This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Backdoor.Tidserv!nf / Backdoor.Tidserv.I!nf

80 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I am new to this forums and I hope you can help me. For the past month, I have been trying to resolve this backdoor.tidserv issue detected in my Norton 360 to no avail. I have browsed all over the web for solutions and tools to remedy my problem to no avail. As of posting, there are still 3 unresolved risks in my history list showing this backdoor.tidserv thing, I really don't know what to do. I have tried using a tool called tdsskiller from kaspersky which found the anomaly but have not fully removed the thing although it says it did. I tried using combofix also, and did a scan in safe mode using MBAM and super antispyware. All of the scan results showed clean but the issue just wouldn't go away, it is still in my unresolved security risks. I am using a pc running windows 7 home premium 32-bit. My tools: norton 360, super anti spyware free ed, malwarebyte's antimalware free ed, tuneup utilities, regcure Below is a script from my firewall log specific to backdoor.tidserv: Category: Resolved Security Risks Date & Time,Severity,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State,File Name 7/23/2010 7:08 AM,High,Backdoor.Tidserv!gen5 detected by Auto-Protect,Quarantined,Resolved - No Action,Auto-Protect,2010.07.21.020,110.1.0.78,Backdoor.Tidserv!gen5,Heuristic Virus,File Based,Fully removed, 7/22/2010 11:02 PM,High,Backdoor.Tidserv!gen5 detected by Auto-Protect,Quarantined,Resolved - No Action,Auto-Protect,2010.07.21.020,110.1.0.78,Backdoor.Tidserv!gen5,Heuristic Virus,File Based,Fully removed, 7/22/2010 10:54 PM,High,Auto-Protect has detected Backdoor.Tidserv!gen5,"Blocked, Blocked",Resolved - No Action,Auto-Protect,2010.07.21.020,,,Heuristic Virus,,,c:\users\darryle\appdata\local\temp\setieinstalleddateb.exe 7/22/2010 10:54 PM,High,Auto-Protect has detected Backdoor.Tidserv!gen5,"Blocked, Blocked",Resolved - No Action,Auto-Protect,2010.07.21.020,,,Heuristic Virus,,,c:\users\darryle\appdata\local\microsoft\windows\temporary internet files\content.ie5\niv8q1vw\nupdater32[1].exe Category: Unresolved Security Risks Date & Time,Severity,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State 9/6/2010 3:22 AM,High,Backdoor.Tidserv!inf detected by Auto-Protect,Manual Removal Required,Review risk details on Symantec Web site.,Auto-Protect,2010.09.04.003,110.1.0.78,Backdoor.Tidserv!inf,Virus,File Based,Not safe to remove 9/6/2010 3:22 AM,High,Backdoor.Tidserv.I!inf detected by Virus scanner,Manual Removal Required,Review risk details on Symantec Web site.,Virus scanner,2010.09.04.003,110.1.0.78,Backdoor.Tidserv.I!inf,Virus,File Based,Not safe to remove 9/6/2010 3:21 AM,High,Backdoor.Tidserv.I!inf detected by Virus scanner,Manual Removal Required,Review risk details on Symantec Web site.,Virus scanner,2010.09.04.003,[removed],Backdoor.Tidserv.I!inf,Virus,File Based,Not safe to remove Category: Quarantine Date & Time,Severity,Activity,Status,Recommended Action,Component,Definitions Version,ERASER Version,Risk Name,Risk Category,Risk Type,Risk State 7/23/2010 7:08 AM,High,Backdoor.Tidserv!gen5 detected by Auto-Protect,Quarantined,Resolved - No Action,Auto-Protect,2010.07.21.020,110.1.0.78,Backdoor.Tidserv!gen5,Heuristic Virus,File Based,Fully removed 7/22/2010 11:02 PM,High,Backdoor.Tidserv!gen5 detected by Auto-Protect,Quarantined,Resolved - No Action,Auto-Protect,2010.07.21.020,[removed],Backdoor.Tidserv!gen5,Heuristic Virus,File Based,Fully removed Category: Sites reported to Symantec Date & Time,Severity,Activity,Status,Recommended Action 9/6/2010 3:40 AM,Info,"URL \"http://208.74.204.196/t5/Norton-360/Backdoor-tidserv/td-p/130319/highlight/true/page/2\" was submitted for further suspicious analysis",Submitted,No Action Required 9/6/2010 3:38 AM,Info,"URL \"http://208.74.204.196/t5/Norton-360/Backdoor-tidserv/td-p/130319/page/2\" was submitted for further suspicious analysis",Submitted,No Action Required 9/6/2010 3:37 AM,Info,"URL \"http://208.74.204.196/t5/Norton-360/Backdoor-tidserv/td-p/130319/page/2\" was submitted for further suspicious analysis",Submitted,No Action Required I would have wanted to post a hijackthis log but the program freezes before it finishes, guess because of the malware also? Any help would be greatly appreciated. Thanks.
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


Please post the ComboFix log.

Locating ComboFix Log
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here.



NEXT:



Rootkit UnHooker (RkU)
Please download Rootkit Unhooker … Save it to your Desktop.
Note: The log can be very long, you may need to post it separately.
  • Double-click on RKUnhookerLE.exe to execute it.
    Vista - W7 users: Right click RKUnhookerLE.exe, choose "Run As Administrator" to execute it. If UAC prompts, please allow it.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth Code, Files and Code Hooks. Uncheck the rest. then Click OK. (See image below…)
    🖼Click to load external image (Posted Image)
    The scanning will toggle through the checked items "tabs" … it will take a while, so please be patient.
  • When the scanner is finished… click File, Save Report.
  • Save the file "Report.txt" to your Desktop… Press Close… then press Yes
  • Copy the entire contents of the Report.txt file in you're next reply.

Please Note:
You may get this warning, it is ok, just ignore it:
"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"




NEXT:



  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello SweetTech, I have read your instructions and will get back to you as soon as I have all the logs you are asking. Appreciate your taking the time in helping me.
This is funny because for some reason, i cannot find the combofix folder or the .txt file anywhere in my computer. I have searched all my 3 drives starting with C:\ without any success. Is that possible? I ran combofix last saturday night, afterwhich I executed combofix \uninstall, would that result in the log file also being erased from the system? I can't remember deleting the file though but I am not so sure. The only log folder present in my C:\ is "TDSSKiller_Quarantine" which I assume was logged by the TDSSKiller tool I also used. That folder is empty but just within C:\ there are 4 TDSSKiller logs in .txt format present, would those be useful to you?
Here are the TDSSKiller logs, in order as I see them in C:\: TDSSKiller.2.4.1.2_04.09.2010_21.51.16_log 2010/09/04 21:51:16.0082 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23 2010/09/04 21:51:16.0082 ================================================================================ 2010/09/04 21:51:16.0082 SystemInfo: 2010/09/04 21:51:16.0082 2010/09/04 21:51:16.0082 OS Version: 6.1.7600 ServicePack: 0.0 2010/09/04 21:51:16.0082 Product type: Workstation 2010/09/04 21:51:16.0082 ComputerName: DARRYL 2010/09/04 21:51:16.0082 UserName: Darryle 2010/09/04 21:51:16.0082 Windows directory: C:\Windows 2010/09/04 21:51:16.0082 System windows directory: C:\Windows 2010/09/04 21:51:16.0082 Processor architecture: Intel x86 2010/09/04 21:51:16.0082 Number of processors: 2 2010/09/04 21:51:16.0082 Page size: 0x1000 2010/09/04 21:51:16.0082 Boot type: Normal boot 2010/09/04 21:51:16.0082 ================================================================================ 2010/09/04 21:51:23.0352 Initialize success 2010/09/04 21:51:25.0645 Deinitialize success TDSSKiller.2.4.1.2_04.09.2010_22.00.00_log 2010/09/04 22:00:00.0967 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23 2010/09/04 22:00:00.0967 ================================================================================ 2010/09/04 22:00:00.0967 SystemInfo: 2010/09/04 22:00:00.0967 2010/09/04 22:00:00.0967 OS Version: 6.1.7600 ServicePack: 0.0 2010/09/04 22:00:00.0967 Product type: Workstation 2010/09/04 22:00:00.0967 ComputerName: DARRYL 2010/09/04 22:00:00.0967 UserName: Darryle 2010/09/04 22:00:00.0967 Windows directory: C:\Windows 2010/09/04 22:00:00.0967 System windows directory: C:\Windows 2010/09/04 22:00:00.0967 Processor architecture: Intel x86 2010/09/04 22:00:00.0967 Number of processors: 2 2010/09/04 22:00:00.0967 Page size: 0x1000 2010/09/04 22:00:00.0967 Boot type: Normal boot 2010/09/04 22:00:00.0967 ================================================================================ 2010/09/04 22:00:01.0482 Initialize success 2010/09/04 22:00:03.0947 ================================================================================ 2010/09/04 22:00:03.0947 Scan started 2010/09/04 22:00:03.0947 Mode: Manual; 2010/09/04 22:00:03.0947 ================================================================================ 2010/09/04 22:00:04.0836 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/09/04 22:00:04.0867 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 2010/09/04 22:00:04.0883 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/09/04 22:00:04.0914 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/09/04 22:00:04.0945 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 2010/09/04 22:00:04.0961 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 2010/09/04 22:00:04.0992 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 2010/09/04 22:00:05.0023 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 2010/09/04 22:00:05.0039 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 2010/09/04 22:00:05.0070 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 2010/09/04 22:00:05.0086 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 2010/09/04 22:00:05.0210 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 2010/09/04 22:00:05.0335 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 2010/09/04 22:00:05.0366 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 2010/09/04 22:00:05.0398 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys 2010/09/04 22:00:05.0413 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/09/04 22:00:05.0429 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys 2010/09/04 22:00:05.0460 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 2010/09/04 22:00:05.0507 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 2010/09/04 22:00:05.0522 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 2010/09/04 22:00:05.0554 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/09/04 22:00:05.0554 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 2010/09/04 22:00:05.0616 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 2010/09/04 22:00:05.0647 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2010/09/04 22:00:05.0663 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2010/09/04 22:00:05.0710 BHDrvx86 (76154fa6a742c613b44bb636b1a7c057) C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys 2010/09/04 22:00:05.0725 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/09/04 22:00:05.0756 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 2010/09/04 22:00:05.0772 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/09/04 22:00:05.0788 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/09/04 22:00:05.0819 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2010/09/04 22:00:05.0834 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/09/04 22:00:05.0866 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/09/04 22:00:05.0881 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/09/04 22:00:05.0912 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/09/04 22:00:05.0944 ccHP (8973ff34b83572d867b5b928905ad5ac) C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys 2010/09/04 22:00:05.0959 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2010/09/04 22:00:05.0990 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 2010/09/04 22:00:06.0006 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 2010/09/04 22:00:06.0037 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2010/09/04 22:00:06.0084 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/09/04 22:00:06.0100 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 2010/09/04 22:00:06.0115 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2010/09/04 22:00:06.0146 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 2010/09/04 22:00:06.0162 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/09/04 22:00:06.0287 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/09/04 22:00:06.0318 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 2010/09/04 22:00:06.0349 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2010/09/04 22:00:06.0365 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 2010/09/04 22:00:06.0427 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2010/09/04 22:00:06.0443 DrvAgent32 (651554e483712b708ede864d0ca1aa73) C:\Windows\system32\Drivers\DrvAgent32.sys 2010/09/04 22:00:06.0490 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys 2010/09/04 22:00:06.0568 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 2010/09/04 22:00:06.0739 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2010/09/04 22:00:06.0895 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 2010/09/04 22:00:06.0942 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2010/09/04 22:00:06.0958 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 2010/09/04 22:00:07.0114 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2010/09/04 22:00:07.0129 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2010/09/04 22:00:07.0160 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 2010/09/04 22:00:07.0192 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2010/09/04 22:00:07.0207 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2010/09/04 22:00:07.0223 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/09/04 22:00:07.0238 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2010/09/04 22:00:07.0270 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2010/09/04 22:00:07.0316 fssfltr (b74b0578fd1d3f897e95f2a2b69ea051) C:\Windows\system32\DRIVERS\fssfltr.sys 2010/09/04 22:00:07.0348 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2010/09/04 22:00:07.0363 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys 2010/09/04 22:00:07.0394 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/09/04 22:00:07.0519 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/09/04 22:00:07.0660 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2010/09/04 22:00:07.0691 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys 2010/09/04 22:00:07.0706 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/09/04 22:00:07.0738 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/09/04 22:00:07.0753 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 2010/09/04 22:00:07.0784 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 2010/09/04 22:00:07.0816 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 2010/09/04 22:00:07.0956 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/09/04 22:00:07.0972 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 2010/09/04 22:00:08.0018 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 2010/09/04 22:00:08.0065 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/09/04 22:00:08.0081 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/09/04 22:00:08.0424 IDSVix86 (2edd3504457691a10328079da011d0b8) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100903.003\IDSvix86.sys 2010/09/04 22:00:08.0455 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 2010/09/04 22:00:08.0549 IntcAzAudAddService (aee99ecf06cd1cea95816ccb5bf73ec8) C:\Windows\system32\drivers\RTKVHDA.sys 2010/09/04 22:00:08.0580 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 2010/09/04 22:00:08.0611 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2010/09/04 22:00:08.0627 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/09/04 22:00:08.0658 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/09/04 22:00:08.0674 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2010/09/04 22:00:08.0720 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2010/09/04 22:00:08.0736 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 2010/09/04 22:00:08.0767 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/09/04 22:00:08.0783 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/09/04 22:00:08.0814 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/09/04 22:00:08.0845 kl1 (ce3958f58547454884e97bda78cd7040) C:\Windows\system32\DRIVERS\kl1.sys 2010/09/04 22:00:08.0861 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 2010/09/04 22:00:08.0876 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys 2010/09/04 22:00:08.0908 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/09/04 22:00:08.0939 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/09/04 22:00:08.0970 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/09/04 22:00:08.0986 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/09/04 22:00:09.0001 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/09/04 22:00:09.0017 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2010/09/04 22:00:09.0048 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 2010/09/04 22:00:09.0079 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/09/04 22:00:09.0126 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\Windows\system32\drivers\Mkd2kfNt.sys 2010/09/04 22:00:09.0157 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\Windows\system32\drivers\Mkd2Nadr.sys 2010/09/04 22:00:09.0173 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2010/09/04 22:00:09.0204 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2010/09/04 22:00:09.0220 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2010/09/04 22:00:09.0235 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2010/09/04 22:00:09.0251 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 2010/09/04 22:00:09.0282 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 2010/09/04 22:00:09.0298 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2010/09/04 22:00:09.0329 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 2010/09/04 22:00:09.0344 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/09/04 22:00:09.0376 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/09/04 22:00:09.0391 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/09/04 22:00:09.0422 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 2010/09/04 22:00:09.0454 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 2010/09/04 22:00:09.0469 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2010/09/04 22:00:09.0500 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2010/09/04 22:00:09.0516 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/09/04 22:00:09.0547 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2010/09/04 22:00:09.0563 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/09/04 22:00:09.0578 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2010/09/04 22:00:09.0594 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2010/09/04 22:00:09.0641 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/09/04 22:00:09.0656 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2010/09/04 22:00:09.0672 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/09/04 22:00:09.0703 MTsensor (dcdaab8697a47894a554050ce18d0b56) C:\Windows\system32\DRIVERS\ASACPI.sys 2010/09/04 22:00:09.0719 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2010/09/04 22:00:09.0750 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2010/09/04 22:00:09.0890 NAVENG (0953bb24c1e70a99c315f44f15993c17) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100903.050\NAVENG.SYS 2010/09/04 22:00:09.0937 NAVEX15 (3ddb0bef60b65df6b110c23e17cd67dc) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100903.050\NAVEX15.SYS 2010/09/04 22:00:09.0968 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 2010/09/04 22:00:10.0000 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/09/04 22:00:10.0015 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/09/04 22:00:10.0031 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/09/04 22:00:10.0046 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/09/04 22:00:10.0062 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 2010/09/04 22:00:10.0093 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2010/09/04 22:00:10.0109 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 2010/09/04 22:00:10.0156 NetworkX (5ef7dd401771693245d46f4b0b69fe2b) C:\Windows\system32\ckldrv.sys 2010/09/04 22:00:10.0171 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/09/04 22:00:10.0202 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\Windows\system32\drivers\ccdcmb.sys 2010/09/04 22:00:10.0234 nmwcdc (3859c69a77793180548802dac9f34a38) C:\Windows\system32\drivers\ccdcmbo.sys 2010/09/04 22:00:10.0265 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\Windows\system32\drivers\nmwcdnsu.sys 2010/09/04 22:00:10.0296 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\Windows\system32\drivers\nmwcdnsuc.sys 2010/09/04 22:00:10.0327 NPF (6623e51595c0076755c29c00846c4eb2) C:\Windows\system32\drivers\npf.sys 2010/09/04 22:00:10.0343 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2010/09/04 22:00:10.0390 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2010/09/04 22:00:10.0436 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 2010/09/04 22:00:10.0468 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2010/09/04 22:00:10.0655 nvlddmkm (07144ee5ecb0eb4ece950bf4b2439865) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/09/04 22:00:10.0811 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys 2010/09/04 22:00:10.0842 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys 2010/09/04 22:00:10.0858 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 2010/09/04 22:00:10.0889 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/09/04 22:00:10.0920 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 2010/09/04 22:00:10.0951 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 2010/09/04 22:00:10.0967 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 2010/09/04 22:00:10.0998 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys 2010/09/04 22:00:11.0014 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 2010/09/04 22:00:11.0029 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 2010/09/04 22:00:11.0060 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/09/04 22:00:11.0076 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2010/09/04 22:00:11.0107 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2010/09/04 22:00:11.0185 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2010/09/04 22:00:11.0201 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 2010/09/04 22:00:11.0232 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2010/09/04 22:00:11.0263 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 2010/09/04 22:00:11.0294 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 2010/09/04 22:00:11.0326 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/09/04 22:00:11.0357 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2010/09/04 22:00:11.0388 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2010/09/04 22:00:11.0404 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/09/04 22:00:11.0419 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/09/04 22:00:11.0450 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/09/04 22:00:11.0466 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2010/09/04 22:00:11.0482 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 2010/09/04 22:00:11.0513 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/09/04 22:00:11.0544 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/09/04 22:00:11.0560 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2010/09/04 22:00:11.0575 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2010/09/04 22:00:11.0606 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 2010/09/04 22:00:11.0622 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 2010/09/04 22:00:11.0684 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys 2010/09/04 22:00:11.0700 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 2010/09/04 22:00:11.0731 ROOTMODEM (564297827d213f52c7a3a2ff749568ca) C:\Windows\system32\Drivers\RootMdm.sys 2010/09/04 22:00:11.0794 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2010/09/04 22:00:11.0825 RTL8167 (d5ede44ca85899e0478208c8413c1c31) C:\Windows\system32\DRIVERS\Rt86win7.sys 2010/09/04 22:00:11.0856 RTL8169 (034033f5a921764d8c4ba6698800d95b) C:\Windows\system32\DRIVERS\Rtlh86.sys 2010/09/04 22:00:11.0918 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2010/09/04 22:00:11.0918 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2010/09/04 22:00:11.0950 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/09/04 22:00:11.0981 SCDEmu (16b1abe7f3e35f21dac57592b6c5d464) C:\Windows\system32\drivers\SCDEmu.sys 2010/09/04 22:00:12.0012 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 2010/09/04 22:00:12.0059 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/09/04 22:00:12.0090 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2010/09/04 22:00:12.0106 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2010/09/04 22:00:12.0121 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 2010/09/04 22:00:12.0184 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/09/04 22:00:12.0199 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/09/04 22:00:12.0246 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/09/04 22:00:12.0262 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/09/04 22:00:12.0293 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 2010/09/04 22:00:12.0324 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/09/04 22:00:12.0340 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/09/04 22:00:12.0371 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2010/09/04 22:00:12.0418 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2010/09/04 22:00:12.0464 SRTSP (e81f6caeab9ad5732e94c07c97866aa2) C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS 2010/09/04 22:00:12.0496 SRTSPX (e28de499d942b08058bffac69d4122b6) C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS 2010/09/04 22:00:12.0527 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\Windows\system32\DRIVERS\srv.sys 2010/09/04 22:00:12.0558 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\Windows\system32\DRIVERS\srv2.sys 2010/09/04 22:00:12.0589 srvnet (08f28676802b58138e48a2b40caf6204) C:\Windows\system32\DRIVERS\srvnet.sys 2010/09/04 22:00:12.0620 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 2010/09/04 22:00:12.0652 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 2010/09/04 22:00:12.0667 SymEFA (d0885f6e24259a6c65e68d6ad749910a) C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS 2010/09/04 22:00:12.0698 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS 2010/09/04 22:00:12.0730 SYMFW (1e825026436c4eac3e1a11d1e9c33f2c) C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS 2010/09/04 22:00:12.0745 SymIM (34f1c9d5dcc19df1e824d6b73767b8af) C:\Windows\system32\DRIVERS\SymIMv.sys 2010/09/04 22:00:12.0776 SYMNDISV (dcbf73da96cce94933c8cc6eded3c98b) C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS 2010/09/04 22:00:12.0792 SYMTDI (e4fa8bbb96e314e9508865de1a767538) C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS 2010/09/04 22:00:12.0854 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys 2010/09/04 22:00:12.0886 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys 2010/09/04 22:00:12.0917 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 2010/09/04 22:00:12.0948 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 2010/09/04 22:00:12.0964 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 2010/09/04 22:00:12.0979 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 2010/09/04 22:00:12.0995 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 2010/09/04 22:00:13.0042 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/09/04 22:00:13.0135 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys 2010/09/04 22:00:13.0151 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 2010/09/04 22:00:13.0182 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 2010/09/04 22:00:13.0198 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 2010/09/04 22:00:13.0244 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/09/04 22:00:13.0291 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 2010/09/04 22:00:13.0307 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 2010/09/04 22:00:13.0338 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 2010/09/04 22:00:13.0369 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 2010/09/04 22:00:13.0416 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 2010/09/04 22:00:13.0432 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/09/04 22:00:13.0463 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 2010/09/04 22:00:13.0478 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 2010/09/04 22:00:13.0494 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 2010/09/04 22:00:13.0525 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 2010/09/04 22:00:13.0541 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 2010/09/04 22:00:13.0588 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 2010/09/04 22:00:13.0603 usbser (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys 2010/09/04 22:00:13.0619 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 2010/09/04 22:00:13.0650 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/09/04 22:00:13.0666 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/09/04 22:00:13.0697 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/09/04 22:00:13.0728 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/09/04 22:00:13.0759 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2010/09/04 22:00:13.0790 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/09/04 22:00:13.0806 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 2010/09/04 22:00:13.0837 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 2010/09/04 22:00:13.0853 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 2010/09/04 22:00:13.0884 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/09/04 22:00:13.0900 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2010/09/04 22:00:13.0931 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 2010/09/04 22:00:13.0946 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/09/04 22:00:13.0978 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 2010/09/04 22:00:14.0009 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 2010/09/04 22:00:14.0040 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/04 22:00:14.0040 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/04 22:00:14.0087 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 2010/09/04 22:00:14.0102 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2010/09/04 22:00:14.0165 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/09/04 22:00:14.0196 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2010/09/04 22:00:14.0258 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 2010/09/04 22:00:14.0290 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/09/04 22:00:14.0336 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/09/04 22:00:14.0383 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 2010/09/04 22:00:14.0414 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/09/04 22:00:14.0461 ZSMC301b (58c938bdd89281dc1a64b1dce675fce4) C:\Windows\system32\Drivers\usbVM31b.sys 2010/09/04 22:00:14.0492 ================================================================================ 2010/09/04 22:00:14.0492 Scan finished 2010/09/04 22:00:14.0492 ================================================================================ 2010/09/04 22:00:38.0501 Deinitialize success TDSSKiller.2.4.1.2_04.09.2010_22.03.53_log 2010/09/04 22:03:53.0441 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23 2010/09/04 22:03:53.0441 ================================================================================ 2010/09/04 22:03:53.0441 SystemInfo: 2010/09/04 22:03:53.0441 2010/09/04 22:03:53.0441 OS Version: 6.1.7600 ServicePack: 0.0 2010/09/04 22:03:53.0441 Product type: Workstation 2010/09/04 22:03:53.0441 ComputerName: DARRYL 2010/09/04 22:03:53.0441 UserName: Darryle 2010/09/04 22:03:53.0441 Windows directory: C:\Windows 2010/09/04 22:03:53.0441 System windows directory: C:\Windows 2010/09/04 22:03:53.0441 Processor architecture: Intel x86 2010/09/04 22:03:53.0441 Number of processors: 2 2010/09/04 22:03:53.0441 Page size: 0x1000 2010/09/04 22:03:53.0441 Boot type: Safe boot 2010/09/04 22:03:53.0441 ================================================================================ 2010/09/04 22:03:53.0722 Initialize success 2010/09/04 22:03:55.0485 ================================================================================ 2010/09/04 22:03:55.0485 Scan started 2010/09/04 22:03:55.0485 Mode: Manual; 2010/09/04 22:03:55.0485 ================================================================================ 2010/09/04 22:03:56.0327 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/09/04 22:03:56.0358 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 2010/09/04 22:03:56.0390 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/09/04 22:03:56.0405 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/09/04 22:03:56.0452 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 2010/09/04 22:03:56.0483 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 2010/09/04 22:03:56.0514 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 2010/09/04 22:03:56.0546 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 2010/09/04 22:03:56.0561 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 2010/09/04 22:03:56.0592 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 2010/09/04 22:03:56.0608 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 2010/09/04 22:03:56.0639 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 2010/09/04 22:03:56.0655 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 2010/09/04 22:03:56.0686 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 2010/09/04 22:03:56.0702 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys 2010/09/04 22:03:56.0717 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/09/04 22:03:56.0748 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys 2010/09/04 22:03:56.0764 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 2010/09/04 22:03:56.0811 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 2010/09/04 22:03:56.0842 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 2010/09/04 22:03:56.0858 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/09/04 22:03:56.0873 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 2010/09/04 22:03:56.0936 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 2010/09/04 22:03:56.0967 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2010/09/04 22:03:56.0998 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2010/09/04 22:03:57.0029 BHDrvx86 (76154fa6a742c613b44bb636b1a7c057) C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys 2010/09/04 22:03:57.0076 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/09/04 22:03:57.0092 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 2010/09/04 22:03:57.0107 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/09/04 22:03:57.0123 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/09/04 22:03:57.0154 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2010/09/04 22:03:57.0170 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/09/04 22:03:57.0201 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/09/04 22:03:57.0201 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/09/04 22:03:57.0216 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/09/04 22:03:57.0263 ccHP (8973ff34b83572d867b5b928905ad5ac) C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys 2010/09/04 22:03:57.0294 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2010/09/04 22:03:57.0310 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 2010/09/04 22:03:57.0326 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 2010/09/04 22:03:57.0357 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2010/09/04 22:03:57.0388 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/09/04 22:03:57.0419 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 2010/09/04 22:03:57.0450 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2010/09/04 22:03:57.0466 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 2010/09/04 22:03:57.0497 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/09/04 22:03:57.0606 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/09/04 22:03:57.0638 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 2010/09/04 22:03:57.0669 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2010/09/04 22:03:57.0684 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 2010/09/04 22:03:57.0731 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2010/09/04 22:03:57.0762 DrvAgent32 (651554e483712b708ede864d0ca1aa73) C:\Windows\system32\Drivers\DrvAgent32.sys 2010/09/04 22:03:57.0794 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys 2010/09/04 22:03:57.0856 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 2010/09/04 22:03:57.0934 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2010/09/04 22:03:57.0965 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 2010/09/04 22:03:58.0028 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2010/09/04 22:03:58.0043 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 2010/09/04 22:03:58.0090 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2010/09/04 22:03:58.0106 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2010/09/04 22:03:58.0137 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 2010/09/04 22:03:58.0168 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2010/09/04 22:03:58.0184 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2010/09/04 22:03:58.0199 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/09/04 22:03:58.0215 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2010/09/04 22:03:58.0246 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2010/09/04 22:03:58.0277 fssfltr (b74b0578fd1d3f897e95f2a2b69ea051) C:\Windows\system32\DRIVERS\fssfltr.sys 2010/09/04 22:03:58.0308 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2010/09/04 22:03:58.0324 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys 2010/09/04 22:03:58.0355 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/09/04 22:03:58.0480 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/09/04 22:03:58.0511 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2010/09/04 22:03:58.0542 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys 2010/09/04 22:03:58.0558 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/09/04 22:03:58.0574 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/09/04 22:03:58.0589 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 2010/09/04 22:03:58.0636 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 2010/09/04 22:03:58.0667 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 2010/09/04 22:03:58.0698 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/09/04 22:03:58.0714 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 2010/09/04 22:03:58.0761 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 2010/09/04 22:03:58.0808 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/09/04 22:03:58.0823 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/09/04 22:03:58.0948 IDSVix86 (2edd3504457691a10328079da011d0b8) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100903.003\IDSvix86.sys 2010/09/04 22:03:58.0964 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 2010/09/04 22:03:59.0057 IntcAzAudAddService (aee99ecf06cd1cea95816ccb5bf73ec8) C:\Windows\system32\drivers\RTKVHDA.sys 2010/09/04 22:03:59.0088 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 2010/09/04 22:03:59.0120 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2010/09/04 22:03:59.0135 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/09/04 22:03:59.0166 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/09/04 22:03:59.0198 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2010/09/04 22:03:59.0229 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2010/09/04 22:03:59.0244 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 2010/09/04 22:03:59.0276 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/09/04 22:03:59.0307 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/09/04 22:03:59.0322 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/09/04 22:03:59.0354 kl1 (ce3958f58547454884e97bda78cd7040) C:\Windows\system32\DRIVERS\kl1.sys 2010/09/04 22:03:59.0385 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 2010/09/04 22:03:59.0400 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys 2010/09/04 22:03:59.0447 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/09/04 22:03:59.0478 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/09/04 22:03:59.0494 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/09/04 22:03:59.0510 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/09/04 22:03:59.0541 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/09/04 22:03:59.0556 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2010/09/04 22:03:59.0572 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 2010/09/04 22:03:59.0603 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/09/04 22:03:59.0634 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\Windows\system32\drivers\Mkd2kfNt.sys 2010/09/04 22:03:59.0666 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\Windows\system32\drivers\Mkd2Nadr.sys 2010/09/04 22:03:59.0697 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2010/09/04 22:03:59.0712 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2010/09/04 22:03:59.0744 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2010/09/04 22:03:59.0759 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2010/09/04 22:03:59.0775 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 2010/09/04 22:03:59.0806 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 2010/09/04 22:03:59.0837 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2010/09/04 22:03:59.0868 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 2010/09/04 22:03:59.0884 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/09/04 22:03:59.0900 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/09/04 22:03:59.0931 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/09/04 