.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001501F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001503FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001E01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001E0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001E0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001E03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001E0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x001F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x001F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x001F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x001F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x001F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x001F1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[2960 sqlwriter.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001001F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00100600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00100804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001003FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00100A08

------------------------------------------------------------------------------------------

      Image File Name[2984 svchost.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x000F0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x000F0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x000F0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x000F0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000F01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000F03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x000F0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x000F1014

------------------------------------------------------------------------------------------

      Image File Name[3060 TeamViewer_Service.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001F01F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x001F0600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x001F0804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001F03FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x001F0A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00200C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00200E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00200804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00200A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x002001F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x002003FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00200600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00201014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - Magnification.dll->USER32.dll:[Ordinal:1911] - 0x75B94AB7->0x75BE0717[C:\Windows\system32\USER32.dll]
             Iat - Magnification.dll->USER32.dll:[Ordinal:1995] - 0x75BB1608->0x75BE076B[C:\Windows\system32\USER32.dll]

------------------------------------------------------------------------------------------

      Image File Name[3192 vmnat.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000801F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00080600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00080804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000803FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00080A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00090C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00090E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00090804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00090A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000901F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000903FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00090600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00091014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[4308 chrome.exe]Process Hook
             Iat - chrome.exe->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000901F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000903FC
             inline - len(6) ntdll.dll->NtCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->NtMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->NtOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->NtOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->NtOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->NtOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->NtOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->NtOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->NtOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->NtQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->NtQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->NtSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->NtSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->NtUnmapViewOfSection - 0x773D69BE->_
             inline - len(6) ntdll.dll->ZwCreateFile - 0x773D55CE->_
             inline - len(6) ntdll.dll->ZwMapViewOfSection - 0x773D5C2E->_
             inline - len(6) ntdll.dll->ZwOpenFile - 0x773D5CDE->_
             inline - len(6) ntdll.dll->ZwOpenProcess - 0x773D5D8E->_
             inline - len(6) ntdll.dll->ZwOpenProcessToken - 0x773D5D9E->0x763D64A4
             inline - len(6) ntdll.dll->ZwOpenProcessTokenEx - 0x773D5DAE->_
             inline - len(6) ntdll.dll->ZwOpenThread - 0x773D5E0E->_
             inline - len(6) ntdll.dll->ZwOpenThreadToken - 0x773D5E1E->_
             inline - len(6) ntdll.dll->ZwOpenThreadTokenEx - 0x773D5E2E->0x763D6535
             inline - len(6) ntdll.dll->ZwQueryAttributesFile - 0x773D5F3E->_
             inline - len(6) ntdll.dll->ZwQueryFullAttributesFile - 0x773D5FEE->0x763D66F3
             inline - len(6) ntdll.dll->ZwSetInformationFile - 0x773D663E->_
             inline - len(6) ntdll.dll->ZwSetInformationThread - 0x773D669E->_
             inline - len(6) ntdll.dll->ZwUnmapViewOfSection - 0x773D69BE->_
             Eat - kernel32.dll->CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(4) kernel32.dll - 0x76555474->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001401F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00140600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00140804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001403FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00140A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00150C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00150E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00150804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00150A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001501F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001503FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00150600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00151014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]
             Iat - chrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             Iat - pdf.dll->GDI32.dll:GetFontData - 0x75FEBCC4->0x5D94791E[C:\Users\dominik\AppData\Local\Google\Chrome\Application\16.0.912.77\chrome.dll]
             Iat - ppGoogleNaClPluginChrome.dll->KERNEL32.dll:CreateNamedPipeW - 0x764D2D47->0x00010010
             inline - len(4) avcodec-53.dll->avcodec_get_chroma_sub_sample - 0x60D9E61D->_
             inline - len(4) avcodec-53.dll->ff_is_hwaccel_pix_fmt - 0x60D9E65A->_
             inline - len(4) avcodec-53.dll - 0x60CF9D90->_
             inline - len(4) avcodec-53.dll - 0x60D04E7C->_
             inline - len(4) avcodec-53.dll - 0x60D04E8B->_
             inline - len(4) avcodec-53.dll - 0x60D04EA2->_
             inline - len(4) avcodec-53.dll - 0x60D04EB3->_
             inline - len(4) avcodec-53.dll - 0x60D05060->_
             inline - len(4) avcodec-53.dll - 0x60D05071->_
             inline - len(4) avcodec-53.dll - 0x60D0507D->_
             inline - len(4) avcodec-53.dll - 0x60D05099->_
             inline - len(4) avcodec-53.dll - 0x60D05531->_
             inline - len(4) avcodec-53.dll - 0x60D0553B->_
             inline - len(4) avcodec-53.dll - 0x60D05547->_
             inline - len(4) avcodec-53.dll - 0x60D0555E->_
             inline - len(4) avcodec-53.dll - 0x60D0572C->_
             inline - len(4) avcodec-53.dll - 0x60D05740->_
             inline - len(4) avcodec-53.dll - 0x60D0574E->_
             inline - len(4) avcodec-53.dll - 0x60D05767->_
             inline - len(4) avcodec-53.dll - 0x60D9E825->_
             inline - len(4) avcodec-53.dll - 0x60D9E843->_
             inline - len(4) avcodec-53.dll - 0x60D9E90A->_
             inline - len(4) avcodec-53.dll - 0x60D9E91C->_
             inline - len(10) avcodec-53.dll - 0x60D9E9DC->_
             inline - len(4) avcodec-53.dll - 0x60D9EB8A->_
             inline - len(4) avcodec-53.dll - 0x60D9EB9B->_
             inline - len(4) avcodec-53.dll - 0x60D9EBA9->_
             inline - len(4) avcodec-53.dll - 0x60D9F153->_
             inline - len(4) avcodec-53.dll - 0x60D9F52E->_
             inline - len(4) avcodec-53.dll - 0x60DAC60D->_
             inline - len(4) avcodec-53.dll - 0x60DAC71C->_
             inline - len(4) avcodec-53.dll - 0x60DAC788->_
             inline - len(4) avcodec-53.dll - 0x60DAC7B0->_
             inline - len(4) avcodec-53.dll - 0x60DAC7F7->_
             inline - len(4) avcodec-53.dll - 0x60DB8FA5->_
             inline - len(4) avcodec-53.dll - 0x60DBD37B->_
             inline - len(11) avcodec-53.dll - 0x60DBEE40->_
             inline - len(4) avcodec-53.dll - 0x60DC0B41->_
             inline - len(4) avcodec-53.dll - 0x60DC44DE->_
             inline - len(4) avcodec-53.dll - 0x60DC687C->_
             inline - len(4) avformat-53.dll - 0x71825CF1->_
             inline - len(3) avformat-53.dll - 0x71826034->_
             inline - len(4) avformat-53.dll - 0x7182A02D->_
             inline - len(4) avformat-53.dll - 0x7182A044->_
             inline - len(4) avformat-53.dll - 0x7182A0F0->_
             inline - len(4) avformat-53.dll - 0x7182A105->_
             inline - len(4) avformat-53.dll - 0x7183EC9B->_

------------------------------------------------------------------------------------------