22:03:59.0962 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 2010/09/04 22:03:59.0978 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 2010/09/04 22:04:00.0009 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2010/09/04 22:04:00.0024 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2010/09/04 22:04:00.0040 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/09/04 22:04:00.0071 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2010/09/04 22:04:00.0087 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/09/04 22:04:00.0102 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2010/09/04 22:04:00.0118 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2010/09/04 22:04:00.0149 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/09/04 22:04:00.0180 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2010/09/04 22:04:00.0196 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/09/04 22:04:00.0227 MTsensor (dcdaab8697a47894a554050ce18d0b56) C:\Windows\system32\DRIVERS\ASACPI.sys 2010/09/04 22:04:00.0243 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2010/09/04 22:04:00.0274 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2010/09/04 22:04:00.0414 NAVENG (0953bb24c1e70a99c315f44f15993c17) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100903.050\NAVENG.SYS 2010/09/04 22:04:00.0446 NAVEX15 (3ddb0bef60b65df6b110c23e17cd67dc) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100903.050\NAVEX15.SYS 2010/09/04 22:04:00.0508 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 2010/09/04 22:04:00.0524 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/09/04 22:04:00.0555 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/09/04 22:04:00.0570 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/09/04 22:04:00.0586 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/09/04 22:04:00.0617 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 2010/09/04 22:04:00.0633 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2010/09/04 22:04:00.0648 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 2010/09/04 22:04:00.0711 NetworkX (5ef7dd401771693245d46f4b0b69fe2b) C:\Windows\system32\ckldrv.sys 2010/09/04 22:04:00.0742 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/09/04 22:04:00.0773 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\Windows\system32\drivers\ccdcmb.sys 2010/09/04 22:04:00.0804 nmwcdc (3859c69a77793180548802dac9f34a38) C:\Windows\system32\drivers\ccdcmbo.sys 2010/09/04 22:04:00.0836 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\Windows\system32\drivers\nmwcdnsu.sys 2010/09/04 22:04:00.0851 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\Windows\system32\drivers\nmwcdnsuc.sys 2010/09/04 22:04:00.0882 NPF (6623e51595c0076755c29c00846c4eb2) C:\Windows\system32\drivers\npf.sys 2010/09/04 22:04:00.0898 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2010/09/04 22:04:00.0960 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2010/09/04 22:04:00.0992 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 2010/09/04 22:04:01.0038 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2010/09/04 22:04:01.0210 nvlddmkm (07144ee5ecb0eb4ece950bf4b2439865) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/09/04 22:04:01.0366 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys 2010/09/04 22:04:01.0397 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys 2010/09/04 22:04:01.0428 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 2010/09/04 22:04:01.0444 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/09/04 22:04:01.0491 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 2010/09/04 22:04:01.0506 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 2010/09/04 22:04:01.0522 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 2010/09/04 22:04:01.0569 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys 2010/09/04 22:04:01.0584 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 2010/09/04 22:04:01.0616 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 2010/09/04 22:04:01.0631 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/09/04 22:04:01.0647 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2010/09/04 22:04:01.0678 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2010/09/04 22:04:01.0756 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2010/09/04 22:04:01.0772 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 2010/09/04 22:04:01.0818 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2010/09/04 22:04:01.0850 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 2010/09/04 22:04:01.0896 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 2010/09/04 22:04:01.0928 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/09/04 22:04:01.0959 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2010/09/04 22:04:01.0990 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2010/09/04 22:04:02.0006 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/09/04 22:04:02.0021 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/09/04 22:04:02.0052 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/09/04 22:04:02.0068 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2010/09/04 22:04:02.0084 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 2010/09/04 22:04:02.0130 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/09/04 22:04:02.0146 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/09/04 22:04:02.0177 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2010/09/04 22:04:02.0193 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2010/09/04 22:04:02.0208 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 2010/09/04 22:04:02.0240 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 2010/09/04 22:04:02.0302 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys 2010/09/04 22:04:02.0333 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 2010/09/04 22:04:02.0349 ROOTMODEM (564297827d213f52c7a3a2ff749568ca) C:\Windows\system32\Drivers\RootMdm.sys 2010/09/04 22:04:02.0411 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2010/09/04 22:04:02.0458 RTL8167 (d5ede44ca85899e0478208c8413c1c31) C:\Windows\system32\DRIVERS\Rt86win7.sys 2010/09/04 22:04:02.0489 RTL8169 (034033f5a921764d8c4ba6698800d95b) C:\Windows\system32\DRIVERS\Rtlh86.sys 2010/09/04 22:04:02.0536 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2010/09/04 22:04:02.0552 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2010/09/04 22:04:02.0583 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/09/04 22:04:02.0614 SCDEmu (16b1abe7f3e35f21dac57592b6c5d464) C:\Windows\system32\drivers\SCDEmu.sys 2010/09/04 22:04:02.0645 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 2010/09/04 22:04:02.0692 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/09/04 22:04:02.0708 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2010/09/04 22:04:02.0739 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2010/09/04 22:04:02.0770 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 2010/09/04 22:04:02.0817 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/09/04 22:04:02.0848 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/09/04 22:04:02.0879 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/09/04 22:04:02.0895 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/09/04 22:04:02.0942 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 2010/09/04 22:04:02.0957 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/09/04 22:04:02.0988 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/09/04 22:04:03.0020 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2010/09/04 22:04:03.0051 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2010/09/04 22:04:03.0113 SRTSP (e81f6caeab9ad5732e94c07c97866aa2) C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS 2010/09/04 22:04:03.0144 SRTSPX (e28de499d942b08058bffac69d4122b6) C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS 2010/09/04 22:04:03.0176 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\Windows\system32\DRIVERS\srv.sys 2010/09/04 22:04:03.0207 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\Windows\system32\DRIVERS\srv2.sys 2010/09/04 22:04:03.0238 srvnet (08f28676802b58138e48a2b40caf6204) C:\Windows\system32\DRIVERS\srvnet.sys 2010/09/04 22:04:03.0269 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 2010/09/04 22:04:03.0300 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 2010/09/04 22:04:03.0332 SymEFA (d0885f6e24259a6c65e68d6ad749910a) C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS 2010/09/04 22:04:03.0347 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS 2010/09/04 22:04:03.0363 SYMFW (1e825026436c4eac3e1a11d1e9c33f2c) C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS 2010/09/04 22:04:03.0394 SymIM (34f1c9d5dcc19df1e824d6b73767b8af) C:\Windows\system32\DRIVERS\SymIMv.sys 2010/09/04 22:04:03.0410 SYMNDISV (dcbf73da96cce94933c8cc6eded3c98b) C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS 2010/09/04 22:04:03.0441 SYMTDI (e4fa8bbb96e314e9508865de1a767538) C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS 2010/09/04 22:04:03.0503 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys 2010/09/04 22:04:03.0550 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys 2010/09/04 22:04:03.0581 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 2010/09/04 22:04:03.0612 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 2010/09/04 22:04:03.0628 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 2010/09/04 22:04:03.0644 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 2010/09/04 22:04:03.0659 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 2010/09/04 22:04:03.0706 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/09/04 22:04:03.0800 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys 2010/09/04 22:04:03.0815 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 2010/09/04 22:04:03.0846 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 2010/09/04 22:04:03.0878 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 2010/09/04 22:04:03.0909 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/09/04 22:04:03.0940 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 2010/09/04 22:04:03.0956 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 2010/09/04 22:04:04.0002 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 2010/09/04 22:04:04.0049 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 2010/09/04 22:04:04.0080 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 2010/09/04 22:04:04.0096 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/09/04 22:04:04.0127 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 2010/09/04 22:04:04.0158 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 2010/09/04 22:04:04.0174 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 2010/09/04 22:04:04.0190 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 2010/09/04 22:04:04.0205 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 2010/09/04 22:04:04.0252 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 2010/09/04 22:04:04.0268 usbser (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys 2010/09/04 22:04:04.0299 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 2010/09/04 22:04:04.0330 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/09/04 22:04:04.0346 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/09/04 22:04:04.0377 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/09/04 22:04:04.0408 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/09/04 22:04:04.0439 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2010/09/04 22:04:04.0470 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/09/04 22:04:04.0486 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 2010/09/04 22:04:04.0517 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 2010/09/04 22:04:04.0533 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 2010/09/04 22:04:04.0548 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/09/04 22:04:04.0580 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2010/09/04 22:04:04.0611 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 2010/09/04 22:04:04.0626 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/09/04 22:04:04.0658 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 2010/09/04 22:04:04.0689 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 2010/09/04 22:04:04.0720 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/04 22:04:04.0720 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/04 22:04:04.0767 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 2010/09/04 22:04:04.0782 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2010/09/04 22:04:04.0829 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/09/04 22:04:04.0860 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2010/09/04 22:04:04.0907 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 2010/09/04 22:04:04.0938 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/09/04 22:04:04.0985 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/09/04 22:04:05.0032 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 2010/09/04 22:04:05.0048 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/09/04 22:04:05.0110 ZSMC301b (58c938bdd89281dc1a64b1dce675fce4) C:\Windows\system32\Drivers\usbVM31b.sys 2010/09/04 22:04:05.0141 ================================================================================ 2010/09/04 22:04:05.0141 Scan finished 2010/09/04 22:04:05.0141 ================================================================================ 2010/09/04 22:04:11.0412 Deinitialize success TDSSKiller.2.4.2.0_06.09.2010_23.09.00_log 2010/09/06 23:09:00.0391 TDSS rootkit removing tool 2.4.2.0 Sep 3 2010 10:26:06 2010/09/06 23:09:00.0391 ================================================================================ 2010/09/06 23:09:00.0391 SystemInfo: 2010/09/06 23:09:00.0391 2010/09/06 23:09:00.0391 OS Version: 6.1.7600 ServicePack: 0.0 2010/09/06 23:09:00.0391 Product type: Workstation 2010/09/06 23:09:00.0392 ComputerName: DARRYL 2010/09/06 23:09:00.0392 UserName: Darryle 2010/09/06 23:09:00.0392 Windows directory: C:\Windows 2010/09/06 23:09:00.0392 System windows directory: C:\Windows 2010/09/06 23:09:00.0392 Processor architecture: Intel x86 2010/09/06 23:09:00.0392 Number of processors: 2 2010/09/06 23:09:00.0392 Page size: 0x1000 2010/09/06 23:09:00.0392 Boot type: Normal boot 2010/09/06 23:09:00.0392 ================================================================================ 2010/09/06 23:09:00.0835 Initialize success 2010/09/06 23:09:02.0615 ================================================================================ 2010/09/06 23:09:02.0615 Scan started 2010/09/06 23:09:02.0615 Mode: Manual; 2010/09/06 23:09:02.0615 ================================================================================ 2010/09/06 23:09:04.0460 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/09/06 23:09:04.0495 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 2010/09/06 23:09:04.0519 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/09/06 23:09:04.0548 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/09/06 23:09:04.0573 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 2010/09/06 23:09:04.0602 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 2010/09/06 23:09:04.0635 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 2010/09/06 23:09:04.0663 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 2010/09/06 23:09:04.0683 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 2010/09/06 23:09:04.0706 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 2010/09/06 23:09:04.0731 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 2010/09/06 23:09:04.0753 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 2010/09/06 23:09:04.0776 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 2010/09/06 23:09:04.0803 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 2010/09/06 23:09:04.0820 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys 2010/09/06 23:09:04.0846 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/09/06 23:09:04.0859 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys 2010/09/06 23:09:04.0886 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 2010/09/06 23:09:04.0936 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 2010/09/06 23:09:04.0958 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 2010/09/06 23:09:04.0984 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/09/06 23:09:04.0996 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 2010/09/06 23:09:05.0048 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 2010/09/06 23:09:05.0075 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2010/09/06 23:09:05.0105 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2010/09/06 23:09:05.0147 BHDrvx86 (76154fa6a742c613b44bb636b1a7c057) C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys 2010/09/06 23:09:05.0172 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/09/06 23:09:05.0201 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 2010/09/06 23:09:05.0218 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/09/06 23:09:05.0240 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/09/06 23:09:05.0266 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2010/09/06 23:09:05.0297 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/09/06 23:09:05.0314 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/09/06 23:09:05.0329 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/09/06 23:09:05.0352 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/09/06 23:09:05.0384 ccHP (8973ff34b83572d867b5b928905ad5ac) C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys 2010/09/06 23:09:05.0415 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2010/09/06 23:09:05.0437 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 2010/09/06 23:09:05.0458 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 2010/09/06 23:09:05.0494 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2010/09/06 23:09:05.0523 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/09/06 23:09:05.0541 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 2010/09/06 23:09:05.0565 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2010/09/06 23:09:05.0590 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 2010/09/06 23:09:05.0610 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/09/06 23:09:05.0723 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/09/06 23:09:05.0767 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 2010/09/06 23:09:05.0794 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2010/09/06 23:09:05.0806 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 2010/09/06 23:09:05.0849 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2010/09/06 23:09:05.0877 DrvAgent32 (651554e483712b708ede864d0ca1aa73) C:\Windows\system32\Drivers\DrvAgent32.sys 2010/09/06 23:09:05.0913 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys 2010/09/06 23:09:05.0989 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 2010/09/06 23:09:06.0059 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2010/09/06 23:09:06.0098 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 2010/09/06 23:09:06.0158 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2010/09/06 23:09:06.0178 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 2010/09/06 23:09:06.0219 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2010/09/06 23:09:06.0239 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2010/09/06 23:09:06.0265 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 2010/09/06 23:09:06.0292 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2010/09/06 23:09:06.0310 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2010/09/06 23:09:06.0328 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/09/06 23:09:06.0346 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2010/09/06 23:09:06.0371 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2010/09/06 23:09:06.0401 fssfltr (b74b0578fd1d3f897e95f2a2b69ea051) C:\Windows\system32\DRIVERS\fssfltr.sys 2010/09/06 23:09:06.0428 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2010/09/06 23:09:06.0450 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys 2010/09/06 23:09:06.0473 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/09/06 23:09:06.0578 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/09/06 23:09:06.0613 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2010/09/06 23:09:06.0648 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys 2010/09/06 23:09:06.0671 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/09/06 23:09:06.0696 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/09/06 23:09:06.0715 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 2010/09/06 23:09:06.0751 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 2010/09/06 23:09:06.0777 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 2010/09/06 23:09:06.0807 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/09/06 23:09:06.0840 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 2010/09/06 23:09:06.0884 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 2010/09/06 23:09:06.0925 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/09/06 23:09:06.0948 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/09/06 23:09:07.0057 IDSVix86 (2edd3504457691a10328079da011d0b8) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100903.003\IDSvix86.sys 2010/09/06 23:09:07.0077 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 2010/09/06 23:09:07.0165 IntcAzAudAddService (aee99ecf06cd1cea95816ccb5bf73ec8) C:\Windows\system32\drivers\RTKVHDA.sys 2010/09/06 23:09:07.0204 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 2010/09/06 23:09:07.0228 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2010/09/06 23:09:07.0251 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/09/06 23:09:07.0280 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/09/06 23:09:07.0303 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2010/09/06 23:09:07.0335 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2010/09/06 23:09:07.0361 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 2010/09/06 23:09:07.0393 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/09/06 23:09:07.0414 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/09/06 23:09:07.0432 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/09/06 23:09:07.0472 kl1 (ce3958f58547454884e97bda78cd7040) C:\Windows\system32\DRIVERS\kl1.sys 2010/09/06 23:09:07.0490 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 2010/09/06 23:09:07.0523 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys 2010/09/06 23:09:07.0564 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/09/06 23:09:07.0602 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/09/06 23:09:07.0620 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/09/06 23:09:07.0640 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/09/06 23:09:07.0667 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/09/06 23:09:07.0693 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2010/09/06 23:09:07.0722 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 2010/09/06 23:09:07.0746 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/09/06 23:09:07.0799 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\Windows\system32\drivers\Mkd2kfNt.sys 2010/09/06 23:09:07.0823 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\Windows\system32\drivers\Mkd2Nadr.sys 2010/09/06 23:09:07.0854 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2010/09/06 23:09:07.0889 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2010/09/06 23:09:07.0904 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2010/09/06 23:09:07.0927 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2010/09/06 23:09:07.0941 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 2010/09/06 23:09:07.0965 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 2010/09/06 23:09:07.0985 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2010/09/06 23:09:08.0011 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 2010/09/06 23:09:08.0034 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/09/06 23:09:08.0058 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/09/06 23:09:08.0080 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/09/06 23:09:08.0104 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 2010/09/06 23:09:08.0128 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 2010/09/06 23:09:08.0157 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2010/09/06 23:09:08.0178 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2010/09/06 23:09:08.0191 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/09/06 23:09:08.0223 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2010/09/06 23:09:08.0239 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/09/06 23:09:08.0254 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2010/09/06 23:09:08.0278 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2010/09/06 23:09:08.0316 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/09/06 23:09:08.0334 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2010/09/06 23:09:08.0356 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/09/06 23:09:08.0390 MTsensor (dcdaab8697a47894a554050ce18d0b56) C:\Windows\system32\DRIVERS\ASACPI.sys 2010/09/06 23:09:08.0405 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2010/09/06 23:09:08.0437 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2010/09/06 23:09:08.0545 NAVENG (0953bb24c1e70a99c315f44f15993c17) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100905.003\NAVENG.SYS 2010/09/06 23:09:08.0579 NAVEX15 (3ddb0bef60b65df6b110c23e17cd67dc) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100905.003\NAVEX15.SYS 2010/09/06 23:09:08.0621 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 2010/09/06 23:09:08.0649 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/09/06 23:09:08.0666 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/09/06 23:09:08.0687 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/09/06 23:09:08.0702 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/09/06 23:09:08.0726 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 2010/09/06 23:09:08.0746 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2010/09/06 23:09:08.0767 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 2010/09/06 23:09:08.0810 NetworkX (5ef7dd401771693245d46f4b0b69fe2b) C:\Windows\system32\ckldrv.sys 2010/09/06 23:09:08.0833 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/09/06 23:09:08.0870 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\Windows\system32\drivers\ccdcmb.sys 2010/09/06 23:09:08.0902 nmwcdc (3859c69a77793180548802dac9f34a38) C:\Windows\system32\drivers\ccdcmbo.sys 2010/09/06 23:09:08.0936 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\Windows\system32\drivers\nmwcdnsu.sys 2010/09/06 23:09:08.0962 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\Windows\system32\drivers\nmwcdnsuc.sys 2010/09/06 23:09:08.0999 NPF (6623e51595c0076755c29c00846c4eb2) C:\Windows\system32\drivers\npf.sys 2010/09/06 23:09:09.0014 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2010/09/06 23:09:09.0069 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2010/09/06 23:09:09.0108 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 2010/09/06 23:09:09.0145 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2010/09/06 23:09:09.0327 nvlddmkm (07144ee5ecb0eb4ece950bf4b2439865) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/09/06 23:09:09.0505 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys 2010/09/06 23:09:09.0535 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys 2010/09/06 23:09:09.0568 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 2010/09/06 23:09:09.0602 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/09/06 23:09:09.0638 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 2010/09/06 23:09:09.0658 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 2010/09/06 23:09:09.0681 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 2010/09/06 23:09:09.0711 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys 2010/09/06 23:09:09.0727 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 2010/09/06 23:09:09.0752 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 2010/09/06 23:09:09.0780 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/09/06 23:09:09.0797 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2010/09/06 23:09:09.0839 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2010/09/06 23:09:09.0918 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2010/09/06 23:09:09.0940 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 2010/09/06 23:09:09.0976 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2010/09/06 23:09:10.0004 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 2010/09/06 23:09:10.0044 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 2010/09/06 23:09:10.0081 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/09/06 23:09:10.0110 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2010/09/06 23:09:10.0131 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2010/09/06 23:09:10.0164 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/09/06 23:09:10.0183 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/09/06 23:09:10.0205 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/09/06 23:09:10.0223 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2010/09/06 23:09:10.0251 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 2010/09/06 23:09:10.0279 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/09/06 23:09:10.0306 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/09/06 23:09:10.0324 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2010/09/06 23:09:10.0346 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2010/09/06 23:09:10.0369 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 2010/09/06 23:09:10.0400 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 2010/09/06 23:09:10.0459 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 2010/09/06 23:09:10.0478 ROOTMODEM (564297827d213f52c7a3a2ff749568ca) C:\Windows\system32\Drivers\RootMdm.sys 2010/09/06 23:09:10.0545 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2010/09/06 23:09:10.0582 RTL8167 (d5ede44ca85899e0478208c8413c1c31) C:\Windows\system32\DRIVERS\Rt86win7.sys 2010/09/06 23:09:10.0615 RTL8169 (034033f5a921764d8c4ba6698800d95b) C:\Windows\system32\DRIVERS\Rtlh86.sys 2010/09/06 23:09:10.0675 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2010/09/06 23:09:10.0690 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2010/09/06 23:09:10.0720 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/09/06 23:09:10.0749 SCDEmu (16b1abe7f3e35f21dac57592b6c5d464) C:\Windows\system32\drivers\SCDEmu.sys 2010/09/06 23:09:10.0783 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 2010/09/06 23:09:10.0822 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/09/06 23:09:10.0859 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2010/09/06 23:09:10.0879 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2010/09/06 23:09:10.0908 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 2010/09/06 23:09:10.0958 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/09/06 23:09:10.0986 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/09/06 23:09:11.0017 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/09/06 23:09:11.0038 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/09/06 23:09:11.0077 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 2010/09/06 23:09:11.0100 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/09/06 23:09:11.0124 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/09/06 23:09:11.0149 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2010/09/06 23:09:11.0202 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2010/09/06 23:09:11.0256 SRTSP (e81f6caeab9ad5732e94c07c97866aa2) C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS 2010/09/06 23:09:11.0281 SRTSPX (e28de499d942b08058bffac69d4122b6) C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS 2010/09/06 23:09:11.0315 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\Windows\system32\DRIVERS\srv.sys 2010/09/06 23:09:11.0353 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\Windows\system32\DRIVERS\srv2.sys 2010/09/06 23:09:11.0379 srvnet (08f28676802b58138e48a2b40caf6204) C:\Windows\system32\DRIVERS\srvnet.sys 2010/09/06 23:09:11.0415 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 2010/09/06 23:09:11.0443 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 2010/09/06 23:09:11.0470 SymEFA (d0885f6e24259a6c65e68d6ad749910a) C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS 2010/09/06 23:09:11.0500 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS 2010/09/06 23:09:11.0519 SYMFW (1e825026436c4eac3e1a11d1e9c33f2c) C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS 2010/09/06 23:09:11.0541 SymIM (34f1c9d5dcc19df1e824d6b73767b8af) C:\Windows\system32\DRIVERS\SymIMv.sys 2010/09/06 23:09:11.0560 SYMNDISV (dcbf73da96cce94933c8cc6eded3c98b) C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS 2010/09/06 23:09:11.0583 SYMTDI (e4fa8bbb96e314e9508865de1a767538) C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS 2010/09/06 23:09:11.0658 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys 2010/09/06 23:09:11.0697 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys 2010/09/06 23:09:11.0727 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 2010/09/06 23:09:11.0748 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 2010/09/06 23:09:11.0774 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 2010/09/06 23:09:11.0790 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 2010/09/06 23:09:11.0808 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 2010/09/06 23:09:11.0863 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/09/06 23:09:11.0951 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys 2010/09/06 23:09:11.0972 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 2010/09/06 23:09:11.0995 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 2010/09/06 23:09:12.0026 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 2010/09/06 23:09:12.0070 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/09/06 23:09:12.0107 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 2010/09/06 23:09:12.0132 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 2010/09/06 23:09:12.0163 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 2010/09/06 23:09:12.0196 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 2010/09/06 23:09:12.0231 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 2010/09/06 23:09:12.0255 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/09/06 23:09:12.0279 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 2010/09/06 23:09:12.0306 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 2010/09/06 23:09:12.0324 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 2010/09/06 23:09:12.0349 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 2010/09/06 23:09:12.0374 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 2010/09/06 23:09:12.0411 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 2010/09/06 23:09:12.0434 usbser (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys 2010/09/06 23:09:12.0464 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 2010/09/06 23:09:12.0490 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/09/06 23:09:12.0519 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/09/06 23:09:12.0551 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/09/06 23:09:12.0575 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/09/06 23:09:12.0598 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2010/09/06 23:09:12.0625 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/09/06 23:09:12.0651 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 2010/09/06 23:09:12.0677 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 2010/09/06 23:09:12.0754 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 2010/09/06 23:09:12.0957 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/09/06 23:09:13.0028 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2010/09/06 23:09:13.0054 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 2010/09/06 23:09:13.0085 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/09/06 23:09:13.0111 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 2010/09/06 23:09:13.0152 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 2010/09/06 23:09:13.0181 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/06 23:09:13.0192 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/09/06 23:09:13.0233 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 2010/09/06 23:09:13.0254 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2010/09/06 23:09:13.0311 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/09/06 23:09:13.0340 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2010/09/06 23:09:13.0399 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 2010/09/06 23:09:13.0435 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/09/06 23:09:13.0481 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/09/06 23:09:13.0531 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 2010/09/06 23:09:13.0562 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/09/06 23:09:13.0625 ZSMC301b (58c938bdd89281dc1a64b1dce675fce4) C:\Windows\system32\Drivers\usbVM31b.sys 2010/09/06 23:09:13.0658 ================================================================================ 2010/09/06 23:09:13.0658 Scan finished 2010/09/06 23:09:13.0658 ================================================================================ 2010/09/06 23:09:20.0580 Deinitialize success Do you want me to go ahead with RootkitUnhooker and OTL even if I wasn't able to provide the combofix log?
Rootkit Unhooker is still scanning, I've been waiting for almost an hour now, does this process really take long? Aside from the main RkU window, there is a small window saying "Please wait while RkU makes scan. You can stop by pressing cancel – Getting list of files and directories (C:\)" Also before the small window initialized, there was a pop-up asking which drives to scan, with all 3 drives checked by default. I clicked ok. Am I doing the right steps so far?
Looks like the scan would really take some serious time, it just finished scanning drive C for more than an hour and now its just about to start at drive D (there's still drive E). I'll just leave it at alone for the meantime and take a power nap (I'm @GMT+8 so its about 2:45AM here). Will update this thread with the logs moving forward. Thanks for the assistance so far SweetTech.