      Image File Name[3260 WLIDSVC.EXE]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000A01F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000A03FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00130C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00130E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00130804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00130A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x001301F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x001303FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00130600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00131014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x001401F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00140600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00140804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x001403FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00140A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[3352 vmware-authd.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00350C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00350E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00350804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00350A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x003501F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x003503FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00350600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00351014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x003601F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00360600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00360804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x003603FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00360A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[3376 WLIDSVCM.EXE]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x000601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x000603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x00080C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x00080E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x00080804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x00080A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x000801F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x000803FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x00080600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x00081014
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x000901F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00090600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00090804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x000903FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00090A08
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[3676 vmware-hostd.exe]Process Hook
             inline - len(5) ntdll.dll->LdrLoadDll - 0x773F223E->0x001601F8
             inline - len(5) ntdll.dll->LdrUnloadDll - 0x773EC86E->0x001603FC
             inline - len(1) kernel32.dll - 0x765069F4->_
             inline - len(5) USER32.dll->SetWinEventHook - 0x75B924DC->0x003901F8
             inline - len(5) USER32.dll->SetWindowsHookExA - 0x75BB6D0C->0x00390600
             inline - len(5) USER32.dll->SetWindowsHookExW - 0x75B8E30C->0x00390804
             inline - len(5) USER32.dll->UnhookWinEvent - 0x75B8B750->0x003903FC
             inline - len(5) USER32.dll->UnhookWindowsHookEx - 0x75B8ADF9->0x00390A08
             inline - len(5) sechost.dll->ChangeServiceConfig2A - 0x774D54C2->0x003A0C0C
             inline - len(5) sechost.dll->ChangeServiceConfig2W - 0x774D55E2->0x003A0E10
             inline - len(5) sechost.dll->ChangeServiceConfigA - 0x774D5254->0x003A0804
             inline - len(5) sechost.dll->ChangeServiceConfigW - 0x774D53D5->0x003A0A08
             inline - len(5) sechost.dll->CreateServiceA - 0x774D567C->0x003A01F8
             inline - len(5) sechost.dll->CreateServiceW - 0x774D589F->0x003A03FC
             inline - len(5) sechost.dll->DeleteService - 0x774D5A22->0x003A0600
             inline - len(5) sechost.dll->SetServiceObjectSecurity - 0x774D5181->0x003A1014
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:845] - 0x77578277->0x77590335[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:50] - 0x764E9989->0x775A001A[C:\Windows\system32\SHLWAPI.dll]
             Iat - SHELL32.dll->SHLWAPI.dll:[Ordinal:828] - 0x7756FE2A->0x77590324[C:\Windows\system32\SHLWAPI.dll]

------------------------------------------------------------------------------------------

      Image File Name[4564 audiodg.exe]Process Hook
             Nothing

==========================================================================================

KernelCallbackTable

      Image File Name[4 System]KernelCallbackTable

------------------------------------------------------------------------------------------

      Image File Name[1608 explorer.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1308 AvastSvc.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[268 smss.exe]KernelCallbackTable

------------------------------------------------------------------------------------------

      Image File Name[1908 AvastUI.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[5080 Skype.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[408 csrss.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1932 chrome.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2220 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[464 daemonu.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[468 csrss.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[476 wininit.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[524 winlogon.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1364 nvxdsync.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[572 services.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[580 lsass.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[588 lsm.exe]KernelCallbackTable

------------------------------------------------------------------------------------------

      Image File Name[1000 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3856 WmiPrvSE.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[4008 iPodService.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1376 nvvsvc.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3140 vmware-usbarbitrator.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1508 chrome.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[692 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[5988 chrome.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2736 PDAgent.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[780 nvvsvc.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[804 nvSCPAPISvr.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[4504 audiodg.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\System32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\System32\USER32.dll
             fnDWORD - OK - C:\Windows\System32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\System32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\System32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\System32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\System32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\System32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\System32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\System32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\System32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\System32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\System32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\System32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\System32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\System32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\System32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\System32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\System32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\System32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\System32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\System32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\System32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\System32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\System32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\System32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\System32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\System32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\System32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\System32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\System32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\System32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\System32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\System32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\System32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\System32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\System32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\System32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\System32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\System32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\System32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\System32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\System32\USER32.dll
             ClientCopyImage - OK - C:\Windows\System32\USER32.dll
             ClientEventCallback - OK - C:\Windows\System32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\System32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\System32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\System32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\System32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\System32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\System32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\System32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\System32\USER32.dll
             ClientLoadImage - OK - C:\Windows\System32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\System32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\System32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\System32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\System32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\System32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\System32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\System32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\System32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\System32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\System32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\System32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\System32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\System32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\System32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\System32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\System32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\System32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\System32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\System32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\System32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\System32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\System32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\System32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\System32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\System32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\System32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\System32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\System32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\System32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\System32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\System32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\System32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\System32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\System32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\System32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\System32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\System32\USER32.dll
             fnTOUCH - OK - C:\Windows\System32\USER32.dll
             fnGESTURE - OK - C:\Windows\System32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\System32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[848 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\user32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\user32.dll
             fnDWORD - OK - C:\Windows\system32\user32.dll
             fnNCDESTROY - OK - C:\Windows\system32\user32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\user32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\user32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\user32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\user32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\user32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\user32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\user32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\user32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\user32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\user32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\user32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\user32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\user32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\user32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\user32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\user32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\user32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\user32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\user32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\user32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\user32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\user32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\user32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\user32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\user32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\user32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\user32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\user32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\user32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\user32.dll
             fnHkINDWORD - OK - C:\Windows\system32\user32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\user32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\user32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\user32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\user32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\user32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\user32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\user32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\user32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\user32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\user32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\user32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\user32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\user32.dll
             ClientCopyImage - OK - C:\Windows\system32\user32.dll
             ClientEventCallback - OK - C:\Windows\system32\user32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\user32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\user32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\user32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\user32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\user32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\user32.dll
             ClientGetListboxString - OK - C:\Windows\system32\user32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\user32.dll
             ClientLoadImage - OK - C:\Windows\system32\user32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\user32.dll
             ClientLoadMenu - OK - C:\Windows\system32\user32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\user32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\user32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\user32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\user32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\user32.dll
             ClientCharToWchar - OK - C:\Windows\system32\user32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\user32.dll
             ClientThreadSetup - OK - C:\Windows\system32\user32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\user32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\user32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\user32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\user32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\user32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\user32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\user32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\user32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\user32.dll
             fnIMECONTROL - OK - C:\Windows\system32\user32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\user32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\user32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\user32.dll
             ClientLoadStringW - OK - C:\Windows\system32\user32.dll
             ClientLoadOLE - OK - C:\Windows\system32\user32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\user32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\user32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\user32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\user32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\user32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\user32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\user32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\user32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\user32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\user32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\user32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\user32.dll
             fnTOUCH - OK - C:\Windows\system32\user32.dll
             fnGESTURE - OK - C:\Windows\system32\user32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\user32.dll

------------------------------------------------------------------------------------------