Here's PART 1 of the RkU Report.txt log: RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows 7 Version 6.1.7600 Number of processors #2 ============================================== >Drivers ============================================== 0x97025000 C:\Windows\system32\DRIVERS\nvlddmkm.sys 11001856 bytes (NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 259.31 ) 0x95414000 C:\Windows\system32\DRIVERS\kl1.sys 5373952 bytes (Kaspersky Lab, Kaspersky Unified Driver) 0x82E4F000 C:\Windows\system32\ntkrnlpa.exe 4259840 bytes (Microsoft Corporation, NT Kernel & System) 0x82E4F000 PnpManager 4259840 bytes 0x82E4F000 RAW 4259840 bytes 0x82E4F000 WMIxWDM 4259840 bytes 0x9A212000 C:\Windows\system32\drivers\RTKVHDA.sys 3149824 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x9AE70000 Win32k 2400256 bytes 0x9AE70000 C:\Windows\System32\win32k.sys 2400256 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x8E47B000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100906.024\NAVEX15.SYS 1359872 bytes (Symantec Corporation, AV Engine) 0x89219000 C:\Windows\System32\drivers\tcpip.sys 1347584 bytes (Microsoft Corporation, TCP/IP Driver) 0x88E83000 C:\Windows\System32\Drivers\Ntfs.sys 1241088 bytes (Microsoft Corporation, NT File System Driver) 0x97AA5000 C:\Windows\System32\drivers\dxgkrnl.sys 749568 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0x8909A000 C:\Windows\system32\drivers\ndis.sys 749568 bytes (Microsoft Corporation, NDIS 6.20 driver) 0x88AE0000 C:\Windows\system32\CI.dll 700416 bytes (Microsoft Corporation, Code Integrity Module) 0xA4A70000 C:\Windows\system32\drivers\peauth.sys 618496 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x99A60000 C:\Windows\system32\drivers\HTTP.sys 544768 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x95F0F000 C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys 503808 bytes (Symantec Corporation, Common Client Hash Provider Driver) 0x88A0D000 C:\Windows\system32\mcupdate_GenuineIntel.dll 491520 bytes (Microsoft Corporation, Intel Microcode Update Library) 0x88B8B000 C:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime) 0x95E70000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0x89026000 C:\Windows\System32\Drivers\cng.sys 380928 bytes (Microsoft Corporation, Kernel Cryptography, Next Generation) 0x95934000 C:\Windows\system32\drivers\afd.sys 368640 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xA4B7B000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100906.001\IDSvix86.sys 360448 bytes (Symantec Corporation, IDS Core Driver) 0x8E428000 C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS 339968 bytes (Symantec Corporation, Symantec AutoProtect) 0xA4A07000 C:\Windows\System32\DRIVERS\srv.sys 331776 bytes (Microsoft Corporation, Server driver) 0x99B98000 C:\Windows\System32\DRIVERS\srv2.sys 323584 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x88E2B000 C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS 323584 bytes (Symantec Corporation, Symantec Extended File Attributes) 0x9B120000 C:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0x9842C000 C:\Windows\system32\DRIVERS\USBPORT.SYS 307200 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x88CD8000 C:\Windows\System32\drivers\volmgrx.sys 307200 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x88C29000 C:\Windows\system32\DRIVERS\ACPI.sys 294912 bytes (Microsoft Corporation, ACPI Driver for NT) 0x97BB4000 C:\Windows\system32\DRIVERS\Rt86win7.sys 282624 bytes (Realtek , Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver ) 0x99A0B000 C:\Windows\system32\DRIVERS\usbhub.sys 278528 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x95F98000 C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys 270336 bytes (Symantec Corporation, BASH Driver) 0x88A9E000 C:\Windows\system32\CLFS.SYS 270336 bytes (Microsoft Corporation, Common Log File System Driver) 0x92F6B000 C:\Windows\system32\DRIVERS\rdbss.sys 266240 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x89393000 C:\Windows\system32\DRIVERS\volsnap.sys 258048 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x89151000 C:\Windows\system32\drivers\NETIO.SYS 253952 bytes (Microsoft Corporation, Network I/O Subsystem) 0x99B42000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 241664 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x97B5C000 C:\Windows\System32\drivers\dxgmms1.sys 233472 bytes (Microsoft Corporation, DirectX Graphics MMS) 0x82E18000 ACPI_HAL 225280 bytes 0x82E18000 C:\Windows\system32\halmacpi.dll 225280 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x88D83000 C:\Windows\system32\drivers\fltmgr.sys 212992 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x9857C000 C:\Windows\system32\DRIVERS\ks.sys 212992 bytes (Microsoft Corporation, Kernel CSA Library) 0x92EB4000 C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS 212992 bytes (Symantec Corporation, Network Dispatch Driver) 0x891B4000 C:\Windows\System32\DRIVERS\fvevol.sys 204800 bytes (Microsoft Corporation, BitLocker Drive Encryption Driver) 0x9598E000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x89362000 C:\Windows\System32\drivers\fwpkclnt.sys 200704 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0xA4B36000 C:\Windows\System32\Drivers\RDPWD.SYS 200704 bytes (Microsoft Corporation, RDP Terminal Stack Driver) 0x9A513000 C:\Windows\system32\drivers\portcls.sys 192512 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x893D2000 C:\Windows\System32\drivers\rdyboost.sys 184320 bytes (Microsoft Corporation, ReadyBoost Driver) 0x88FB2000 C:\Windows\System32\Drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x88C82000 C:\Windows\system32\DRIVERS\pci.sys 172032 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x89000000 C:\Windows\system32\DRIVERS\CLASSPNP.SYS 151552 bytes (Microsoft Corporation, SCSI Class System Dll) 0x8918F000 C:\Windows\System32\Drivers\ksecpkg.sys 151552 bytes (Microsoft Corporation, Kernel Security Support Provider Interface Packages) 0x8E5C7000 C:\Windows\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library) 0x88D57000 C:\Windows\system32\DRIVERS\ataport.SYS 143360 bytes (Microsoft Corporation, ATAPI Driver Extension) 0x99B1F000 C:\Windows\system32\DRIVERS\mrxsmb.sys 143360 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x98512000 C:\Windows\system32\DRIVERS\ndiswan.sys 139264 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x92F43000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS) 0x99AE5000 C:\Windows\System32\DRIVERS\srvnet.sys 135168 bytes (Microsoft Corporation, Server Network driver) 0x95FDA000 C:\Windows\system32\DRIVERS\tunnel.sys 135168 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x92E33000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x88DC8000 C:\Windows\system32\DRIVERS\cdrom.sys 126976 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x97B95000 C:\Windows\system32\DRIVERS\HDAudBus.sys 126976 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x959C7000 C:\Windows\system32\DRIVERS\pacer.sys 126976 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x9B100000 C:\Windows\System32\cdd.dll 122880 bytes (Microsoft Corporation, Canonical Display Driver) 0x95ECE000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0x9A5A2000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0x99B7D000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 110592 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x92F0B000 C:\Windows\system32\DRIVERS\serial.sys 106496 bytes (Microsoft Corporation, Serial Device Driver) 0x9A5BD000 C:\Windows\system32\drivers\WudfPf.sys 106496 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0x99B06000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x9A542000 C:\Windows\system32\drivers\drmk.sys 102400 bytes (Microsoft Corporation, Microsoft Trusted Audio Drivers) 0x95EF7000 C:\Windows\System32\Drivers\dfsc.sys 98304 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x9848E000 C:\Windows\system32\DRIVERS\i8042prt.sys 98304 bytes (Microsoft Corporation, i8042 Port Driver) 0x984EF000 C:\Windows\system32\DRIVERS\rasl2tp.sys 98304 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x98534000 C:\Windows\system32\DRIVERS\raspppoe.sys 98304 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x9854C000 C:\Windows\system32\DRIVERS\raspptp.sys 94208 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x98563000 C:\Windows\system32\DRIVERS\rassstp.sys 94208 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x92E92000 C:\Windows\system32\DRIVERS\tdx.sys 94208 bytes (Microsoft Corporation, TDI Translation Driver) 0x88D38000 C:\Windows\System32\drivers\mountmgr.sys 90112 bytes (Microsoft Corporation, Mount Point Manager) 0x92EF6000 C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS 86016 bytes (Symantec Corporation, Firewall Filter Driver) 0xA4B67000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100906.024\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0x88FDD000 C:\Windows\System32\Drivers\ksecdd.sys 77824 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0x9A5E7000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x95400000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x984DD000 C:\Windows\system32\DRIVERS\AgileVpn.sys 73728 bytes (Microsoft Corporation, RAS Agile Vpn Miniport Call Manager) 0x95E00000 C:\Windows\system32\DRIVERS\intelppm.sys 73728 bytes (Microsoft Corporation, Processor Device Driver) 0x9A200000 C:\Windows\System32\drivers\mpsdrv.sys 73728 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x891E6000 C:\Windows\system32\DRIVERS\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x9A57C000 C:\Windows\System32\Drivers\dump_dumpfve.sys 69632 bytes 0x88DB7000 C:\Windows\system32\drivers\fileinfo.sys 69632 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x99A4F000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x88CB7000 C:\Windows\System32\drivers\partmgr.sys 69632 bytes (Microsoft Corporation, Partition Management Driver) 0x88A85000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x9A5D7000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x89200000 C:\Windows\System32\Drivers\mup.sys 65536 bytes (Microsoft Corporation, Multiple UNC Provider Driver) 0x92F25000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Remote Desktop Server Driver) 0x88CC8000 C:\Windows\system32\DRIVERS\volmgr.sys 65536 bytes (Microsoft Corporation, Volume Manager Driver) 0x98477000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x95F8A000 C:\Windows\system32\DRIVERS\blbdrive.sys 57344 bytes (Microsoft Corporation, BLB Drive Driver) 0x959EF000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x92E84000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x88D2A000 C:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x89083000 C:\Windows\System32\drivers\pcw.sys 57344 bytes (Microsoft Corporation, Performance Counters for Windows Driver) 0x92F35000 C:\Windows\System32\Drivers\SCDEmu.SYS 57344 bytes (PowerISO Computing, Inc., PowerISO Virtual Drive) 0x92EE8000 C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS 57344 bytes (Symantec Corporation, NDIS Filter Driver) 0x985B0000 C:\Windows\system32\DRIVERS\umbus.sys 57344 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x88C1B000 C:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader) 0x984D0000 C:\Windows\system32\DRIVERS\CompositeBus.sys 53248 bytes (Microsoft Corporation, Multi-Transport Composite Bus Enumerator) 0x9A55B000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x984A6000 C:\Windows\system32\DRIVERS\kbdclass.sys 53248 bytes (Microsoft Corporation, Keyboard Class Driver) 0x984B3000 C:\Windows\system32\DRIVERS\mouclass.sys 53248 bytes (Microsoft Corporation, Mouse Class Driver) 0xA4B11000 C:\Windows\System32\drivers\tcpipreg.sys 53248 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0xA4B29000 C:\Windows\System32\DRIVERS\tssecsrv.sys 53248 bytes (Microsoft Corporation, TS Security Filter Driver) 0x92E54000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver) 0x95EEB000 C:\Windows\System32\drivers\discache.sys 49152 bytes (Microsoft Corporation, System Indexer/Cache Driver) 0x8E418000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x9A568000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes 0x9A597000 C:\Windows\system32\DRIVERS\monitor.sys 45056 bytes (Microsoft Corporation, Monitor Driver) 0x92E79000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x98507000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x92EA9000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x97000000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0x88CAC000 C:\Windows\system32\DRIVERS\vdrvroot.sys 45056 bytes (Microsoft Corporation, Virtual Drive Root Enumerator) 0x9A58D000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x92FBB000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0x92FAC000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0xA4B07000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x984C0000 C:\Windows\system32\DRIVERS\serenum.sys 40960 bytes (Microsoft Corporation, Serial Port Enumerator) 0x8E400000 C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect) 0xA4B1F000 C:\Windows\system32\drivers\tdtcp.sys 40960 bytes (Microsoft Corporation, TCP Transport Driver) 0x88D7A000 C:\Windows\system32\DRIVERS\amdxata.sys 36864 bytes (Advanced Micro Devices, Storage Filter Driver) 0x88D4E000 C:\Windows\system32\DRIVERS\atapi.sys 36864 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x9A573000 C:\Windows\System32\Drivers\dump_atapi.sys 36864 bytes 0x89091000 C:\Windows\System32\Drivers\Fs_Rec.sys 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0xA4BD3000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x88E7A000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0x959E6000 C:\Windows\system32\DRIVERS\SymIMv.sys 36864 bytes (Symantec Corporation, NDIS 6.0 Filter Driver for Windows Vista) 0x9B0D0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x88C71000 C:\Windows\system32\DRIVERS\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x98486000 C:\Windows\system32\DRIVERS\ASACPI.sys 32768 bytes (-, ATK0110 ACPI Utility) 0x88A96000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x89210000 C:\Windows\System32\drivers\hwpolicy.sys 32768 bytes (Microsoft Corporation, Hardware Policy Driver) 0x80BCA000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Serial Kernel Debugger) 0x88C7A000 C:\Windows\system32\DRIVERS\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x92E61000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x92E69000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Encoder Miniport) 0x92E71000 C:\Windows\system32\drivers\rdprefmp.sys 32768 bytes (Microsoft Corporation, RDP Reflector Driver Miniport) 0x8E411000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x88D23000 C:\Windows\system32\DRIVERS\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0x8E40A000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x959C0000 C:\Windows\system32\DRIVERS\wfplwf.sys 28672 bytes (Microsoft Corporation, WFP NDIS 6.20 Lightweight Filter Driver) 0x984CA000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0x92F65000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS) 0x92FB6000 C:\Windows\system32\ckldrv.sys 20480 bytes 0x97AA3000 C:\Windows\system32\DRIVERS\nvBridge.kmd 8192 bytes (NVIDIA Corporation, NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 259.31 ) 0x9857A000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xA4B1E000 C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys 4096 bytes (TuneUp Software, TuneUp Utilities Driver) ============================================== >Stealth ============================================== 0x00C70000 Hidden Image–>winlogon.exe [ EPROCESS 0x85578468 ] PID: 992, 286720 bytes WARNING: File locked for read access [C:\Windows\system32\drivers\atapi(56).sys] ============================================== >Files ============================================== !–>[Hidden] C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_C58B7928.exe_eb6360d9a5c3aef46c7e28e5ebf63cd238f4_cab_15c730a5\Report.wer !–>[Hidden] C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_C58B7928.exe_eb6360d9a5c3aef46c7e28e5ebf63cd238f4_cab_15c730a5\WER2B49.tmp.appcompat.txt !–>[Hidden] C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_C58B7928.exe_eb6360d9a5c3aef46c7e28e5ebf63cd238f4_cab_15c730a5\WER2C91.tmp.WERInternalMetadata.xml !–>[Hidden] C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_C58B7928.exe_eb6360d9a5c3aef46c7e28e5ebf63cd238f4_cab_15c730a5\WER2C92.tmp.hdmp !–>[Hidden] C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_C58B7928.exe_eb6360d9a5c3aef46c7e28e5ebf63cd238f4_cab_15c730a5\WER307A.tmp.mdmp !–>[Hidden] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\tagfiles\20100907.023.sst !–>[Hidden] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\tagfiles\20100907.024.sst !–>[Hidden] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IdentitySafeDataStore\S-1-5-21-4237152153-1231085273-1120153137-1000\{4aa89e34-6f44-4388-af94-00b6a7f4c92c}.ico !–>[Hidden] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IdentitySafeDataStore\S-1-5-21-4237152153-1231085273-1120153137-1000\{4aa89e34-6f44-4388-af94-00b6a7f4c92c}.png !–>[Hidden] C:\Users\Darryle\AppData\Roaming\Microsoft\Windows\Recent\ScreenShot.lnk !–>[Hidden] C:\Users\Darryle\Desktop\ScreenShot.jpg !–>[Hidden] C:\Users\Darryle\Documents\LoaderBackup-(2010-08-09).ipd::$DATA !–>[Hidden] C:\Users\Darryle\Documents\LoaderBackup-(2010-08-13).ipd::$DATA !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\2O0CACAOD546HCAQEVZHTCAMSO95DCAX2700ZCAU4E64WCABWAV4MCA70FOCHCAL3LQQKCATOHE S3CABGOXUPCAW8K5VFCAU7RCH2CA7VR1FUCAKCFYG5CAH9BKL0CA68G63TCAZL3ZI6CA59AL3ACALNGBP 0htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\3QWCMCA4V2R3DCA0MFGS4CA6KEDQACAG4YMXTCAGA66QSCACATWUSCA7YLEMVCALYOWIKCA8E8X CICA0DVVXXCAINKBFJCAM6200RCAZ1RX0OCAYYNUJFCA2CZKRMCA2SUK20CAMM176XCAZ22XKTCAXZAHI Phtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\91K1JCA5GKUGRCA8U1HEWCABO9NSCCAAEMREHCAUJ0QZ0CADLLE55CAEMC2K8CA5LKH0FCATEFS 9SCAIJ4VJSCAMFIMCZCAI45MFVCASA5RPGCA8II5T5CALIVYOHCAG8Z4SUCAJ9ZBM3CA0UUHHTCARAC8I Rhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\ANN01CA5GGFJ1CA8LQNF7CABYG76HCAA5NK54CANFEXFKCALJLTW8CACK0TVYCA2WK8YGCAQ5X0 J9CAZOIIFACA4FFRWTCAMABVK1CA8XEO8ZCAD8PPSLCAXG0NGACA0BBI14CAAIBDI7CAFLS00ICAXQ6VX Fhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\BK2D0CA7CJLK2CAH9KBE1CABQNUB3CAFMCDQDCADUTXP1CAGDYNWZCANLOSA0CA2ABFFBCALD2F OSCAK11OSXCA1RQ1B6CARKIOHNCAA6TXIZCA1BR00HCAHTEQPOCAPFG06WCAWCMKM3CA4Z6R9BCAG3KZO 5218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\BUJXRCACS5BEJCAM2C8B7CAI1BZ6VCAYA7KRTCAHWOUFZCADA7MO0CANV8MW5CASVZPIFCAWP22 VUCAKO6GKTCA5TRE2UCA3A94YACAK7P86UCA4GM4OJCANG7JMUCA9ZOLOQCAMH26BZCARCMDPWCA1PLT3 2htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\DSAGKCA8TUOX7CAVZSZOCCATRM0GLCA5H2TR4CA9HDAR4CAYLO0CBCAVA167SCA6QQPJ4CAF19H SQCAGGS7X9CAVFCAF3CA6M2965CAP4I8K8CAPZ2BMICAFW5BTQCAN3PQXGCAEZ6PAQCAFLHD9CCAW9SNG Zhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\F2R69CAVIJTBNCA5LMBZZCA9FO27LCAJ01IEWCA3GMR6SCA8B2VCXCA6FWOFMCALX6A8GCA5YL9 2UCAFRFN8PCA1UKICRCAKHUER9CAYX6Q3RCAI4GEY9CA5V8J8ECAL2K57CCAUG52J9CA3Z9S36CAAEKZE 3218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\G7CSFCAONQ8DCCAPBHE26CAP3HO7DCA90KXTOCAP9NOTLCAQODLQVCAX432J4CAKQBRWQCAD346 9XCA6O1LFFCA4LA116CA17J6U7CA6HP66ZCAACRL5RCARUAO8TCA7MXH8UCAIQZS7VCAQV7Q1FCASFWVE Whtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\G7N5KCAOQU93JCADWZEHWCAARM3LACA0OHBTKCA50MNJOCA22F5PLCAX9L3BFCA0EOVGLCAWRUF J2CASFQ9MLCATBBTQOCAEELV83CAE1KZZKCAXFNAMOCAWB9JQICAGK99OQCAJA4VYCCA2O27A6CA17TQI 7htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\GAFX4CA0ZNILMCATFWJOVCAZIOPT0CAO0Z26ZCAB20ZSPCAOCYW5TCAXEQ3INCAC86ADBCA4MT8 P0CAKN1U2MCAOS0MM2CABYEI4ICADGTIX1CAIUXP8NCA6OMEY4CA4OJNJECADXZ5XVCAR2GQVVCALXDKN Rhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\GZRMPCANQDZ1WCANY3DTRCA96I62XCAKNUPP0CAR5HWZPCAGSVYBKCA115EQJCAERAB76CAF66T 24CAPZ3JP9CA4MQL8VCAMXYIGCCA17D9Z7CAR723O2CACVGM10CAXQAJE9CADN04RRCAXWYZ5NCA9JUML Ahtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\JCWBYCAQ3DJDJCA7EN2E9CATL7W9SCADLI9FOCAFSAOKCCAWA7ARJCAC6YWURCAE4UUF0CANOK4 ZYCAHCZ0MMCAD5KYMCCAWR0RJ5CA3F8JLBCAPWJVSYCAQXRI0UCAOP5815CAE2ILK5CA5JOTUXCASFPV1 Khtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\JNN7RCABVGYQACADKP7RJCAD3URC8CAOGZ5X2CA9MUTT1CAOS86ENCAVGSFBZCAEQBMAACAT5JX 8CCA98RFNWCAZ3BQ2ECA2WNB3GCAW7WXH2CAT2BNU1CAA2XLUMCA32G37ICAYC21SDCAVPAN2ACAG0T19 Nhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\LPRASCAYBAZA8CA2CDYZ6CAEXYH0UCAAP0H85CAQTE3GZCAO1LJZSCAJXBZPGCAJ9D2XLCA21VV 2PCA6Q884LCAQTF2CXCAL4SJGCCAHJKJR6CAM6ILJUCAD9W0G1CAKM7QGSCAQOMD52CA32A6KVCAFI0HD H218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\NMR7FCA2J631BCA6IX2NJCAAB317SCA7XY6MYCAAB4ZC3CAVL0XZRCABNCEENCAQLI9TACAOYEK YRCAA20E8ECA3RWA81CA8DJI46CA4OLGMFCAD1YSYJCA0PG7DECA9HORFACAM79V9YCATJX9AACAE9E24 R218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\ORTR4CAA036LSCAJ5S4I9CAXA8PNMCAGEV5JHCA96BG69CA6ZWZT3CAL6EIG8CAPQE2MXCA46F6 KOCAYAELCTCAVHIM4RCA7EAGBOCAF9JEMYCAE5VV6JCAA927UFCA4DDY2XCAJLMLDGCAKV16VGCANB718 J218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\OS6JGCAI4S1AVCAU23WU8CAS28LNICAHMTTDACAMAJ606CA2I0PISCAAT695FCADQIFUZCANT5C GVCA6K8BVBCA7E296ICA34VCHZCAZ93TEGCAM2P8JHCASIW4V2CAEZAMVPCAG6NNMCCAFTR9YXCAORZ5G A218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\U4PN4CA0GWQDACADZ7RW9CAY1E18BCACPKG35CANF3WKOCA5S6X7LCA3IX82ICAWYHLC9CARE0X 0HCAU5YYRZCA3QN1AACA7ETWQICAEHL64MCABN47OJCADKUETHCA5B52H3CAYY5070CA4EK9COCAV7I5Q Ohtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\UUQ05CAEE0M6LCAW26U50CAK1GI97CA0SGO15CA1I3JUVCAGJL2AJCA4UT0NBCAP0CNMWCAIK91 XWCA3X1TJ9CABNC9KECAP6MYQ3CAO8O54CCAL0URX8CA3REKATCA3E9X37CAWKXC6MCAAGU9UKCAMBAVT Khtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\VVJTUCAKTIFW0CAA0P9KTCAKDTZMDCARNPB7FCA6PEDJACA2LOCJSCAWY18WECATT2BH0CA5A84 OTCAACZO1HCA4GJC6ACAGIRXOACACUMJCQCAXF3103CAJSI1PBCACK5CVSCAMIRZAACAIF1355CATLB4S Jhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\XYXGBCAXM60OLCAE77TPACA0F8UKSCAZKHMQ3CAHM77KCCA5SNB70CAT8059ECA0X5GMCCAFDE2 NJCAP0P2W4CAEHFAMFCAHE62PICAGW3ZTDCAKNUHLYCAB87UXDCAPZEO6VCA70LCCBCADD8Q3ACAI4GBH Rhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BAIRQB3J\YC2EDCAK4BFM2CA35RLTACAJJJOVCCA2H5DUJCAQZQ95ECAASNK17CANMY7J9CAER7Z19CAZAV5 9LCACMU9VOCA15JESUCAJXELVHCAZ3I3R3CAAFQAECCATIY613CANSGHOKCAP9SQ0ACA7H46T2CAMF8CQ Yhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\1BS4HCAD0XU14CASXXS7OCA16ZRBUCA5H3HWNCALHSN05CAO1QTDWCA5Z05KXCAXDKVBBCAMGFQ 7WCAR4EOOZCABTWXGTCAGUDX24CAQ79E63CAS8GWTYCAIFHCIJCAO5RSVMCAY8QQXYCA4R3P48CAOBPN2 Hhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\2O76ICA6HFENJCAAZBSSFCA5QQ68GCAALP9XDCAD67DZ6CAIK6UY8CADY7D52CAISVE0PCAL7OB TLCAJKXJDCCA1QVK28CAMVK3ZHCAXAO5RJCA30J7TICAOG9903CA5JAQ3SCA10RQ6ZCAXJUS70CATC643 Hhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\378DMCARPNTG0CAUNCD5DCA2GL5X1CA5NYSJCCA8YNYO4CA19CQZOCALLAGUVCA55KG1ZCAEFP6 VSCABYTWBXCADC80E3CATYZNJWCA2ZJO83CA7PAB5QCAO0B1P5CAYR1EC0CAG1YNWKCA0Y2MS6CA8AEYD J[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\3BVUHCAVILMYQCAD0XW4QCASXS4DJCAZE8B70CAHZEGDGCAIUSGLICAYRLFUZCA8QS65PCA2S0T NVCA3GM87CCAC5CPTXCA56ZDZXCACVVMCPCAV0IL8NCA0I3S33CAX097GPCA6ZSULTCA1RJTZ9CAS5VBK 0[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\3VMLVCACCX29JCA0X5BS2CA9N3KF8CADRMB2PCAUYUDZGCA7XS7YJCAOXJ2ZICAE885X7CACJFY E3CAK82CDFCA4Z09U6CAR4GD2ACA2IP2CYCAA2L94FCA9QDADHCAV52P3VCA2WDN6NCAVD2YSGCAFWVIQ G[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\56GGJCAJ1VC3NCAILRPAZCAF0EAJ1CAZ88RUXCAGTLK2HCA53J4OSCAN8JKWPCAVOM10CCASOIG CDCA6QOTOFCA1VFEUPCAAU9CD9CAHGZLGJCAZD8QT5CAFK8RPVCANYO6FRCAMML1D8CAYADNMBCAV1ZX9 4htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\ES00YCAW2RVO1CA2KP266CAFGB9L1CAACF550CA1E5XNFCA0Q3IC3CAMZU4TYCAA0NKVTCA37AY WXCAKH6AKKCAXF4XO5CAWF3DDQCA7UNNI3CA3MJYTGCA8BJA4DCA2DLTHWCAGATVZNCAFSK2EWCAI43WL 3htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\F47T4CA4UA938CAEJ3NXGCA504LIDCA9MQ2XACAHNTFKFCAMHCGHFCAN593SSCA2TB7DFCAU43J 5SCA3U9QJBCAEJOS9CCA29ZIAVCA4XMQH2CAPVQ8RJCANZFBN7CAITOESOCAGESEHDCAF4R023CAS1QT2 Ihtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\J8BRLCANUB2RCCA7T5V3YCAORQ17VCATL40CYCA9NJG51CAFVBBC7CA8UCGSMCAQ0M9WMCAIXF8 PICALRNQJQCAY0M5X0CAQ2HGWDCAX1NCFBCA1GHNMZCAJALH06CAB5HU48CAOI82WRCAEVI1BECAE8WMT 2htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\KG4V1CAX4OVI1CADINSINCA2JSNENCACHL8YNCAM4CCGJCA1X8NQTCALRI4Q0CAAOJ8WCCAHYNG BZCA6EFW50CA4IPH3KCAICPFBDCATJZ921CAAVC7PNCAMAAYVOCAYKDN7GCA73541QCA4WE92ZCAJA3BT Whtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\MH0M1CACK93TMCANQ9VZOCADF10LDCAF6WN8QCAC4SIMLCAFKN24JCAA4UQ02CAZBW2NQCA3NXW UQCAX07XMNCAK0BGAUCAOWZWRGCAB2FOYRCA33IEYOCAA4ME6ACAVKQG3HCANXV3P9CASWQ217CAWQX8T F[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\O1L9ECAOQJ2VQCACMW2SLCAH4802FCAP4ISCTCAUSM76ACAJW2G0ZCA18V3DFCAN2BTSXCAQIFF BVCAM2BXCGCA10RE7NCAV2NHV8CARO48C5CALJFSOXCABNNLEZCA454QS5CARGO1D8CAQXMQP8CAHF160 Rhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\PVOWKCAHFT0O1CA7SJU9RCADO6NB8CACFNDABCA79XNLBCAAJNFVPCANBKJKMCABQ33HPCAWJ7O OQCAQ4X6ENCAJTX657CA2QF9GGCAO55VMSCAM72VC1CA4Q0KPQCA8W4IY7CA7OJFKICAMQIJR5CA6JO4W S[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\QIDXXCA22MLEMCAAEBHM1CAKE8O1LCAYQNGODCAAO9J9DCA98EF07CAPTDZLLCAPLUK61CA1P1G 3WCAJL1VU2CAX172LDCA2VJO9ZCAMHCEB3CAJYJNEHCAL3AUD8CA9WZ6UQCAE72RGJCA5WDVZGCA3PAZ3 0[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\RCNLPCA7QYQ8OCANDJ6TMCANLZKGRCAOEJLLACAZDJCA6CA9A9T2ZCAPEF5H3CA406JFRCAKWSP V3CACYDKVYCAKYGS8FCAM0JON0CAQGENDTCANJ4URHCAKSIKJHCAOOFGR4CAQQNLLFCA620MB3CAR7BX0 A[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\SQ2JLCAFO4OEICAXY3V07CAB1CI7ACA30I79SCAK3B6BWCAMG4138CAV9XJS5CAABSF68CAE0HX 50CA7R00N1CAK0MO1DCA97M05WCA0UD5MBCA8XZI1SCAWMADZ0CA4G9T28CAQ9WZ5YCA23V31ECAK403V Ahtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\U0MUJCA204OTCCABY1GJSCAKZJDRUCAKZPSZUCA2CMAGWCA5JARHDCA2DFKPLCA0N551LCAN3RR DRCA92OEY6CAJ0MM7FCACURD0GCAAAVMOICAGPKQLRCAH6VWDWCAOW6YCJCA3KQXCZCA2JT0MYCAHW2CA Mhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\U2S5QCA033WKNCACZN8ICCAS3PYYWCAJJKVD3CATK1M31CAGGKMDQCA0AZ1G3CA16M1KNCA3F1Z Q4CAL8P31NCAI8E6DQCALJVPKVCAA3TUYHCATKH0TYCA1YKF51CA7BSC0VCA92QCF3CAFI09ODCAECN85 Dhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\UBSTQCAELJO4ECAIEFQEACA92AJABCAYIR8JJCAD9H2M0CA9293DXCAVRV0OOCA255QR3CANZWC L6CAD3XSLQCA6CZTAVCANWP3MWCAF5TJAQCAQDBKA1CA4DOU1LCAAUCPJ2CA3BLXPRCAUS5781CAX8DOS Yhtm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IHS5JFJ4\XCY0ECAE7ERH0CADP92MTCA64TGA3CA7PMRMTCAZVCKSLCA9LRYMUCAQGTV57CAAHYA4MCA7YE3 6HCA9TB5E3CABNG474CAB1YSHMCA5L2V55CAWXO9NTCABAPO6HCAOH4ZVECAYGN9ZRCA2WIYTLCABSWG3 8htm !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\1MN82CASTX5U1CAVW98HWCAU807S0CA06OK1GCAW7KEV2CABG1JZTCAC03HMXCAXVG704CAQ251 U5CA5CHT2FCA2NEITQCANOZAQMCAB1FXBMCA6VD5SHCAJWW98PCAZ4Y1KCCAJB42GOCAD68T6WCA74GKL 4218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\3BTJ8CA49K5VYCA1PVMFHCA0MXPBJCACIZAE3CAOCFW16CA6SLW5SCAEXERC1CAIAORR3CA2ECX SLCAK9433FCAZGOJN8CAE54E9FCAE6FVGJCAY57WZ8CATKF6KSCARU569FCALEVOBOCA5SED2UCANC74U T218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\4TUUOCATC0S8YCA74L767CAPH0TJJCAWL4720CARD2HX7CATLVS86CAYWF1I7CA1GMYC0CA6DMN JNCA7EPPEZCA8KN8QFCA76I1S3CA4LW0BTCA8W1AB8CAAMK00DCAELYIVQCAJ0U2NBCAD2CFPRCANFXTM G218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\A0H16CA030NKGCAQX3RRNCA4LAN1MCA2UFQNBCA44PK0WCAIB3GAUCACAR02PCARXO097CAAB05 XYCAQESPCPCA5I12W8CA72OBKYCA0DQMAMCAIYF0SUCAPQMV32CA1Y6UDMCA5A12YICABIMM2LCA32020 S218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\A56LECASAWTQGCAUR1J8XCA91AKFFCA0UAFYVCA7KF8VZCAP7GEQWCAK3JP1DCAI8XOH9CAGFRC HJCA4ZQWH0CAFVTRTLCAZF800VCAU19B1BCAK3P0APCAP9QDUNCATAEKE9CADUPEWHCAG3QXYSCAYSF2Y H218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\BMUY7CA8G32WTCAK0VKW8CAMOULJFCAW6ESB7CAEJBWT3CAJ1DMBECASKL1UQCAAUY7DOCA0Q9B 2QCAR7BV00CAE229JZCA1DWRF2CADVBTAXCAATNMJCCAIRFAHUCAIWGKNTCA70XRZ0CACZIHJUCATSI8U Y218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\BP75GCAL7G3L2CAQK1S5CCAISFTAVCA56Q53ECA30KR9OCAU8D06KCAHS291WCAL54W33CAHV59 9DCAHKB7UICA60VPOSCAOV8XLKCAFF65C8CACXRPCMCAHRVH7KCA4GB4T4CAK58N0KCA2PZCR7CAPBDH4 F218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\DB41DCAWUFVWRCAH7LO0FCA9Q5JMRCAQ4CUI8CALBLQ78CAAA88A1CA5W1L90CAXSMZ47CA1P4O EKCAKFTWM2CADV4P4ZCA39K1NACAZPV03DCAD5ET7QCAY3G101CAZF68DVCAFLV6RFCAIU4GC5CA4AF4B 6218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\E31ORCAQYIOO0CAK897OACASY0XOXCAKT3VX9CA250YBRCAQXCATXCAHN84VGCA8IXJAMCAGG4C PCCA0AB0OSCA5BM34MCA94PSTNCAIN5M25CAQWMWYGCAAG6UXDCA3S41HNCA372AV5CAVMVJVOCAG1YF6 6218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\JSHS5CACJHE0YCAZPD5ODCAUWPBYXCA65GG9NCAQV6IJ5CAARIDR8CAYWCSNSCA762SJKCAN6OO 5PCAVPIDIRCAH18CMRCAFOE7OFCA2ILEFRCA38GXLUCAP6H7KQCAXSY0ZHCAF96AVOCAPYHHAJCA67G4R Q218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\M3I0ECADA3X8GCAZMR3I5CAH708HICAZ6CKCVCA9JE31FCAC50ZYSCADFBF1YCAB0ZJ6FCA0W0P AZCAPHGPUQCAGUG1EYCAF8YQ0YCAEJS3V0CAA4N2GDCACANC50CAO5HN24CAABEW4JCAZ8KOF0CAJ53GQ Q218 !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\QHPTECACSU3F2CA6ZYAB6CAT5YO4KCANYUU2QCA4IAWOKCABLGG6LCALF656FCA4M1QVFCAZTOT YXCARIUB7YCAJCQTZNCA8FM520CA2RZJ2QCAV6POJ8CAE7J2M3CANTPOEOCACBD74YCA1439HXCA0E27K Y[1] !–>[Hidden] D:\D Drive - Main Folder\Users\Darryl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UWLGRZJ6\WTM78CAKAZIF4CAX2F1A1CAR56VDGCA17T82SCAW89KINCA3QJ21DCA0E7CCLCAIEUUG2CASDMA GTCAALKA86CA642FJSCAU59HMUCA9M54Q1CAJF02JJCAZJHOZBCAGYULLWCA5GNJ2DCAF8XQKYCA7RY6C 6[1] ==============================================
Here's PART 2 of the RkU Report.txt log: ============================================== >Hooks ============================================== ntkrnlpa.exe+0x0006F858, Type: Inline - RelativeJump 0x82EBE858–>82EBE7E6 [ntkrnlpa.exe] ntkrnlpa.exe+0x0006F90C, Type: Inline - RelativeJump 0x82EBE90C–>82EBE89A [ntkrnlpa.exe] ntkrnlpa.exe+0x0006F9F8, Type: Inline - RelativeJump 0x82EBE9F8–>82EBE9DF [ntkrnlpa.exe] ntkrnlpa.exe+0x0006FA18, Type: Inline - RelativeJump 0x82EBEA18–>82EBE9A6 [ntkrnlpa.exe] ntkrnlpa.exe+0x0006FA5C, Type: Inline - RelativeJump 0x82EBEA5C–>82EBE9EA [ntkrnlpa.exe] ntkrnlpa.exe+0x0006FC34, Type: Inline - RelativeJump 0x82EBEC34–>82EBEBC1 [ntkrnlpa.exe] ntkrnlpa.exe+0x0006FCB8, Type: Inline - RelativeJump 0x82EBECB8–>82EBEC49 [ntkrnlpa.exe] ntkrnlpa.exe+0x0006FCC8, Type: Inline - RelativeJump 0x82EBECC8–>82EBEC59 [ntkrnlpa.exe] ntkrnlpa.exe+0x0006FD3C, Type: Inline - RelativeJump 0x82EBED3C–>82EBECCA [ntkrnlpa.exe] ntkrnlpa.exe–>AlpcGetHeaderSize, Type: EAT modification 0x8319F1A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>AlpcGetMessageAttribute, Type: EAT modification 0x8319F1A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>AlpcInitializeMessageAttribute, Type: EAT modification 0x8319F1A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>atoi, Type: EAT modification 0x831A1124–>84B02037 [unknown_code_page] ntkrnlpa.exe–>atol, Type: EAT modification 0x831A1128–>B1075A8E [unknown_code_page] ntkrnlpa.exe–>bsearch, Type: EAT modification 0x831A112C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>CcCanIWrite, Type: EAT modification 0x8319F1AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcCoherencyFlushAndPurgeCache, Type: EAT modification 0x8319F1B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcCopyRead, Type: EAT modification 0x8319F1B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcCopyWrite, Type: EAT modification 0x8319F1B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcCopyWriteWontFlush, Type: EAT modification 0x8319F1BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcDeferWrite, Type: EAT modification 0x8319F1C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcFastCopyRead, Type: EAT modification 0x8319F1C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcFastCopyWrite, Type: EAT modification 0x8319F1C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcFastMdlReadWait, Type: EAT modification 0x8319F1CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcFlushCache, Type: EAT modification 0x8319F1D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcGetDirtyPages, Type: EAT modification 0x8319F1D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcGetFileObjectFromBcb, Type: EAT modification 0x8319F1D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcGetFileObjectFromSectionPtrs, Type: EAT modification 0x8319F1DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcGetFileObjectFromSectionPtrsRef, Type: EAT modification 0x8319F1E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcGetFlushedValidData, Type: EAT modification 0x8319F1E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcGetLsnForFileObject, Type: EAT modification 0x8319F1E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcInitializeCacheMap, Type: EAT modification 0x8319F1EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcIsThereDirtyData, Type: EAT modification 0x8319F1F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcIsThereDirtyDataEx, Type: EAT modification 0x8319F1F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcMapData, Type: EAT modification 0x8319F1F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcMdlRead, Type: EAT modification 0x8319F1FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcMdlReadComplete, Type: EAT modification 0x8319F200–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcMdlWriteAbort, Type: EAT modification 0x8319F204–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcMdlWriteComplete, Type: EAT modification 0x8319F208–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcPinMappedData, Type: EAT modification 0x8319F20C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcPinRead, Type: EAT modification 0x8319F210–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcPrepareMdlWrite, Type: EAT modification 0x8319F214–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcPreparePinWrite, Type: EAT modification 0x8319F218–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcPurgeCacheSection, Type: EAT modification 0x8319F21C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcRemapBcb, Type: EAT modification 0x8319F220–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcRepinBcb, Type: EAT modification 0x8319F224–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcScheduleReadAhead, Type: EAT modification 0x8319F228–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetAdditionalCacheAttributes, Type: EAT modification 0x8319F22C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetBcbOwnerPointer, Type: EAT modification 0x8319F230–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetDirtyPageThreshold, Type: EAT modification 0x8319F234–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetDirtyPinnedData, Type: EAT modification 0x8319F238–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetFileSizes, Type: EAT modification 0x8319F23C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetFileSizesEx, Type: EAT modification 0x8319F240–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetLogHandleForFile, Type: EAT modification 0x8319F244–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetParallelFlushFile, Type: EAT modification 0x8319F248–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcSetReadAheadGranularity, Type: EAT modification 0x8319F24C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcTestControl, Type: EAT modification 0x8319F250–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcUninitializeCacheMap, Type: EAT modification 0x8319F254–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcUnpinData, Type: EAT modification 0x8319F258–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcUnpinDataForThread, Type: EAT modification 0x8319F25C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcUnpinRepinnedBcb, Type: EAT modification 0x8319F260–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcWaitForCurrentLazyWriterActivity, Type: EAT modification 0x8319F264–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CcZeroData, Type: EAT modification 0x8319F268–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmCallbackGetKeyObjectID, Type: EAT modification 0x8319F26C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmGetBoundTransaction, Type: EAT modification 0x8319F270–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmGetCallbackVersion, Type: EAT modification 0x8319F274–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmKeyObjectType, Type: EAT modification 0x8319F278–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmRegisterCallback, Type: EAT modification 0x8319F27C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmRegisterCallbackEx, Type: EAT modification 0x8319F280–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmSetCallbackObjectContext, Type: EAT modification 0x8319F284–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>CmUnRegisterCallback, Type: EAT modification 0x8319F288–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgBreakPoint, Type: EAT modification 0x8319F28C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgBreakPointWithStatus, Type: EAT modification 0x8319F290–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgCommandString, Type: EAT modification 0x8319F294–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgkLkmdRegisterCallback, Type: EAT modification 0x8319F2B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgkLkmdUnregisterCallback, Type: EAT modification 0x8319F2BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgLoadImageSymbols, Type: EAT modification 0x8319F298–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgPrint, Type: EAT modification 0x8319F29C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgPrintEx, Type: EAT modification 0x8319F2A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgPrintReturnControlC, Type: EAT modification 0x8319F2A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgPrompt, Type: EAT modification 0x8319F2A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgQueryDebugFilterState, Type: EAT modification 0x8319F2AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgSetDebugFilterState, Type: EAT modification 0x8319F2B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>DbgSetDebugPrintCallback, Type: EAT modification 0x8319F2B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmClientQueryRuleState, Type: EAT modification 0x8319F2C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmClientRuleDeregisterNotification, Type: EAT modification 0x8319F2C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmClientRuleEvaluate, Type: EAT modification 0x8319F2C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmClientRuleRegisterNotification, Type: EAT modification 0x8319F2CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmpProviderRegister, Type: EAT modification 0x8319F2E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmProviderDeregister, Type: EAT modification 0x8319F2D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmProviderDeregisterEntry, Type: EAT modification 0x8319F2D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmProviderRegister, Type: EAT modification 0x8319F2D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EmProviderRegisterEntry, Type: EAT modification 0x8319F2DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwActivityIdControl, Type: EAT modification 0x8319F2E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwEnableTrace, Type: EAT modification 0x8319F2E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwEventEnabled, Type: EAT modification 0x8319F2EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwProviderEnabled, Type: EAT modification 0x8319F2F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwRegister, Type: EAT modification 0x8319F2F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwRegisterClassicProvider, Type: EAT modification 0x8319F2F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwSendTraceBuffer, Type: EAT modification 0x8319F2FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwUnregister, Type: EAT modification 0x8319F300–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwWrite, Type: EAT modification 0x8319F304–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwWriteEndScenario, Type: EAT modification 0x8319F308–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwWriteEx, Type: EAT modification 0x8319F30C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwWriteStartScenario, Type: EAT modification 0x8319F310–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwWriteString, Type: EAT modification 0x8319F314–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>EtwWriteTransfer, Type: EAT modification 0x8319F318–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireCacheAwarePushLockExclusive, Type: EAT modification 0x8319F31C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireFastMutexUnsafe, Type: EAT modification 0x8319F028–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireResourceExclusiveLite, Type: EAT modification 0x8319F320–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireResourceSharedLite, Type: EAT modification 0x8319F324–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireRundownProtection, Type: EAT modification 0x8319F02C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireRundownProtectionCacheAware, Type: EAT modification 0x8319F030–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireRundownProtectionCacheAwareEx, Type: EAT modification 0x8319F034–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireRundownProtectionEx, Type: EAT modification 0x8319F038–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireSharedStarveExclusive, Type: EAT modification 0x8319F328–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireSharedWaitForExclusive, Type: EAT modification 0x8319F32C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireSpinLockExclusive, Type: EAT modification 0x8319F330–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireSpinLockExclusiveAtDpcLevel, Type: EAT modification 0x8319F334–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireSpinLockShared, Type: EAT modification 0x8319F338–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAcquireSpinLockSharedAtDpcLevel, Type: EAT modification 0x8319F33C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocateCacheAwarePushLock, Type: EAT modification 0x8319F340–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocateCacheAwareRundownProtection, Type: EAT modification 0x8319F344–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocateFromPagedLookasideList, Type: EAT modification 0x8319F348–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocatePool, Type: EAT modification 0x8319F34C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocatePoolWithQuota, Type: EAT modification 0x8319F350–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocatePoolWithQuotaTag, Type: EAT modification 0x8319F354–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocatePoolWithTag, Type: EAT modification 0x8319F358–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExAllocatePoolWithTagPriority, Type: EAT modification 0x8319F35C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExConvertExclusiveToSharedLite, Type: EAT modification 0x8319F360–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExCreateCallback, Type: EAT modification 0x8319F364–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExDeleteLookasideListEx, Type: EAT modification 0x8319F368–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExDeleteNPagedLookasideList, Type: EAT modification 0x8319F36C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExDeletePagedLookasideList, Type: EAT modification 0x8319F370–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExDeleteResourceLite, Type: EAT modification 0x8319F374–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExDesktopObjectType, Type: EAT modification 0x8319F378–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExDisableResourceBoostLite, Type: EAT modification 0x8319F37C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnterCriticalRegionAndAcquireFastMutexUnsafe, Type: EAT modification 0x8319F03C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnterCriticalRegionAndAcquireResourceExclusive, Type: EAT modification 0x8319F380–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnterCriticalRegionAndAcquireResourceShared, Type: EAT modification 0x8319F384–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnterCriticalRegionAndAcquireSharedWaitForExclusive, Type: EAT modification 0x8319F388–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnterPriorityRegionAndAcquireResourceExclusive, Type: EAT modification 0x8319F38C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnterPriorityRegionAndAcquireResourceShared, Type: EAT modification 0x8319F390–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEnumHandleTable, Type: EAT modification 0x8319F394–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExEventObjectType, Type: EAT modification 0x8319F398–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExExtendZone, Type: EAT modification 0x8319F39C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfAcquirePushLockExclusive, Type: EAT modification 0x8319F094–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfAcquirePushLockShared, Type: EAT modification 0x8319F098–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFetchLicenseData, Type: EAT modification 0x8319F3A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>Exfi386InterlockedDecrementLong, Type: EAT modification 0x8319F0D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>Exfi386InterlockedExchangeUlong, Type: EAT modification 0x8319F0D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>Exfi386InterlockedIncrementLong, Type: EAT modification 0x8319F0D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedAddUlong, Type: EAT modification 0x8319F09C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedCompareExchange64, Type: EAT modification 0x8319F0A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedInsertHeadList, Type: EAT modification 0x8319F0A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedInsertTailList, Type: EAT