      Image File Name[2404 mDNSResponder.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[944 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[976 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1520 wmpnetwk.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2640 sqlservr.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3452 chrome.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1176 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1204 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1224 nvtray.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3844 PDAgentS1.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3820 SearchIndexer.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1468 taskmgr.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1984 soffice.bin]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1588 dwm.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2532 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[4732 XueTr.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[5268 chrome.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2352 AppleMobileDeviceService.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1920 VM305_STI.EXE]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[1968 soffice.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3584 vmnetdhcp.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2188 spoolsv.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2228 taskhost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2440 CepstralLicSrv.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[4064 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3032 TeamViewer_Service.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2500 launcherd.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2820 PnkBstrA.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2904 PnkBstrB.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2960 sqlwriter.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[2984 svchost.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3060 TeamViewer_Service.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3192 vmnat.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[4308 chrome.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3260 WLIDSVC.EXE]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3352 vmware-authd.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3376 WLIDSVCM.EXE]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3780 PDEngine.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[3676 vmware-hostd.exe]KernelCallbackTable
             fnCOPYDATA - OK - C:\Windows\system32\USER32.dll
             fnCOPYGLOBALDATA - OK - C:\Windows\system32\USER32.dll
             fnDWORD - OK - C:\Windows\system32\USER32.dll
             fnNCDESTROY - OK - C:\Windows\system32\USER32.dll
             fnDWORDOPTINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTDRAG - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINCNTOUTSTRING - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPCOMPAREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDELETEITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPDRAWITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPMDICREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPMEASUREITEMSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnINLPWINDOWPOS - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPPOINT5 - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnINOUTNCCALCSIZE - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPSCROLLINFO - OK - C:\Windows\system32\USER32.dll
             fnINPAINTCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSIZECLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINDESTROYCLIPBRD - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINSTRINGNULL - OK - C:\Windows\system32\USER32.dll
             fnINDEVICECHANGE - OK - C:\Windows\system32\USER32.dll
             fnPOWERBROADCAST - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOPTOUTLPDWORDOPTOUTLPDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTDWORDINDWORD - OK - C:\Windows\system32\USER32.dll
             fnOUTLPRECT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnPOUTLPINT - OK - C:\Windows\system32\USER32.dll
             fnSENTDDEMSG - OK - C:\Windows\system32\USER32.dll
             fnINOUTSTYLECHANGE - OK - C:\Windows\system32\USER32.dll
             fnHkINDWORD - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTACTIVATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPCBTCREATESTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPDEBUGHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMOUSEHOOKSTRUCTEX - OK - C:\Windows\system32\USER32.dll
             fnHkINLPKBDLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSLLHOOKSTRUCT - OK - C:\Windows\system32\USER32.dll
             fnHkINLPMSG - OK - C:\Windows\system32\USER32.dll
             fnHkINLPRECT - OK - C:\Windows\system32\USER32.dll
             fnHkOPTINLPEVENTMSG - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEIn2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut1 - OK - C:\Windows\system32\USER32.dll
             ClientCopyDDEOut2 - OK - C:\Windows\system32\USER32.dll
             ClientCopyImage - OK - C:\Windows\system32\USER32.dll
             ClientEventCallback - OK - C:\Windows\system32\USER32.dll
             ClientFindMnemChar - OK - C:\Windows\system32\USER32.dll
             ClientFreeDDEHandle - OK - C:\Windows\system32\USER32.dll
             ClientFreeLibrary - OK - C:\Windows\system32\USER32.dll
             ClientGetCharsetInfo - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEFlags - OK - C:\Windows\system32\USER32.dll
             ClientGetDDEHookData - OK - C:\Windows\system32\USER32.dll
             ClientGetListboxString - OK - C:\Windows\system32\USER32.dll
             ClientGetMessageMPH - OK - C:\Windows\system32\USER32.dll
             ClientLoadImage - OK - C:\Windows\system32\USER32.dll
             ClientLoadLibrary - OK - C:\Windows\system32\USER32.dll
             ClientLoadMenu - OK - C:\Windows\system32\USER32.dll
             ClientLoadLocalT1Fonts - OK - C:\Windows\system32\USER32.dll
             ClientPSMTextOut - OK - C:\Windows\system32\USER32.dll
             ClientLpkDrawTextEx - OK - C:\Windows\system32\USER32.dll
             ClientExtTextOutW - OK - C:\Windows\system32\USER32.dll
             ClientGetTextExtentPointW - OK - C:\Windows\system32\USER32.dll
             ClientCharToWchar - OK - C:\Windows\system32\USER32.dll
             ClientAddFontResourceW - OK - C:\Windows\system32\USER32.dll
             ClientThreadSetup - OK - C:\Windows\system32\USER32.dll
             ClientDeliverUserApc - OK - C:\Windows\system32\USER32.dll
             ClientNoMemoryPopup - OK - C:\Windows\system32\USER32.dll
             ClientMonitorEnumProc - OK - C:\Windows\system32\USER32.dll
             ClientCallWinEventProc - OK - C:\Windows\system32\USER32.dll
             ClientWaitMessageExMPH - OK - C:\Windows\system32\USER32.dll
             ClientWOWGetProcModule - OK - C:\Windows\system32\USER32.dll
             ClientWOWTask16SchedNotify - OK - C:\Windows\system32\USER32.dll
             ClientImmLoadLayout - OK - C:\Windows\system32\USER32.dll
             ClientImmProcessKey - OK - C:\Windows\system32\USER32.dll
             fnIMECONTROL - OK - C:\Windows\system32\USER32.dll
             fnINWPARAMDBCSCHAR - OK - C:\Windows\system32\USER32.dll
             fnGETTEXTLENGTHS - OK - C:\Windows\system32\USER32.dll
             fnINLPKDRAWSWITCHWND - OK - C:\Windows\system32\USER32.dll
             ClientLoadStringW - OK - C:\Windows\system32\USER32.dll
             ClientLoadOLE - OK - C:\Windows\system32\USER32.dll
             ClientRegisterDragDrop - OK - C:\Windows\system32\USER32.dll
             ClientRevokeDragDrop - OK - C:\Windows\system32\USER32.dll
             fnINOUTMENUGETOBJECT - OK - C:\Windows\system32\USER32.dll
             ClientPrinterThunk - OK - C:\Windows\system32\USER32.dll
             fnOUTLPCOMBOBOXINFO - OK - C:\Windows\system32\USER32.dll
             fnOUTLPSCROLLBARINFO - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnINOUTLPUAHMEASUREMENUITEM - OK - C:\Windows\system32\USER32.dll
             fnINLPUAHDRAWMENU - OK - C:\Windows\system32\USER32.dll
             fnOUTLPTITLEBARINFOEX - OK - C:\Windows\system32\USER32.dll
             fnTOUCH - OK - C:\Windows\system32\USER32.dll
             fnGESTURE - OK - C:\Windows\system32\USER32.dll
             fnINLPHLPSTRUCT - OK - C:\Windows\system32\USER32.dll

------------------------------------------------------------------------------------------

      Image File Name[0 Idle]KernelCallbackTable

==========================================================================================

Port

       Tcp 0.0.0.0 : 80 - 0.0.0.0 : 0 - LISTENING - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 0.0.0.0 : 135 - 0.0.0.0 : 0 - LISTENING - 848 - C:\Windows\System32\svchost.exe
       Tcp 5.165.60.133 : 139 - 0.0.0.0 : 0 - LISTENING - 4 - System
       Tcp 192.168.1.2 : 139 - 0.0.0.0 : 0 - LISTENING - 4 - System
       Tcp 192.168.37.1 : 139 - 0.0.0.0 : 0 - LISTENING - 4 - System
       Tcp 192.168.56.1 : 139 - 0.0.0.0 : 0 - LISTENING - 4 - System
       Tcp 192.168.79.1 : 139 - 0.0.0.0 : 0 - LISTENING - 4 - System
       Tcp 0.0.0.0 : 443 - 0.0.0.0 : 0 - LISTENING - 3676 - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe
       Tcp 0.0.0.0 : 902 - 0.0.0.0 : 0 - LISTENING - 3352 - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
       Tcp 0.0.0.0 : 912 - 0.0.0.0 : 0 - LISTENING - 3352 - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
       Tcp 0.0.0.0 : 1025 - 0.0.0.0 : 0 - LISTENING - 476 - C:\Windows\System32\wininit.exe
       Tcp 0.0.0.0 : 1026 - 0.0.0.0 : 0 - LISTENING - 944 - C:\Windows\System32\svchost.exe
       Tcp 0.0.0.0 : 1027 - 0.0.0.0 : 0 - LISTENING - 580 - C:\Windows\System32\lsass.exe
       Tcp 0.0.0.0 : 1097 - 0.0.0.0 : 0 - LISTENING - 1000 - C:\Windows\System32\svchost.exe
       Tcp 127.0.0.1 : 1100 - 127.0.0.1 : 5354 - ESTABLISHED - 2352 - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
       Tcp 127.0.0.1 : 1116 - 127.0.0.1 : 1117 - ESTABLISHED - 3032 - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
       Tcp 127.0.0.1 : 1117 - 127.0.0.1 : 1116 - ESTABLISHED - 3032 - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
       Tcp 0.0.0.0 : 1129 - 0.0.0.0 : 0 - LISTENING - 572 - C:\Windows\System32\services.exe
       Tcp 0.0.0.0 : 1135 - 0.0.0.0 : 0 - LISTENING - 4064 - C:\Windows\System32\svchost.exe
       Tcp 0.0.0.0 : 1480 - 0.0.0.0 : 0 - LISTENING - 2440 - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe
       Tcp 127.0.0.1 : 2559 - 0.0.0.0 : 0 - LISTENING - 464 - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
       Tcp 192.168.1.2 : 2839 - 65.55.223.13 : 40001 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 192.168.1.2 : 2840 - 193.120.199.13 : 12350 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 127.0.0.1 : 5354 - 0.0.0.0 : 0 - LISTENING - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Tcp 127.0.0.1 : 5354 - 127.0.0.1 : 1100 - ESTABLISHED - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Tcp 127.0.0.1 : 5939 - 0.0.0.0 : 0 - LISTENING - 3060 - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
       Tcp 127.0.0.1 : 5940 - 0.0.0.0 : 0 - LISTENING - 3032 - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
       Tcp 192.168.1.2 : 6470 - 66.220.156.48 : 443 - ESTABLISHED - 1508 - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe
       Tcp 192.168.1.2 : 6623 - 69.171.227.67 : 443 - ESTABLISHED - 1508 - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe
       Tcp 192.168.1.2 : 6659 - 89.176.226.105 : 43489 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 192.168.1.2 : 6660 - 94.112.114.196 : 27635 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 192.168.1.2 : 6661 - 89.29.18.170 : 62246 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 192.168.1.2 : 6666 - 89.29.18.170 : 62246 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 192.168.1.2 : 6667 - 84.47.15.153 : 42654 - ESTABLISHED - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Tcp 192.168.1.2 : 6673 - 66.220.158.45 : 443 - ESTABLISHED - 1508 - C:\Users\dominik\AppData\Local\Google\Chrome\Application\chrome.exe
       Tcp 127.0.0.1 : 8307 - 0.0.0.0 : 0 - LISTENING - 3676 - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe
       Tcp 127.0.0.1 : 12001 - 0.0.0.0 : 0 - LISTENING - 3676 - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe
       Tcp 127.0.0.1 : 12025 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12080 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12110 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12119 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12143 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12465 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12563 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12993 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 12995 - 0.0.0.0 : 0 - LISTENING - 1308 - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
       Tcp 127.0.0.1 : 27015 - 0.0.0.0 : 0 - LISTENING - 2352 - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
       Tcp 0.0.0.0 : 42079 - 0.0.0.0 : 0 - LISTENING - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Udp 5.165.60.133 : 68 - * : * - 944 - C:\Windows\System32\svchost.exe
       Udp 5.165.60.133 : 137 - * : * - 4 - System
       Udp 192.168.1.2 : 137 - * : * - 4 - System
       Udp 192.168.37.1 : 137 - * : * - 4 - System
       Udp 192.168.56.1 : 137 - * : * - 4 - System
       Udp 192.168.79.1 : 137 - * : * - 4 - System
       Udp 5.165.60.133 : 138 - * : * - 4 - System
       Udp 192.168.1.2 : 138 - * : * - 4 - System
       Udp 192.168.37.1 : 138 - * : * - 4 - System
       Udp 192.168.56.1 : 138 - * : * - 4 - System
       Udp 192.168.79.1 : 138 - * : * - 4 - System
       Udp 0.0.0.0 : 443 - * : * - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Udp 0.0.0.0 : 500 - * : * - 1000 - C:\Windows\System32\svchost.exe
       Udp 5.165.60.133 : 1900 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 127.0.0.1 : 1900 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.1.2 : 1900 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.37.1 : 1900 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.56.1 : 1900 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.79.1 : 1900 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 0.0.0.0 : 3702 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 0.0.0.0 : 3702 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 0.0.0.0 : 3702 - * : * - 1176 - C:\Windows\System32\svchost.exe
       Udp 0.0.0.0 : 3702 - * : * - 1176 - C:\Windows\System32\svchost.exe
       Udp 0.0.0.0 : 4500 - * : * - 1000 - C:\Windows\System32\svchost.exe
       Udp 5.165.60.133 : 5353 - * : * - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Udp 192.168.1.2 : 5353 - * : * - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Udp 192.168.37.1 : 5353 - * : * - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Udp 192.168.56.1 : 5353 - * : * - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Udp 192.168.79.1 : 5353 - * : * - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Udp 0.0.0.0 : 5355 - * : * - 1204 - C:\Windows\System32\svchost.exe
       Udp 0.0.0.0 : 42079 - * : * - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Udp 127.0.0.1 : 44301 - * : * - 2820 - C:\Windows\System32\PnkBstrA.exe
       Udp 127.0.0.1 : 45301 - * : * - 2904 - C:\Windows\System32\PnkBstrB.exe
       Udp 127.0.0.1 : 48000 - * : * - 464 - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
       Udp 127.0.0.1 : 48001 - * : * - 1224 - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
       Udp 127.0.0.1 : 50110 - * : * - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Udp 127.0.0.1 : 51407 - * : * - 5080 - C:\Program Files\Skype\Phone\Skype.exe
       Udp 0.0.0.0 : 52794 - * : * - 1176 - C:\Windows\System32\svchost.exe
       Udp 192.168.1.2 : 55036 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 5.165.60.133 : 55037 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.56.1 : 55038 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.37.1 : 55039 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 192.168.79.1 : 55040 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 127.0.0.1 : 55041 - * : * - 2532 - C:\Windows\System32\svchost.exe
       Udp 127.0.0.1 : 65112 - * : * - 2352 - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
       Udp 127.0.0.1 : 65113 - * : * - 2352 - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
       Udp 0.0.0.0 : 65114 - * : * - 2404 - C:\Program Files\Bonjour\mDNSResponder.exe
       Udp 0.0.0.0 : 65116 - * : * - 2532 - C:\Windows\System32\svchost.exe

==========================================================================================

Tcpip

       IRP_MJ_CREATE - OK - 0x8902E671 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x8902E671 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       IRP_MJ_READ - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x89069787 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x8902E671 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x8902E671 - C:\Windows\System32\drivers\tcpip.sys - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x82CF3D83 - C:\Windows\system32\ntkrnlpa.exe - Microsoft Corporation

==========================================================================================

Nsiproxy

       IRP_MJ_CREATE - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_CREATE_NAMED_PIPE - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_CLOSE - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_READ - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_WRITE - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_QUERY_INFORMATION - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SET_INFORMATION - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_QUERY_EA - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SET_EA - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_FLUSH_BUFFERS - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_QUERY_VOLUME_INFORMATION - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SET_VOLUME_INFORMATION - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_DIRECTORY_CONTROL - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_FILE_SYSTEM_CONTROL - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_DEVICE_CONTROL - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_INTERNAL_DEVICE_CONTROL - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SHUTDOWN - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_LOCK_CONTROL - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_CLEANUP - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_CREATE_MAILSLOT - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_QUERY_SECURITY - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SET_SECURITY - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_POWER - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SYSTEM_CONTROL - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_DEVICE_CHANGE - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_QUERY_QUOTA - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_SET_QUOTA - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation
       IRP_MJ_PNP_POWER - OK - 0x90D5BFB2 - C:\Windows\system32\drivers\nsiproxy.sys - Microsoft Corporation

==========================================================================================

IE Plugin

       Browser Helper Objects - Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - Microsoft Corp. - {9030D464-4C02-4ABF-8ECC-5164760863C6}
       Browser Helper Objects - Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll - Oracle Corporation - {DBC80044-A445-435b-BC74-9C25C1C588A9}
       URLSearchHooks - Microsoft Url Search Hook - C:\Windows\System32\ieframe.dll - Microsoft Corporation - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
       ActiveX - HTML Document - C:\Windows\System32\mshtml.dll - Microsoft Corporation - {25336920-03F9-11CF-8FD0-00AA00686F13}
       ActiveX - Windows Media Player - C:\Windows\System32\wmp.dll - Microsoft Corporation - {6BF52A52-394A-11D3-B153-00C04F79FAA6}
       ActiveX - Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - Microsoft Corp. - {9030D464-4C02-4ABF-8ECC-5164760863C6}
       ActiveX -  -  -  - {C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
       ActiveX -  -  -  - {C442AC41-9200-4770-8CC0-7CDB4F245C55}
       ActiveX - Shockwave Flash Object - C:\Windows\System32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc. - {D27CDB6E-AE6D-11CF-96B8-444553540000}
       ActiveX - Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll - Oracle Corporation - {DBC80044-A445-435B-BC74-9C25C1C588A9}
       ActiveX - Microsoft Silverlight - C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll -  Microsoft Corporation - {DFEAF541-F3E1-4C24-ACAC-99C30715084A}
       ActiveX - XML HTTP Request - C:\Windows\System32\msxml3.dll - Microsoft Corporation - {ED8C108E-4349-11D2-91A4-00C04F7969E8}
       ActiveX - XML HTTP - C:\Windows\System32\msxml3.dll - Microsoft Corporation - {F6D90F16-9C73-11D3-B32E-00C04F990BB4}
       Distribution Units - jp2iexp.dll - C:\Program Files\Java\jre7\bin\jp2iexp.dll -  - {8AD9C840-044E-11D1-B3E9-00805F499D93}
       Distribution Units - jp2iexp.dll - C:\Program Files\Java\jre7\bin\jp2iexp.dll -  - {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
       Distribution Units - jp2iexp.dll - C:\Program Files\Java\jre7\bin\jp2iexp.dll -  - {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}
       Distribution Units - ssv.dll - C:\Program Files\Java\jre7\bin\ssv.dll - Oracle Corporation - {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
       Distribution Units - Flash11e.ocx - C:\Windows\System32\Macromed\Flash\Flash11e.ocx - Adobe Systems, Inc. - {D27CDB6E-AE6D-11CF-96B8-444553540000}