modification 0x8319F0A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedPopEntryList, Type: EAT modification 0x8319F0AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedPushEntryList, Type: EAT modification 0x8319F0B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfInterlockedRemoveHeadList, Type: EAT modification 0x8319F0B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFlushLookasideListEx, Type: EAT modification 0x8319F3A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFreeCacheAwarePushLock, Type: EAT modification 0x8319F3A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFreeCacheAwareRundownProtection, Type: EAT modification 0x8319F3AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFreePool, Type: EAT modification 0x8319F3B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFreePoolWithTag, Type: EAT modification 0x8319F3B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExFreeToPagedLookasideList, Type: EAT modification 0x8319F3B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfReleasePushLock, Type: EAT modification 0x8319F0B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfReleasePushLockExclusive, Type: EAT modification 0x8319F0BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfReleasePushLockShared, Type: EAT modification 0x8319F0C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfTryAcquirePushLockShared, Type: EAT modification 0x8319F0C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfTryToWakePushLock, Type: EAT modification 0x8319F0C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExfUnblockPushLock, Type: EAT modification 0x8319F0CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExGetCurrentProcessorCounts, Type: EAT modification 0x8319F3BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExGetCurrentProcessorCpuUsage, Type: EAT modification 0x8319F3C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExGetExclusiveWaiterCount, Type: EAT modification 0x8319F3C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExGetLicenseTamperState, Type: EAT modification 0x8319F3C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExGetPreviousMode, Type: EAT modification 0x8319F3CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExGetSharedWaiterCount, Type: EAT modification 0x8319F3D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>Exi386InterlockedDecrementLong, Type: EAT modification 0x8319F4B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>Exi386InterlockedExchangeUlong, Type: EAT modification 0x8319F4BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>Exi386InterlockedIncrementLong, Type: EAT modification 0x8319F4C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExiAcquireFastMutex, Type: EAT modification 0x8319F0DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializeLookasideListEx, Type: EAT modification 0x8319F3D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializeNPagedLookasideList, Type: EAT modification 0x8319F3D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializePagedLookasideList, Type: EAT modification 0x8319F3DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializePushLock, Type: EAT modification 0x8319F3E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializeResourceLite, Type: EAT modification 0x8319F3E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializeRundownProtection, Type: EAT modification 0x8319F040–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializeRundownProtectionCacheAware, Type: EAT modification 0x8319F3E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInitializeZone, Type: EAT modification 0x8319F3EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedAddLargeInteger, Type: EAT modification 0x8319F3F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedAddLargeStatistic, Type: EAT modification 0x8319F044–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedAddUlong, Type: EAT modification 0x8319F3F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedCompareExchange64, Type: EAT modification 0x8319F048–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedDecrementLong, Type: EAT modification 0x8319F3F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedExchangeUlong, Type: EAT modification 0x8319F3FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedExtendZone, Type: EAT modification 0x8319F400–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedFlushSList, Type: EAT modification 0x8319F04C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedIncrementLong, Type: EAT modification 0x8319F404–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedInsertHeadList, Type: EAT modification 0x8319F408–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedInsertTailList, Type: EAT modification 0x8319F40C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedPopEntryList, Type: EAT modification 0x8319F410–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedPopEntrySList, Type: EAT modification 0x8319F050–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedPushEntryList, Type: EAT modification 0x8319F414–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedPushEntrySList, Type: EAT modification 0x8319F054–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExInterlockedRemoveHeadList, Type: EAT modification 0x8319F418–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExiReleaseFastMutex, Type: EAT modification 0x8319F0E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExIsProcessorFeaturePresent, Type: EAT modification 0x8319F41C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExIsResourceAcquiredExclusiveLite, Type: EAT modification 0x8319F420–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExIsResourceAcquiredSharedLite, Type: EAT modification 0x8319F424–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExiTryToAcquireFastMutex, Type: EAT modification 0x8319F0E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExLocalTimeToSystemTime, Type: EAT modification 0x8319F428–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExNotifyCallback, Type: EAT modification 0x8319F42C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExQueryAttributeInformation, Type: EAT modification 0x8319F430–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExQueryPoolBlockSize, Type: EAT modification 0x8319F434–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExQueueWorkItem, Type: EAT modification 0x8319F438–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRaiseAccessViolation, Type: EAT modification 0x8319F43C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRaiseDatatypeMisalignment, Type: EAT modification 0x8319F440–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRaiseException, Type: EAT modification 0x8319F444–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRaiseHardError, Type: EAT modification 0x8319F448–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRaiseStatus, Type: EAT modification 0x8319F44C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRegisterAttributeInformationCallback, Type: EAT modification 0x8319F450–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRegisterCallback, Type: EAT modification 0x8319F454–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRegisterExtension, Type: EAT modification 0x8319F458–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReinitializeResourceLite, Type: EAT modification 0x8319F45C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReInitializeRundownProtection, Type: EAT modification 0x8319F058–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReInitializeRundownProtectionCacheAware, Type: EAT modification 0x8319F05C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseCacheAwarePushLockExclusive, Type: EAT modification 0x8319F460–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseFastMutexUnsafe, Type: EAT modification 0x8319F060–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseFastMutexUnsafeAndLeaveCriticalRegion, Type: EAT modification 0x8319F064–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseResourceAndLeaveCriticalRegion, Type: EAT modification 0x8319F068–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseResourceAndLeavePriorityRegion, Type: EAT modification 0x8319F06C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseResourceForThreadLite, Type: EAT modification 0x8319F464–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseResourceLite, Type: EAT modification 0x8319F070–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseRundownProtection, Type: EAT modification 0x8319F074–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseRundownProtectionCacheAware, Type: EAT modification 0x8319F078–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseRundownProtectionCacheAwareEx, Type: EAT modification 0x8319F07C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseRundownProtectionEx, Type: EAT modification 0x8319F080–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseSpinLockExclusive, Type: EAT modification 0x8319F468–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseSpinLockExclusiveFromDpcLevel, Type: EAT modification 0x8319F46C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseSpinLockShared, Type: EAT modification 0x8319F470–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExReleaseSpinLockSharedFromDpcLevel, Type: EAT modification 0x8319F474–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRundownCompleted, Type: EAT modification 0x8319F084–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExRundownCompletedCacheAware, Type: EAT modification 0x8319F088–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSemaphoreObjectType, Type: EAT modification 0x8319F478–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSetLicenseTamperState, Type: EAT modification 0x8319F47C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSetResourceOwnerPointer, Type: EAT modification 0x8319F480–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSetResourceOwnerPointerEx, Type: EAT modification 0x8319F484–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSetTimerResolution, Type: EAT modification 0x8319F488–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSizeOfRundownProtectionCacheAware, Type: EAT modification 0x8319F48C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSystemExceptionFilter, Type: EAT modification 0x8319F490–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExSystemTimeToLocalTime, Type: EAT modification 0x8319F494–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExTryConvertSharedSpinLockExclusive, Type: EAT modification 0x8319F498–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExUnregisterAttributeInformationCallback, Type: EAT modification 0x8319F49C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExUnregisterCallback, Type: EAT modification 0x8319F4A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExUnregisterExtension, Type: EAT modification 0x8319F4A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExUpdateLicenseData, Type: EAT modification 0x8319F4A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExUuidCreate, Type: EAT modification 0x8319F4AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExVerifySuite, Type: EAT modification 0x8319F4B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExWaitForRundownProtectionRelease, Type: EAT modification 0x8319F08C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExWaitForRundownProtectionReleaseCacheAware, Type: EAT modification 0x8319F090–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ExWindowStationObjectType, Type: EAT modification 0x8319F4B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FirstEntrySList, Type: EAT modification 0x8319F4C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAcknowledgeEcp, Type: EAT modification 0x8319F4C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAcquireFileExclusive, Type: EAT modification 0x8319F4CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAddBaseMcbEntry, Type: EAT modification 0x8319F4D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAddBaseMcbEntryEx, Type: EAT modification 0x8319F4D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAddLargeMcbEntry, Type: EAT modification 0x8319F4D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAddMcbEntry, Type: EAT modification 0x8319F4DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAddToTunnelCache, Type: EAT modification 0x8319F4E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocateExtraCreateParameter, Type: EAT modification 0x8319F4E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocateExtraCreateParameterFromLookasideList, Type: EAT modification 0x8319F4E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocateExtraCreateParameterList, Type: EAT modification 0x8319F4EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocateFileLock, Type: EAT modification 0x8319F4F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocatePool, Type: EAT modification 0x8319F4F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocatePoolWithQuota, Type: EAT modification 0x8319F4F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocatePoolWithQuotaTag, Type: EAT modification 0x8319F4FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocatePoolWithTag, Type: EAT modification 0x8319F500–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAllocateResource, Type: EAT modification 0x8319F504–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAreNamesEqual, Type: EAT modification 0x8319F508–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAreThereCurrentOrInProgressFileLocks, Type: EAT modification 0x8319F50C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlAreVolumeStartupApplicationsComplete, Type: EAT modification 0x8319F510–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlBalanceReads, Type: EAT modification 0x8319F514–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCancellableWaitForMultipleObjects, Type: EAT modification 0x8319F518–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCancellableWaitForSingleObject, Type: EAT modification 0x8319F51C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlChangeBackingFileObject, Type: EAT modification 0x8319F520–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCheckLockForReadAccess, Type: EAT modification 0x8319F524–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCheckLockForWriteAccess, Type: EAT modification 0x8319F528–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCheckOplock, Type: EAT modification 0x8319F52C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCheckOplockEx, Type: EAT modification 0x8319F530–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCopyRead, Type: EAT modification 0x8319F534–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCopyWrite, Type: EAT modification 0x8319F538–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCreateSectionForDataScan, Type: EAT modification 0x8319F53C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCurrentBatchOplock, Type: EAT modification 0x8319F540–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCurrentOplock, Type: EAT modification 0x8319F544–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlCurrentOplockH, Type: EAT modification 0x8319F548–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDeleteExtraCreateParameterLookasideList, Type: EAT modification 0x8319F54C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDeleteKeyFromTunnelCache, Type: EAT modification 0x8319F550–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDeleteTunnelCache, Type: EAT modification 0x8319F554–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDeregisterUncProvider, Type: EAT modification 0x8319F558–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDissectDbcs, Type: EAT modification 0x8319F55C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDissectName, Type: EAT modification 0x8319F560–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDoesDbcsContainWildCards, Type: EAT modification 0x8319F564–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlDoesNameContainWildCards, Type: EAT modification 0x8319F568–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFastCheckLockForRead, Type: EAT modification 0x8319F56C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFastCheckLockForWrite, Type: EAT modification 0x8319F570–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFastUnlockAll, Type: EAT modification 0x8319F574–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFastUnlockAllByKey, Type: EAT modification 0x8319F578–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFastUnlockSingle, Type: EAT modification 0x8319F57C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFindExtraCreateParameter, Type: EAT modification 0x8319F580–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFindInTunnelCache, Type: EAT modification 0x8319F584–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFreeExtraCreateParameter, Type: EAT modification 0x8319F588–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFreeExtraCreateParameterList, Type: EAT modification 0x8319F58C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlFreeFileLock, Type: EAT modification 0x8319F590–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetEcpListFromIrp, Type: EAT modification 0x8319F594–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetFileSize, Type: EAT modification 0x8319F598–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetNextBaseMcbEntry, Type: EAT modification 0x8319F59C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetNextExtraCreateParameter, Type: EAT modification 0x8319F5A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetNextFileLock, Type: EAT modification 0x8319F5A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetNextLargeMcbEntry, Type: EAT modification 0x8319F5A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetNextMcbEntry, Type: EAT modification 0x8319F5AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlGetVirtualDiskNestingLevel, Type: EAT modification 0x8319F5B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIncrementCcFastMdlReadWait, Type: EAT modification 0x8319F5B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIncrementCcFastReadNotPossible, Type: EAT modification 0x8319F5BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIncrementCcFastReadNoWait, Type: EAT modification 0x8319F5B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIncrementCcFastReadResourceMiss, Type: EAT modification 0x8319F5C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIncrementCcFastReadWait, Type: EAT modification 0x8319F5C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitExtraCreateParameterLookasideList, Type: EAT modification 0x8319F5C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeBaseMcb, Type: EAT modification 0x8319F5CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeBaseMcbEx, Type: EAT modification 0x8319F5D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeExtraCreateParameter, Type: EAT modification 0x8319F5D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeExtraCreateParameterList, Type: EAT modification 0x8319F5D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeFileLock, Type: EAT modification 0x8319F5DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeLargeMcb, Type: EAT modification 0x8319F5E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeMcb, Type: EAT modification 0x8319F5E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeOplock, Type: EAT modification 0x8319F5E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInitializeTunnelCache, Type: EAT modification 0x8319F5EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInsertExtraCreateParameter, Type: EAT modification 0x8319F5F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInsertPerFileContext, Type: EAT modification 0x8319F5F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInsertPerFileObjectContext, Type: EAT modification 0x8319F5F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlInsertPerStreamContext, Type: EAT modification 0x8319F5FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsDbcsInExpression, Type: EAT modification 0x8319F600–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsEcpAcknowledged, Type: EAT modification 0x8319F604–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsEcpFromUserMode, Type: EAT modification 0x8319F608–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsFatDbcsLegal, Type: EAT modification 0x8319F60C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsHpfsDbcsLegal, Type: EAT modification 0x8319F610–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsNameInExpression, Type: EAT modification 0x8319F614–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsNtstatusExpected, Type: EAT modification 0x8319F618–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsPagingFile, Type: EAT modification 0x8319F61C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlIsTotalDeviceFailure, Type: EAT modification 0x8319F620–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLegalAnsiCharacterArray, Type: EAT modification 0x8319F624–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLogCcFlushError, Type: EAT modification 0x8319F628–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupBaseMcbEntry, Type: EAT modification 0x8319F62C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupLargeMcbEntry, Type: EAT modification 0x8319F630–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupLastBaseMcbEntry, Type: EAT modification 0x8319F634–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupLastBaseMcbEntryAndIndex, Type: EAT modification 0x8319F638–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupLastLargeMcbEntry, Type: EAT modification 0x8319F63C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupLastLargeMcbEntryAndIndex, Type: EAT modification 0x8319F640–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupLastMcbEntry, Type: EAT modification 0x8319F644–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupMcbEntry, Type: EAT modification 0x8319F648–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupPerFileContext, Type: EAT modification 0x8319F64C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupPerFileObjectContext, Type: EAT modification 0x8319F650–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlLookupPerStreamContextInternal, Type: EAT modification 0x8319F654–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMdlRead, Type: EAT modification 0x8319F658–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMdlReadComplete, Type: EAT modification 0x8319F65C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMdlReadCompleteDev, Type: EAT modification 0x8319F660–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMdlReadDev, Type: EAT modification 0x8319F664–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMdlWriteComplete, Type: EAT modification 0x8319F668–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMdlWriteCompleteDev, Type: EAT modification 0x8319F66C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMupGetProviderIdFromName, Type: EAT modification 0x8319F670–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlMupGetProviderInfoFromFileObject, Type: EAT modification 0x8319F674–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNormalizeNtstatus, Type: EAT modification 0x8319F678–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyChangeDirectory, Type: EAT modification 0x8319F67C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyCleanup, Type: EAT modification 0x8319F680–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyCleanupAll, Type: EAT modification 0x8319F684–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyFilterChangeDirectory, Type: EAT modification 0x8319F688–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyFilterReportChange, Type: EAT modification 0x8319F68C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyFullChangeDirectory, Type: EAT modification 0x8319F690–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyFullReportChange, Type: EAT modification 0x8319F694–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyInitializeSync, Type: EAT modification 0x8319F698–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyReportChange, Type: EAT modification 0x8319F69C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyUninitializeSync, Type: EAT modification 0x8319F6A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyVolumeEvent, Type: EAT modification 0x8319F6A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNotifyVolumeEventEx, Type: EAT modification 0x8319F6A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNumberOfRunsInBaseMcb, Type: EAT modification 0x8319F6AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNumberOfRunsInLargeMcb, Type: EAT modification 0x8319F6B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlNumberOfRunsInMcb, Type: EAT modification 0x8319F6B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockBreakH, Type: EAT modification 0x8319F6B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockBreakToNone, Type: EAT modification 0x8319F6BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockBreakToNoneEx, Type: EAT modification 0x8319F6C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockFsctrl, Type: EAT modification 0x8319F6C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockFsctrlEx, Type: EAT modification 0x8319F6C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockIsFastIoPossible, Type: EAT modification 0x8319F6CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockIsSharedRequest, Type: EAT modification 0x8319F6D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlOplockKeysEqual, Type: EAT modification 0x8319F6D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlPostPagingFileStackOverflow, Type: EAT modification 0x8319F6D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlPostStackOverflow, Type: EAT modification 0x8319F6DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlPrepareMdlWrite, Type: EAT modification 0x8319F6E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlPrepareMdlWriteDev, Type: EAT modification 0x8319F6E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlPrivateLock, Type: EAT modification 0x8319F6E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlProcessFileLock, Type: EAT modification 0x8319F6EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlQueryMaximumVirtualDiskNestingLevel, Type: EAT modification 0x8319F6F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRegisterFileSystemFilterCallbacks, Type: EAT modification 0x8319F6F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRegisterFltMgrCalls, Type: EAT modification 0x8319F6F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRegisterMupCalls, Type: EAT modification 0x8319F6FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRegisterUncProvider, Type: EAT modification 0x8319F700–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRegisterUncProviderEx, Type: EAT modification 0x8319F704–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlReleaseFile, Type: EAT modification 0x8319F708–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemoveBaseMcbEntry, Type: EAT modification 0x8319F70C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemoveDotsFromPath, Type: EAT modification 0x8319F710–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemoveExtraCreateParameter, Type: EAT modification 0x8319F714–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemoveLargeMcbEntry, Type: EAT modification 0x8319F718–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemoveMcbEntry, Type: EAT modification 0x8319F71C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemovePerFileContext, Type: EAT modification 0x8319F720–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemovePerFileObjectContext, Type: EAT modification 0x8319F724–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlRemovePerStreamContext, Type: EAT modification 0x8319F728–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlResetBaseMcb, Type: EAT modification 0x8319F72C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlResetLargeMcb, Type: EAT modification 0x8319F730–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlSetEcpListIntoIrp, Type: EAT modification 0x8319F734–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlSplitBaseMcb, Type: EAT modification 0x8319F738–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlSplitLargeMcb, Type: EAT modification 0x8319F73C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlSyncVolumes, Type: EAT modification 0x8319F740–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlTeardownPerFileContexts, Type: EAT modification 0x8319F744–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlTeardownPerStreamContexts, Type: EAT modification 0x8319F748–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlTruncateBaseMcb, Type: EAT modification 0x8319F74C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlTruncateLargeMcb, Type: EAT modification 0x8319F750–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlTruncateMcb, Type: EAT modification 0x8319F754–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlUninitializeBaseMcb, Type: EAT modification 0x8319F758–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlUninitializeFileLock, Type: EAT modification 0x8319F75C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlUninitializeLargeMcb, Type: EAT modification 0x8319F760–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlUninitializeMcb, Type: EAT modification 0x8319F764–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlUninitializeOplock, Type: EAT modification 0x8319F768–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>FsRtlValidateReparsePointBuffer, Type: EAT modification 0x8319F76C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>HalDispatchTable, Type: EAT modification 0x8319F770–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>HalExamineMBR, Type: EAT modification 0x8319F0E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>HalPrivateDispatchTable, Type: EAT modification 0x8319F774–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>HeadlessDispatch, Type: EAT modification 0x8319F778–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>HvlQueryConnection, Type: EAT modification 0x8319F77C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvAcquireDisplayOwnership, Type: EAT modification 0x8319F780–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvCheckDisplayOwnership, Type: EAT modification 0x8319F784–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvDisplayString, Type: EAT modification 0x8319F788–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvEnableBootDriver, Type: EAT modification 0x8319F78C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvEnableDisplayString, Type: EAT modification 0x8319F790–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvInstallDisplayStringFilter, Type: EAT modification 0x8319F794–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvIsBootDriverInstalled, Type: EAT modification 0x8319F798–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvNotifyDisplayOwnershipLost, Type: EAT modification 0x8319F79C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvResetDisplay, Type: EAT modification 0x8319F7A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvSetScrollRegion, Type: EAT modification 0x8319F7A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvSetTextColor, Type: EAT modification 0x8319F7A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InbvSolidColorFill, Type: EAT modification 0x8319F7AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InitSafeBootMode, Type: EAT modification 0x8319F7B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedCompareExchange, Type: EAT modification 0x8319F0EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedDecrement, Type: EAT modification 0x8319F0F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedExchange, Type: EAT modification 0x8319F0F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedExchangeAdd, Type: EAT modification 0x8319F0F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedIncrement, Type: EAT modification 0x8319F0FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedPopEntrySList, Type: EAT modification 0x8319F100–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>InterlockedPushEntrySList, Type: EAT modification 0x8319F104–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAcquireCancelSpinLock, Type: EAT modification 0x8319F7B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAcquireRemoveLockEx, Type: EAT modification 0x8319F7B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAcquireVpbSpinLock, Type: EAT modification 0x8319F7BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAdapterObjectType, Type: EAT modification 0x8319F7C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAdjustStackSizeForRedirection, Type: EAT modification 0x8319F7C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateAdapterChannel, Type: EAT modification 0x8319F7C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateController, Type: EAT modification 0x8319F7CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateDriverObjectExtension, Type: EAT modification 0x8319F7D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateErrorLogEntry, Type: EAT modification 0x8319F7D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateIrp, Type: EAT modification 0x8319F7D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateMdl, Type: EAT modification 0x8319F7DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateMiniCompletionPacket, Type: EAT modification 0x8319F7E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateSfioStreamIdentifier, Type: EAT modification 0x8319F7E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAllocateWorkItem, Type: EAT modification 0x8319F7E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoApplyPriorityInfoThread, Type: EAT modification 0x8319F7EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAssignResources, Type: EAT modification 0x8319F7F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAttachDevice, Type: EAT modification 0x8319F7F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAttachDeviceByPointer, Type: EAT modification 0x8319F7F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAttachDeviceToDeviceStack, Type: EAT modification 0x8319F7FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoAttachDeviceToDeviceStackSafe, Type: EAT modification 0x8319F800–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoBuildAsynchronousFsdRequest, Type: EAT modification 0x8319F804–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoBuildDeviceIoControlRequest, Type: EAT modification 0x8319F808–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoBuildPartialMdl, Type: EAT modification 0x8319F80C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoBuildSynchronousFsdRequest, Type: EAT modification 0x8319F810–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCallDriver, Type: EAT modification 0x8319F814–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCancelFileOpen, Type: EAT modification 0x8319F818–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCancelIrp, Type: EAT modification 0x8319F81C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckDesiredAccess, Type: EAT modification 0x8319F820–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckEaBufferValidity, Type: EAT modification 0x8319F824–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckFunctionAccess, Type: EAT modification 0x8319F828–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckQuerySetFileInformation, Type: EAT modification 0x8319F82C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckQuerySetVolumeInformation, Type: EAT modification 0x8319F830–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckQuotaBufferValidity, Type: EAT modification 0x8319F834–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckShareAccess, Type: EAT modification 0x8319F838–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCheckShareAccessEx, Type: EAT modification 0x8319F83C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoClearDependency, Type: EAT modification 0x8319F840–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoClearIrpExtraCreateParameter, Type: EAT modification 0x8319F844–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCompleteRequest, Type: EAT modification 0x8319F848–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoConnectInterrupt, Type: EAT modification 0x8319F84C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoConnectInterruptEx, Type: EAT modification 0x8319F850–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateArcName, Type: EAT modification 0x8319F854–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateController, Type: EAT modification 0x8319F858–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateDevice, Type: EAT modification 0x8319F85C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateDisk, Type: EAT modification 0x8319F860–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateDriver, Type: EAT modification 0x8319F864–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateFile, Type: EAT modification 0x8319F868–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateFileEx, Type: EAT modification 0x8319F86C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateFileSpecifyDeviceObjectHint, Type: EAT modification 0x8319F870–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateNotificationEvent, Type: EAT modification 0x8319F874–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateStreamFileObject, Type: EAT modification 0x8319F878–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateStreamFileObjectEx, Type: EAT modification 0x8319F87C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateStreamFileObjectLite, Type: EAT modification 0x8319F880–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateSymbolicLink, Type: EAT modification 0x8319F884–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateSynchronizationEvent, Type: EAT modification 0x8319F888–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCreateUnprotectedSymbolicLink, Type: EAT modification 0x8319F88C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCsqInitialize, Type: EAT modification 0x8319F890–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCsqInitializeEx, Type: EAT modification 0x8319F894–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCsqInsertIrp, Type: EAT modification 0x8319F898–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCsqInsertIrpEx, Type: EAT modification 0x8319F89C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCsqRemoveIrp, Type: EAT modification 0x8319F8A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoCsqRemoveNextIrp, Type: EAT modification 0x8319F8A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeleteAllDependencyRelations, Type: EAT modification 0x8319F8A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeleteController, Type: EAT modification 0x8319F8AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeleteDevice, Type: EAT modification 0x8319F8B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeleteDriver, Type: EAT modification 0x8319F8B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeleteSymbolicLink, Type: EAT modification 0x8319F8B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDetachDevice, Type: EAT modification 0x8319F8BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeviceHandlerObjectSize, Type: EAT modification 0x8319F8C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeviceHandlerObjectType, Type: EAT modification 0x8319F8C4–>831A0364 [ntkrnlpa.exe] ntkrnlpa.exe–>IoDeviceObjectType, Type: EAT modification 0x8319F8C8–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoDisconnectInterrupt, Type: EAT modification 0x8319F8CC–>8EE77DBF [unknown_code_page] ntkrnlpa.exe–>IoDisconnectInterruptEx, Type: EAT modification 0x8319F8D0–>85F31E78 [unknown_code_page] ntkrnlpa.exe–>IoDriverObjectType, Type: EAT modification 0x8319F8D4–>8319F59C [ntkrnlpa.exe] ntkrnlpa.exe–>IoDuplicateDependency, Type: EAT modification 0x8319F8D8–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoEnqueueIrp, Type: EAT modification 0x8319F8DC–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoEnumerateDeviceObjectList, Type: EAT modification 0x8319F8E0–>82E4F061 [ntkrnlpa.exe] ntkrnlpa.exe–>IoEnumerateRegisteredFiltersList, Type: EAT modification 0x8319F8E4–>85F31668 [unknown_code_page] ntkrnlpa.exe–>IoFastQueryNetworkAttributes, Type: EAT modification 0x8319F8E8–>8319F5B4 [ntkrnlpa.exe] ntkrnlpa.exe–>IofCallDriver, Type: EAT modification 0x8319F118–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IofCompleteRequest, Type: EAT modification 0x8319F11C–>85F43D58 [unknown_code_page] ntkrnlpa.exe–>IoFileObjectType, Type: EAT modification 0x8319F8EC–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoForwardAndCatchIrp, Type: EAT modification 0x8319F8F0–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoForwardIrpSynchronously, Type: EAT modification 0x8319F8F4–>82E4F13B [ntkrnlpa.exe] ntkrnlpa.exe–>IoFreeController, Type: EAT modification 0x8319F8F8–>85F31028 [unknown_code_page] ntkrnlpa.exe–>IoFreeErrorLogEntry, Type: EAT modification 0x8319F8FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoFreeIrp, Type: EAT modification 0x8319F900–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoFreeMdl, Type: EAT modification 0x8319F904–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoFreeMiniCompletionPacket, Type: EAT modification 0x8319F908–>85F330D8 [unknown_code_page] ntkrnlpa.exe–>IoFreeSfioStreamIdentifier, Type: EAT modification 0x8319F90C–>8319F58C [ntkrnlpa.exe] ntkrnlpa.exe–>IoFreeWorkItem, Type: EAT modification 0x8319F910–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetAffinityInterrupt, Type: EAT modification 0x8319F914–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetAttachedDevice, Type: EAT modification 0x8319F918–>82E4F05C [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetAttachedDeviceReference, Type: EAT modification 0x8319F91C–>85F328C8 [unknown_code_page] ntkrnlpa.exe–>IoGetBaseFileSystemDeviceObject, Type: EAT modification 0x8319F920–>8319F5A4 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetBootDiskInformation, Type: EAT modification 0x8319F924–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetBootDiskInformationLite, Type: EAT modification 0x8319F928–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetConfigurationInformation, Type: EAT modification 