==========================================================================================

IE Shell

       Nothing

==========================================================================================

Spi

       @%SystemRoot%\System32\wshtcpip.dll,-60100 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
       @%SystemRoot%\System32\wshtcpip.dll,-60101 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
       @%SystemRoot%\System32\wshtcpip.dll,-60102 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
       @%SystemRoot%\System32\wship6.dll,-60100 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
       @%SystemRoot%\System32\wship6.dll,-60101 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
       @%SystemRoot%\System32\wship6.dll,-60102 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
       @%SystemRoot%\System32\wshqos.dll,-100 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {9D60A9E0-337A-11D0-BD88-0000C082E69A}
       @%SystemRoot%\System32\wshqos.dll,-101 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {9D60A9E0-337A-11D0-BD88-0000C082E69A}
       @%SystemRoot%\System32\wshqos.dll,-102 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {9D60A9E0-337A-11D0-BD88-0000C082E69A}
       @%SystemRoot%\System32\wshqos.dll,-103 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {9D60A9E0-337A-11D0-BD88-0000C082E69A}
       VMCI sockets DGRAM - C:\Windows\System32\vsocklib.dll - VMware, Inc. - {570ADC4B-67B2-42CE-92B2-ACD33D88D842}
       VMCI sockets STREAM - C:\Windows\System32\vsocklib.dll - VMware, Inc. - {570ADC4B-67B2-42CE-92B2-ACD33D88D842}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A9ACB603-1F16-4088-ADF6-0B3B0C731234}] SEQPACKET 17 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A9ACB603-1F16-4088-ADF6-0B3B0C731234}] DATAGRAM 17 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{448D5BFD-7E90-4699-8187-DD56E10DBA5D}] SEQPACKET 14 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{448D5BFD-7E90-4699-8187-DD56E10DBA5D}] DATAGRAM 14 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{9DFA6765-C071-40C0-82BA-C6FD8BF3CBFB}] SEQPACKET 7 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{9DFA6765-C071-40C0-82BA-C6FD8BF3CBFB}] DATAGRAM 7 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{320C15F6-1163-4C74-A563-45AC30C810DB}] SEQPACKET 19 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{320C15F6-1163-4C74-A563-45AC30C810DB}] DATAGRAM 19 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EB22FB5A-36CD-4712-8A3A-DCDBF34E227C}] SEQPACKET 16 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EB22FB5A-36CD-4712-8A3A-DCDBF34E227C}] DATAGRAM 16 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{C796E046-EC7C-4E78-AC44-FED35F84F534}] SEQPACKET 13 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{C796E046-EC7C-4E78-AC44-FED35F84F534}] DATAGRAM 13 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E00A53BF-27E1-41EB-82DE-18A4943A97DA}] SEQPACKET 11 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E00A53BF-27E1-41EB-82DE-18A4943A97DA}] DATAGRAM 11 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{01825FD0-F8E8-4803-809E-B0BC755409B5}] SEQPACKET 10 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{01825FD0-F8E8-4803-809E-B0BC755409B5}] DATAGRAM 10 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{676D8C37-37E6-4F7D-8B6D-718F98F92ABE}] SEQPACKET 9 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{676D8C37-37E6-4F7D-8B6D-718F98F92ABE}] DATAGRAM 9 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E2E3BD7D-6C60-4C1F-9EB8-77D7EC0A9191}] SEQPACKET 6 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{E2E3BD7D-6C60-4C1F-9EB8-77D7EC0A9191}] DATAGRAM 6 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{F2979F3C-B8D7-4668-A9EA-A946DC74BC6B}] SEQPACKET 3 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{F2979F3C-B8D7-4668-A9EA-A946DC74BC6B}] DATAGRAM 3 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{B3749057-662F-4BF4-B189-5C19C85D4E3F}] SEQPACKET 0 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{B3749057-662F-4BF4-B189-5C19C85D4E3F}] DATAGRAM 0 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{7998A5DB-A2E8-4C7E-953C-E51E656B17BE}] SEQPACKET 2 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{7998A5DB-A2E8-4C7E-953C-E51E656B17BE}] DATAGRAM 2 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{684428F5-F4E3-4ED2-A0FF-E9AC81F0036C}] SEQPACKET 5 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip6_{684428F5-F4E3-4ED2-A0FF-E9AC81F0036C}] DATAGRAM 5 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{E00A53BF-27E1-41EB-82DE-18A4943A97DA}] SEQPACKET 12 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{E00A53BF-27E1-41EB-82DE-18A4943A97DA}] DATAGRAM 12 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{7998A5DB-A2E8-4C7E-953C-E51E656B17BE}] SEQPACKET 1 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{7998A5DB-A2E8-4C7E-953C-E51E656B17BE}] DATAGRAM 1 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{676D8C37-37E6-4F7D-8B6D-718F98F92ABE}] SEQPACKET 8 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{676D8C37-37E6-4F7D-8B6D-718F98F92ABE}] DATAGRAM 8 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{684428F5-F4E3-4ED2-A0FF-E9AC81F0036C}] SEQPACKET 4 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{684428F5-F4E3-4ED2-A0FF-E9AC81F0036C}] DATAGRAM 4 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{448D5BFD-7E90-4699-8187-DD56E10DBA5D}] SEQPACKET 15 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{448D5BFD-7E90-4699-8187-DD56E10DBA5D}] DATAGRAM 15 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{A9ACB603-1F16-4088-ADF6-0B3B0C731234}] SEQPACKET 18 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       MSAFD NetBIOS [\Device\NetBT_Tcpip_{A9ACB603-1F16-4088-ADF6-0B3B0C731234}] DATAGRAM 18 - C:\Windows\System32\mswsock.dll - Microsoft Corporation - {8D5F1830-C273-11CF-95C8-00805F48A192}
       @%SystemRoot%\system32\nlasvc.dll,-1000 - C:\Windows\System32\nlaapi.dll - Microsoft Corporation
       @%SystemRoot%\system32\napinsp.dll,-1000 - C:\Windows\System32\NapiNSP.dll - Microsoft Corporation
       @%SystemRoot%\system32\pnrpnsp.dll,-1000 - C:\Windows\System32\pnrpnsp.dll - Microsoft Corporation
       @%SystemRoot%\system32\pnrpnsp.dll,-1001 - C:\Windows\System32\pnrpnsp.dll - Microsoft Corporation
       @%SystemRoot%\system32\wshtcpip.dll,-60103 - C:\Windows\System32\mswsock.dll - Microsoft Corporation
       NTDS - C:\Windows\System32\winrnr.dll - Microsoft Corporation
       WindowsLive NSP - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
       WindowsLive Local NSP - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - Microsoft Corp.
       mdnsNSP - C:\Program Files\Bonjour\mdnsNSP.dll - Apple Inc.

==========================================================================================

Hosts File

       


==========================================================================================

Startup

       avast - C:\Program Files\AVAST Software\Avast\AvastUI.exe - AVAST Software - [\Registry\Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\Run avast]
       BigDog305 - C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305) - File not found - [\Registry\Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\Run BigDog305]
       APSDaemon - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe - Apple Inc. - [\Registry\Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\Run APSDaemon]
       iTunesHelper - C:\Program Files\iTunes\iTunesHelper.exe - Apple Inc. - [\Registry\Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\Run iTunesHelper]
        -  -  - [\REGISTRY\USER\S-1-5-21-3678732471-1654464958-2998469604-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
       Google Update - C:\Users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe - Google Inc. - [\REGISTRY\USER\S-1-5-21-3678732471-1654464958-2998469604-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Google Update]
       OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe -  - [C:\Users\dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk]
       wdmaud.drv - C:\Windows\system32\wdmaud.drv - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 aux]
       Shell - explorer.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell]
       Userinit - C:\Windows\system32\userinit.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit]
       LIDIL hpzllw71 - C:\Windows\system32\hpzllw71.dll - Hewlett-Packard Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Monitors LIDIL hpzllw71]
       Local Port - C:\Windows\system32\localspl.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Monitors Local Port]
       Microsoft Shared Fax Monitor - C:\Windows\system32\FXSMON.DLL - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Monitors Microsoft Shared Fax Monitor]
       Standard TCP/IP Port - C:\Windows\system32\tcpmon.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Monitors Standard TCP/IP Port]
       USB Monitor - C:\Windows\system32\usbmon.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Monitors USB Monitor]
       WSD Port - C:\Windows\system32\WSDMon.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Monitors WSD Port]
       Internet Print Provider - C:\Windows\system32\inetpp.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Providers Internet Print Provider]
       LanMan Print Services - C:\Windows\system32\win32spl.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Print\Providers LanMan Print Services]
       clbcatq - C:\Windows\System32\clbcatq.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs clbcatq]
       ole32 - C:\Windows\System32\ole32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs ole32]
       advapi32 - C:\Windows\System32\advapi32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs advapi32]
       COMDLG32 - C:\Windows\System32\comdlg32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs COMDLG32]
       gdi32 - C:\Windows\System32\gdi32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs gdi32]
       IERTUTIL - C:\Windows\System32\iertutil.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs IERTUTIL]
       IMAGEHLP - C:\Windows\System32\imagehlp.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs IMAGEHLP]
       IMM32 - C:\Windows\System32\imm32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs IMM32]
       kernel32 - C:\Windows\System32\kernel32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs kernel32]
       LPK - C:\Windows\System32\lpk.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs LPK]
       MSCTF - C:\Windows\System32\msctf.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs MSCTF]
       MSVCRT - C:\Windows\System32\msvcrt.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs MSVCRT]
       NORMALIZ - C:\Windows\System32\normaliz.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs NORMALIZ]
       NSI - C:\Windows\System32\nsi.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs NSI]
       OLEAUT32 - C:\Windows\System32\oleaut32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs OLEAUT32]
       PSAPI - C:\Windows\System32\psapi.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs PSAPI]
       rpcrt4 - C:\Windows\System32\rpcrt4.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs rpcrt4]
       sechost - C:\Windows\System32\sechost.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs sechost]
       Setupapi - C:\Windows\System32\setupapi.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs Setupapi]
       SHELL32 - C:\Windows\System32\shell32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs SHELL32]
       SHLWAPI - C:\Windows\System32\shlwapi.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs SHLWAPI]
       URLMON - C:\Windows\System32\urlmon.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs URLMON]
       user32 - C:\Windows\System32\user32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs user32]
       USP10 - C:\Windows\System32\usp10.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs USP10]
       WININET - C:\Windows\System32\wininet.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs WININET]
       WLDAP32 - C:\Windows\System32\Wldap32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs WLDAP32]
       WS2_32 - C:\Windows\System32\ws2_32.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs WS2_32]
       DifxApi - C:\Windows\System32\difxapi.dll - Microsoft Corporation - [\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs DifxApi]
       ashShell.dll(avast) - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers avast]
       syncui.dll(BriefcaseMenu) - C:\Windows\System32\syncui.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers BriefcaseMenu]
       NppShell_04.dll(Notepad++) - C:\Program Files\Notepad++\NppShell_04.dll -  - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers Notepad++]
       shell32.dll(Open With) - C:\Windows\System32\shell32.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers Open With]
       shell32.dll(Open With EncryptionMenu) - C:\Windows\System32\shell32.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers Open With EncryptionMenu]
       ntshrui.dll(Sharing) - C:\Windows\System32\ntshrui.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers Sharing]
       RarExt.dll(WinRAR) - C:\Program Files\WinRAR\RarExt.dll -  - [\Registry\Machine\SOFTWARE\Classes\*\shellex\ContextMenuHandlers WinRAR]
       ashShell.dll(00avast) - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software - [\Registry\Machine\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers 00avast]
       shell32.dll(CopyAsPathMenu) - C:\Windows\System32\shell32.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers CopyAsPathMenu]
       shell32.dll(SendTo) - C:\Windows\System32\shell32.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers SendTo]
       ashShell.dll(avast) - C:\Program Files\AVAST Software\Avast\ashShell.dll - AVAST Software - [\Registry\Machine\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers avast]
       syncui.dll(BriefcaseMenu) - C:\Windows\System32\syncui.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers BriefcaseMenu]
       shell32.dll(Library Location) - C:\Windows\System32\shell32.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers Library Location]
       RarExt.dll(WinRAR) - C:\Program Files\WinRAR\RarExt.dll -  - [\Registry\Machine\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers WinRAR]
       Microsoft Windows Media Player(>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}) - C:\Windows\System32\unregmp2.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
       Internet Explorer(>{26923b43-4d38-484f-9b9e-de460746276c}) - C:\Windows\System32\ie4uinit.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components >{26923b43-4d38-484f-9b9e-de460746276c}]
       Browser Customizations(>{60B49E34-C7CC-11D0-8953-00A0C90347FF}) - C:\Windows\System32\iedkcs32.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components >{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
       Themes Setup({2C7339CF-2B09-4501-B3F3-F3508C9228ED}) - C:\Windows\System32\regsvr32.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components {2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
       Microsoft Windows({44BBA840-CC51-11CF-AAFA-00AA00B6015C}) - C:\Program Files\Windows Mail\WinMail.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components {44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
       Microsoft Windows Media Player({6BF52A52-394A-11d3-B153-00C04F79FAA6}) - C:\Windows\System32\unregmp2.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components {6BF52A52-394A-11d3-B153-00C04F79FAA6}]
       Windows Desktop Update({89820200-ECBD-11cf-8B85-00AA005B4340}) - C:\Windows\system32\regsvr32.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components {89820200-ECBD-11cf-8B85-00AA005B4340}]
       Web Platform Customizations({89820200-ECBD-11cf-8B85-00AA005B4383}) - C:\Windows\System32\ie4uinit.exe - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components {89820200-ECBD-11cf-8B85-00AA005B4383}]
       ({89B4C1CD-B018-4511-B0A1-5476DBF70820}) - C:\Windows\System32\mscories.dll - Microsoft Corporation - [\Registry\Machine\SOFTWARE\Microsoft\Active Setup\Installed Components {89B4C1CD-B018-4511-B0A1-5476DBF70820}]
       GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000UA.job - C:\Users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe - Google Inc. - [Task Scheduler]
       GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000Core.job - C:\Users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe - Google Inc. - [Task Scheduler]

==========================================================================================