0x8319F92C–>82E4F13C [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetContainerInformation, Type: EAT modification 0x8319F930–>85F32288 [unknown_code_page] ntkrnlpa.exe–>IoGetCurrentProcess, Type: EAT modification 0x8319F934–>831A02E4 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDeviceAttachmentBaseRef, Type: EAT modification 0x8319F938–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoGetDeviceInterfaceAlias, Type: EAT modification 0x8319F93C–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoGetDeviceInterfaces, Type: EAT modification 0x8319F940–>85F34338 [unknown_code_page] ntkrnlpa.exe–>IoGetDeviceNumaNode, Type: EAT modification 0x8319F944–>8319F57C [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDeviceObjectPointer, Type: EAT modification 0x8319F948–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDeviceProperty, Type: EAT modification 0x8319F94C–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDevicePropertyData, Type: EAT modification 0x8319F950–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDeviceToVerify, Type: EAT modification 0x8319F954–>85F33B28 [unknown_code_page] ntkrnlpa.exe–>IoGetDiskDeviceObject, Type: EAT modification 0x8319F958–>8319F594 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDmaAdapter, Type: EAT modification 0x8319F95C–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetDriverObjectExtension, Type: EAT modification 0x8319F960–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetFileObjectGenericMapping, Type: EAT modification 0x8319F964–>82E4F13D [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetInitialStack, Type: EAT modification 0x8319F968–>85F334E8 [unknown_code_page] ntkrnlpa.exe–>IoGetIoPriorityHint, Type: EAT modification 0x8319F96C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetIrpExtraCreateParameter, Type: EAT modification 0x8319F970–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoGetLowerDeviceObject, Type: EAT modification 0x8319F974–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoGetOplockKeyContext, Type: EAT modification 0x8319F978–>85F36598 [unknown_code_page] ntkrnlpa.exe–>IoGetPagingIoPriority, Type: EAT modification 0x8319F108–>8319F56C [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetRelatedDeviceObject, Type: EAT modification 0x8319F97C–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetRequestorProcess, Type: EAT modification 0x8319F980–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetRequestorProcessId, Type: EAT modification 0x8319F984–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetRequestorSessionId, Type: EAT modification 0x8319F988–>85F35D88 [unknown_code_page] ntkrnlpa.exe–>IoGetSfioStreamIdentifier, Type: EAT modification 0x8319F98C–>8319F584 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetStackLimits, Type: EAT modification 0x8319F990–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetSymlinkSupportInformation, Type: EAT modification 0x8319F994–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetTopLevelIrp, Type: EAT modification 0x8319F998–>82E4F13E [ntkrnlpa.exe] ntkrnlpa.exe–>IoGetTransactionParameterBlock, Type: EAT modification 0x8319F99C–>85F35748 [unknown_code_page] ntkrnlpa.exe–>IoInitializeIrp, Type: EAT modification 0x8319F9A0–>89F5F801 [unknown_code_page] ntkrnlpa.exe–>IoInitializeRemoveLockEx, Type: EAT modification 0x8319F9A4–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoInitializeTimer, Type: EAT modification 0x8319F9A8–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoInitializeWorkItem, Type: EAT modification 0x8319F9AC–>85F377F8 [unknown_code_page] ntkrnlpa.exe–>IoInvalidateDeviceRelations, Type: EAT modification 0x8319F9B0–>8319F55C [ntkrnlpa.exe] ntkrnlpa.exe–>IoInvalidateDeviceState, Type: EAT modification 0x8319F9B4–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoIsFileObjectIgnoringSharing, Type: EAT modification 0x8319F9B8–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoIsFileOriginRemote, Type: EAT modification 0x8319F9BC–>82E4F066 [ntkrnlpa.exe] ntkrnlpa.exe–>IoIsOperationSynchronous, Type: EAT modification 0x8319F9C0–>85F36FE8 [unknown_code_page] ntkrnlpa.exe–>IoIsSystemThread, Type: EAT modification 0x8319F9C4–>8319F574 [ntkrnlpa.exe] ntkrnlpa.exe–>IoIsValidNameGraftingBuffer, Type: EAT modification 0x8319F9C8–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoIsWdmVersionAvailable, Type: EAT modification 0x8319F9CC–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoMakeAssociatedIrp, Type: EAT modification 0x8319F9D0–>82E4F13F [ntkrnlpa.exe] ntkrnlpa.exe–>IoOpenDeviceInterfaceRegistryKey, Type: EAT modification 0x8319F9D4–>85F369A8 [unknown_code_page] ntkrnlpa.exe–>IoOpenDeviceRegistryKey, Type: EAT modification 0x8319F9D8–>8AEE0108 [unknown_code_page] ntkrnlpa.exe–>IoPageRead, Type: EAT modification 0x8319F9DC–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoQueryDeviceDescription, Type: EAT modification 0x8319F9E0–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoQueryFileDosDeviceName, Type: EAT modification 0x8319F9E4–>85F38A58 [unknown_code_page] ntkrnlpa.exe–>IoQueryFileInformation, Type: EAT modification 0x8319F9E8–>8319F54C [ntkrnlpa.exe] ntkrnlpa.exe–>IoQueryVolumeInformation, Type: EAT modification 0x8319F9EC–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoQueueThreadIrp, Type: EAT modification 0x8319F9F0–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoQueueWorkItem, Type: EAT modification 0x8319F9F4–>82E4F06B [ntkrnlpa.exe] ntkrnlpa.exe–>IoQueueWorkItemEx, Type: EAT modification 0x8319F9F8–>85F38248 [unknown_code_page] ntkrnlpa.exe–>IoRaiseHardError, Type: EAT modification 0x8319F9FC–>8319F564 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRaiseInformationalHardError, Type: EAT modification 0x8319FA00–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReadDiskSignature, Type: EAT modification 0x8319FA04–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReadOperationCount, Type: EAT modification 0x8319FA08–>82E4F140 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReadPartitionTable, Type: EAT modification 0x8319F10C–>85F37C08 [unknown_code_page] ntkrnlpa.exe–>IoReadPartitionTableEx, Type: EAT modification 0x8319FA0C–>83ECF811 [unknown_code_page] ntkrnlpa.exe–>IoReadTransferCount, Type: EAT modification 0x8319FA10–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoRegisterBootDriverReinitialization, Type: EAT modification 0x8319FA14–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoRegisterContainerNotification, Type: EAT modification 0x8319FA18–>85F39CB8 [unknown_code_page] ntkrnlpa.exe–>IoRegisterDeviceInterface, Type: EAT modification 0x8319FA1C–>8319F53C [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterDriverReinitialization, Type: EAT modification 0x8319FA20–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterFileSystem, Type: EAT modification 0x8319FA24–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterFsRegistrationChange, Type: EAT modification 0x8319FA28–>82E4F06C [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterFsRegistrationChangeMountAware, Type: EAT modification 0x8319FA2C–>85F394A8 [unknown_code_page] ntkrnlpa.exe–>IoRegisterLastChanceShutdownNotification, Type: EAT modification 0x8319FA30–>8319F554 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterPlugPlayNotification, Type: EAT modification 0x8319FA34–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterPriorityCallback, Type: EAT modification 0x8319FA38–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRegisterShutdownNotification, Type: EAT modification 0x8319FA3C–>82E4F141 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReleaseCancelSpinLock, Type: EAT modification 0x8319FA40–>85F38E68 [unknown_code_page] ntkrnlpa.exe–>IoReleaseRemoveLockAndWaitEx, Type: EAT modification 0x8319FA44–>8BE5F807 [unknown_code_page] ntkrnlpa.exe–>IoReleaseRemoveLockEx, Type: EAT modification 0x8319FA48–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoReleaseVpbSpinLock, Type: EAT modification 0x8319FA4C–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoRemoveShareAccess, Type: EAT modification 0x8319FA50–>85F3AF18 [unknown_code_page] ntkrnlpa.exe–>IoReplaceFileObjectName, Type: EAT modification 0x8319FA54–>8319F52C [ntkrnlpa.exe] ntkrnlpa.exe–>IoReplacePartitionUnit, Type: EAT modification 0x8319FA58–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReportDetectedDevice, Type: EAT modification 0x8319FA5C–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReportHalResourceUsage, Type: EAT modification 0x8319FA60–>82E4F064 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReportResourceForDetection, Type: EAT modification 0x8319FA64–>85F3A708 [unknown_code_page] ntkrnlpa.exe–>IoReportResourceUsage, Type: EAT modification 0x8319FA68–>8319F544 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReportRootDevice, Type: EAT modification 0x8319FA6C–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReportTargetDeviceChange, Type: EAT modification 0x8319FA70–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoReportTargetDeviceChangeAsynchronous, Type: EAT modification 0x8319FA74–>82E4F142 [ntkrnlpa.exe] ntkrnlpa.exe–>IoRequestDeviceEject, Type: EAT modification 0x8319FA78–>85F3A0C8 [unknown_code_page] ntkrnlpa.exe–>IoRequestDeviceEjectEx, Type: EAT modification 0x8319FA7C–>93EDF107 [unknown_code_page] ntkrnlpa.exe–>IoRetrievePriorityInfo, Type: EAT modification 0x8319FA80–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoReuseIrp, Type: EAT modification 0x8319FA84–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoSetCompletionRoutineEx, Type: EAT modification 0x8319FA88–>85F3D178 [unknown_code_page] ntkrnlpa.exe–>IoSetDependency, Type: EAT modification 0x8319FA8C–>8319F51C [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetDeviceInterfaceState, Type: EAT modification 0x8319FA90–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetDevicePropertyData, Type: EAT modification 0x8319FA94–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetDeviceToVerify, Type: EAT modification 0x8319FA98–>82E4F072 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetFileObjectIgnoreSharing, Type: EAT modification 0x8319FA9C–>85F3C968 [unknown_code_page] ntkrnlpa.exe–>IoSetFileOrigin, Type: EAT modification 0x8319FAA0–>8319F534 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetHardErrorOrVerifyDevice, Type: EAT modification 0x8319FAA4–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetInformation, Type: EAT modification 0x8319FAA8–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetIoCompletion, Type: EAT modification 0x8319FAAC–>82E4F143 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetIoCompletionEx, Type: EAT modification 0x8319FAB0–>85F3C328 [unknown_code_page] ntkrnlpa.exe–>IoSetIoPriorityHint, Type: EAT modification 0x8319FAB4–>89F5F901 [unknown_code_page] ntkrnlpa.exe–>IoSetIoPriorityHintIntoFileObject, Type: EAT modification 0x8319FAB8–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoSetIoPriorityHintIntoThread, Type: EAT modification 0x8319FABC–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoSetIrpExtraCreateParameter, Type: EAT modification 0x8319FAC0–>85F3E3D8 [unknown_code_page] ntkrnlpa.exe–>IoSetOplockKeyContext, Type: EAT modification 0x8319FAC4–>8319F50C [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetPartitionInformation, Type: EAT modification 0x8319F110–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetPartitionInformationEx, Type: EAT modification 0x8319FAC8–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetShareAccess, Type: EAT modification 0x8319FACC–>82E4F05E [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetShareAccessEx, Type: EAT modification 0x8319FAD0–>85F3DBC8 [unknown_code_page] ntkrnlpa.exe–>IoSetStartIoAttributes, Type: EAT modification 0x8319FAD4–>8319F524 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetSystemPartition, Type: EAT modification 0x8319FAD8–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetThreadHardErrorMode, Type: EAT modification 0x8319FADC–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSetTopLevelIrp, Type: EAT modification 0x8319FAE0–>82E4F144 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSizeofWorkItem, Type: EAT modification 0x8319FAE4–>85F3D588 [unknown_code_page] ntkrnlpa.exe–>IoStartNextPacket, Type: EAT modification 0x8319FAE8–>89EC0109 [unknown_code_page] ntkrnlpa.exe–>IoStartNextPacketByKey, Type: EAT modification 0x8319FAEC–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoStartPacket, Type: EAT modification 0x8319FAF0–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoStartTimer, Type: EAT modification 0x8319FAF4–>85F3F638 [unknown_code_page] ntkrnlpa.exe–>IoStatisticsLock, Type: EAT modification 0x8319FAF8–>8319F4FC [ntkrnlpa.exe] ntkrnlpa.exe–>IoStopTimer, Type: EAT modification 0x8319FAFC–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSynchronousInvalidateDeviceRelations, Type: EAT modification 0x8319FB00–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoSynchronousPageWrite, Type: EAT modification 0x8319FB04–>82E4F060 [ntkrnlpa.exe] ntkrnlpa.exe–>IoThreadToProcess, Type: EAT modification 0x8319FB08–>85F3EE28 [unknown_code_page] ntkrnlpa.exe–>IoTranslateBusAddress, Type: EAT modification 0x8319FB0C–>8319F514 [ntkrnlpa.exe] ntkrnlpa.exe–>IoUninitializeWorkItem, Type: EAT modification 0x8319FB10–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoUnregisterContainerNotification, Type: EAT modification 0x8319FB14–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoUnregisterFileSystem, Type: EAT modification 0x8319FB18–>82E4F145 [ntkrnlpa.exe] ntkrnlpa.exe–>IoUnregisterFsRegistrationChange, Type: EAT modification 0x8319FB1C–>85F3E7E8 [unknown_code_page] ntkrnlpa.exe–>IoUnregisterPlugPlayNotification, Type: EAT modification 0x8319FB20–>83EBF811 [unknown_code_page] ntkrnlpa.exe–>IoUnregisterPlugPlayNotificationEx, Type: EAT modification 0x8319FB24–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoUnregisterPriorityCallback, Type: EAT modification 0x8319FB28–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoUnregisterShutdownNotification, Type: EAT modification 0x8319FB2C–>85F40898 [unknown_code_page] ntkrnlpa.exe–>IoUpdateShareAccess, Type: EAT modification 0x8319FB30–>8319F4EC [ntkrnlpa.exe] ntkrnlpa.exe–>IoValidateDeviceIoControlAccess, Type: EAT modification 0x8319FB34–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoVerifyPartitionTable, Type: EAT modification 0x8319FB38–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoVerifyVolume, Type: EAT modification 0x8319FB3C–>82E4F06B [ntkrnlpa.exe] ntkrnlpa.exe–>IoVolumeDeviceToDosName, Type: EAT modification 0x8319FB40–>85F40088 [unknown_code_page] ntkrnlpa.exe–>IoWithinStackLimits, Type: EAT modification 0x8319FB80–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMIAllocateInstanceIds, Type: EAT modification 0x8319FB44–>8319F504 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMIDeviceObjectToInstanceName, Type: EAT modification 0x8319FB48–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMIExecuteMethod, Type: EAT modification 0x8319FB4C–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMIHandleToInstanceName, Type: EAT modification 0x8319FB50–>82E4F146 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMIOpenBlock, Type: EAT modification 0x8319FB54–>85F3FA48 [unknown_code_page] ntkrnlpa.exe–>IoWMIQueryAllData, Type: EAT modification 0x8319FB58–>8BE5F707 [unknown_code_page] ntkrnlpa.exe–>IoWMIQueryAllDataMultiple, Type: EAT modification 0x8319FB5C–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>IoWMIQuerySingleInstance, Type: EAT modification 0x8319FB60–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>IoWMIQuerySingleInstanceMultiple, Type: EAT modification 0x8319FB64–>85F41AF8 [unknown_code_page] ntkrnlpa.exe–>IoWMIRegistrationControl, Type: EAT modification 0x8319FB68–>8319F4DC [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMISetNotificationCallback, Type: EAT modification 0x8319FB6C–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMISetSingleInstance, Type: EAT modification 0x8319FB70–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMISetSingleItem, Type: EAT modification 0x8319FB74–>82E4F06F [ntkrnlpa.exe] ntkrnlpa.exe–>IoWMISuggestInstanceName, Type: EAT modification 0x8319FB78–>85F412E8 [unknown_code_page] ntkrnlpa.exe–>IoWMIWriteEvent, Type: EAT modification 0x8319FB7C–>8319F4F4 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWriteErrorLogEntry, Type: EAT modification 0x8319FB84–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWriteOperationCount, Type: EAT modification 0x8319FB88–>82E4F147 [ntkrnlpa.exe] ntkrnlpa.exe–>IoWritePartitionTable, Type: EAT modification 0x8319F114–>85F40CA8 [unknown_code_page] ntkrnlpa.exe–>IoWritePartitionTableEx, Type: EAT modification 0x8319FB8C–>93EEF108 [unknown_code_page] ntkrnlpa.exe–>IoWriteTransferCount, Type: EAT modification 0x8319FB90–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>isdigit, Type: EAT modification 0x831A1130–>B107337D [unknown_code_page] ntkrnlpa.exe–>islower, Type: EAT modification 0x831A1134–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>isprint, Type: EAT modification 0x831A1138–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>isspace, Type: EAT modification 0x831A113C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>isupper, Type: EAT modification 0x831A1140–>82E5010E [ntkrnlpa.exe] ntkrnlpa.exe–>isxdigit, Type: EAT modification 0x831A1144–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KdChangeOption, Type: EAT modification 0x8319FB94–>8319F4CC [ntkrnlpa.exe] ntkrnlpa.exe–>KdDebuggerEnabled, Type: EAT modification 0x8319FB98–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>KdDebuggerNotPresent, Type: EAT modification 0x8319FB9C–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>KdDisableDebugger, Type: EAT modification 0x8319FBA0–>82E4F05F [ntkrnlpa.exe] ntkrnlpa.exe–>KdEnableDebugger, Type: EAT modification 0x8319FBA4–>85F43548 [unknown_code_page] ntkrnlpa.exe–>KdEnteredDebugger, Type: EAT modification 0x8319FBA8–>8319F4E4 [ntkrnlpa.exe] ntkrnlpa.exe–>KdPollBreakIn, Type: EAT modification 0x8319FBAC–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>KdPowerTransition, Type: EAT modification 0x8319FBB0–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>KdRefreshDebuggerNotPresent, Type: EAT modification 0x8319FBB4–>82E4F148 [ntkrnlpa.exe] ntkrnlpa.exe–>KdSystemDebugControl, Type: EAT modification 0x8319FBB8–>85F42F08 [unknown_code_page] ntkrnlpa.exe–>Ke386CallBios, Type: EAT modification 0x8319FBBC–>8CF5F401 [unknown_code_page] ntkrnlpa.exe–>Ke386IoSetAccessProcess, Type: EAT modification 0x8319FBC0–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>Ke386QueryIoAccessMap, Type: EAT modification 0x8319FBC4–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>Ke386SetIoAccessMap, Type: EAT modification 0x8319FBC8–>85F44FB8 [unknown_code_page] ntkrnlpa.exe–>KeAcquireGuardedMutex, Type: EAT modification 0x8319F120–>8319F4BC [ntkrnlpa.exe] ntkrnlpa.exe–>KeAcquireGuardedMutexUnsafe, Type: EAT modification 0x8319F124–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAcquireInStackQueuedSpinLockAtDpcLevel, Type: EAT modification 0x8319F128–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAcquireInStackQueuedSpinLockForDpc, Type: EAT modification 0x8319F12C–>82E4F05F [ntkrnlpa.exe] ntkrnlpa.exe–>KeAcquireInterruptSpinLock, Type: EAT modification 0x8319FBCC–>85F447A8 [unknown_code_page] ntkrnlpa.exe–>KeAcquireSpinLockAtDpcLevel, Type: EAT modification 0x8319FBD0–>8319F4D4 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAcquireSpinLockForDpc, Type: EAT modification 0x8319F130–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAddGroupAffinityEx, Type: EAT modification 0x8319FBD4–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAddProcessorAffinityEx, Type: EAT modification 0x8319FBD8–>82E4F149 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAddProcessorGroupAffinity, Type: EAT modification 0x8319FBDC–>85F44168 [unknown_code_page] ntkrnlpa.exe–>KeAddSystemServiceTable, Type: EAT modification 0x8319FBE0–>89EC0109 [unknown_code_page] ntkrnlpa.exe–>KeAlertThread, Type: EAT modification 0x8319FBE4–>F6BC87E3 [unknown_code_page] ntkrnlpa.exe–>KeAllocateCalloutStack, Type: EAT modification 0x8319FBE8–>8EE77CBA [unknown_code_page] ntkrnlpa.exe–>KeAllocateCalloutStackEx, Type: EAT modification 0x8319FBEC–>85F46218 [unknown_code_page] ntkrnlpa.exe–>KeAndAffinityEx, Type: EAT modification 0x8319FBF0–>8319F4AC [ntkrnlpa.exe] ntkrnlpa.exe–>KeAndGroupAffinityEx, Type: EAT modification 0x8319FBF4–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAreAllApcsDisabled, Type: EAT modification 0x8319FBF8–>82E4F400 [ntkrnlpa.exe] ntkrnlpa.exe–>KeAreApcsDisabled, Type: EAT modification 0x8319FBFC–>82E4F05A [ntkrnlpa.exe] ntkrnlpa.exe–>KeAttachProcess, Type: EAT modification 0x8319FC00–>85F45A08 [unknown_code_page] ntkrnlpa.exe–>KeBugCheck, Type: EAT modification 0x8319FC04–>8319F4C4 [ntkrnlpa.exe] ntkrnlpa.exe–>KeBugCheckEx, Type: EAT modification 0x8319FC08–>82E4F003 [ntkrnlpa.exe] ntkrnlpa.exe–>KeCancelTimer, Type: EAT modification 0x8319FC0C–>82E4F200 [ntkrnlpa.exe] ntkrnlpa.exe–>KeCapturePersistentThreadState, Type: EAT modification 0x8319FC10–>82E4F14A [ntkrnlpa.exe] ntkrnlpa.exe–>KeCheckProcessorAffinityEx, Type: EAT modification 0x8319FC14–>85F453C8 [unknown_code_page] ntkrnlpa.exe–>KeCheckProcessorGroupAffinity, Type: EAT modification 0x8319FC18–>83EAF811 [unknown_code_page] ntkrnlpa.exe–>KeClearEvent, Type: EAT modification 0x8319FC1C–>F4BB87E0 [unknown_code_page] ntkrnlpa.exe–>KeComplementAffinityEx, Type: EAT modification 0x8319FC20–>82E77CBA [ntkrnlpa.exe] ntkrnlpa.exe–>KeCopyAffinityEx, Type: EAT modification 0x8319FC24–>82FA3980 [ntkrnlpa.exe] ntkrnlpa.exe–>KeCountSetBitsAffinityEx, Type: EAT modification 0x8319FC28–>83006500 [ntkrnlpa.exe] ntkrnlpa.exe–>KeCountSetBitsGroupAffinity, Type: EAT modification 0x8319FC2C–>83EBF611 [unknown_code_page] ntkrnlpa.exe–>KeDelayExecutionThread, Type: EAT modification 0x8319FC30–>82EEF00A [ntkrnlpa.exe] ntkrnlpa.exe–>KeDeregisterBugCheckCallback, Type: EAT modification 0x8319FC34–>85E0D1F0 [unknown_code_page] ntkrnlpa.exe–>KeDeregisterBugCheckReasonCallback, Type: EAT modification 0x8319FC38–>82F2F0C4 [ntkrnlpa.exe] ntkrnlpa.exe–>KeDeregisterNmiCallback, Type: EAT modification 0x8319FC3C–>F7C48FE4 [unknown_code_page] ntkrnlpa.exe–>KeDeregisterProcessorChangeCallback, Type: EAT modification 0x8319FC40–>8AE77CB9 [unknown_code_page] ntkrnlpa.exe–>KeDetachProcess, Type: EAT modification 0x8319FC44–>82FABDD8 [ntkrnlpa.exe] ntkrnlpa.exe–>KeEnterCriticalRegion, Type: EAT modification 0x8319FC48–>82FE4738 [ntkrnlpa.exe] ntkrnlpa.exe–>KeEnterGuardedRegion, Type: EAT modification 0x8319FC4C–>82E4F00E [ntkrnlpa.exe] ntkrnlpa.exe–>KeEnumerateNextProcessor, Type: EAT modification 0x8319FC54–>B8F99F86 [unknown_code_page] ntkrnlpa.exe–>KeExpandKernelStackAndCalloutEx, Type: EAT modification 0x8319FC5C–>8340F05F [unknown_code_page] ntkrnlpa.exe–>KefAcquireSpinLockAtDpcLevel, Type: EAT modification 0x8319F160–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeFindConfigurationEntry, Type: EAT modification 0x8319FC60–>8340F03F [unknown_code_page] ntkrnlpa.exe–>KeFindConfigurationNextEntry, Type: EAT modification 0x8319FC64–>831EF045 [ntkrnlpa.exe] ntkrnlpa.exe–>KeFindFirstSetLeftAffinityEx, Type: EAT modification 0x8319FC68–>8357F05C [unknown_code_page] ntkrnlpa.exe–>KeFindFirstSetLeftGroupAffinity, Type: EAT modification 0x8319FC6C–>8352F06F [unknown_code_page] ntkrnlpa.exe–>KeFindFirstSetRightGroupAffinity, Type: EAT modification 0x8319FC70–>8357F067 [unknown_code_page] ntkrnlpa.exe–>KeFirstGroupAffinityEx, Type: EAT modification 0x8319FC74–>8334F05C [unknown_code_page] ntkrnlpa.exe–>KeFlushEntireTb, Type: EAT modification 0x8319FC78–>834DF068 [unknown_code_page] ntkrnlpa.exe–>KeFlushQueuedDpcs, Type: EAT modification 0x8319FC7C–>8304F06C [ntkrnlpa.exe] ntkrnlpa.exe–>KeFreeCalloutStack, Type: EAT modification 0x8319FC80–>8353F043 [unknown_code_page] ntkrnlpa.exe–>KefReleaseSpinLockFromDpcLevel, Type: EAT modification 0x8319F164–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeGenericCallDpc, Type: EAT modification 0x8319FC84–>8350F06C [unknown_code_page] ntkrnlpa.exe–>KeGetCurrentNodeNumber, Type: EAT modification 0x8319FC88–>8352F069 [unknown_code_page] ntkrnlpa.exe–>KeGetCurrentProcessorNumberEx, Type: EAT modification 0x8319FC8C–>8304F073 [ntkrnlpa.exe] ntkrnlpa.exe–>KeGetCurrentThread, Type: EAT modification 0x8319FC90–>8304F02D [ntkrnlpa.exe] ntkrnlpa.exe–>KeGetPreviousMode, Type: EAT modification 0x8319FC94–>8359F042 [unknown_code_page] ntkrnlpa.exe–>KeGetProcessorIndexFromNumber, Type: EAT modification 0x8319FC98–>8304F074 [ntkrnlpa.exe] ntkrnlpa.exe–>KeGetProcessorNumberFromIndex, Type: EAT modification 0x8319FC9C–>8349F053 [unknown_code_page] ntkrnlpa.exe–>KeGetRecommendedSharedDataAlignment, Type: EAT modification 0x8319FCA0–>834DF072 [unknown_code_page] ntkrnlpa.exe–>KeGetXSaveFeatureFlags, Type: EAT modification 0x8319FCA4–>8359F06F [unknown_code_page] ntkrnlpa.exe–>KeI386AbiosCall, Type: EAT modification 0x8319FCA8–>8350F073 [unknown_code_page] ntkrnlpa.exe–>KeI386AllocateGdtSelectors, Type: EAT modification 0x8319FCAC–>8340F079 [unknown_code_page] ntkrnlpa.exe–>KeI386Call16BitCStyleFunction, Type: EAT modification 0x8319FCB0–>8356F054 [unknown_code_page] ntkrnlpa.exe–>KeI386Call16BitFunction, Type: EAT modification 0x8319FCB4–>8354F06F [unknown_code_page] ntkrnlpa.exe–>Kei386EoiHelper, Type: EAT modification 0x8319F19C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeI386FlatToGdtSelector, Type: EAT modification 0x8319FCB8–>8347F069 [unknown_code_page] ntkrnlpa.exe–>KeI386GetLid, Type: EAT modification 0x8319FCBC–>8350F061 [unknown_code_page] ntkrnlpa.exe–>KeI386MachineType, Type: EAT modification 0x8319FCC0–>8328F020 [unknown_code_page] ntkrnlpa.exe–>KeI386ReleaseGdtSelectors, Type: EAT modification 0x8319FCC4–>8354F065 [unknown_code_page] ntkrnlpa.exe–>KeI386ReleaseLid, Type: EAT modification 0x8319FCC8–>8349F072 [unknown_code_page] ntkrnlpa.exe–>KeI386SetGdtSelector, Type: EAT modification 0x8319FCCC–>8357F073 [unknown_code_page] ntkrnlpa.exe–>KeInitializeAffinityEx, Type: EAT modification 0x8319FCD0–>8353F069 [unknown_code_page] ntkrnlpa.exe–>KeInitializeApc, Type: EAT modification 0x8319FCD4–>8304F06E [ntkrnlpa.exe] ntkrnlpa.exe–>KeInitializeCrashDumpHeader, Type: EAT modification 0x8319FCD8–>8349F046 [unknown_code_page] ntkrnlpa.exe–>KeInitializeDeviceQueue, Type: EAT modification 0x8319FCDC–>8358F061 [unknown_code_page] ntkrnlpa.exe–>KeInitializeDpc, Type: EAT modification 0x8319FCE0–>8304F02E [ntkrnlpa.exe] ntkrnlpa.exe–>KeInitializeEnumerationContext, Type: EAT modification 0x8319FCE4–>8349F050 [unknown_code_page] ntkrnlpa.exe–>KeInitializeEnumerationContextFromGroup, Type: EAT modification 0x8319FCE8–>8349F070 [unknown_code_page] ntkrnlpa.exe–>KeInitializeEvent, Type: EAT modification 0x8319FCEC–>8337F020 [unknown_code_page] ntkrnlpa.exe–>KeInitializeGuardedMutex, Type: EAT modification 0x8319F134–>834DF06D [unknown_code_page] ntkrnlpa.exe–>KeInitializeInterrupt, Type: EAT modification 0x8319FCF0–>834CF074 [unknown_code_page] ntkrnlpa.exe–>KeInitializeMutant, Type: EAT modification 0x8319FCF4–>830AF020 [ntkrnlpa.exe] ntkrnlpa.exe–>KeInitializeMutex, Type: EAT modification 0x8319FCF8–>832EF020 [unknown_code_page] ntkrnlpa.exe–>KeInitializeQueue, Type: EAT modification 0x8319FCFC–>8312F072 [ntkrnlpa.exe] ntkrnlpa.exe–>KeInitializeSemaphore, Type: EAT modification 0x8319FD00–>832FF020 [unknown_code_page] ntkrnlpa.exe–>KeInitializeSpinLock, Type: EAT modification 0x8319FD04–>8350F069 [unknown_code_page] ntkrnlpa.exe–>KeInitializeThreadedDpc, Type: EAT modification 0x8319FD08–>8358F061 [unknown_code_page] ntkrnlpa.exe–>KeInitializeTimer, Type: EAT modification 0x8319FD0C–>8311F020 [ntkrnlpa.exe] ntkrnlpa.exe–>KeInitializeTimerEx, Type: EAT modification 0x8319FD10–>8339F020 [unknown_code_page] ntkrnlpa.exe–>KeInsertByKeyDeviceQueue, Type: EAT modification 0x8319FD14–>834FF06E [unknown_code_page] ntkrnlpa.exe–>KeInsertDeviceQueue, Type: EAT modification 0x8319FD18–>8353F06E [unknown_code_page] ntkrnlpa.exe–>KeInsertHeadQueue, Type: EAT modification 0x8319FD1C–>8352F077 [unknown_code_page] ntkrnlpa.exe–>KeInsertQueue, Type: EAT modification 0x8319FD20–>8325F020 [unknown_code_page] ntkrnlpa.exe–>KeInsertQueueApc, Type: EAT modification 0x8319FD24–>8346F06C [unknown_code_page] ntkrnlpa.exe–>KeInsertQueueDpc, Type: EAT modification 0x8319FD28–>8351F075 [unknown_code_page] ntkrnlpa.exe–>KeInterlockedClearProcessorAffinityEx, Type: EAT modification 0x8319FD2C–>8314F05C [ntkrnlpa.exe] ntkrnlpa.exe–>KeInterlockedSetProcessorAffinityEx, Type: EAT modification 0x8319FD30–>8304F030 [ntkrnlpa.exe] ntkrnlpa.exe–>KeInvalidateAllCaches, Type: EAT modification 0x8319FD34–>8304F02D [ntkrnlpa.exe] ntkrnlpa.exe–>KeInvalidateRangeAllCaches, Type: EAT modification 0x8319F138–>8356F054 [unknown_code_page] ntkrnlpa.exe–>KeIpiGenericCall, Type: EAT modification 0x8319FD38–>8354F06F [unknown_code_page] ntkrnlpa.exe–>KeIsAttachedProcess, Type: EAT modification 0x8319FD3C–>8347F069 [unknown_code_page] ntkrnlpa.exe–>KeIsEmptyAffinityEx, Type: EAT modification 0x8319FD40–>8350F061 [unknown_code_page] ntkrnlpa.exe–>KeIsEqualAffinityEx, Type: EAT modification 0x8319FD44–>8328F020 [unknown_code_page] ntkrnlpa.exe–>KeIsExecutingDpc, Type: EAT modification 0x8319FD48–>8354F065 [unknown_code_page] ntkrnlpa.exe–>KeIsSingleGroupAffinityEx, Type: EAT modification 0x8319FD4C–>8349F072 [unknown_code_page] ntkrnlpa.exe–>KeIsSubsetAffinityEx, Type: EAT modification 0x8319FD50–>8357F073 [unknown_code_page] ntkrnlpa.exe–>KeIsWaitListEmpty, Type: EAT modification 0x8319FD54–>8353F069 [unknown_code_page] ntkrnlpa.exe–>KeLeaveCriticalRegion, Type: EAT modification 0x8319FD58–>8304F06E [ntkrnlpa.exe] ntkrnlpa.exe–>KeLeaveGuardedRegion, Type: EAT modification 0x8319FD5C–>8349F046 [unknown_code_page] ntkrnlpa.exe–>KeLoaderBlock, Type: EAT modification 0x8319FD60–>8358F061 [unknown_code_page] ntkrnlpa.exe–>KeNumberProcessors, Type: EAT modification 0x8319FD64–>8304F02E [ntkrnlpa.exe] ntkrnlpa.exe–>KeOrAffinityEx, Type: EAT modification 0x8319FD68–>8349F050 [unknown_code_page] ntkrnlpa.exe–>KePollFreezeExecution, Type: EAT modification 0x8319FD6C–>8349F070 [unknown_code_page] ntkrnlpa.exe–>KeProcessorGroupAffinity, Type: EAT modification 0x8319FD70–>8337F020 [unknown_code_page] ntkrnlpa.exe–>KeProfileInterrupt, Type: EAT modification 0x8319FD74–>834DF06D [unknown_code_page] ntkrnlpa.exe–>KeProfileInterruptWithSource, Type: EAT modification 0x8319FD78–>834CF074 [unknown_code_page] ntkrnlpa.exe–>KePulseEvent, Type: EAT modification 0x8319FD7C–>830AF020 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryActiveGroupCount, Type: EAT modification 0x8319FD80–>832EF020 [unknown_code_page] ntkrnlpa.exe–>KeQueryActiveProcessorAffinity, Type: EAT modification 0x8319FD84–>8312F072 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryActiveProcessorCount, Type: EAT modification 0x8319FD88–>832FF020 [unknown_code_page] ntkrnlpa.exe–>KeQueryActiveProcessorCountEx, Type: EAT modification 0x8319FD8C–>8350F069 [unknown_code_page] ntkrnlpa.exe–>KeQueryActiveProcessors, Type: EAT modification 0x8319FD90–>8358F061 [unknown_code_page] ntkrnlpa.exe–>KeQueryDpcWatchdogInformation, Type: EAT modification 0x8319FD94–>8311F020 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryGroupAffinity, Type: EAT modification 0x8319FD98–>8325F020 [unknown_code_page] ntkrnlpa.exe–>KeQueryGroupAffinityEx, Type: EAT modification 0x8319FD9C–>834BF06E [unknown_code_page] ntkrnlpa.exe–>KeQueryHardwareCounterConfiguration, Type: EAT modification 0x8319FDA0–>832CF020 [unknown_code_page] ntkrnlpa.exe–>KeQueryHighestNodeNumber, Type: EAT modification 0x8319FDA4–>8351F069 [unknown_code_page] ntkrnlpa.exe–>KeQueryInterruptTime, Type: EAT modification 0x8319FDA8–>834BF069 [unknown_code_page] ntkrnlpa.exe–>KeQueryLogicalProcessorRelationship, Type: EAT modification 0x8319FDAC–>8332F020 [unknown_code_page] ntkrnlpa.exe–>KeQueryMaximumGroupCount, Type: EAT modification 0x8319FDB0–>8358F061 [unknown_code_page] ntkrnlpa.exe–>KeQueryMaximumProcessorCount, Type: EAT modification 0x8319FDB4–>8352F069 [unknown_code_page] ntkrnlpa.exe–>KeQueryMaximumProcessorCountEx, Type: EAT modification 0x8319FDB8–>8351F02E [unknown_code_page] ntkrnlpa.exe–>KeQueryNodeActiveAffinity, Type: EAT modification 0x8319FDBC–>8317F070 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryNodeMaximumProcessorCount, Type: EAT modification 0x8319FDC0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryPriorityThread, Type: EAT modification 0x8319FDC4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryRuntimeThread, Type: EAT modification 0x8319FDC8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQuerySystemTime, Type: EAT modification 0x8319FDCC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryTickCount, Type: EAT modification 0x8319FDD0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryTimeIncrement, Type: EAT modification 0x8319FDD4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeQueryUnbiasedInterruptTime, Type: EAT modification 0x8319FDD8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRaiseUserException, Type: EAT modification 0x8319FDDC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReadStateEvent, Type: EAT modification 0x8319FDE0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReadStateMutant, Type: EAT modification 0x8319FDE4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReadStateMutex, Type: EAT modification 0x8319FDE8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReadStateQueue, Type: EAT modification 0x8319FDEC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReadStateSemaphore, Type: EAT modification 0x8319FDF0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReadStateTimer, Type: EAT modification 0x8319FDF4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRegisterBugCheckCallback, Type: EAT modification 0x8319FDF8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRegisterBugCheckReasonCallback, Type: EAT modification 0x8319FDFC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRegisterNmiCallback, Type: EAT modification 0x8319FE00–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRegisterProcessorChangeCallback, Type: EAT modification 0x8319FE04–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseGuardedMutex, Type: EAT modification 0x8319F13C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseGuardedMutexUnsafe, Type: EAT modification 0x8319F140–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseInStackQueuedSpinLockForDpc, Type: EAT modification 0x8319F144–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseInStackQueuedSpinLockFromDpcLevel, Type: EAT modification 0x8319F148–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseInterruptSpinLock, Type: EAT modification 0x8319FE08–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseMutant, Type: EAT modification 0x8319FE0C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseMutex, Type: EAT modification 0x8319FE10–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseSemaphore, Type: EAT modification 0x8319FE14–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseSpinLockForDpc, Type: EAT modification 0x8319F14C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeReleaseSpinLockFromDpcLevel, Type: EAT modification 0x8319FE18–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveByKeyDeviceQueue, Type: EAT modification 0x8319FE1C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveByKeyDeviceQueueIfBusy, Type: EAT modification 0x8319FE20–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveDeviceQueue, Type: EAT modification 0x8319FE24–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveEntryDeviceQueue, Type: EAT modification 0x8319FE28–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveGroupAffinityEx, Type: EAT modification 0x8319FE2C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveProcessorAffinityEx, Type: EAT modification 0x8319FE30–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveProcessorGroupAffinity, Type: EAT modification 0x8319FE34–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveQueue, Type: EAT modification 0x8319FE38–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveQueueDpc, Type: EAT modification 0x8319FE3C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveQueueEx, Type: EAT modification 0x8319FE40–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRemoveSystemServiceTable, Type: EAT modification 0x8319FE44–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeResetEvent, Type: EAT modification 0x8319FE48–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRestoreExtendedProcessorState, Type: EAT modification 0x8319FE4C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRestoreFloatingPointState, Type: EAT modification 0x8319FE50–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRevertToUserAffinityThread, Type: EAT modification 0x8319FE54–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRevertToUserAffinityThreadEx, Type: EAT modification 0x8319FE58–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRevertToUserGroupAffinityThread, Type: EAT modification 0x8319FE5C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeRundownQueue, Type: EAT modification 0x8319FE60–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSaveExtendedProcessorState, Type: EAT modification 0x8319FE64–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSaveFloatingPointState, Type: EAT modification 0x8319FE68–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSaveStateForHibernate, Type: EAT modification 0x8319FE6C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeServiceDescriptorTable, Type: EAT modification 0x8319FE70–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetActualBasePriorityThread, Type: EAT modification 0x8319FE74–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetAffinityThread, Type: EAT modification 0x8319FE78–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetBasePriorityThread, Type: EAT modification 0x8319FE7C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetCoalescableTimer, Type: EAT modification 0x8319FE80–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetDmaIoCoherency, Type: EAT modification 0x8319FE84–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetEvent, Type: EAT modification 0x8319FE88–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetEventBoostPriority, Type: EAT modification 0x8319FE8C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetHardwareCounterConfiguration, Type: EAT modification 0x8319FE90–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetIdealProcessorThread, Type: EAT modification 0x8319FE94–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetImportanceDpc, Type: EAT modification 0x8319FE98–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetKernelStackSwapEnable, Type: EAT modification 0x8319FE9C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetPriorityThread, Type: EAT modification 0x8319FEA0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetProfileIrql, Type: EAT modification 0x8319FEA4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetSystemAffinityThread, Type: EAT modification 0x8319FEA8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetSystemAffinityThreadEx, Type: EAT modification 0x8319FEAC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetSystemGroupAffinityThread, Type: EAT modification 0x8319FEB0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetTargetProcessorDpc, Type: EAT modification 0x8319FEB4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetTargetProcessorDpcEx, Type: EAT modification 0x8319FEB8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetTimeIncrement, Type: EAT modification 0x8319FEBC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetTimer, Type: EAT modification 0x8319FEC0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSetTimerEx, Type: EAT modification 0x8319FEC4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSignalCallDpcDone, Type: EAT modification 0x8319FEC8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSignalCallDpcSynchronize, Type: EAT modification 0x8319FECC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeStackAttachProcess, Type: EAT modification 0x8319FED0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeStartDynamicProcessor, Type: EAT modification 0x8319FED4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSubtractAffinityEx, Type: EAT modification 0x8319FED8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeSynchronizeExecution, Type: EAT modification 0x8319FEDC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeTestAlertThread, Type: EAT modification 0x8319FEE0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeTestSpinLock, Type: EAT modification 0x8319F150–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeTickCount, Type: EAT modification 0x8319FEE4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeTryToAcquireGuardedMutex, Type: EAT modification 0x8319F154–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeTryToAcquireSpinLockAtDpcLevel, Type: EAT modification 0x8319F158–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeUnstackDetachProcess, Type: EAT modification 0x8319FEE8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeUpdateRunTime, Type: EAT modification 0x8319F15C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeUpdateSystemTime, Type: EAT modification 0x8319FEEC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeUserModeCallback, Type: EAT modification 0x8319FEF0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeWaitForMultipleObjects, Type: EAT modification 0x8319FEF4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeWaitForMutexObject, Type: EAT modification 0x8319FEF8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KeWaitForSingleObject, Type: EAT modification 0x8319FEFC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KiAcquireSpinLock, Type: EAT modification 0x8319F168–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>KiBugCheckData, Type: EAT modification 0x8319FF00–>B8F99FD9 [unknown_code_page] ntkrnlpa.exe–>KiCheckForSListAddress, Type: EAT modification 0x8319F16C–>8340F0BC [unknown_code_page] ntkrnlpa.exe–>KiCoprocessorError, Type: EAT modification 0x8319FF08–>8340F03F [unknown_code_page] ntkrnlpa.exe–>KiDeliverApc, Type: EAT modification 0x8319FF0C–>831EF044 [ntkrnlpa.exe] ntkrnlpa.exe–>KiDispatchInterrupt, Type: EAT modification 0x8319FF10–>8338F05C [unknown_code_page] ntkrnlpa.exe–>KiIpiServiceRoutine, Type: EAT modification 0x8319FF14–>8336F04F [unknown_code_page] ntkrnlpa.exe–>KiReleaseSpinLock, Type: EAT modification 0x8319F170–>8329F052 [unknown_code_page] ntkrnlpa.exe–>KiUnexpectedInterrupt, Type: EAT modification 0x8319FF18–>8338F04E [unknown_code_page] ntkrnlpa.exe–>LdrAccessResource, Type: EAT modification 0x8319FF1C–>8328F020 [unknown_code_page] ntkrnlpa.exe–>LdrEnumResources, Type: EAT modification 0x8319FF20–>830BF04C [ntkrnlpa.exe] ntkrnlpa.exe–>LdrFindResourceDirectory_U, Type: EAT modification 0x8319FF24–>8340F073 [unknown_code_page] ntkrnlpa.exe–>LdrFindResourceEx_U, Type: EAT modification 0x8319FF28–>834DF043 [unknown_code_page] ntkrnlpa.exe–>LdrFindResource_U, Type: EAT modification 0x8319FF2C–>8355F072 [unknown_code_page] ntkrnlpa.exe–>LdrResFindResource, Type: EAT modification 0x8319FF30–>8349F075 [unknown_code_page] ntkrnlpa.exe–>LdrResFindResourceDirectory, Type: EAT modification 0x8319FF34–>8348F02E [unknown_code_page] ntkrnlpa.exe–>LdrResSearchResource, Type: EAT modification 0x8319FF38–>8312F075 [ntkrnlpa.exe] ntkrnlpa.exe–>LpcPortObjectType, Type: EAT modification 0x8319FF3C–>8356F046 [unknown_code_page] ntkrnlpa.exe–>LpcReplyWaitReplyPort, Type: EAT modification 0x8319FF40–>8345F065 [unknown_code_page] ntkrnlpa.exe–>LpcRequestPort, Type: EAT modification 0x8319FF44–>8312F06B [ntkrnlpa.exe] ntkrnlpa.exe–>LpcRequestWaitReplyPort, Type: EAT modification 0x8319FF48–>834CF054 [unknown_code_page] ntkrnlpa.exe–>LpcRequestWaitReplyPortEx, Type: EAT modification 0x8319FF4C–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>LpcSendWaitReceivePort, Type: EAT modification 0x8319FF50–>8345F056 [unknown_code_page] ntkrnlpa.exe–>LsaCallAuthenticationPackage, Type: EAT modification 0x8319FF54–>8354F06D [unknown_code_page] ntkrnlpa.exe–>LsaDeregisterLogonProcess, Type: EAT modification 0x8319FF58–>8356F069 [unknown_code_page] ntkrnlpa.exe–>LsaFreeReturnBuffer, Type: EAT modification 0x8319FF5C–>8357F065 [unknown_code_page] ntkrnlpa.exe–>LsaLogonUser, Type: EAT modification 0x8319FF60–>8325F02E [unknown_code_page] ntkrnlpa.exe–>LsaLookupAuthenticationPackage, Type: EAT modification 0x8319FF64–>8357F073 [unknown_code_page] ntkrnlpa.exe–>LsaRegisterLogonProcess, Type: EAT modification 0x8319FF68–>8357F069 [unknown_code_page] ntkrnlpa.exe–>mbstowcs, Type: EAT modification 0x831A1148–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>mbtowc, Type: EAT modification 0x831A114C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>memchr, Type: EAT modification 0x831A1150–>8328F20C [unknown_code_page] ntkrnlpa.exe–>memcpy, Type: EAT modification 0x831A1154–>8314F045 [ntkrnlpa.exe] ntkrnlpa.exe–>memcpy_s, Type: EAT modification 0x831A1158–>8318F045 [ntkrnlpa.exe] ntkrnlpa.exe–>memmove, Type: EAT modification 0x831A115C–>8362F046 [unknown_code_page] ntkrnlpa.exe–>memmove_s, Type: EAT modification 0x831A1160–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>memset, Type: EAT modification 0x831A1164–>8332F050 [unknown_code_page] ntkrnlpa.exe–>Mm64BitPhysicalAddress, Type: EAT modification 0x8319FF6C–>8345F074 [unknown_code_page] ntkrnlpa.exe–>MmAddPhysicalMemory, Type: EAT modification 0x8319FF70–>8358F06E [unknown_code_page] ntkrnlpa.exe–>MmAddVerifierThunks, Type: EAT modification 0x8319FF74–>8316F02E [ntkrnlpa.exe] ntkrnlpa.exe–>MmAdjustWorkingSetSize, Type: EAT modification 0x8319FF78–>8314F030 [ntkrnlpa.exe] ntkrnlpa.exe–>MmAdvanceMdl, Type: EAT modification 0x8319FF7C–>8312F039 [ntkrnlpa.exe] ntkrnlpa.exe–>MmAllocateContiguousMemory, Type: EAT modification 0x8319FF80–>833AF044 [unknown_code_page] ntkrnlpa.exe–>MmAllocateContiguousMemorySpecifyCache, Type: EAT modification 0x8319FF84–>8336F044 [unknown_code_page] ntkrnlpa.exe–>MmAllocateContiguousMemorySpecifyCacheNode, Type: EAT modification 0x8319FF88–>8354F069 [unknown_code_page] ntkrnlpa.exe–>MmAllocateMappingAddress, Type: EAT modification 0x8319FF8C–>833CF02E [unknown_code_page] ntkrnlpa.exe–>MmAllocateNonCachedMemory, Type: EAT modification 0x8319FF90–>834DF076 [unknown_code_page] ntkrnlpa.exe–>MmAllocatePagesForMdl, Type: EAT modification 0x8319FF94–>8311F044 [ntkrnlpa.exe] ntkrnlpa.exe–>MmAllocatePagesForMdlEx, Type: EAT modification 0x8319FF98–>8331F041 [unknown_code_page] ntkrnlpa.exe–>MmBadPointer, Type: EAT modification 0x8319FF9C–>8325F049 [unknown_code_page] ntkrnlpa.exe–>MmBuildMdlForNonPagedPool, Type: EAT modification 0x8319FFA0–>8330F042 [unknown_code_page] ntkrnlpa.exe–>MmCanFileBeTruncated, Type: EAT modification 0x8319FFA4–>8311F045 [ntkrnlpa.exe] ntkrnlpa.exe–>MmCommitSessionMappedView, Type: EAT modification 0x8319FFA8–>833FF020 [unknown_code_page] ntkrnlpa.exe–>MmCopyVirtualMemory, Type: EAT modification 0x8319FFAC–>835BF020 [unknown_code_page] ntkrnlpa.exe–>MmCreateMdl, Type: EAT modification 0x8319FFB0–>835BF077 [unknown_code_page] ntkrnlpa.exe–>MmCreateMirror, Type: EAT modification 0x8319FFB4–>8358F02E [unknown_code_page] ntkrnlpa.exe–>MmCreateSection, Type: EAT modification 0x8319FFB8–>8356F06F [unknown_code_page] ntkrnlpa.exe–>MmDisableModifiedWriteOfSection, Type: EAT modification 0x8319FFBC–>8349F072 [unknown_code_page] ntkrnlpa.exe–>MmDoesFileHaveUserWritableReferences, Type: EAT modification 0x8319FFC0–>8358F06E [unknown_code_page] ntkrnlpa.exe–>MmFlushImageSection, Type: EAT modification 0x8319FFC4–>8345F064 [unknown_code_page] ntkrnlpa.exe–>MmForceSectionClosed, Type: EAT modification 0x8319FFC8–>8312F079 [ntkrnlpa.exe] ntkrnlpa.exe–>MmFreeContiguousMemory, Type: EAT modification 0x8319FFCC–>8353F063 [unknown_code_page] ntkrnlpa.exe–>MmFreeContiguousMemorySpecifyCache, Type: EAT modification 0x8319FFD0–>8304F06D [ntkrnlpa.exe] ntkrnlpa.exe–>MmFreeMappingAddress, Type: EAT modification 0x8319FFD4–>8340F05D [unknown_code_page] ntkrnlpa.exe–>MmFreeNonCachedMemory, Type: EAT modification 0x8319FFD8–>8359F053 [unknown_code_page] ntkrnlpa.exe–>MmFreePagesFromMdl, Type: EAT modification 0x8319FFDC–>8357F062 [unknown_code_page] ntkrnlpa.exe–>MmGetPhysicalAddress, Type: EAT modification 0x8319FFE0–>8347F05C [unknown_code_page] ntkrnlpa.exe–>MmGetPhysicalMemoryRanges, Type: EAT modification 0x8319FFE4–>834AF064 [unknown_code_page] ntkrnlpa.exe–>MmGetSystemRoutineAddress, Type: EAT modification 0x8319FFE8–>835AF074 [unknown_code_page] ntkrnlpa.exe–>MmGetVirtualForPhysical, Type: EAT modification 0x8319FFEC–>8312F061 [ntkrnlpa.exe] ntkrnlpa.exe–>MmGrowKernelStack, Type: EAT modification 0x8319FFF0–>8314F032 [ntkrnlpa.exe] ntkrnlpa.exe–>MmHighestUserAddress, Type: EAT modification 0x8319FFF4–>831DF030 [ntkrnlpa.exe] ntkrnlpa.exe–>MmIsAddressValid, Type: EAT modification 0x8319FFF8–>8348F02E [unknown_code_page] ntkrnlpa.exe–>MmIsDriverVerifying, Type: EAT modification 0x8319FFFC–>8348F076 [unknown_code_page] ntkrnlpa.exe–>MmIsDriverVerifyingByAddress, Type: EAT modification 0x831A0000–>834DF072 [unknown_code_page] ntkrnlpa.exe–>MmIsIoSpaceActive, Type: EAT modification 0x831A0004–>8312F070 [ntkrnlpa.exe] ntkrnlpa.exe–>MmIsNonPagedSystemAddressValid, Type: EAT modification 0x831A0008–>835AF078 [unknown_code_page] ntkrnlpa.exe–>MmIsRecursiveIoFault, Type: EAT modification 0x831A000C–>8348F069 [unknown_code_page] ntkrnlpa.exe–>MmIsThisAnNtAsSystem, Type: EAT modification 0x831A0010–>8345F02D [unknown_code_page] ntkrnlpa.exe–>MmIsVerifierEnabled, Type: EAT modification 0x831A0014–>834DF06D [unknown_code_page] ntkrnlpa.exe–>MmLockPagableDataSection, Type: EAT modification 0x831A0018–>8346F061 [unknown_code_page] ntkrnlpa.exe–>MmLockPagableImageSection, Type: EAT modification 0x831A001C–>8349F06C [unknown_code_page] ntkrnlpa.exe–>MmLockPagableSectionByHandle, Type: EAT modification 0x831A0020–>8357F02E [unknown_code_page] ntkrnlpa.exe–>MmMapIoSpace, Type: EAT modification 0x831A0024–>8346F075 [unknown_code_page] ntkrnlpa.exe–>MmMapLockedPages, Type: EAT modification 0x831A0028–>8312F073 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapLockedPagesSpecifyCache, Type: EAT modification 0x831A002C–>8345F072 [unknown_code_page] ntkrnlpa.exe–>MmMapLockedPagesWithReservedMapping, Type: EAT modification 0x831A0030–>82E4F072 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapMemoryDumpMdl, Type: EAT modification 0x831A0034–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapUserAddressesToPage, Type: EAT modification 0x831A0038–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapVideoDisplay, Type: EAT modification 0x831A003C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapViewInSessionSpace, Type: EAT modification 0x831A0040–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapViewInSystemSpace, Type: EAT modification 0x831A0044–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMapViewOfSection, Type: EAT modification 0x831A0048–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMarkPhysicalMemoryAsBad, Type: EAT modification 0x831A004C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmMarkPhysicalMemoryAsGood, Type: EAT modification 0x831A0050–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmPageEntireDriver, Type: EAT modification 0x831A0054–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmPrefetchPages, Type: EAT modification 0x831A0058–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmProbeAndLockPages, Type: EAT modification 0x831A005C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmProbeAndLockProcessPages, Type: EAT modification 0x831A0060–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmProbeAndLockSelectedPages, Type: EAT modification 0x831A0064–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmProtectMdlSystemAddress, Type: EAT modification 0x831A0068–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmQuerySystemSize, Type: EAT modification 0x831A006C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmRemovePhysicalMemory, Type: EAT modification 0x831A0070–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmResetDriverPaging, Type: EAT modification 0x831A0074–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmRotatePhysicalView, Type: EAT modification 0x831A0078–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmSectionObjectType, Type: EAT modification 0x831A007C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmSecureVirtualMemory, Type: EAT modification 0x831A0080–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmSetAddressRangeModified, Type: EAT modification 0x831A0084–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmSetBankedSection, Type: EAT modification 0x831A0088–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmSizeOfMdl, Type: EAT modification 0x831A008C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmSystemRangeStart, Type: EAT modification 0x831A0090–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmTrimAllSystemPagableMemory, Type: EAT modification 0x831A0094–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnlockPagableImageSection, Type: EAT modification 0x831A0098–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnlockPages, Type: EAT modification 0x831A009C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapIoSpace, Type: EAT modification 0x831A00A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapLockedPages, Type: EAT modification 0x831A00A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapReservedMapping, Type: EAT modification 0x831A00A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapVideoDisplay, Type: EAT modification 0x831A00AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapViewInSessionSpace, Type: EAT modification 0x831A00B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapViewInSystemSpace, Type: EAT modification 0x831A00B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnmapViewOfSection, Type: EAT modification 0x831A00B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUnsecureVirtualMemory, Type: EAT modification 0x831A00BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>MmUserProbeAddress, Type: EAT modification 0x831A00C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NlsAnsiCodePage, Type: EAT modification 0x831A00C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NlsLeadByteInfo, Type: EAT modification 0x831A00C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NlsMbCodePageTag, Type: EAT modification 0x831A00CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NlsMbOemCodePageTag, Type: EAT modification 0x831A00D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NlsOemCodePage, Type: EAT modification 0x831A00D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NlsOemLeadByteInfo, Type: EAT modification 0x831A00D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtAddAtom, Type: EAT modification 0x831A00DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtAdjustPrivilegesToken, Type: EAT modification 0x831A00E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtAllocateLocallyUniqueId, Type: EAT modification 0x831A00E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtAllocateUuids, Type: EAT modification 0x831A00E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtAllocateVirtualMemory, Type: EAT modification 0x831A00EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtBuildGUID, Type: EAT modification 0x831A00F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtBuildLab, Type: EAT modification 0x831A00F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtBuildNumber, Type: EAT modification 0x831A00F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtClose, Type: EAT modification 0x831A00FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCommitComplete, Type: EAT modification 0x831A0100–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCommitEnlistment, Type: EAT modification 0x831A0104–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCommitTransaction, Type: EAT modification 0x831A0108–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtConnectPort, Type: EAT modification 0x831A010C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateEnlistment, Type: EAT modification 0x831A0110–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateEvent, Type: EAT modification 0x831A0114–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateFile, Type: EAT modification 0x831A0118–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateResourceManager, Type: EAT modification 0x831A011C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateSection, Type: EAT modification 0x831A0120–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateTransaction, Type: EAT modification 0x831A0124–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtCreateTransactionManager, Type: EAT modification 0x831A0128–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtDeleteAtom, Type: EAT modification 0x831A012C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtDeleteFile, Type: EAT modification 0x831A0130–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtDeviceIoControlFile, Type: EAT modification 0x831A0134–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtDuplicateObject, Type: EAT modification 0x831A0138–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtDuplicateToken, Type: EAT modification 0x831A013C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtEnumerateTransactionObject, Type: EAT modification 0x831A0140–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtFindAtom, Type: EAT modification 0x831A0144–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtFreeVirtualMemory, Type: EAT modification 0x831A0148–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtFreezeTransactions, Type: EAT modification 0x831A014C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtFsControlFile, Type: EAT modification 0x831A0150–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtGetEnvironmentVariableEx, Type: EAT modification 0x831A0154–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtGetNotificationResourceManager, Type: EAT modification 0x831A0158–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtGlobalFlag, Type: EAT modification 0x831A015C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtLockFile, Type: EAT modification 0x831A0160–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtMakePermanentObject, Type: EAT modification 0x831A0164–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtMapViewOfSection, Type: EAT modification 0x831A0168–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtNotifyChangeDirectoryFile, Type: EAT modification 0x831A016C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenEnlistment, Type: EAT modification 0x831A0170–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenFile, Type: EAT modification 0x831A0174–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenProcess, Type: EAT modification 0x831A0178–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenProcessToken, Type: EAT modification 0x831A017C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenProcessTokenEx, Type: EAT modification 0x831A0180–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenResourceManager, Type: EAT modification 0x831A0184–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenThread, Type: EAT modification 0x831A0188–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenThreadToken, Type: EAT modification 0x831A018C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenThreadTokenEx, Type: EAT modification 0x831A0190–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenTransaction, Type: EAT modification 0x831A0194–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtOpenTransactionManager, Type: EAT modification 0x831A0198–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtPrepareComplete, Type: EAT modification 0x831A01A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtPrepareEnlistment, Type: EAT modification 0x831A01A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtPrePrepareComplete, Type: EAT modification 0x831A019C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtPrePrepareEnlistment, Type: EAT modification 0x831A01A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtPropagationComplete, Type: EAT modification 0x831A01AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtPropagationFailed, Type: EAT modification 0x831A01B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryDirectoryFile, Type: EAT modification 0x831A01B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryEaFile, Type: EAT modification 0x831A01B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryEnvironmentVariableInfoEx, Type: EAT modification 0x831A01BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationAtom, Type: EAT modification 0x831A01C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationEnlistment, Type: EAT modification 0x831A01C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationFile, Type: EAT modification 0x831A01C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationProcess, Type: EAT modification 0x831A01CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationResourceManager, Type: EAT modification 0x831A01D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationThread, Type: EAT modification 0x831A01D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationToken, Type: EAT modification 0x831A01D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationTransaction, Type: EAT modification 0x831A01DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQueryInformationTransactionManager, Type: EAT modification 0x831A01E0–>B8F99F3C [unknown_code_page] ntkrnlpa.exe–>NtQuerySecurityAttributesToken, Type: EAT modification 0x831A01E8–>8340F119 [unknown_code_page] ntkrnlpa.exe–>NtQuerySecurityObject, Type: EAT modification 0x831A01EC–>8340F03F [unknown_code_page] ntkrnlpa.exe–>NtQuerySystemInformation, Type: EAT modification 0x831A01F0–>831EF044 [ntkrnlpa.exe] ntkrnlpa.exe–>NtQuerySystemInformationEx, Type: EAT modification 0x831A01F4–>8328F05C [unknown_code_page] ntkrnlpa.exe–>NtQueryVolumeInformationFile, Type: EAT modification 0x831A01F8–>8328F020 [unknown_code_page] ntkrnlpa.exe–>NtReadFile, Type: EAT modification 0x831A01FC–>834DF072 [unknown_code_page] ntkrnlpa.exe–>NtReadOnlyEnlistment, Type: EAT modification 0x831A0200–>8349F076 [unknown_code_page] ntkrnlpa.exe–>NtRecoverEnlistment, Type: EAT modification 0x831A0204–>8311F020 [ntkrnlpa.exe] ntkrnlpa.exe–>NtRecoverResourceManager, Type: EAT modification 0x831A0208–>8331F020 [unknown_code_page] ntkrnlpa.exe–>NtRecoverTransactionManager, Type: EAT modification 0x831A020C–>834DF061 [unknown_code_page] ntkrnlpa.exe–>NtRequestPort, Type: EAT modification 0x831A0210–>8304F06E [ntkrnlpa.exe] ntkrnlpa.exe–>NtRequestWaitReplyPort, Type: EAT modification 0x831A0214–>8353F046 [unknown_code_page] ntkrnlpa.exe–>NtRollbackComplete, Type: EAT modification 0x831A0218–>8348F06C [unknown_code_page] ntkrnlpa.exe–>NtRollbackEnlistment, Type: EAT modification 0x831A021C–>8356F065 [unknown_code_page] ntkrnlpa.exe–>NtRollbackTransaction, Type: EAT modification 0x831A0220–>8339F05C [unknown_code_page] ntkrnlpa.exe–>NtSetEaFile, Type: EAT modification 0x831A0224–>8349F073 [unknown_code_page] ntkrnlpa.exe–>NtSetEvent, Type: EAT modification 0x831A0228–>8357F072 [unknown_code_page] ntkrnlpa.exe–>NtSetInformationEnlistment, Type: EAT modification 0x831A022C–>8328F05C [unknown_code_page] ntkrnlpa.exe–>NtSetInformationFile, Type: EAT modification 0x831A0230–>8356F061 [unknown_code_page] ntkrnlpa.exe–>NtSetInformationProcess, Type: EAT modification 0x831A0234–>835DF072 [unknown_code_page] ntkrnlpa.exe–>NtSetInformationResourceManager, Type: EAT modification 0x831A0238–>8340F06C [unknown_code_page] ntkrnlpa.exe–>NtSetInformationThread, Type: EAT modification 0x831A023C–>8354F041 [unknown_code_page] ntkrnlpa.exe–>NtSetInformationToken, Type: EAT modification 0x831A0240–>8328F070 [unknown_code_page] ntkrnlpa.exe–>NtSetInformationTransaction, Type: EAT modification 0x831A0244–>8358F061 [unknown_code_page] ntkrnlpa.exe–>NtSetQuotaInformationFile, Type: EAT modification 0x831A0248–>8340F061 [unknown_code_page] ntkrnlpa.exe–>NtSetSecurityObject, Type: EAT modification 0x831A024C–>8353F052 [unknown_code_page] ntkrnlpa.exe–>NtSetVolumeInformationFile, Type: EAT modification 0x831A0250–>8351F061 [unknown_code_page] ntkrnlpa.exe–>NtShutdownSystem, Type: EAT modification 0x831A0254–>8352F069 [unknown_code_page] ntkrnlpa.exe–>NtThawTransactions, Type: EAT modification 0x831A0258–>8340F067 [unknown_code_page] ntkrnlpa.exe–>NtTraceControl, Type: EAT modification 0x831A025C–>834DF04C [unknown_code_page] ntkrnlpa.exe–>NtTraceEvent, Type: EAT modification 0x831A0260–>8349F06D [unknown_code_page] ntkrnlpa.exe–>NtUnlockFile, Type: EAT modification 0x831A0264–>834DF057 [unknown_code_page] ntkrnlpa.exe–>NtVdmControl, Type: EAT modification 0x831A0268–>8349F072 [unknown_code_page] ntkrnlpa.exe–>NtWaitForSingleObject, Type: EAT modification 0x831A026C–>8346F05C [unknown_code_page] ntkrnlpa.exe–>NtWriteFile, Type: EAT modification 0x831A0270–>8353F072 [unknown_code_page] ntkrnlpa.exe–>ObAssignSecurity, Type: EAT modification 0x831A0274–>8357F077 [unknown_code_page] ntkrnlpa.exe–>ObCheckCreateObjectAccess, Type: EAT modification 0x831A0278–>8356F065 [unknown_code_page] ntkrnlpa.exe–>ObCheckObjectAccess, Type: EAT modification 0x831A027C–>835CF05C [unknown_code_page] ntkrnlpa.exe–>ObCloseHandle, Type: EAT modification 0x831A0280–>8350F075 [unknown_code_page] ntkrnlpa.exe–>ObCreateObject, Type: EAT modification 0x831A0284–>8359F072 [unknown_code_page] ntkrnlpa.exe–>ObCreateObjectType, Type: EAT modification 0x831A0288–>8352F06E [unknown_code_page] ntkrnlpa.exe–>ObDeleteCapturedInsertInfo, Type: EAT modification 0x831A028C–>8356F065 [unknown_code_page] ntkrnlpa.exe–>ObDereferenceObject, Type: EAT modification 0x831A0290–>8348F05C [unknown_code_page] ntkrnlpa.exe–>ObDereferenceObjectDeferDelete, Type: EAT modification 0x831A0294–>834AF065 [unknown_code_page] ntkrnlpa.exe–>ObDereferenceObjectDeferDeleteWithTag, Type: EAT modification 0x831A0298–>8359F061 [unknown_code_page] ntkrnlpa.exe–>ObDereferenceSecurityDescriptor, Type: EAT modification 0x831A029C–>8358F06C [unknown_code_page] ntkrnlpa.exe–>ObfDereferenceObject, Type: EAT modification 0x8319F174–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObfDereferenceObjectWithTag, Type: EAT modification 0x8319F178–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObFindHandleForObject, Type: EAT modification 0x831A02A0–>8340F073 [unknown_code_page] ntkrnlpa.exe–>ObfReferenceObject, Type: EAT modification 0x8319F17C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObfReferenceObjectWithTag, Type: EAT modification 0x8319F180–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObGetFilterVersion, Type: EAT modification 0x831A02A4–>8356F070 [unknown_code_page] ntkrnlpa.exe–>ObGetObjectSecurity, Type: EAT modification 0x831A02A8–>834AF06F [unknown_code_page] ntkrnlpa.exe–>ObGetObjectType, Type: EAT modification 0x831A02AC–>8350F069 [unknown_code_page] ntkrnlpa.exe–>ObInsertObject, Type: EAT modification 0x831A02B0–>8340F065 [unknown_code_page] ntkrnlpa.exe–>ObIsDosDeviceLocallyMapped, Type: EAT modification 0x831A02B4–>8337F055 [unknown_code_page] ntkrnlpa.exe–>ObIsKernelHandle, Type: EAT modification 0x831A02B8–>8347F05C [unknown_code_page] ntkrnlpa.exe–>ObLogSecurityDescriptor, Type: EAT modification 0x831A02BC–>8356F068 [unknown_code_page] ntkrnlpa.exe–>ObMakeTemporaryObject, Type: EAT modification 0x831A02C0–>8351F06F [unknown_code_page] ntkrnlpa.exe–>ObOpenObjectByName, Type: EAT modification 0x831A02C4–>8340F065 [unknown_code_page] ntkrnlpa.exe–>ObOpenObjectByPointer, Type: EAT modification 0x831A02C8–>8357F075 [unknown_code_page] ntkrnlpa.exe–>ObOpenObjectByPointerWithTag, Type: EAT modification 0x831A02CC–>8356F065 [unknown_code_page] ntkrnlpa.exe–>ObQueryNameInfo, Type: EAT modification 0x831A02D0–>8353F043 [unknown_code_page] ntkrnlpa.exe–>ObQueryNameString, Type: EAT modification 0x831A02D4–>8358F06E [unknown_code_page] ntkrnlpa.exe–>ObQueryObjectAuditingByHandle, Type: EAT modification 0x831A02D8–>8352F065 [unknown_code_page] ntkrnlpa.exe–>ObReferenceObjectByHandle, Type: EAT modification 0x831A02DC–>8311F074 [ntkrnlpa.exe] ntkrnlpa.exe–>ObReferenceObjectByHandleWithTag, Type: EAT modification 0x831A02E0–>835CF065 [unknown_code_page] ntkrnlpa.exe–>ObReferenceObjectByName, Type: EAT modification 0x831A02E4–>8351F061 [unknown_code_page] ntkrnlpa.exe–>ObReferenceObjectByPointer, Type: EAT modification 0x831A02E8–>8350F070 [unknown_code_page] ntkrnlpa.exe–>ObReferenceObjectByPointerWithTag, Type: EAT modification 0x831A02EC–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>ObReferenceSecurityDescriptor, Type: EAT modification 0x831A02F0–>8357F063 [unknown_code_page] ntkrnlpa.exe–>ObRegisterCallbacks, Type: EAT modification 0x831A02F4–>82E4F073 [ntkrnlpa.exe] ntkrnlpa.exe–>ObReleaseObjectSecurity, Type: EAT modification 0x831A02F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObSetHandleAttributes, Type: EAT modification 0x831A02FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObSetSecurityDescriptorInfo, Type: EAT modification 0x831A0300–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObSetSecurityObjectByPointer, Type: EAT modification 0x831A0304–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ObUnRegisterCallbacks, Type: EAT modification 0x831A0308–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PcwAddInstance, Type: EAT modification 0x831A0310–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PcwCloseInstance, Type: EAT modification 0x831A0314–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PcwCreateInstance, Type: EAT modification 0x831A0318–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PcwRegister, Type: EAT modification 0x831A031C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PcwUnregister, Type: EAT modification 0x831A0320–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PfFileInfoNotify, Type: EAT modification 0x831A0324–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PfxFindPrefix, Type: EAT modification 0x831A0328–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PfxInitialize, Type: EAT modification 0x831A032C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PfxInsertPrefix, Type: EAT modification 0x831A0330–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PfxRemovePrefix, Type: EAT modification 0x831A0334–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoCallDriver, Type: EAT modification 0x831A0338–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoCancelDeviceNotify, Type: EAT modification 0x831A033C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoClearPowerRequest, Type: EAT modification 0x831A0340–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoCreatePowerRequest, Type: EAT modification 0x831A0344–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoDeletePowerRequest, Type: EAT modification 0x831A0348–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoDisableSleepStates, Type: EAT modification 0x831A034C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoEndDeviceBusy, Type: EAT modification 0x831A0350–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoGetSystemWake, Type: EAT modification 0x831A0354–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>POGOBuffer, Type: EAT modification 0x831A030C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoQueryWatchdogTime, Type: EAT modification 0x831A0358–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoQueueShutdownWorkItem, Type: EAT modification 0x831A035C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoReenableSleepStates, Type: EAT modification 0x831A0360–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoRegisterDeviceForIdleDetection, Type: EAT modification 0x831A0364–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoRegisterDeviceNotify, Type: EAT modification 0x831A0368–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoRegisterPowerSettingCallback, Type: EAT modification 0x831A036C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoRegisterSystemState, Type: EAT modification 0x831A0370–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoRequestPowerIrp, Type: EAT modification 0x831A0374–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoRequestShutdownEvent, Type: EAT modification 0x831A0378–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetDeviceBusyEx, Type: EAT modification 0x831A037C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetFixedWakeSource, Type: EAT modification 0x831A0380–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetHiberRange, Type: EAT modification 0x831A0384–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetPowerRequest, Type: EAT modification 0x831A0388–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetPowerState, Type: EAT modification 0x831A038C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetSystemState, Type: EAT modification 0x831A0390–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoSetSystemWake, Type: EAT modification 0x831A0394–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoShutdownBugCheck, Type: EAT modification 0x831A0398–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoStartDeviceBusy, Type: EAT modification 0x831A039C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoStartNextPowerIrp, Type: EAT modification 0x831A03A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoUnregisterPowerSettingCallback, Type: EAT modification 0x831A03A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoUnregisterSystemState, Type: EAT modification 0x831A03A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PoUserShutdownInitiated, Type: EAT modification 0x831A03AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ProbeForRead, Type: EAT modification 0x831A03B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ProbeForWrite, Type: EAT modification 0x831A03B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsAcquireProcessExitSynchronization, Type: EAT modification 0x831A03B8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsAssignImpersonationToken, Type: EAT modification 0x831A03BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsChargePoolQuota, Type: EAT modification 0x831A03C0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsChargeProcessCpuCycles, Type: EAT modification 0x831A03C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsChargeProcessNonPagedPoolQuota, Type: EAT modification 0x831A03C8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsChargeProcessPagedPoolQuota, Type: EAT modification 0x831A03CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsChargeProcessPoolQuota, Type: EAT modification 0x831A03D0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsCreateSystemThread, Type: EAT modification 0x831A03D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsDereferenceImpersonationToken, Type: EAT modification 0x831A03D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsDereferencePrimaryToken, Type: EAT modification 0x831A03DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsDisableImpersonation, Type: EAT modification 0x831A03E0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsEnterPriorityRegion, Type: EAT modification 0x831A03E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsEstablishWin32Callouts, Type: EAT modification 0x831A03E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetContextThread, Type: EAT modification 0x831A03EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentProcess, Type: EAT modification 0x831A03F0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentProcessId, Type: EAT modification 0x831A03F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentProcessSessionId, Type: EAT modification 0x831A03F8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentProcessWin32Process, Type: EAT modification 0x831A03FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThread, Type: EAT modification 0x831A0400–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadId, Type: EAT modification 0x831A0404–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadPreviousMode, Type: EAT modification 0x831A0408–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadProcess, Type: EAT modification 0x831A040C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadProcessId, Type: EAT modification 0x831A0410–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadStackBase, Type: EAT modification 0x831A0414–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadStackLimit, Type: EAT modification 0x831A0418–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadTeb, Type: EAT modification 0x831A041C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadWin32Thread, Type: EAT modification 0x831A0420–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetCurrentThreadWin32ThreadAndEnterCriticalRegion, Type: EAT modification 0x831A0424–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetJobLock, Type: EAT modification 0x831A0428–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetJobSessionId, Type: EAT modification 0x831A042C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetJobUIRestrictionsClass, Type: EAT modification 0x831A0430–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessCreateTimeQuadPart, Type: EAT modification 0x831A0434–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessDebugPort, Type: EAT modification 0x831A0438–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessExitProcessCalled, Type: EAT modification 0x831A043C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessExitStatus, Type: EAT modification 0x831A0440–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessExitTime, Type: EAT modification 0x831A0444–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessId, Type: EAT modification 0x831A0448–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessImageFileName, Type: EAT modification 0x831A044C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessInheritedFromUniqueProcessId, Type: EAT modification 0x831A0450–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessJob, Type: EAT modification 0x831A0454–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessPeb, Type: EAT modification 0x831A0458–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessPriorityClass, Type: EAT modification 0x831A045C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessSectionBaseAddress, Type: EAT modification 0x831A0460–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessSecurityPort, Type: EAT modification 0x831A0464–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessSessionId, Type: EAT modification 0x831A0468–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessSessionIdEx, Type: EAT modification 0x831A046C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessWin32Process, Type: EAT modification 0x831A0470–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetProcessWin32WindowStation, Type: EAT modification 0x831A0474–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadFreezeCount, Type: EAT modification 0x831A0478–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadHardErrorsAreDisabled, Type: EAT modification 0x831A047C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadId, Type: EAT modification 0x831A0480–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadProcess, Type: EAT modification 0x831A0484–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadProcessId, Type: EAT modification 0x831A0488–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadSessionId, Type: EAT modification 0x831A048C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadTeb, Type: EAT modification 0x831A0490–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetThreadWin32Thread, Type: EAT modification 0x831A0494–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsGetVersion, Type: EAT modification 0x831A0498–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsImpersonateClient, Type: EAT modification 0x831A049C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsInitialSystemProcess, Type: EAT modification 0x831A04A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsIsCurrentThreadPrefetching, Type: EAT modification 0x831A04A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsIsProcessBeingDebugged, Type: EAT modification 0x831A04A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsIsProtectedProcess, Type: EAT modification 0x831A04AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsIsSystemProcess, Type: EAT modification 0x831A04B0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsIsSystemThread, Type: EAT modification 0x831A04B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsIsThreadImpersonating, Type: EAT modification 0x831A04B8–>B8F99E9F [unknown_code_page] ntkrnlpa.exe–>PsJobType, Type: EAT modification 0x831A04C0–>82E4F176 [ntkrnlpa.exe] ntkrnlpa.exe–>PsLeavePriorityRegion, Type: EAT modification 0x831A04C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsLookupProcessByProcessId, Type: EAT modification 0x831A04C8–>8327F20C [unknown_code_page] ntkrnlpa.exe–>PsLookupProcessThreadByCid, Type: EAT modification 0x831A04CC–>8329F04C [unknown_code_page] ntkrnlpa.exe–>PsLookupThreadByThreadId, Type: EAT modification 0x831A04D0–>8336F041 [unknown_code_page] ntkrnlpa.exe–>psMUITest, Type: EAT modification 0x831A1168–>834DF047 [unknown_code_page] ntkrnlpa.exe–>PsProcessType, Type: EAT modification 0x831A04D4–>8362F043 [unknown_code_page] ntkrnlpa.exe–>PsQueryProcessExceptionFlags, Type: EAT modification 0x831A04D8–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>PsReferenceImpersonationToken, Type: EAT modification 0x831A04DC–>8332F050 [unknown_code_page] ntkrnlpa.exe–>PsReferencePrimaryToken, Type: EAT modification 0x831A04E0–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>PsReferenceProcessFilePointer, Type: EAT modification 0x831A04E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsReleaseProcessExitSynchronization, Type: EAT modification 0x831A04E8–>82E62C9F [ntkrnlpa.exe] ntkrnlpa.exe–>PsRemoveCreateThreadNotifyRoutine, Type: EAT modification 0x831A04EC–>8327F000 [unknown_code_page] ntkrnlpa.exe–>PsRemoveLoadImageNotifyRoutine, Type: EAT modification 0x831A04F0–>8346F078 [unknown_code_page] ntkrnlpa.exe–>PsRestoreImpersonation, Type: EAT modification 0x831A04F4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsResumeProcess, Type: EAT modification 0x831A04F8–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>PsReturnPoolQuota, Type: EAT modification 0x831A04FC–>8326F000 [unknown_code_page] ntkrnlpa.exe–>PsReturnProcessNonPagedPoolQuota, Type: EAT modification 0x831A0500–>B1062209 [unknown_code_page] ntkrnlpa.exe–>PsReturnProcessPagedPoolQuota, Type: EAT modification 0x831A0504–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>PsRevertToSelf, Type: EAT modification 0x831A050C–>84B02037 [unknown_code_page] ntkrnlpa.exe–>PsSetContextThread, Type: EAT modification 0x831A0510–>B1062209 [unknown_code_page] ntkrnlpa.exe–>PsSetCreateProcessNotifyRoutine, Type: EAT modification 0x831A0514–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>PsSetCreateProcessNotifyRoutineEx, Type: EAT modification 0x831A0518–>B1062209 [unknown_code_page] ntkrnlpa.exe–>PsSetCreateThreadNotifyRoutine, Type: EAT modification 0x831A051C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>PsSetCurrentThreadPrefetching, Type: EAT modification 0x831A0520–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsSetJobUIRestrictionsClass, Type: EAT modification 0x831A0524–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsSetLegoNotifyRoutine, Type: EAT modification 0x831A0528–>82E50103 [ntkrnlpa.exe] ntkrnlpa.exe–>PsSetLoadImageNotifyRoutine, Type: EAT modification 0x831A052C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsSetProcessPriorityByClass, Type: EAT modification 0x831A0530–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>PsSetProcessPriorityClass, Type: EAT modification 0x831A0534–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>PsSetProcessSecurityPort, Type: EAT modification 0x831A0538–>8347F110 [unknown_code_page] ntkrnlpa.exe–>PsSetProcessWin32Process, Type: EAT modification 0x831A053C–>8353F06C [unknown_code_page] ntkrnlpa.exe–>PsSetProcessWindowStation, Type: EAT modification 0x831A0540–>8349F073 [unknown_code_page] ntkrnlpa.exe–>PsSetThreadHardErrorsAreDisabled, Type: EAT modification 0x831A0544–>8359F042 [unknown_code_page] ntkrnlpa.exe–>PsSetThreadWin32Thread, Type: EAT modification 0x831A0548–>8358F074 [unknown_code_page] ntkrnlpa.exe–>PsSuspendProcess, Type: EAT modification 0x831A054C–>8352F06F [unknown_code_page] ntkrnlpa.exe–>PsTerminateSystemThread, Type: EAT modification 0x831A0550–>8312F073 [ntkrnlpa.exe] ntkrnlpa.exe–>PsThreadType, Type: EAT modification 