Service

       AeLookupSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       ALG - Stopped - Manual - C:\Windows\System32\alg.exe - C:\Windows\System32\alg.exe -  - 
       AppIDSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       Appinfo - Started - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       Apple Mobile Device - Started - Automatic - "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -  - 
       aspnet_state - Stopped - Manual - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -  - 
       AudioEndpointBuilder - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       Audiosrv - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       avast! Antivirus - Started - Automatic - "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" - C:\Program Files\AVAST Software\Avast\AvastSvc.exe -  - 
       AxInstSV - Stopped - Manual - C:\Windows\system32\svchost.exe -k AxInstSVGroup - C:\Windows\system32\svchost.exe -  - 
       BDESVC - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       BFE - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - C:\Windows\system32\svchost.exe -  - 
       BITS - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       Bonjour Service - Started - Automatic - "C:\Program Files\Bonjour\mDNSResponder.exe" - C:\Program Files\Bonjour\mDNSResponder.exe -  - 
       Browser - Started - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       bthserv - Stopped - Manual - C:\Windows\system32\svchost.exe -k bthsvcs - C:\Windows\system32\svchost.exe -  - 
       Cepstral License Server - Started - Automatic - "C:\Program Files\Cepstral\bin\CepstralLicSrv.exe" - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe -  - 
       CertPropSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       clr_optimization_v2.0.50727_32 - Stopped - Disabled - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -  - 
       clr_optimization_v4.0.30319_32 - Stopped - Automatic - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -  - 
       COMSysApp - Stopped - Manual - C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} - C:\Windows\system32\dllhost.exe -  - 
       CryptSvc - Started - Automatic - C:\Windows\system32\svchost.exe -k NetworkService - C:\Windows\system32\svchost.exe -  - 
       DcomLaunch - Started - Automatic - C:\Windows\system32\svchost.exe -k DcomLaunch - C:\Windows\system32\svchost.exe -  - 
       defragsvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k defragsvc - C:\Windows\system32\svchost.exe -  - 
       Dhcp - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       Dnscache - Started - Automatic - C:\Windows\system32\svchost.exe -k NetworkService - C:\Windows\system32\svchost.exe -  - 
       dot3svc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       DPS - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork - C:\Windows\System32\svchost.exe -  - 
       Dyyno Launcher - Started - Automatic - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe -  - 
       EapHost - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       EFS - Stopped - Manual - C:\Windows\System32\lsass.exe - C:\Windows\System32\lsass.exe -  - 
       ehRecvr - Stopped - Manual - C:\Windows\ehome\ehrecvr.exe - C:\Windows\ehome\ehrecvr.exe -  - 
       ehSched - Stopped - Manual - C:\Windows\ehome\ehsched.exe - C:\Windows\ehome\ehsched.exe -  - 
       eventlog - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       EventSystem - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       Fax - Stopped - Manual - C:\Windows\System32\FXSSVC.exe - C:\Windows\System32\FXSSVC.exe -  - 
       fdPHost - Started - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       FDResPub - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       FLEXnet Licensing Service - Stopped - Manual - "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -  - 
       FontCache - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       FontCache3.0.0.0 - Stopped - Manual - C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe - C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -  - 
       gpsvc - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       hidserv - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       hkmsvc - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       HomeGroupListener - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       HomeGroupProvider - Started - Manual - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       idsvc - Stopped - Manual - "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" - C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -  - 
       IKEEXT - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       IPBusEnum - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       iphlpsvc - Started - Automatic - C:\Windows\System32\svchost.exe -k NetSvcs - C:\Windows\System32\svchost.exe -  - 
       iPod Service - Started - Manual - "C:\Program Files\iPod\bin\iPodService.exe" - C:\Program Files\iPod\bin\iPodService.exe -  - 
       KeyIso - Stopped - Manual - C:\Windows\System32\lsass.exe - C:\Windows\System32\lsass.exe -  - 
       KtmRm - Stopped - Manual - C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation - C:\Windows\System32\svchost.exe -  - 
       LanmanServer - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       LanmanWorkstation - Started - Automatic - C:\Windows\System32\svchost.exe -k NetworkService - C:\Windows\System32\svchost.exe -  - 
       lltdsvc - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalService - C:\Windows\System32\svchost.exe -  - 
       lmhosts - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       Mcx2Svc - Stopped - Disabled - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       MMCSS - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       MpsSvc - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - C:\Windows\system32\svchost.exe -  - 
       MSDTC - Stopped - Manual - C:\Windows\System32\msdtc.exe - C:\Windows\System32\msdtc.exe -  - 
       MSiSCSI - Stopped - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       msiserver - Stopped - Manual - C:\Windows\system32\msiexec.exe /V - C:\Windows\system32\msiexec.exe -  - 
       MSSQL$SQLEXPRESS - Started - Automatic - "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe -  - 
       MSSQLServerADHelper100 - Stopped - Disabled - "C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE" - C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE -  - 
       napagent - Stopped - Manual - C:\Windows\System32\svchost.exe -k NetworkService - C:\Windows\System32\svchost.exe -  - 
       Netlogon - Stopped - Manual - C:\Windows\System32\lsass.exe - C:\Windows\System32\lsass.exe -  - 
       Netman - Started - Manual - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       NetMsmqActivator - Stopped - Disabled - "C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -  - 
       NetPipeActivator - Stopped - Disabled - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -  - 
       netprofm - Started - Manual - C:\Windows\System32\svchost.exe -k LocalService - C:\Windows\System32\svchost.exe -  - 
       NetTcpActivator - Stopped - Disabled - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -  - 
       NetTcpPortSharing - Stopped - Disabled - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -  - 
       NlaSvc - Started - Automatic - C:\Windows\System32\svchost.exe -k NetworkService - C:\Windows\System32\svchost.exe -  - 
       nsi - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       nvsvc - Started - Automatic - C:\Windows\System32\nvvsvc.exe - C:\Windows\System32\nvvsvc.exe -  - 
       nvUpdatusService - Started - Automatic - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -  - 
       p2pimsvc - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalServicePeerNet - C:\Windows\System32\svchost.exe -  - 
       p2psvc - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalServicePeerNet - C:\Windows\System32\svchost.exe -  - 
       PcaSvc - Started - Manual - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       PDAgent - Started - Automatic - "C:\Program Files\Raxco\PerfectDisk\PDAgent.exe" - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe -  - 
       PDEngine - Started - Manual - "C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe" - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe -  - 
       pla - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork - C:\Windows\System32\svchost.exe -  - 
       PlugPlay - Started - Automatic - C:\Windows\system32\svchost.exe -k DcomLaunch - C:\Windows\system32\svchost.exe -  - 
       PnkBstrA - Started - Automatic - C:\Windows\System32\PnkBstrA.exe - C:\Windows\System32\PnkBstrA.exe -  - 
       PnkBstrB - Started - Automatic - C:\Windows\System32\PnkBstrB.exe - C:\Windows\System32\PnkBstrB.exe -  - 
       PNRPAutoReg - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalServicePeerNet - C:\Windows\System32\svchost.exe -  - 
       PNRPsvc - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalServicePeerNet - C:\Windows\System32\svchost.exe -  - 
       PolicyAgent - Started - Manual - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       Power - Started - Automatic - C:\Windows\system32\svchost.exe -k DcomLaunch - C:\Windows\system32\svchost.exe -  - 
       ProfSvc - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       ProtectedStorage - Stopped - Manual - C:\Windows\System32\lsass.exe - C:\Windows\System32\lsass.exe -  - 
       QWAVE - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       RasAuto - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       RasMan - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       RemoteAccess - Stopped - Disabled - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       RemoteRegistry - Stopped - Disabled - C:\Windows\system32\svchost.exe -k regsvc - C:\Windows\system32\svchost.exe -  - 
       RpcEptMapper - Started - Automatic - C:\Windows\system32\svchost.exe -k RPCSS - C:\Windows\system32\svchost.exe -  - 
       RpcLocator - Stopped - Manual - C:\Windows\System32\Locator.exe - C:\Windows\System32\Locator.exe -  - 
       RpcSs - Started - Automatic - C:\Windows\system32\svchost.exe -k rpcss - C:\Windows\system32\svchost.exe -  - 
       SamSs - Started - Automatic - C:\Windows\System32\lsass.exe - C:\Windows\System32\lsass.exe -  - 
       SCardSvr - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       Schedule - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       SCPolicySvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       SDRSVC - Stopped - Manual - C:\Windows\system32\svchost.exe -k SDRSVC - C:\Windows\system32\svchost.exe -  - 
       seclogon - Stopped - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       SENS - Stopped - Manual - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       SensrSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       ServiceLayer - Stopped - Manual - "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe" - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -  - 
       SessionEnv - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       SharedAccess - Stopped - Disabled - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       ShellHWDetection - Started - Automatic - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       SNMPTRAP - Stopped - Manual - C:\Windows\System32\snmptrap.exe - C:\Windows\System32\snmptrap.exe -  - 
       Spooler - Started - Automatic - C:\Windows\System32\spoolsv.exe - C:\Windows\System32\spoolsv.exe -  - 
       sppsvc - Stopped - Automatic - C:\Windows\System32\sppsvc.exe - C:\Windows\System32\sppsvc.exe -  - 
       sppuinotify - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       SQLAgent$SQLEXPRESS - Stopped - Disabled - "C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE" -i SQLEXPRESS - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE -  - 
       SQLBrowser - Stopped - Disabled - "C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -  - 
       SQLWriter - Started - Automatic - "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -  - 
       SSDPSRV - Started - Manual - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       SstpSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       Stereo Service - Started - Automatic - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -  - 
       StiSvc - Started - Automatic - C:\Windows\system32\svchost.exe -k imgsvc - C:\Windows\system32\svchost.exe -  - 
       swprv - Stopped - Manual - C:\Windows\System32\svchost.exe -k swprv - C:\Windows\System32\svchost.exe -  - 
       SysMain - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       TabletInputService - Stopped - Disabled - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       TapiSrv - Stopped - Manual - C:\Windows\System32\svchost.exe -k NetworkService - C:\Windows\System32\svchost.exe -  - 
       TBS - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\System32\svchost.exe -  - 
       TeamViewer6 - Started - Automatic - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -  - 
       TeamViewer7 - Started - Automatic - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -  - 
       TermService - Stopped - Manual - C:\Windows\System32\svchost.exe -k NetworkService - C:\Windows\System32\svchost.exe -  - 
       Themes - Started - Automatic - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       THREADORDER - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       TrkWks - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       TrustedInstaller - Stopped - Manual - C:\Windows\servicing\TrustedInstaller.exe - C:\Windows\servicing\TrustedInstaller.exe -  - 
       TunngleService - Stopped - Disabled - C:\Program Files\Tunngle\TnglCtrl.exe - C:\Program Files\Tunngle\TnglCtrl.exe -  - 
       UI0Detect - Stopped - Manual - C:\Windows\System32\UI0Detect.exe - C:\Windows\System32\UI0Detect.exe -  - 
       upnphost - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -  - 
       UxSms - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       VaultSvc - Stopped - Manual - C:\Windows\System32\lsass.exe - C:\Windows\System32\lsass.exe -  - 
       vds - Stopped - Manual - C:\Windows\System32\vds.exe - C:\Windows\System32\vds.exe -  - 
       VMAuthdService - Started - Automatic - "C:\Program Files\VMware\VMware Workstation\vmware-authd.exe" - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe -  - 
       VMnetDHCP - Started - Automatic - C:\Windows\System32\vmnetdhcp.exe - C:\Windows\System32\vmnetdhcp.exe -  - 
       VMUSBArbService - Started - Automatic - "C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe" - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe -  - 
       VMware NAT Service - Started - Automatic - C:\Windows\System32\vmnat.exe - C:\Windows\System32\vmnat.exe -  - 
       VMwareHostd - Started - Automatic - "C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe -  - 
       VSS - Stopped - Manual - C:\Windows\System32\VSSVC.exe - C:\Windows\System32\VSSVC.exe -  - 
       W32Time - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       WatAdminSvc - Stopped - Manual - C:\Windows\System32\Wat\WatAdminSvc.exe - C:\Windows\System32\Wat\WatAdminSvc.exe -  - 
       wbengine - Stopped - Manual - "C:\Windows\system32\wbengine.exe" - C:\Windows\system32\wbengine.exe -  - 
       WbioSrvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k WbioSvcGroup - C:\Windows\system32\svchost.exe -  - 
       wcncsvc - Started - Manual - C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation - C:\Windows\System32\svchost.exe -  - 
       WcsPlugInService - Stopped - Manual - C:\Windows\system32\svchost.exe -k wcssvc - C:\Windows\system32\svchost.exe -  - 
       WdiServiceHost - Started - Manual - C:\Windows\System32\svchost.exe -k LocalService - C:\Windows\System32\svchost.exe -  - 
       WdiSystemHost - Stopped - Manual - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       WebClient - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       Wecsvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k NetworkService - C:\Windows\system32\svchost.exe -  - 
       wercplsupport - Stopped - Manual - C:\Windows\System32\svchost.exe -k netsvcs - C:\Windows\System32\svchost.exe -  - 
       WerSvc - Stopped - Manual - C:\Windows\System32\svchost.exe -k WerSvcGroup - C:\Windows\System32\svchost.exe -  - 
       WinDefend - Stopped - Manual - C:\Windows\System32\svchost.exe -k secsvcs - C:\Windows\System32\svchost.exe -  - 
       WinHttpAutoProxySvc - Started - Manual - C:\Windows\system32\svchost.exe -k LocalService - C:\Windows\system32\svchost.exe -  - 
       Winmgmt - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       WinRM - Stopped - Manual - C:\Windows\System32\svchost.exe -k NetworkService - C:\Windows\System32\svchost.exe -  - 
       Wlansvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       wlidsvc - Started - Automatic - "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -  - 
       wmiApSrv - Stopped - Manual - C:\Windows\System32\wbem\WmiApSrv.exe - C:\Windows\System32\wbem\WmiApSrv.exe -  - 
       WMPNetworkSvc - Started - Manual - "C:\Program Files\Windows Media Player\wmpnetwk.exe" - C:\Program Files\Windows Media Player\wmpnetwk.exe -  - 
       WPCSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       WPDBusEnum - Stopped - Disabled - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       wscsvc - Started - Automatic - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - C:\Windows\System32\svchost.exe -  - 
       WSearch - Started - Automatic - C:\Windows\system32\SearchIndexer.exe /Embedding - C:\Windows\system32\SearchIndexer.exe -  - 
       wuauserv - Started - Automatic - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -  - 
       wudfsvc - Started - Automatic - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - C:\Windows\system32\svchost.exe -  - 
       WwanSvc - Stopped - Manual - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - C:\Windows\system32\svchost.exe -  - 