0x831A0554–>8352F070 [unknown_code_page] ntkrnlpa.exe–>PsUILanguageComitted, Type: EAT modification 0x831A0558–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>PsWrapApcWow64Thread, Type: EAT modification 0x831A055C–>82E4F002 [ntkrnlpa.exe] ntkrnlpa.exe–>qsort, Type: EAT modification 0x831A116C–>8359F06E [unknown_code_page] ntkrnlpa.exe–>rand, Type: EAT modification 0x831A1170–>82E62CAE [ntkrnlpa.exe] ntkrnlpa.exe–>READ_REGISTER_BUFFER_UCHAR, Type: EAT modification 0x831A0560–>82E62C9F [ntkrnlpa.exe] ntkrnlpa.exe–>READ_REGISTER_BUFFER_ULONG, Type: EAT modification 0x831A0564–>8327F000 [unknown_code_page] ntkrnlpa.exe–>READ_REGISTER_BUFFER_USHORT, Type: EAT modification 0x831A0568–>833EF070 [unknown_code_page] ntkrnlpa.exe–>READ_REGISTER_UCHAR, Type: EAT modification 0x831A056C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>READ_REGISTER_ULONG, Type: EAT modification 0x831A0570–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>READ_REGISTER_USHORT, Type: EAT modification 0x831A0574–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlAbsoluteToSelfRelativeSD, Type: EAT modification 0x831A0578–>B1062209 [unknown_code_page] ntkrnlpa.exe–>RtlAddAccessAllowedAce, Type: EAT modification 0x831A057C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlAddAce, Type: EAT modification 0x831A0584–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlAddAtomToAtomTable, Type: EAT modification 0x831A0588–>B1062209 [unknown_code_page] ntkrnlpa.exe–>RtlAddRange, Type: EAT modification 0x831A058C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlAllocateHeap, Type: EAT modification 0x831A0590–>B1062209 [unknown_code_page] ntkrnlpa.exe–>RtlAnsiCharToUnicodeChar, Type: EAT modification 0x831A0594–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlAnsiStringToUnicodeSize, Type: EAT modification 0x831A0598–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlAnsiStringToUnicodeString, Type: EAT modification 0x831A059C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlAppendAsciizToString, Type: EAT modification 0x831A05A0–>82E50103 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlAppendStringToString, Type: EAT modification 0x831A05A4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlAppendUnicodeStringToString, Type: EAT modification 0x831A05A8–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlAppendUnicodeToString, Type: EAT modification 0x831A05AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlAreAllAccessesGranted, Type: EAT modification 0x831A05B0–>8327F20C [unknown_code_page] ntkrnlpa.exe–>RtlAreAnyAccessesGranted, Type: EAT modification 0x831A05B4–>8333F04C [unknown_code_page] ntkrnlpa.exe–>RtlAreBitsClear, Type: EAT modification 0x831A05B8–>8329F053 [unknown_code_page] ntkrnlpa.exe–>RtlAreBitsSet, Type: EAT modification 0x831A05BC–>8362F042 [unknown_code_page] ntkrnlpa.exe–>RtlAssert, Type: EAT modification 0x831A05C0–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCaptureContext, Type: EAT modification 0x831A05C4–>8332F050 [unknown_code_page] ntkrnlpa.exe–>RtlCaptureStackBackTrace, Type: EAT modification 0x831A05C8–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCharToInteger, Type: EAT modification 0x831A05CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCheckRegistryKey, Type: EAT modification 0x831A05D0–>82E62CA0 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlClearAllBits, Type: EAT modification 0x831A05D4–>8304F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlClearBit, Type: EAT modification 0x831A05D8–>8352F080 [unknown_code_page] ntkrnlpa.exe–>RtlClearBits, Type: EAT modification 0x831A05DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCmDecodeMemIoResource, Type: EAT modification 0x831A05E0–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCmEncodeMemIoResource, Type: EAT modification 0x831A05E4–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlCompareAltitudes, Type: EAT modification 0x831A05E8–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlCompareMemory, Type: EAT modification 0x831A05EC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlCompareString, Type: EAT modification 0x831A05F4–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlCompareUnicodeString, Type: EAT modification 0x831A05F8–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlCompareUnicodeStrings, Type: EAT modification 0x831A05FC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlCompressBuffer, Type: EAT modification 0x831A0600–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlCompressChunks, Type: EAT modification 0x831A0604–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlComputeCrc32, Type: EAT modification 0x831A0608–>82E4F0B8 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlContractHashTable, Type: EAT modification 0x831A060C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlConvertLongToLargeInteger, Type: EAT modification 0x831A0610–>82E4F0B7 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlConvertSidToUnicodeString, Type: EAT modification 0x831A0614–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlConvertUlongToLargeInteger, Type: EAT modification 0x831A0618–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCopyLuid, Type: EAT modification 0x831A061C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCopyLuidAndAttributesArray, Type: EAT modification 0x831A0620–>8347F116 [unknown_code_page] ntkrnlpa.exe–>RtlCopyRangeList, Type: EAT modification 0x831A0624–>8352F06F [unknown_code_page] ntkrnlpa.exe–>RtlCopySid, Type: EAT modification 0x831A0628–>8353F073 [unknown_code_page] ntkrnlpa.exe–>RtlCopySidAndAttributesArray, Type: EAT modification 0x831A062C–>8349F06C [unknown_code_page] ntkrnlpa.exe–>RtlCopyString, Type: EAT modification 0x831A0630–>8359F042 [unknown_code_page] ntkrnlpa.exe–>RtlCopyUnicodeString, Type: EAT modification 0x831A0634–>8358F074 [unknown_code_page] ntkrnlpa.exe–>RtlCreateAcl, Type: EAT modification 0x831A0638–>8352F06F [unknown_code_page] ntkrnlpa.exe–>RtlCreateAtomTable, Type: EAT modification 0x831A063C–>8350F047 [unknown_code_page] ntkrnlpa.exe–>RtlCreateHashTable, Type: EAT modification 0x831A0640–>8354F079 [unknown_code_page] ntkrnlpa.exe–>RtlCreateHeap, Type: EAT modification 0x831A0644–>8312F068 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCreateRegistryKey, Type: EAT modification 0x831A0648–>8352F070 [unknown_code_page] ntkrnlpa.exe–>RtlCreateSecurityDescriptor, Type: EAT modification 0x831A064C–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCreateSystemVolumeInformationFolder, Type: EAT modification 0x831A0650–>82E62CA5 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCreateUnicodeString, Type: EAT modification 0x831A0654–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlCustomCPToUnicodeN, Type: EAT modification 0x831A0658–>8344F070 [unknown_code_page] ntkrnlpa.exe–>RtlDecompressBuffer, Type: EAT modification 0x831A065C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDecompressChunks, Type: EAT modification 0x831A0660–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDecompressFragment, Type: EAT modification 0x831A0664–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlDelete, Type: EAT modification 0x831A0668–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlDeleteAce, Type: EAT modification 0x831A066C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlDeleteElementGenericTable, Type: EAT modification 0x831A0674–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlDeleteElementGenericTableAvl, Type: EAT modification 0x831A0678–>B106702A [unknown_code_page] ntkrnlpa.exe–>RtlDeleteHashTable, Type: EAT modification 0x831A067C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlDeleteNoSplay, Type: EAT modification 0x831A0680–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlDeleteOwnersRanges, Type: EAT modification 0x831A0684–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlDeleteRange, Type: EAT modification 0x831A0688–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDeleteRegistryValue, Type: EAT modification 0x831A068C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDescribeChunk, Type: EAT modification 0x831A0690–>82E4FB72 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDestroyAtomTable, Type: EAT modification 0x831A0694–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDestroyHeap, Type: EAT modification 0x831A0698–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDowncaseUnicodeChar, Type: EAT modification 0x831A069C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlDowncaseUnicodeString, Type: EAT modification 0x831A06A0–>8347F10F [unknown_code_page] ntkrnlpa.exe–>RtlDuplicateUnicodeString, Type: EAT modification 0x831A06A4–>8352F06F [unknown_code_page] ntkrnlpa.exe–>RtlEmptyAtomTable, Type: EAT modification 0x831A06A8–>8353F073 [unknown_code_page] ntkrnlpa.exe–>RtlEndEnumerationHashTable, Type: EAT modification 0x831A06AC–>8349F06C [unknown_code_page] ntkrnlpa.exe–>RtlEndWeakEnumerationHashTable, Type: EAT modification 0x831A06B0–>8347F049 [unknown_code_page] ntkrnlpa.exe–>RtlEnlargedIntegerMultiply, Type: EAT modification 0x831A06B4–>8352F06F [unknown_code_page] ntkrnlpa.exe–>RtlEnlargedUnsignedDivide, Type: EAT modification 0x831A06B8–>8354F02E [unknown_code_page] ntkrnlpa.exe–>RtlEnlargedUnsignedMultiply, Type: EAT modification 0x831A06BC–>834BF06E [unknown_code_page] ntkrnlpa.exe–>RtlEnumerateEntryHashTable, Type: EAT modification 0x831A06C0–>82E62CA0 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlEnumerateGenericTable, Type: EAT modification 0x831A06C4–>8304F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlEnumerateGenericTableAvl, Type: EAT modification 0x831A06C8–>833EF070 [unknown_code_page] ntkrnlpa.exe–>RtlEnumerateGenericTableLikeADirectory, Type: EAT modification 0x831A06CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlEnumerateGenericTableWithoutSplaying, Type: EAT modification 0x831A06D0–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlEnumerateGenericTableWithoutSplayingAvl, Type: EAT modification 0x831A06D4–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlEqualLuid, Type: EAT modification 0x831A06D8–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlEqualSid, Type: EAT modification 0x831A06DC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlEqualUnicodeString, Type: EAT modification 0x831A06E4–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlEthernetAddressToStringA, Type: EAT modification 0x831A06E8–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlEthernetAddressToStringW, Type: EAT modification 0x831A06EC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlEthernetStringToAddressA, Type: EAT modification 0x831A06F0–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlEthernetStringToAddressW, Type: EAT modification 0x831A06F4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlExpandHashTable, Type: EAT modification 0x831A06F8–>82E4F0B8 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlExtendedIntegerMultiply, Type: EAT modification 0x831A06FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlExtendedLargeIntegerDivide, Type: EAT modification 0x831A0700–>82E4F0B7 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlExtendedMagicDivide, Type: EAT modification 0x831A0704–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFillMemory, Type: EAT modification 0x831A0708–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFillMemoryUlong, Type: EAT modification 0x831A070C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFillMemoryUlonglong, Type: EAT modification 0x831A0710–>8327F20C [unknown_code_page] ntkrnlpa.exe–>RtlFindAceByType, Type: EAT modification 0x831A0714–>8332F04F [unknown_code_page] ntkrnlpa.exe–>RtlFindClearBits, Type: EAT modification 0x831A0718–>8333F053 [unknown_code_page] ntkrnlpa.exe–>RtlFindClearBitsAndSet, Type: EAT modification 0x831A071C–>8362F04C [unknown_code_page] ntkrnlpa.exe–>RtlFindClearRuns, Type: EAT modification 0x831A0720–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindClosestEncodableLength, Type: EAT modification 0x831A0724–>8332F050 [unknown_code_page] ntkrnlpa.exe–>RtlFindFirstRunClear, Type: EAT modification 0x831A0728–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindLastBackwardRunClear, Type: EAT modification 0x831A072C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindLeastSignificantBit, Type: EAT modification 0x831A0730–>82E62CA5 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindLongestRunClear, Type: EAT modification 0x831A0734–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindMessage, Type: EAT modification 0x831A0738–>833EF070 [unknown_code_page] ntkrnlpa.exe–>RtlFindMostSignificantBit, Type: EAT modification 0x831A073C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindNextForwardRunClear, Type: EAT modification 0x831A0740–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFindRange, Type: EAT modification 0x831A0744–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlFindSetBits, Type: EAT modification 0x831A0748–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlFindSetBitsAndClear, Type: EAT modification 0x831A074C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlFormatCurrentUserKeyPath, Type: EAT modification 0x831A0754–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlFormatMessage, Type: EAT modification 0x831A0758–>B106702A [unknown_code_page] ntkrnlpa.exe–>RtlFreeAnsiString, Type: EAT modification 0x831A075C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlFreeHeap, Type: EAT modification 0x831A0760–>B106491A [unknown_code_page] ntkrnlpa.exe–>RtlFreeOemString, Type: EAT modification 0x831A0764–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlFreeRangeList, Type: EAT modification 0x831A0768–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlFreeUnicodeString, Type: EAT modification 0x831A076C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGenerate8dot3Name, Type: EAT modification 0x831A0774–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetAce, Type: EAT modification 0x831A0778–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetCallersAddress, Type: EAT modification 0x831A077C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetCompressionWorkSpaceSize, Type: EAT modification 0x831A0780–>8327F20C [unknown_code_page] ntkrnlpa.exe–>RtlGetDaclSecurityDescriptor, Type: EAT modification 0x831A0784–>8332F04F [unknown_code_page] ntkrnlpa.exe–>RtlGetDefaultCodePage, Type: EAT modification 0x831A0788–>8333F053 [unknown_code_page] ntkrnlpa.exe–>RtlGetElementGenericTable, Type: EAT modification 0x831A078C–>8362F04C [unknown_code_page] ntkrnlpa.exe–>RtlGetElementGenericTableAvl, Type: EAT modification 0x831A0790–>8312F032 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetEnabledExtendedFeatures, Type: EAT modification 0x831A0794–>8332F050 [unknown_code_page] ntkrnlpa.exe–>RtlGetFirstRange, Type: EAT modification 0x831A0798–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetGroupSecurityDescriptor, Type: EAT modification 0x831A079C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetIntegerAtom, Type: EAT modification 0x831A07A0–>B8F99EF2 [unknown_code_page] ntkrnlpa.exe–>RtlGetNextEntryHashTable, Type: EAT modification 0x831A07A8–>833AF1D3 [unknown_code_page] ntkrnlpa.exe–>RtlGetNextRange, Type: EAT modification 0x831A07AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetNtGlobalFlags, Type: EAT modification 0x831A07B0–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlGetOwnerSecurityDescriptor, Type: EAT modification 0x831A07B4–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlGetProductInfo, Type: EAT modification 0x831A07B8–>B106702A [unknown_code_page] ntkrnlpa.exe–>RtlGetSaclSecurityDescriptor, Type: EAT modification 0x831A07BC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlGetThreadLangIdByIndex, Type: EAT modification 0x831A07C4–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlGetVersion, Type: EAT modification 0x831A07C8–>B106973B [unknown_code_page] ntkrnlpa.exe–>RtlGUIDFromString, Type: EAT modification 0x831A0770–>82E4FB72 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlHashUnicodeString, Type: EAT modification 0x831A07CC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIdnToAscii, Type: EAT modification 0x831A07D0–>B106702A [unknown_code_page] ntkrnlpa.exe–>RtlIdnToNameprepUnicode, Type: EAT modification 0x831A07D4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIdnToUnicode, Type: EAT modification 0x831A07D8–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlImageDirectoryEntryToData, Type: EAT modification 0x831A07DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlImageNtHeader, Type: EAT modification 0x831A07E0–>82E4F8C6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitAnsiString, Type: EAT modification 0x831A07E4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitAnsiStringEx, Type: EAT modification 0x831A07E8–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitCodePageTable, Type: EAT modification 0x831A07EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitEnumerationHashTable, Type: EAT modification 0x831A07F0–>8347F30A [unknown_code_page] ntkrnlpa.exe–>RtlInitializeBitMap, Type: EAT modification 0x831A0804–>834AF067 [unknown_code_page] ntkrnlpa.exe–>RtlInitializeGenericTable, Type: EAT modification 0x831A0808–>82E62CA9 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitializeGenericTableAvl, Type: EAT modification 0x831A080C–>8321F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitializeRangeList, Type: EAT modification 0x831A0810–>833EF070 [unknown_code_page] ntkrnlpa.exe–>RtlInitializeSid, Type: EAT modification 0x831A0814–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitializeUnicodePrefix, Type: EAT modification 0x831A0818–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitString, Type: EAT modification 0x831A07F4–>8353F06F [unknown_code_page] ntkrnlpa.exe–>RtlInitUnicodeString, Type: EAT modification 0x831A07F8–>834DF06B [unknown_code_page] ntkrnlpa.exe–>RtlInitUnicodeStringEx, Type: EAT modification 0x831A07FC–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInitWeakEnumerationHashTable, Type: EAT modification 0x831A0800–>8352F070 [unknown_code_page] ntkrnlpa.exe–>RtlInsertElementGenericTable, Type: EAT modification 0x831A081C–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlInsertElementGenericTableAvl, Type: EAT modification 0x831A0820–>B106973B [unknown_code_page] ntkrnlpa.exe–>RtlInsertElementGenericTableFull, Type: EAT modification 0x831A0824–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlInsertEntryHashTable, Type: EAT modification 0x831A082C–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlInsertUnicodePrefix, Type: EAT modification 0x831A0830–>B106973B [unknown_code_page] ntkrnlpa.exe–>RtlInt64ToUnicodeString, Type: EAT modification 0x831A0834–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIntegerToChar, Type: EAT modification 0x831A0838–>B106973B [unknown_code_page] ntkrnlpa.exe–>RtlIntegerToUnicode, Type: EAT modification 0x831A083C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIntegerToUnicodeString, Type: EAT modification 0x831A0840–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInvertRangeList, Type: EAT modification 0x831A0844–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlInvertRangeListEx, Type: EAT modification 0x831A0848–>82E4F919 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIoDecodeMemIoResource, Type: EAT modification 0x831A084C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIoEncodeMemIoResource, Type: EAT modification 0x831A0850–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv4AddressToStringA, Type: EAT modification 0x831A0854–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv4AddressToStringExA, Type: EAT modification 0x831A0858–>8348F30C [unknown_code_page] ntkrnlpa.exe–>RtlIpv4AddressToStringExW, Type: EAT modification 0x831A085C–>8358F061 [unknown_code_page] ntkrnlpa.exe–>RtlIpv4AddressToStringW, Type: EAT modification 0x831A0860–>8346F061 [unknown_code_page] ntkrnlpa.exe–>RtlIpv4StringToAddressA, Type: EAT modification 0x831A0864–>8357F061 [unknown_code_page] ntkrnlpa.exe–>RtlIpv4StringToAddressExA, Type: EAT modification 0x831A0868–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv4StringToAddressExW, Type: EAT modification 0x831A086C–>8352F070 [unknown_code_page] ntkrnlpa.exe–>RtlIpv4StringToAddressW, Type: EAT modification 0x831A0870–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv6AddressToStringA, Type: EAT modification 0x831A0874–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv6AddressToStringExA, Type: EAT modification 0x831A0878–>82E62CAC [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv6AddressToStringExW, Type: EAT modification 0x831A087C–>8330F000 [unknown_code_page] ntkrnlpa.exe–>RtlIpv6AddressToStringW, Type: EAT modification 0x831A0880–>8348F078 [unknown_code_page] ntkrnlpa.exe–>RtlIpv6StringToAddressA, Type: EAT modification 0x831A0884–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv6StringToAddressExA, Type: EAT modification 0x831A0888–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlIpv6StringToAddressExW, Type: EAT modification 0x831A088C–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlIpv6StringToAddressW, Type: EAT modification 0x831A0890–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlIsGenericTableEmpty, Type: EAT modification 0x831A0894–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIsNameLegalDOS8Dot3, Type: EAT modification 0x831A089C–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlIsNormalizedString, Type: EAT modification 0x831A08A0–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlIsNtDdiVersionAvailable, Type: EAT modification 0x831A08A4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIsRangeAvailable, Type: EAT modification 0x831A08A8–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlIsServicePackVersionInstalled, Type: EAT modification 0x831A08AC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlIsValidOemCharacter, Type: EAT modification 0x831A08B0–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLargeIntegerAdd, Type: EAT modification 0x831A08B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLargeIntegerArithmeticShift, Type: EAT modification 0x831A08B8–>82E500E5 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLargeIntegerDivide, Type: EAT modification 0x831A08BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLargeIntegerNegate, Type: EAT modification 0x831A08C0–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLargeIntegerShiftLeft, Type: EAT modification 0x831A08C4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLargeIntegerShiftRight, Type: EAT modification 0x831A08C8–>8348F111 [unknown_code_page] ntkrnlpa.exe–>RtlLargeIntegerSubtract, Type: EAT modification 0x831A08CC–>8358F061 [unknown_code_page] ntkrnlpa.exe–>RtlLengthRequiredSid, Type: EAT modification 0x831A08D0–>8346F061 [unknown_code_page] ntkrnlpa.exe–>RtlLengthSecurityDescriptor, Type: EAT modification 0x831A08D4–>8357F061 [unknown_code_page] ntkrnlpa.exe–>RtlLengthSid, Type: EAT modification 0x831A08D8–>8338F065 [unknown_code_page] ntkrnlpa.exe–>RtlLoadString, Type: EAT modification 0x831A08DC–>8346F061 [unknown_code_page] ntkrnlpa.exe–>RtlLocalTimeToSystemTime, Type: EAT modification 0x831A08E0–>8349F06C [unknown_code_page] ntkrnlpa.exe–>RtlLockBootStatusData, Type: EAT modification 0x831A08E4–>8354F02E [unknown_code_page] ntkrnlpa.exe–>RtlLookupAtomInAtomTable, Type: EAT modification 0x831A08E8–>834BF06E [unknown_code_page] ntkrnlpa.exe–>RtlLookupElementGenericTable, Type: EAT modification 0x831A08EC–>82E4F002 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLookupElementGenericTableAvl, Type: EAT modification 0x831A08F0–>82E62CAC [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLookupElementGenericTableFull, Type: EAT modification 0x831A08F4–>8330F000 [unknown_code_page] ntkrnlpa.exe–>RtlLookupElementGenericTableFullAvl, Type: EAT modification 0x831A08F8–>833EF070 [unknown_code_page] ntkrnlpa.exe–>RtlLookupEntryHashTable, Type: EAT modification 0x831A08FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlLookupFirstMatchingElementGenericTableAvl, Type: EAT modification 0x831A0900–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlMapGenericMask, Type: EAT modification 0x831A0904–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlMapSecurityErrorToNtStatus, Type: EAT modification 0x831A0908–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlMergeRangeLists, Type: EAT modification 0x831A090C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlMultiByteToUnicodeN, Type: EAT modification 0x831A0914–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlMultiByteToUnicodeSize, Type: EAT modification 0x831A0918–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlNextUnicodePrefix, Type: EAT modification 0x831A091C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlNormalizeString, Type: EAT modification 0x831A0920–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlNtStatusToDosError, Type: EAT modification 0x831A0924–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlNtStatusToDosErrorNoTeb, Type: EAT modification 0x831A0928–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlNumberGenericTableElements, Type: EAT modification 0x831A092C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlNumberGenericTableElementsAvl, Type: EAT modification 0x831A0930–>82E500E5 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlNumberOfClearBits, Type: EAT modification 0x831A0934–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlNumberOfSetBits, Type: EAT modification 0x831A0938–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlNumberOfSetBitsUlongPtr, Type: EAT modification 0x831A093C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlOemStringToCountedUnicodeString, Type: EAT modification 0x831A0940–>8328F20C [unknown_code_page] ntkrnlpa.exe–>RtlOemStringToUnicodeSize, Type: EAT modification 0x831A0944–>8338F041 [unknown_code_page] ntkrnlpa.exe–>RtlOemStringToUnicodeString, Type: EAT modification 0x831A0948–>8326F041 [unknown_code_page] ntkrnlpa.exe–>RtlOemToUnicodeN, Type: EAT modification 0x831A094C–>8362F041 [unknown_code_page] ntkrnlpa.exe–>RtlOwnerAcesPresent, Type: EAT modification 0x831A0950–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlPinAtomInAtomTable, Type: EAT modification 0x831A0954–>8332F050 [unknown_code_page] ntkrnlpa.exe–>RtlPrefetchMemoryNonTemporal, Type: EAT modification 0x8319F184–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlPrefixString, Type: EAT modification 0x831A0958–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlPrefixUnicodeString, Type: EAT modification 0x831A095C–>82E62CAE [ntkrnlpa.exe] ntkrnlpa.exe–>RtlQueryAtomInAtomTable, Type: EAT modification 0x831A0960–>830DF000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlQueryDynamicTimeZoneInformation, Type: EAT modification 0x831A0964–>834EF080 [unknown_code_page] ntkrnlpa.exe–>RtlQueryElevationFlags, Type: EAT modification 0x831A0968–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlQueryModuleInformation, Type: EAT modification 0x831A096C–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlQueryRegistryValues, Type: EAT modification 0x831A0970–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlQueryTimeZoneInformation, Type: EAT modification 0x831A0974–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlRaiseException, Type: EAT modification 0x831A0978–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlRandomEx, Type: EAT modification 0x831A0980–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlRealPredecessor, Type: EAT modification 0x831A0984–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlRealSuccessor, Type: EAT modification 0x831A0988–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlRemoveEntryHashTable, Type: EAT modification 0x831A098C–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlRemoveUnicodePrefix, Type: EAT modification 0x831A0990–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlReplaceSidInSd, Type: EAT modification 0x831A0994–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlReserveChunk, Type: EAT modification 0x831A0998–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlRunOnceBeginInitialize, Type: EAT modification 0x831A099C–>82E5005E [ntkrnlpa.exe] ntkrnlpa.exe–>RtlRunOnceComplete, Type: EAT modification 0x831A09A0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlRunOnceExecuteOnce, Type: EAT modification 0x831A09A4–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlRunOnceInitialize, Type: EAT modification 0x831A09A8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSecondsSince1970ToTime, Type: EAT modification 0x831A09AC–>8348F114 [unknown_code_page] ntkrnlpa.exe–>RtlSecondsSince1980ToTime, Type: EAT modification 0x831A09B0–>8346F065 [unknown_code_page] ntkrnlpa.exe–>RtlSelfRelativeToAbsoluteSD, Type: EAT modification 0x831A09B8–>834BF075 [unknown_code_page] ntkrnlpa.exe–>RtlSelfRelativeToAbsoluteSD2, Type: EAT modification 0x831A09B4–>8349F067 [unknown_code_page] ntkrnlpa.exe–>RtlSetAllBits, Type: EAT modification 0x831A09BC–>8327F072 [unknown_code_page] ntkrnlpa.exe–>RtlSetBit, Type: EAT modification 0x831A09C0–>8352F06F [unknown_code_page] ntkrnlpa.exe–>RtlSetBits, Type: EAT modification 0x831A09C4–>834DF074 [unknown_code_page] ntkrnlpa.exe–>RtlSetDaclSecurityDescriptor, Type: EAT modification 0x831A09C8–>8359F06E [unknown_code_page] ntkrnlpa.exe–>RtlSetDynamicTimeZoneInformation, Type: EAT modification 0x831A09CC–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSetGroupSecurityDescriptor, Type: EAT modification 0x831A09D0–>8352F070 [unknown_code_page] ntkrnlpa.exe–>RtlSetOwnerSecurityDescriptor, Type: EAT modification 0x831A09D4–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSetSaclSecurityDescriptor, Type: EAT modification 0x831A09D8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSetTimeZoneInformation, Type: EAT modification 0x831A09DC–>82E62CB5 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSidHashInitialize, Type: EAT modification 0x831A09E0–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSidHashLookup, Type: EAT modification 0x831A09E4–>8348F078 [unknown_code_page] ntkrnlpa.exe–>RtlSizeHeap, Type: EAT modification 0x831A09E8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlSplay, Type: EAT modification 0x831A09EC–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlStringFromGUID, Type: EAT modification 0x831A09F0–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlSubAuthorityCountSid, Type: EAT modification 0x831A09F4–>B106E55C [unknown_code_page] ntkrnlpa.exe–>RtlSubAuthoritySid, Type: EAT modification 0x831A09F8–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlSubtreeSuccessor, Type: EAT modification 0x831A0A00–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlSystemTimeToLocalTime, Type: EAT modification 0x831A0A04–>B106E55C [unknown_code_page] ntkrnlpa.exe–>RtlTestBit, Type: EAT modification 0x831A0A08–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlTimeFieldsToTime, Type: EAT modification 0x831A0A0C–>B106E55C [unknown_code_page] ntkrnlpa.exe–>RtlTimeToElapsedTimeFields, Type: EAT modification 0x831A0A10–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlTimeToSecondsSince1970, Type: EAT modification 0x831A0A14–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlTimeToSecondsSince1980, Type: EAT modification 0x831A0A18–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlTimeToTimeFields, Type: EAT modification 0x831A0A1C–>82E4FFF1 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlTraceDatabaseAdd, Type: EAT modification 0x831A0A20–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlTraceDatabaseCreate, Type: EAT modification 0x831A0A24–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlTraceDatabaseDestroy, Type: EAT modification 0x831A0A28–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlTraceDatabaseEnumerate, Type: EAT modification 0x831A0A2C–>8348F111 [unknown_code_page] ntkrnlpa.exe–>RtlTraceDatabaseFind, Type: EAT modification 0x831A0A30–>8346F065 [unknown_code_page] ntkrnlpa.exe–>RtlTraceDatabaseLock, Type: EAT modification 0x831A0A34–>834BF075 [unknown_code_page] ntkrnlpa.exe–>RtlTraceDatabaseUnlock, Type: EAT modification 0x831A0A38–>8349F067 [unknown_code_page] ntkrnlpa.exe–>RtlTraceDatabaseValidate, Type: EAT modification 0x831A0A3C–>8334F072 [unknown_code_page] ntkrnlpa.exe–>RtlUlongByteSwap, Type: EAT modification 0x8319F188–>8349F073 [unknown_code_page] ntkrnlpa.exe–>RtlUlonglongByteSwap, Type: EAT modification 0x8319F18C–>8354F02E [unknown_code_page] ntkrnlpa.exe–>RtlUnicodeStringToAnsiSize, Type: EAT modification 0x831A0A44–>834BF06E [unknown_code_page] ntkrnlpa.exe–>RtlUnicodeStringToAnsiString, Type: EAT modification 0x831A0A48–>8315F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUnicodeStringToCountedOemString, Type: EAT modification 0x831A0A4C–>82E62CAE [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUnicodeStringToInteger, Type: EAT modification 0x831A0A50–>830DF000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUnicodeStringToOemSize, Type: EAT modification 0x831A0A54–>833EF070 [unknown_code_page] ntkrnlpa.exe–>RtlUnicodeStringToOemString, Type: EAT modification 0x831A0A58–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUnicodeToCustomCPN, Type: EAT modification 0x831A0A5C–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUnicodeToMultiByteN, Type: EAT modification 0x831A0A60–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlUnicodeToMultiByteSize, Type: EAT modification 0x831A0A64–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlUnicodeToOemN, Type: EAT modification 0x831A0A68–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlUnlockBootStatusData, Type: EAT modification 0x831A0A70–>84B02037 [unknown_code_page] ntkrnlpa.exe–>RtlUnwind, Type: EAT modification 0x831A0A74–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>RtlUpcaseUnicodeChar, Type: EAT modification 0x831A0A78–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlUpcaseUnicodeString, Type: EAT modification 0x831A0A7C–>B8F99E55 [unknown_code_page] ntkrnlpa.exe–>RtlUpcaseUnicodeStringToCountedOemString, Type: EAT modification 0x831A0A84–>82E4F230 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUpcaseUnicodeStringToOemString, Type: EAT modification 0x831A0A88–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUpcaseUnicodeToCustomCPN, Type: EAT modification 0x831A0A8C–>82E5005E [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUpcaseUnicodeToMultiByteN, Type: EAT modification 0x831A0A90–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUpcaseUnicodeToOemN, Type: EAT modification 0x831A0A94–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUpperChar, Type: EAT modification 0x831A0A98–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlUpperString, Type: EAT modification 0x831A0A9C–>8328F20C [unknown_code_page] ntkrnlpa.exe–>RtlUshortByteSwap, Type: EAT modification 0x8319F190–>8326F045 [unknown_code_page] ntkrnlpa.exe–>RtlUTF8ToUnicodeN, Type: EAT modification 0x831A0A40–>8359F061 [unknown_code_page] ntkrnlpa.exe–>RtlValidateUnicodeString, Type: EAT modification 0x831A0AAC–>8332F050 [unknown_code_page] ntkrnlpa.exe–>RtlValidRelativeSecurityDescriptor, Type: EAT modification 0x831A0AA0–>832BF055 [unknown_code_page] ntkrnlpa.exe–>RtlValidSecurityDescriptor, Type: EAT modification 0x831A0AA4–>8362F047 [unknown_code_page] ntkrnlpa.exe–>RtlValidSid, Type: EAT modification 0x831A0AA8–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlVerifyVersionInfo, Type: EAT modification 0x831A0AB0–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlVolumeDeviceToDosName, Type: EAT modification 0x831A0AB4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlWalkFrameChain, Type: EAT modification 0x831A0AB8–>82E62CB5 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlWeaklyEnumerateEntryHashTable, Type: EAT modification 0x831A0ABC–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlWriteRegistryValue, Type: EAT modification 0x831A0AC0–>833EF070 [unknown_code_page] ntkrnlpa.exe–>RtlxAnsiStringToUnicodeSize, Type: EAT modification 0x831A0ACC–>8326F000 [unknown_code_page] ntkrnlpa.exe–>RtlxOemStringToUnicodeSize, Type: EAT modification 0x831A0AD0–>B106E55C [unknown_code_page] ntkrnlpa.exe–>RtlxUnicodeStringToAnsiSize, Type: EAT modification 0x831A0AD4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>RtlZeroHeap, Type: EAT modification 0x831A0AC4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>RtlZeroMemory, Type: EAT modification 0x831A0AC8–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAccessCheck, Type: EAT modification 0x831A0ADC–>84B02037 [unknown_code_page] ntkrnlpa.exe–>SeAccessCheckEx, Type: EAT modification 0x831A0AE0–>B106E55C [unknown_code_page] ntkrnlpa.exe–>SeAccessCheckFromState, Type: EAT modification 0x831A0AE4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>SeAccessCheckWithHint, Type: EAT modification 0x831A0AE8–>B106E55C [unknown_code_page] ntkrnlpa.exe–>SeAppendPrivileges, Type: EAT modification 0x831A0AEC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>SeAssignSecurity, Type: EAT modification 0x831A0AF0–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAssignSecurityEx, Type: EAT modification 0x831A0AF4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAuditHardLinkCreation, Type: EAT modification 0x831A0AF8–>82E4FFF1 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAuditHardLinkCreationWithTransaction, Type: EAT modification 0x831A0AFC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAuditingAnyFileEventsWithContext, Type: EAT modification 0x831A0B04–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAuditingFileEvents, Type: EAT modification 0x831A0B08–>8328F20C [unknown_code_page] ntkrnlpa.exe–>SeAuditingFileEventsWithContext, Type: EAT modification 0x831A0B0C–>8326F045 [unknown_code_page] ntkrnlpa.exe–>SeAuditingFileOrGlobalEvents, Type: EAT modification 0x831A0B10–>832BF055 [unknown_code_page] ntkrnlpa.exe–>SeAuditingHardLinkEvents, Type: EAT modification 0x831A0B14–>8362F047 [unknown_code_page] ntkrnlpa.exe–>SeAuditingHardLinkEventsWithContext, Type: EAT modification 0x831A0B18–>8312F032 [ntkrnlpa.exe] ntkrnlpa.exe–>SeAuditingWithTokenForSubcategory, Type: EAT modification 0x8319F194–>8332F050 [unknown_code_page] ntkrnlpa.exe–>SeAuditTransactionStateChange, Type: EAT modification 0x831A0B00–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>SeCaptureSecurityDescriptor, Type: EAT modification 0x831A0B1C–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>SeCaptureSubjectContext, Type: EAT modification 0x831A0B20–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeCaptureSubjectContextEx, Type: EAT modification 0x831A0B24–>82E62C5D [ntkrnlpa.exe] ntkrnlpa.exe–>SeCloseObjectAuditAlarm, Type: EAT modification 0x831A0B28–>8315F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeCloseObjectAuditAlarmForNonObObject, Type: EAT modification 0x831A0B2C–>833CF068 [unknown_code_page] ntkrnlpa.exe–>SeComputeAutoInheritByObjectType, Type: EAT modification 0x831A0B30–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeCreateAccessState, Type: EAT modification 0x831A0B34–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>SeCreateAccessStateEx, Type: EAT modification 0x831A0B38–>8326F000 [unknown_code_page] ntkrnlpa.exe–>SeCreateClientSecurity, Type: EAT modification 0x831A0B3C–>B0FC0FC3 [unknown_code_page] ntkrnlpa.exe–>SeCreateClientSecurityFromSubjectContext, Type: EAT modification 0x831A0B40–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>SeDeleteAccessState, Type: EAT modification 0x831A0B48–>84B02037 [unknown_code_page] ntkrnlpa.exe–>SeDeleteObjectAuditAlarm, Type: EAT modification 0x831A0B4C–>B0FC0FC3 [unknown_code_page] ntkrnlpa.exe–>SeDeleteObjectAuditAlarmWithTransaction, Type: EAT modification 0x831A0B50–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>SeExamineSacl, Type: EAT modification 0x831A0B54–>B0FC0FC3 [unknown_code_page] ntkrnlpa.exe–>SeExports, Type: EAT modification 0x831A0B58–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>SeFilterToken, Type: EAT modification 0x831A0B5C–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeFreePrivileges, Type: EAT modification 0x831A0B60–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeGetLinkedToken, Type: EAT modification 0x831A0B64–>82E4F694 [ntkrnlpa.exe] ntkrnlpa.exe–>SeImpersonateClient, Type: EAT modification 0x831A0B68–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeImpersonateClientEx, Type: EAT modification 0x831A0B6C–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>SeLocateProcessImageName, Type: EAT modification 0x831A0B70–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeLockSubjectContext, Type: EAT modification 0x831A0B74–>8357F30B [unknown_code_page] ntkrnlpa.exe–>SeMarkLogonSessionForTerminationNotification, Type: EAT modification 0x831A0B78–>834DF070 [unknown_code_page] ntkrnlpa.exe–>SeOpenObjectAuditAlarm, Type: EAT modification 0x831A0B7C–>8352F06E [unknown_code_page] ntkrnlpa.exe–>SeOpenObjectAuditAlarmForNonObObject, Type: EAT modification 0x831A0B80–>8356F065 [unknown_code_page] ntkrnlpa.exe–>SeOpenObjectAuditAlarmWithTransaction, Type: EAT modification 0x831A0B84–>834BF02E [unknown_code_page] ntkrnlpa.exe–>SeOpenObjectForDeleteAuditAlarm, Type: EAT modification 0x831A0B88–>834AF069 [unknown_code_page] ntkrnlpa.exe–>SeOpenObjectForDeleteAuditAlarmWithTransaction, Type: EAT modification 0x831A0B8C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SePrivilegeCheck, Type: EAT modification 0x831A0B90–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SePrivilegeObjectAuditAlarm, Type: EAT modification 0x831A0B94–>82E4F010 [ntkrnlpa.exe] ntkrnlpa.exe–>SePublicDefaultDacl, Type: EAT modification 0x831A0B98–>82E4F002 [ntkrnlpa.exe] ntkrnlpa.exe–>SeQueryAuthenticationIdToken, Type: EAT modification 0x831A0B9C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeQueryInformationToken, Type: EAT modification 0x831A0BA0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeQuerySecurityAttributesToken, Type: EAT modification 0x831A0BA4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeQuerySecurityDescriptorInfo, Type: EAT modification 0x831A0BA8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeQuerySessionIdToken, Type: EAT modification 0x831A0BAC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeRegisterLogonSessionTerminatedRoutine, Type: EAT modification 0x831A0BB0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeReleaseSecurityDescriptor, Type: EAT modification 