==========================================================================================

File Association

       .bat - "%1" %* - HKEY_CLASSES_ROOT\.bat
       .cmd - "%1" %* - HKEY_CLASSES_ROOT\.cmd
       .com - "%1" %* - HKEY_CLASSES_ROOT\.com
       .exe - "%1" %* - HKEY_CLASSES_ROOT\.exe
       .scr - "%1" /S - HKEY_CLASSES_ROOT\.scr
       .txt - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CLASSES_ROOT\.txt
       .ini - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CLASSES_ROOT\.ini
       .pif - "%1" %* - HKEY_CLASSES_ROOT\.pif
       .reg - regedit.exe "%1" - HKEY_CLASSES_ROOT\.reg
       .inf - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CLASSES_ROOT\.inf
       .hlp - %SystemRoot%\winhlp32.exe %1 - HKEY_CLASSES_ROOT\.hlp
       .chm - "%SystemRoot%\hh.exe" %1 - HKEY_CLASSES_ROOT\.chm
       .vbs - "%SystemRoot%\System32\WScript.exe" "%1" %* - HKEY_CLASSES_ROOT\.vbs
       .js - C:\Windows\System32\WScript.exe "%1" %* - HKEY_CLASSES_ROOT\.js
       .lnk - lnkfile - HKEY_CLASSES_ROOT\.lnk
       batfile - "%1" %* - HKEY_CLASSES_ROOT\batfile\Shell\Open\Command
       cmdfile - "%1" %* - HKEY_CLASSES_ROOT\cmdfile\Shell\Open\Command
       comfile - "%1" %* - HKEY_CLASSES_ROOT\comfile\Shell\Open\Command
       exefile - "%1" %* - HKEY_CLASSES_ROOT\exefile\Shell\Open\Command
       scrfile - "%1" /S - HKEY_CLASSES_ROOT\scrfile\Shell\Open\Command
       txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CLASSES_ROOT\txtfile\Shell\Open\Command
       inifile - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CLASSES_ROOT\inifile\Shell\Open\Command
       piffile - "%1" %* - HKEY_CLASSES_ROOT\piffile\Shell\Open\Command
       regfile - regedit.exe "%1" - HKEY_CLASSES_ROOT\regfile\Shell\Open\Command
       inffile - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CLASSES_ROOT\inffile\Shell\Open\Command
       hlpfile - %SystemRoot%\winhlp32.exe %1 - HKEY_CLASSES_ROOT\hlpfile\Shell\Open\Command
       chm.file - "%SystemRoot%\hh.exe" %1 - HKEY_CLASSES_ROOT\chm.file\Shell\Open\Command
       vbsfile - "%SystemRoot%\System32\WScript.exe" "%1" %* - HKEY_CLASSES_ROOT\vbsfile\Shell\Open\Command
       jsfile - C:\Windows\System32\WScript.exe "%1" %* - HKEY_CLASSES_ROOT\jsfile\Shell\Open\Command
       HKCU .bat Progid - "%1" %* - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat\OpenWithProgids
       HKCU .cmd Progid - "%1" %* - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cmd\OpenWithProgids
       HKCU .exe Progid - "%1" %* - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
       HKCU .scr Progid - "%1" /S - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scr\OpenWithProgids
       HKCU .txt Progid - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
       HKCU .ini Progid - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithProgids
       HKCU .inf Progid - %SystemRoot%\system32\NOTEPAD.EXE %1 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\OpenWithProgids
       HKCU .lnk Progid -  - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk\OpenWithProgids
       HKCU .ini Progid - Applications\WordPad.exe - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\UserChoice

==========================================================================================

IFEO

       Nothing

==========================================================================================

IME

       US -  -  - C:\Windows\system32\KBDUS.DLL - Microsoft Corporation
       Slovak -  -  - C:\Windows\system32\KBDSL.DLL - Microsoft Corporation

==========================================================================================

Firewall Rule

       Nothing

==========================================================================================

Scan MBR Rootkit

       MBR OK!