0x831A0BB4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeReleaseSubjectContext, Type: EAT modification 0x831A0BB8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeReportSecurityEvent, Type: EAT modification 0x831A0BBC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeReportSecurityEventWithSubCategory, Type: EAT modification 0x831A0BC0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSetAccessStateGenericMapping, Type: EAT modification 0x831A0BC4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSetAuditParameter, Type: EAT modification 0x831A0BC8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSetSecurityAttributesToken, Type: EAT modification 0x831A0BCC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSetSecurityDescriptorInfo, Type: EAT modification 0x831A0BD0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSetSecurityDescriptorInfoEx, Type: EAT modification 0x831A0BD4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSinglePrivilegeCheck, Type: EAT modification 0x831A0BD8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeSrpAccessCheck, Type: EAT modification 0x831A0BDC–>DB293E49 [unknown_code_page] ntkrnlpa.exe–>SeSystemDefaultDacl, Type: EAT modification 0x831A0BE0–>82EDF028 [ntkrnlpa.exe] ntkrnlpa.exe–>SeTokenIsAdmin, Type: EAT modification 0x831A0BE8–>82E4F007 [ntkrnlpa.exe] ntkrnlpa.exe–>SeTokenIsRestricted, Type: EAT modification 0x831A0BEC–>82E4F001 [ntkrnlpa.exe] ntkrnlpa.exe–>SeTokenIsWriteRestricted, Type: EAT modification 0x831A0BF0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeTokenObjectType, Type: EAT modification 0x831A0BF4–>82E4F028 [ntkrnlpa.exe] ntkrnlpa.exe–>SeTokenType, Type: EAT modification 0x831A0BF8–>82E4F800 [ntkrnlpa.exe] ntkrnlpa.exe–>SeUnlockSubjectContext, Type: EAT modification 0x831A0BFC–>82E4FFE8 [ntkrnlpa.exe] ntkrnlpa.exe–>SeUnregisterLogonSessionTerminatedRoutine, Type: EAT modification 0x831A0C00–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>SeValidSecurityDescriptor, Type: EAT modification 0x831A0C04–>82E6F002 [ntkrnlpa.exe] ntkrnlpa.exe–>sprintf, Type: EAT modification 0x831A1174–>830DF000 [ntkrnlpa.exe] ntkrnlpa.exe–>sprintf_s, Type: EAT modification 0x831A1178–>834EF080 [unknown_code_page] ntkrnlpa.exe–>srand, Type: EAT modification 0x831A117C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>sscanf_s, Type: EAT modification 0x831A1180–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>strcat, Type: EAT modification 0x831A1184–>8326F000 [unknown_code_page] ntkrnlpa.exe–>strcat_s, Type: EAT modification 0x831A1188–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>strchr, Type: EAT modification 0x831A118C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>strcpy, Type: EAT modification 0x831A1194–>84B02037 [unknown_code_page] ntkrnlpa.exe–>strcpy_s, Type: EAT modification 0x831A1198–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>strlen, Type: EAT modification 0x831A119C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>strncat, Type: EAT modification 0x831A11A0–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>strncat_s, Type: EAT modification 0x831A11A4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>strncmp, Type: EAT modification 0x831A11A8–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>strncpy, Type: EAT modification 0x831A11AC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>strncpy_s, Type: EAT modification 0x831A11B0–>82E5005E [ntkrnlpa.exe] ntkrnlpa.exe–>strnlen, Type: EAT modification 0x831A11B4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>strrchr, Type: EAT modification 0x831A11B8–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>strspn, Type: EAT modification 0x831A11BC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>strstr, Type: EAT modification 0x831A11C0–>8348F114 [unknown_code_page] ntkrnlpa.exe–>strtok_s, Type: EAT modification 0x831A11C4–>8346F065 [unknown_code_page] ntkrnlpa.exe–>swprintf, Type: EAT modification 0x831A11C8–>834BF075 [unknown_code_page] ntkrnlpa.exe–>swprintf_s, Type: EAT modification 0x831A11CC–>8349F067 [unknown_code_page] ntkrnlpa.exe–>swscanf_s, Type: EAT modification 0x831A11D0–>8327F072 [unknown_code_page] ntkrnlpa.exe–>TmCancelPropagationRequest, Type: EAT modification 0x831A0C08–>82E6F002 [ntkrnlpa.exe] ntkrnlpa.exe–>TmCommitComplete, Type: EAT modification 0x831A0C0C–>82E6F002 [ntkrnlpa.exe] ntkrnlpa.exe–>TmCommitEnlistment, Type: EAT modification 0x831A0C10–>82E6F002 [ntkrnlpa.exe] ntkrnlpa.exe–>TmCommitTransaction, Type: EAT modification 0x831A0C14–>82E4F002 [ntkrnlpa.exe] ntkrnlpa.exe–>TmCreateEnlistment, Type: EAT modification 0x831A0C18–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>TmCurrentTransaction, Type: EAT modification 0x831A0C1C–>82E62C9D [ntkrnlpa.exe] ntkrnlpa.exe–>TmDereferenceEnlistmentKey, Type: EAT modification 0x831A0C20–>8434F000 [unknown_code_page] ntkrnlpa.exe–>TmEnableCallbacks, Type: EAT modification 0x831A0C24–>833EF070 [unknown_code_page] ntkrnlpa.exe–>TmEndPropagationRequest, Type: EAT modification 0x831A0C28–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>TmEnlistmentObjectType, Type: EAT modification 0x831A0C2C–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>TmFreezeTransactions, Type: EAT modification 0x831A0C30–>8326F000 [unknown_code_page] ntkrnlpa.exe–>TmGetTransactionId, Type: EAT modification 0x831A0C34–>B105FAF9 [unknown_code_page] ntkrnlpa.exe–>TmInitializeResourceManager, Type: EAT modification 0x831A0C40–>84B02037 [unknown_code_page] ntkrnlpa.exe–>TmInitializeTransaction, Type: EAT modification 0x831A0C44–>B1062209 [unknown_code_page] ntkrnlpa.exe–>TmInitSystem, Type: EAT modification 0x831A0C38–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>TmIsTransactionActive, Type: EAT modification 0x831A0C48–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>TmpIsKTMCommitCoordinator, Type: EAT modification 0x831A0C9C–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>TmPrepareComplete, Type: EAT modification 0x831A0C54–>82E4F190 [ntkrnlpa.exe] ntkrnlpa.exe–>TmPrepareEnlistment, Type: EAT modification 0x831A0C58–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>TmPrePrepareComplete, Type: EAT modification 0x831A0C4C–>B105FAF9 [unknown_code_page] ntkrnlpa.exe–>TmPrePrepareEnlistment, Type: EAT modification 0x831A0C50–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>TmPropagationComplete, Type: EAT modification 0x831A0C5C–>82E4F18C [ntkrnlpa.exe] ntkrnlpa.exe–>TmPropagationFailed, Type: EAT modification 0x831A0C60–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>TmReadOnlyEnlistment, Type: EAT modification 0x831A0C64–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>TmRecoverEnlistment, Type: EAT modification 0x831A0C68–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>TmRecoverResourceManager, Type: EAT modification 0x831A0C6C–>8327F20C [unknown_code_page] ntkrnlpa.exe–>TmRecoverTransactionManager, Type: EAT modification 0x831A0C70–>8329F04C [unknown_code_page] ntkrnlpa.exe–>TmReferenceEnlistmentKey, Type: EAT modification 0x831A0C74–>8336F041 [unknown_code_page] ntkrnlpa.exe–>TmRequestOutcomeEnlistment, Type: EAT modification 0x831A0C78–>8362F043 [unknown_code_page] ntkrnlpa.exe–>TmResourceManagerObjectType, Type: EAT modification 0x831A0C7C–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>TmRollbackComplete, Type: EAT modification 0x831A0C80–>8332F050 [unknown_code_page] ntkrnlpa.exe–>TmRollbackEnlistment, Type: EAT modification 0x831A0C84–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>TmRollbackTransaction, Type: EAT modification 0x831A0C88–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>TmSetCurrentTransaction, Type: EAT modification 0x831A0C8C–>82E62C9F [ntkrnlpa.exe] ntkrnlpa.exe–>TmThawTransactions, Type: EAT modification 0x831A0C90–>8327F000 [unknown_code_page] ntkrnlpa.exe–>TmTransactionManagerObjectType, Type: EAT modification 0x831A0C94–>8346F078 [unknown_code_page] ntkrnlpa.exe–>TmTransactionObjectType, Type: EAT modification 0x831A0C98–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>tolower, Type: EAT modification 0x831A11D4–>8352F06F [unknown_code_page] ntkrnlpa.exe–>toupper, Type: EAT modification 0x831A11D8–>834DF074 [unknown_code_page] ntkrnlpa.exe–>towlower, Type: EAT modification 0x831A11DC–>8359F06E [unknown_code_page] ntkrnlpa.exe–>towupper, Type: EAT modification 0x831A11E0–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>vDbgPrintEx, Type: EAT modification 0x831A11E4–>8352F070 [unknown_code_page] ntkrnlpa.exe–>vDbgPrintExWithPrefix, Type: EAT modification 0x831A11E8–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>VerSetConditionMask, Type: EAT modification 0x831A0CA0–>8326F000 [unknown_code_page] ntkrnlpa.exe–>VfFailDeviceNode, Type: EAT modification 0x831A0CA4–>B1062209 [unknown_code_page] ntkrnlpa.exe–>VfFailDriver, Type: EAT modification 0x831A0CA8–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>VfIsVerificationEnabled, Type: EAT modification 0x831A0CB0–>84B02037 [unknown_code_page] ntkrnlpa.exe–>vsprintf, Type: EAT modification 0x831A11EC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>vsprintf_s, Type: EAT modification 0x831A11F0–>82E62CB5 [ntkrnlpa.exe] ntkrnlpa.exe–>vswprintf_s, Type: EAT modification 0x831A11F4–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>wcscat, Type: EAT modification 0x831A11F8–>8348F078 [unknown_code_page] ntkrnlpa.exe–>wcscat_s, Type: EAT modification 0x831A11FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>wcschr, Type: EAT modification 0x831A1200–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>wcscmp, Type: EAT modification 0x831A1204–>8326F000 [unknown_code_page] ntkrnlpa.exe–>wcscpy, Type: EAT modification 0x831A1208–>B106E55C [unknown_code_page] ntkrnlpa.exe–>wcscpy_s, Type: EAT modification 0x831A120C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>wcslen, Type: EAT modification 0x831A1214–>84B02037 [unknown_code_page] ntkrnlpa.exe–>wcsncat, Type: EAT modification 0x831A1218–>B106E55C [unknown_code_page] ntkrnlpa.exe–>wcsncat_s, Type: EAT modification 0x831A121C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>wcsncmp, Type: EAT modification 0x831A1220–>B106E55C [unknown_code_page] ntkrnlpa.exe–>wcsncpy, Type: EAT modification 0x831A1224–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>wcsncpy_s, Type: EAT modification 0x831A1228–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>wcsnlen, Type: EAT modification 0x831A122C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>wcsrchr, Type: EAT modification 0x831A1230–>82E4FFF1 [ntkrnlpa.exe] ntkrnlpa.exe–>wcsspn, Type: EAT modification 0x831A1234–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>wcsstr, Type: EAT modification 0x831A1238–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>wcstombs, Type: EAT modification 0x831A123C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>wcstoul, Type: EAT modification 0x831A1240–>8348F111 [unknown_code_page] ntkrnlpa.exe–>wctomb, Type: EAT modification 0x831A1244–>8346F065 [unknown_code_page] ntkrnlpa.exe–>WheaAddErrorSource, Type: EAT modification 0x831A0CCC–>82E50103 [ntkrnlpa.exe] ntkrnlpa.exe–>WheaConfigureErrorSource, Type: EAT modification 0x831A0CD0–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>WheaGetErrorSource, Type: EAT modification 0x831A0CD4–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>WheaInitializeRecordHeader, Type: EAT modification 0x831A0CD8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>WheaReportHwError, Type: EAT modification 0x831A0CDC–>8347F110 [unknown_code_page] ntkrnlpa.exe–>WmiGetClock, Type: EAT modification 0x8319F198–>8353F06C [unknown_code_page] ntkrnlpa.exe–>WmiQueryTraceInformation, Type: EAT modification 0x831A0CE0–>8349F073 [unknown_code_page] ntkrnlpa.exe–>WmiTraceMessage, Type: EAT modification 0x831A0CE4–>8359F042 [unknown_code_page] ntkrnlpa.exe–>WmiTraceMessageVa, Type: EAT modification 0x831A0CE8–>8358F074 [unknown_code_page] ntkrnlpa.exe–>WRITE_REGISTER_BUFFER_UCHAR, Type: EAT modification 0x831A0CB4–>B1062209 [unknown_code_page] ntkrnlpa.exe–>WRITE_REGISTER_BUFFER_ULONG, Type: EAT modification 0x831A0CB8–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>WRITE_REGISTER_BUFFER_USHORT, Type: EAT modification 0x831A0CBC–>B1062209 [unknown_code_page] ntkrnlpa.exe–>WRITE_REGISTER_UCHAR, Type: EAT modification 0x831A0CC0–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>WRITE_REGISTER_ULONG, Type: EAT modification 0x831A0CC4–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>WRITE_REGISTER_USHORT, Type: EAT modification 0x831A0CC8–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>XIPDispatch, Type: EAT modification 0x831A0CEC–>8352F06F [unknown_code_page] ntkrnlpa.exe–>ZwAccessCheckAndAuditAlarm, Type: EAT modification 0x831A0CF0–>8312F073 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAddBootEntry, Type: EAT modification 0x831A0CF4–>8352F070 [unknown_code_page] ntkrnlpa.exe–>ZwAddDriverEntry, Type: EAT modification 0x831A0CF8–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAdjustPrivilegesToken, Type: EAT modification 0x831A0CFC–>82E4F002 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlertThread, Type: EAT modification 0x831A0D00–>82E62C9F [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAllocateLocallyUniqueId, Type: EAT modification 0x831A0D04–>8327F000 [unknown_code_page] ntkrnlpa.exe–>ZwAllocateVirtualMemory, Type: EAT modification 0x831A0D08–>833EF070 [unknown_code_page] ntkrnlpa.exe–>ZwAlpcAcceptConnectPort, Type: EAT modification 0x831A0D0C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlpcCancelMessage, Type: EAT modification 0x831A0D10–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlpcConnectPort, Type: EAT modification 0x831A0D14–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwAlpcCreatePort, Type: EAT modification 0x831A0D18–>B1062209 [unknown_code_page] ntkrnlpa.exe–>ZwAlpcCreatePortSection, Type: EAT modification 0x831A0D1C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwAlpcCreateSectionView, Type: EAT modification 0x831A0D24–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwAlpcCreateSecurityContext, Type: EAT modification 0x831A0D28–>B1062209 [unknown_code_page] ntkrnlpa.exe–>ZwAlpcDeletePortSection, Type: EAT modification 0x831A0D2C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwAlpcDeleteResourceReserve, Type: EAT modification 0x831A0D30–>B1062209 [unknown_code_page] ntkrnlpa.exe–>ZwAlpcDeleteSectionView, Type: EAT modification 0x831A0D34–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwAlpcDeleteSecurityContext, Type: EAT modification 0x831A0D38–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlpcDisconnectPort, Type: EAT modification 0x831A0D3C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlpcQueryInformation, Type: EAT modification 0x831A0D40–>82E50103 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlpcSendWaitReceivePort, Type: EAT modification 0x831A0D44–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAlpcSetInformation, Type: EAT modification 0x831A0D48–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwAssignProcessToJobObject, Type: EAT modification 0x831A0D4C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCancelIoFile, Type: EAT modification 0x831A0D50–>8327F20C [unknown_code_page] ntkrnlpa.exe–>ZwCancelTimer, Type: EAT modification 0x831A0D54–>8333F04C [unknown_code_page] ntkrnlpa.exe–>ZwClearEvent, Type: EAT modification 0x831A0D58–>B8F99DA8 [unknown_code_page] ntkrnlpa.exe–>ZwCloseObjectAuditAlarm, Type: EAT modification 0x831A0D60–>8312F28D [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCommitComplete, Type: EAT modification 0x831A0D64–>8332F050 [unknown_code_page] ntkrnlpa.exe–>ZwCommitEnlistment, Type: EAT modification 0x831A0D68–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCommitTransaction, Type: EAT modification 0x831A0D6C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwConnectPort, Type: EAT modification 0x831A0D70–>82E62CA0 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCreateDirectoryObject, Type: EAT modification 0x831A0D74–>8304F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCreateEnlistment, Type: EAT modification 0x831A0D78–>8352F080 [unknown_code_page] ntkrnlpa.exe–>ZwCreateEvent, Type: EAT modification 0x831A0D7C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCreateFile, Type: EAT modification 0x831A0D80–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwCreateIoCompletion, Type: EAT modification 0x831A0D84–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwCreateJobObject, Type: EAT modification 0x831A0D88–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwCreateKey, Type: EAT modification 0x831A0D8C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwCreateResourceManager, Type: EAT modification 0x831A0D94–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwCreateSection, Type: EAT modification 0x831A0D98–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwCreateSymbolicLinkObject, Type: EAT modification 0x831A0D9C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwCreateTimer, Type: EAT modification 0x831A0DA0–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwCreateTransaction, Type: EAT modification 0x831A0DA4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwCreateTransactionManager, Type: EAT modification 0x831A0DA8–>82E4F0B8 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwDeleteBootEntry, Type: EAT modification 0x831A0DAC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwDeleteDriverEntry, Type: EAT modification 0x831A0DB0–>82E4F0B7 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwDeleteFile, Type: EAT modification 0x831A0DB4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwDeleteKey, Type: EAT modification 0x831A0DB8–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwDeleteValueKey, Type: EAT modification 0x831A0DBC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwDeviceIoControlFile, Type: EAT modification 0x831A0DC0–>8347F116 [unknown_code_page] ntkrnlpa.exe–>ZwDisplayString, Type: EAT modification 0x831A0DC4–>8352F06F [unknown_code_page] ntkrnlpa.exe–>ZwDuplicateObject, Type: EAT modification 0x831A0DC8–>8353F073 [unknown_code_page] ntkrnlpa.exe–>ZwDuplicateToken, Type: EAT modification 0x831A0DCC–>8349F06C [unknown_code_page] ntkrnlpa.exe–>ZwEnumerateBootEntries, Type: EAT modification 0x831A0DD0–>8359F042 [unknown_code_page] ntkrnlpa.exe–>ZwEnumerateDriverEntries, Type: EAT modification 0x831A0DD4–>8358F074 [unknown_code_page] ntkrnlpa.exe–>ZwEnumerateKey, Type: EAT modification 0x831A0DD8–>8352F06F [unknown_code_page] ntkrnlpa.exe–>ZwEnumerateTransactionObject, Type: EAT modification 0x831A0DDC–>8350F047 [unknown_code_page] ntkrnlpa.exe–>ZwEnumerateValueKey, Type: EAT modification 0x831A0DE0–>8354F079 [unknown_code_page] ntkrnlpa.exe–>ZwFlushBuffersFile, Type: EAT modification 0x831A0DE4–>8312F068 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwFlushInstructionCache, Type: EAT modification 0x831A0DE8–>8352F070 [unknown_code_page] ntkrnlpa.exe–>ZwFlushKey, Type: EAT modification 0x831A0DEC–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwFlushVirtualMemory, Type: EAT modification 0x831A0DF0–>82E62CA5 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwFreeVirtualMemory, Type: EAT modification 0x831A0DF4–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwFsControlFile, Type: EAT modification 0x831A0DF8–>8344F070 [unknown_code_page] ntkrnlpa.exe–>ZwGetNotificationResourceManager, Type: EAT modification 0x831A0DFC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwImpersonateAnonymousToken, Type: EAT modification 0x831A0E00–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwInitiatePowerAction, Type: EAT modification 0x831A0E04–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwIsProcessInJob, Type: EAT modification 0x831A0E08–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwLoadDriver, Type: EAT modification 0x831A0E0C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwLoadKeyEx, Type: EAT modification 0x831A0E14–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwLockFile, Type: EAT modification 0x831A0E18–>B106702A [unknown_code_page] ntkrnlpa.exe–>ZwLockProductActivationKeys, Type: EAT modification 0x831A0E1C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwMakeTemporaryObject, Type: EAT modification 0x831A0E20–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwMapViewOfSection, Type: EAT modification 0x831A0E24–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwModifyBootEntry, Type: EAT modification 0x831A0E28–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwModifyDriverEntry, Type: EAT modification 0x831A0E2C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwNotifyChangeKey, Type: EAT modification 0x831A0E30–>82E4FB72 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwNotifyChangeSession, Type: EAT modification 0x831A0E34–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenDirectoryObject, Type: EAT modification 0x831A0E38–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenEnlistment, Type: EAT modification 0x831A0E3C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenEvent, Type: EAT modification 0x831A0E40–>8347F10F [unknown_code_page] ntkrnlpa.exe–>ZwOpenFile, Type: EAT modification 0x831A0E44–>8352F06F [unknown_code_page] ntkrnlpa.exe–>ZwOpenJobObject, Type: EAT modification 0x831A0E48–>8353F073 [unknown_code_page] ntkrnlpa.exe–>ZwOpenKey, Type: EAT modification 0x831A0E4C–>8349F06C [unknown_code_page] ntkrnlpa.exe–>ZwOpenKeyEx, Type: EAT modification 0x831A0E50–>8347F049 [unknown_code_page] ntkrnlpa.exe–>ZwOpenKeyTransacted, Type: EAT modification 0x831A0E54–>8352F06F [unknown_code_page] ntkrnlpa.exe–>ZwOpenKeyTransactedEx, Type: EAT modification 0x831A0E58–>8354F02E [unknown_code_page] ntkrnlpa.exe–>ZwOpenProcess, Type: EAT modification 0x831A0E5C–>834BF06E [unknown_code_page] ntkrnlpa.exe–>ZwOpenProcessToken, Type: EAT modification 0x831A0E60–>82E62CA0 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenProcessTokenEx, Type: EAT modification 0x831A0E64–>8304F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenResourceManager, Type: EAT modification 0x831A0E68–>833EF070 [unknown_code_page] ntkrnlpa.exe–>ZwOpenSection, Type: EAT modification 0x831A0E6C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenSession, Type: EAT modification 0x831A0E70–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwOpenSymbolicLinkObject, Type: EAT modification 0x831A0E74–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwOpenThread, Type: EAT modification 0x831A0E78–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwOpenThreadToken, Type: EAT modification 0x831A0E7C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwOpenTimer, Type: EAT modification 0x831A0E84–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwOpenTransaction, Type: EAT modification 0x831A0E88–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwOpenTransactionManager, Type: EAT modification 0x831A0E8C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwPowerInformation, Type: EAT modification 0x831A0E90–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwPrepareComplete, Type: EAT modification 0x831A0E9C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwPrepareEnlistment, Type: EAT modification 0x831A0EA0–>82E4F0B7 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwPrePrepareComplete, Type: EAT modification 0x831A0E94–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwPrePrepareEnlistment, Type: EAT modification 0x831A0E98–>82E4F0B8 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwPropagationComplete, Type: EAT modification 0x831A0EA4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwPropagationFailed, Type: EAT modification 0x831A0EA8–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwPulseEvent, Type: EAT modification 0x831A0EAC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryBootEntryOrder, Type: EAT modification 0x831A0EB0–>8327F20C [unknown_code_page] ntkrnlpa.exe–>ZwQueryBootOptions, Type: EAT modification 0x831A0EB4–>8332F04F [unknown_code_page] ntkrnlpa.exe–>ZwQueryDefaultLocale, Type: EAT modification 0x831A0EB8–>8333F053 [unknown_code_page] ntkrnlpa.exe–>ZwQueryDefaultUILanguage, Type: EAT modification 0x831A0EBC–>8362F04C [unknown_code_page] ntkrnlpa.exe–>ZwQueryDirectoryFile, Type: EAT modification 0x831A0EC0–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryDirectoryObject, Type: EAT modification 0x831A0EC4–>8332F050 [unknown_code_page] ntkrnlpa.exe–>ZwQueryDriverEntryOrder, Type: EAT modification 0x831A0EC8–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryEaFile, Type: EAT modification 0x831A0ECC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryFullAttributesFile, Type: EAT modification 0x831A0ED0–>82E62CA5 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryInformationEnlistment, Type: EAT modification 0x831A0ED4–>82F7F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryInformationFile, Type: EAT modification 0x831A0ED8–>833EF070 [unknown_code_page] ntkrnlpa.exe–>ZwQueryInformationJobObject, Type: EAT modification 0x831A0EDC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryInformationProcess, Type: EAT modification 0x831A0EE0–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryInformationResourceManager, Type: EAT modification 0x831A0EE4–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwQueryInformationThread, Type: EAT modification 0x831A0EE8–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwQueryInformationToken, Type: EAT modification 0x831A0EEC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwQueryInformationTransactionManager, Type: EAT modification 0x831A0EF4–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwQueryInstallUILanguage, Type: EAT modification 0x831A0EF8–>B106702A [unknown_code_page] ntkrnlpa.exe–>ZwQueryKey, Type: EAT modification 0x831A0EFC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwQueryLicenseValue, Type: EAT modification 0x831A0F00–>B106491A [unknown_code_page] ntkrnlpa.exe–>ZwQueryObject, Type: EAT modification 0x831A0F04–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwQueryQuotaInformationFile, Type: EAT modification 0x831A0F08–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQuerySection, Type: EAT modification 0x831A0F0C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQuerySecurityAttributesToken, Type: EAT modification 0x831A0F10–>82E4FB72 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQuerySecurityObject, Type: EAT modification 0x831A0F14–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQuerySymbolicLinkObject, Type: EAT modification 0x831A0F18–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQuerySystemInformation, Type: EAT modification 0x831A0F1C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwQueryValueKey, Type: EAT modification 0x831A0F20–>8327F20C [unknown_code_page] ntkrnlpa.exe–>ZwQueryVirtualMemory, Type: EAT modification 0x831A0F24–>8332F04F [unknown_code_page] ntkrnlpa.exe–>ZwQueryVolumeInformationFile, Type: EAT modification 0x831A0F28–>8333F053 [unknown_code_page] ntkrnlpa.exe–>ZwReadFile, Type: EAT modification 0x831A0F2C–>8362F04C [unknown_code_page] ntkrnlpa.exe–>ZwReadOnlyEnlistment, Type: EAT modification 0x831A0F30–>8312F032 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwRecoverEnlistment, Type: EAT modification 0x831A0F34–>8332F050 [unknown_code_page] ntkrnlpa.exe–>ZwRecoverResourceManager, Type: EAT modification 0x831A0F38–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwRecoverTransactionManager, Type: EAT modification 0x831A0F3C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwRemoveIoCompletion, Type: EAT modification 0x831A0F40–>82E62CA7 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwRemoveIoCompletionEx, Type: EAT modification 0x831A0F44–>82FCF000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwReplaceKey, Type: EAT modification 0x831A0F48–>833AF068 [unknown_code_page] ntkrnlpa.exe–>ZwRequestPort, Type: EAT modification 0x831A0F4C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwRequestWaitReplyPort, Type: EAT modification 0x831A0F50–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwResetEvent, Type: EAT modification 0x831A0F54–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwRestoreKey, Type: EAT modification 0x831A0F58–>B106702A [unknown_code_page] ntkrnlpa.exe–>ZwRollbackComplete, Type: EAT modification 0x831A0F5C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwRollbackTransaction, Type: EAT modification 0x831A0F64–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwSaveKey, Type: EAT modification 0x831A0F68–>B106973B [unknown_code_page] ntkrnlpa.exe–>ZwSaveKeyEx, Type: EAT modification 0x831A0F6C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwSecureConnectPort, Type: EAT modification 0x831A0F70–>B106702A [unknown_code_page] ntkrnlpa.exe–>ZwSetBootEntryOrder, Type: EAT modification 0x831A0F74–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwSetBootOptions, Type: EAT modification 0x831A0F78–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetDefaultLocale, Type: EAT modification 0x831A0F7C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetDefaultUILanguage, Type: EAT modification 0x831A0F80–>82E4F8C6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetDriverEntryOrder, Type: EAT modification 0x831A0F84–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetEaFile, Type: EAT modification 0x831A0F88–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetEvent, Type: EAT modification 0x831A0F8C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetInformationEnlistment, Type: EAT modification 0x831A0F90–>8347F30A [unknown_code_page] ntkrnlpa.exe–>ZwSetInformationFile, Type: EAT modification 0x831A0F94–>8353F06F [unknown_code_page] ntkrnlpa.exe–>ZwSetInformationJobObject, Type: EAT modification 0x831A0F98–>834DF06B [unknown_code_page] ntkrnlpa.exe–>ZwSetInformationObject, Type: EAT modification 0x831A0F9C–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetInformationProcess, Type: EAT modification 0x831A0FA0–>8352F070 [unknown_code_page] ntkrnlpa.exe–>ZwSetInformationResourceManager, Type: EAT modification 0x831A0FA4–>834AF067 [unknown_code_page] ntkrnlpa.exe–>ZwSetInformationThread, Type: EAT modification 0x831A0FA8–>82E62CA9 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetInformationToken, Type: EAT modification 0x831A0FAC–>8321F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetInformationTransaction, Type: EAT modification 0x831A0FB0–>833EF070 [unknown_code_page] ntkrnlpa.exe–>ZwSetQuotaInformationFile, Type: EAT modification 0x831A0FB4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetSecurityObject, Type: EAT modification 0x831A0FB8–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwSetSystemInformation, Type: EAT modification 0x831A0FBC–>8326F000 [unknown_code_page] ntkrnlpa.exe–>ZwSetSystemTime, Type: EAT modification 0x831A0FC0–>B106973B [unknown_code_page] ntkrnlpa.exe–>ZwSetTimer, Type: EAT modification 0x831A0FC4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwSetValueKey, Type: EAT modification 0x831A0FCC–>84B02037 [unknown_code_page] ntkrnlpa.exe–>ZwSetVolumeInformationFile, Type: EAT modification 0x831A0FD0–>B106973B [unknown_code_page] ntkrnlpa.exe–>ZwTerminateJobObject, Type: EAT modification 0x831A0FD4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwTerminateProcess, Type: EAT modification 0x831A0FD8–>B106973B [unknown_code_page] ntkrnlpa.exe–>ZwTraceEvent, Type: EAT modification 0x831A0FDC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>ZwTranslateFilePath, Type: EAT modification 0x831A0FE0–>82E50000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwUnloadDriver, Type: EAT modification 0x831A0FE4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwUnloadKey, Type: EAT modification 0x831A0FE8–>82E4F919 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwUnloadKeyEx, Type: EAT modification 0x831A0FEC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwUnlockFile, Type: EAT modification 0x831A0FF0–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwUnmapViewOfSection, Type: EAT modification 0x831A0FF4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>ZwWaitForMultipleObjects, Type: EAT modification 0x831A0FF8–>8348F30C [unknown_code_page] ntkrnlpa.exe–>ZwWaitForSingleObject, Type: EAT modification 0x831A0FFC–>8358F061 [unknown_code_page] ntkrnlpa.exe–>ZwWriteFile, Type: EAT modification 0x831A1000–>8346F061 [unknown_code_page] ntkrnlpa.exe–>ZwYieldExecution, Type: EAT modification 0x831A1004–>8357F061 [unknown_code_page] ntkrnlpa.exe–>_abnormal_termination, Type: EAT modification 0x831A1014–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_alldiv, Type: EAT modification 0x831A1018–>82E62CAC [ntkrnlpa.exe] ntkrnlpa.exe–>_alldvrm, Type: EAT modification 0x831A101C–>8330F000 [unknown_code_page] ntkrnlpa.exe–>_allmul, Type: EAT modification 0x831A1020–>8348F078 [unknown_code_page] ntkrnlpa.exe–>_alloca_probe, Type: EAT modification 0x831A1024–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_alloca_probe_16, Type: EAT modification 0x831A1028–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>_alloca_probe_8, Type: EAT modification 0x831A102C–>8326F000 [unknown_code_page] ntkrnlpa.exe–>_allrem, Type: EAT modification 0x831A1030–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>_allshl, Type: EAT modification 0x831A1034–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>_aulldiv, Type: EAT modification 0x831A103C–>84B02037 [unknown_code_page] ntkrnlpa.exe–>_aulldvrm, Type: EAT modification 0x831A1040–>B8F99D0B [unknown_code_page] ntkrnlpa.exe–>_aullshr, Type: EAT modification 0x831A1048–>B105F2EA [unknown_code_page] ntkrnlpa.exe–>_chkstk, Type: EAT modification 0x831A104C–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>_CIcos, Type: EAT modification 0x831A1008–>8312F065 [ntkrnlpa.exe] ntkrnlpa.exe–>_CIsin, Type: EAT modification 0x831A100C–>8352F070 [unknown_code_page] ntkrnlpa.exe–>_CIsqrt, Type: EAT modification 0x831A1010–>82E4F067 [ntkrnlpa.exe] ntkrnlpa.exe–>_except_handler2, Type: EAT modification 0x831A1050–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>_except_handler3, Type: EAT modification 0x831A1054–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_global_unwind2, Type: EAT modification 0x831A1058–>82E500E5 [ntkrnlpa.exe] ntkrnlpa.exe–>_i64toa_s, Type: EAT modification 0x831A105C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_i64tow_s, Type: EAT modification 0x831A1060–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>_itoa, Type: EAT modification 0x831A1064–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_itoa_s, Type: EAT modification 0x831A1068–>8348F111 [unknown_code_page] ntkrnlpa.exe–>_itow, Type: EAT modification 0x831A106C–>8358F061 [unknown_code_page] ntkrnlpa.exe–>_itow_s, Type: EAT modification 0x831A1070–>8346F061 [unknown_code_page] ntkrnlpa.exe–>_local_unwind2, Type: EAT modification 0x831A1074–>8357F061 [unknown_code_page] ntkrnlpa.exe–>_ltoa_s, Type: EAT modification 0x831A1078–>8338F065 [unknown_code_page] ntkrnlpa.exe–>_ltow_s, Type: EAT modification 0x831A107C–>8346F061 [unknown_code_page] ntkrnlpa.exe–>_makepath_s, Type: EAT modification 0x831A1080–>8349F06C [unknown_code_page] ntkrnlpa.exe–>_purecall, Type: EAT modification 0x831A1084–>8354F02E [unknown_code_page] ntkrnlpa.exe–>_snprintf, Type: EAT modification 0x831A1088–>834BF06E [unknown_code_page] ntkrnlpa.exe–>_snprintf_s, Type: EAT modification 0x831A108C–>82E4F002 [ntkrnlpa.exe] ntkrnlpa.exe–>_snscanf_s, Type: EAT modification 0x831A1090–>82E62CAC [ntkrnlpa.exe] ntkrnlpa.exe–>_snwprintf, Type: EAT modification 0x831A1094–>8330F000 [unknown_code_page] ntkrnlpa.exe–>_snwprintf_s, Type: EAT modification 0x831A1098–>833EF070 [unknown_code_page] ntkrnlpa.exe–>_snwscanf_s, Type: EAT modification 0x831A109C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_splitpath_s, Type: EAT modification 0x831A10A0–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>_stricmp, Type: EAT modification 0x831A10A4–>8326F000 [unknown_code_page] ntkrnlpa.exe–>_strlwr, Type: EAT modification 0x831A10A8–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>_strnicmp, Type: EAT modification 0x831A10AC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>_strnset_s, Type: EAT modification 0x831A10B4–>84B02037 [unknown_code_page] ntkrnlpa.exe–>_strrev, Type: EAT modification 0x831A10B8–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>_strset, Type: EAT modification 0x831A10BC–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>_strset_s, Type: EAT modification 0x831A10C0–>B106BE4B [unknown_code_page] ntkrnlpa.exe–>_strtoui64, Type: EAT modification 0x831A10C4–>84B02A1C [unknown_code_page] ntkrnlpa.exe–>_strupr, Type: EAT modification 0x831A10C8–>82E51000 [ntkrnlpa.exe] ntkrnlpa.exe–>_swprintf, Type: EAT modification 0x831A10CC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_ui64toa_s, Type: EAT modification 0x831A10D0–>82E500E5 [ntkrnlpa.exe] ntkrnlpa.exe–>_ui64tow_s, Type: EAT modification 0x831A10D4–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_ultoa_s, Type: EAT modification 0x831A10D8–>82E4F020 [ntkrnlpa.exe] ntkrnlpa.exe–>_ultow_s, Type: EAT modification 0x831A10DC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_vsnprintf, Type: EAT modification 0x831A10E0–>8328F20C [unknown_code_page] ntkrnlpa.exe–>_vsnprintf_s, Type: EAT modification 0x831A10E4–>8338F041 [unknown_code_page] ntkrnlpa.exe–>_vsnwprintf, Type: EAT modification 0x831A10E8–>8326F041 [unknown_code_page] ntkrnlpa.exe–>_vsnwprintf_s, Type: EAT modification 0x831A10EC–>8362F041 [unknown_code_page] ntkrnlpa.exe–>_vswprintf, Type: EAT modification 0x831A10F0–>8312F031 [ntkrnlpa.exe] ntkrnlpa.exe–>_wcsicmp, Type: EAT modification 0x831A10F4–>8332F050 [unknown_code_page] ntkrnlpa.exe–>_wcslwr, Type: EAT modification 0x831A10F8–>82E4F047 [ntkrnlpa.exe] ntkrnlpa.exe–>_wcsnicmp, Type: EAT modification 0x831A10FC–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_wcsnset, Type: EAT modification 0x831A1100–>82E62CB9 [ntkrnlpa.exe] ntkrnlpa.exe–>_wcsnset_s, Type: EAT modification 0x831A1104–>834DF000 [unknown_code_page] ntkrnlpa.exe–>_wcsrev, Type: EAT modification 0x831A1108–>833EF070 [unknown_code_page] ntkrnlpa.exe–>_wcsset_s, Type: EAT modification 0x831A110C–>82E4F000 [ntkrnlpa.exe] ntkrnlpa.exe–>_wcsupr, Type: EAT modification 0x831A1110–>82E627A6 [ntkrnlpa.exe] ntkrnlpa.exe–>_wmakepath_s, Type: EAT modification 0x831A1114–>8326F000 [unknown_code_page] ntkrnlpa.exe–>_wsplitpath_s, Type: EAT modification 0x831A1118–>B107337D [unknown_code_page] ntkrnlpa.exe–>_wtoi, Type: EAT modification 0x831A111C–>84B02A1C [unknown_code_page] [2728]YahooAUService.exe–>advapi32.dll–>CreateServiceW, Type: IAT modification 0x00467054–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x77C6178C–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77C617F0–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x77C61848–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77C617B8–>00000000 [apphelp.dll] [2728]YahooAUService.exe–>advapi32.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x77C61844–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>RegCreateKeyExW, Type: IAT modification 0x00467088–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>RegDeleteValueW, Type: IAT modification 0x00467090–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>RegOpenKeyExA, Type: IAT modification 0x00467004–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>RegOpenKeyExW, Type: IAT modification 0x00467084–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>advapi32.dll–>RegSetValueExW, Type: IAT modification 0x0046707C–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>gdi32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x77B61154–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>gdi32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77B611E0–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>gdi32.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x77B6118C–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77B611B8–>00000000 [apphelp.dll] [2728]YahooAUService.exe–>kernel32.dll–>CreateFileA, Type: IAT modification 0x00467138–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>kernel32.dll–>CreateFileW, Type: IAT modification 0x004670C8–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>kernel32.dll–>CreateProcessW, Type: IAT modification 0x004670D8–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>kernel32.dll–>DeleteFileA, Type: IAT modification 0x00467250–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x004670AC–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>kernel32.dll–>GetFileAttributesW, Type: IAT modification 0x00467108–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x004670F0–>00000000 [apphelp.dll] [2728]YahooAUService.exe–>kernel32.dll–>MoveFileA, Type: IAT modification 0x00467254–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>shell32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x738022C4–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>shell32.dll–>kernel32.dll–>MoveFileExW, Type: IAT modification 0x73802240–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>shell32.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x73802298–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>user32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77D11524–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77D114E0–>00000000 [apphelp.dll] [2728]YahooAUService.exe–>user32.dll–>kernel32.dll–>RegCreateKeyExW, Type: IAT modification 0x77D114B4–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>user32.dll–>kernel32.dll–>RegOpenKeyExW, Type: IAT modification 0x77D11444–>00000000 [AcGenral.dll] [2728]YahooAUService.exe–>user32.dll–>kernel32.dll–>RegSetValueExW, Type: IAT modification 0x77D114AC–>00000000 [AcGenral.dll] [5020]plugin-container.exe–>user32.dll–>TrackPopupMenu, Type: Inline - RelativeJump 0x77174B3B–>00000000 [xul.dll] [5852]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7731F625–>00000000 [unknown_code_page]
The OTL scan didn't finish because an error screen appeared with the ff lines: "Cannot create file cmd.bat…" or something to that effect. What to do?
Re-Run OTL with the custom scan in my last post, and ensure that you right click on and select Run as Administrator. See if that works for you.
I actually did right-click-Run-as-admin the first time around. No luck on my 2nd try, it is still stuck at the same point when I did it the first time. Error: Cannot create file C:\Users\Darryle\Desktop\cmd.bat.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI