GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-04-11 15:56:03 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST750LM0 rev.2AR1 698,64GB Running: o8fqn03l.exe; Driver: C:\Users\Ewa\AppData\Local\Temp\pxtiipog.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800031bd000 64 bytes [00, 00, 00, 00, 00, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594 fffff800031bd042 4 bytes [00, 00, 00, 00] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 000000014a0c0460 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 000000014a0c0450 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 000000014a0c0370 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 000000014a0c0470 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 000000014a0c03e0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 000000014a0c0320 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 000000014a0c03b0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 000000014a0c0390 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 000000014a0c02e0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 000000014a0c02d0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 000000014a0c0310 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 000000014a0c03c0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 000000014a0c03f0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 000000014a0c0230 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 000000014a0c0480 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 000000014a0c03a0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 000000014a0c02f0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 000000014a0c0350 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 000000014a0c0290 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 000000014a0c02b0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 000000014a0c03d0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 000000014a0c0330 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 000000014a0c0410 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 000000014a0c0240 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 000000014a0c01e0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 000000014a0c0250 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 000000014a0c0490 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 000000014a0c04a0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 000000014a0c0300 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 000000014a0c0360 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 000000014a0c02a0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 000000014a0c02c0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 000000014a0c0380 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 000000014a0c0340 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 000000014a0c0440 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 000000014a0c0260 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 000000014a0c0270 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 000000014a0c0400 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 000000014a0c01f0 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 000000014a0c0210 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 000000014a0c0200 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 000000014a0c0420 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 000000014a0c0430 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 000000014a0c0220 .text C:\Windows\system32\csrss.exe[540] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 000000014a0c0280 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 000000014a0c0460 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 000000014a0c0450 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 000000014a0c0370 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 000000014a0c0470 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 000000014a0c03e0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 000000014a0c0320 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 000000014a0c03b0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 000000014a0c0390 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 000000014a0c02e0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 000000014a0c02d0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 000000014a0c0310 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 000000014a0c03c0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 000000014a0c03f0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 000000014a0c0230 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 000000014a0c0480 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 000000014a0c03a0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 000000014a0c02f0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 000000014a0c0350 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 000000014a0c0290 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 000000014a0c02b0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 000000014a0c03d0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 000000014a0c0330 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 000000014a0c0410 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 000000014a0c0240 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 000000014a0c01e0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 000000014a0c0250 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 000000014a0c0490 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 000000014a0c04a0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 000000014a0c0300 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 000000014a0c0360 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 000000014a0c02a0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 000000014a0c02c0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 000000014a0c0380 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 000000014a0c0340 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 000000014a0c0440 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 000000014a0c0260 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 000000014a0c0270 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 000000014a0c0400 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 000000014a0c01f0 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 000000014a0c0210 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 000000014a0c0200 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 000000014a0c0420 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 000000014a0c0430 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 000000014a0c0220 .text C:\Windows\system32\csrss.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 000000014a0c0280 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\wininit.exe[664] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\wininit.exe[664] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\winlogon.exe[712] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\services.exe[760] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Windows\system32\services.exe[760] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\lsass.exe[768] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\lsm.exe[776] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\System32\svchost.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\System32\svchost.exe[548] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\System32\svchost.exe[548] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\svchost.exe[860] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Windows\system32\svchost.exe[860] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\svchost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1356] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\nvvsvc.exe[1368] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\Dwm.exe[1640] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\Explorer.EXE[1648] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\Explorer.EXE[1648] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\System32\spoolsv.exe[1864] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\taskhost.exe[1916] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\svchost.exe[1932] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\System32\igfxtray.exe[1180] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\System32\hkcmd.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\System32\igfxpers.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files\Elantech\ETDCtrl.exe[1772] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1752] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[2032] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1168] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1560] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[2108] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[2240] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files\Windows Sidebar\sidebar.exe[2356] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2536] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c41465 2 bytes [C4, 77] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c414bb 2 bytes [C4, 77] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3056] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3076] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000100070460 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000100070450 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000100070370 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000100070470 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 00000001000703e0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000100070320 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 00000001000703b0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000100070390 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 00000001000702e0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 00000001000702d0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000100070310 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 00000001000703c0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 00000001000703f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000100070230 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000100070480 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 00000001000703a0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 00000001000702f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000100070350 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000100070290 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 00000001000702b0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 00000001000703d0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000100070330 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000100070410 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000100070240 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 00000001000701e0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000100070250 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000100070490 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 00000001000704a0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000100070300 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000100070360 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 00000001000702a0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 00000001000702c0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000100070380 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000100070340 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000100070440 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000100070260 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000100070270 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000100070400 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 00000001000701f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000100070210 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000100070200 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000100070420 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000100070430 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000100070220 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000100070280 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[3096] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[3124] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3188] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3320] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000000021465 2 bytes [02, 00] .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000000214bb 2 bytes [02, 00] .text ... * 2 .text C:\Program Files (x86)\FindRight\bin\utilFindRight.exe[3396] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\FindRight\bin\utilFindRight.exe[3396] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c41465 2 bytes [C4, 77] .text C:\Program Files (x86)\FindRight\bin\utilFindRight.exe[3396] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c414bb 2 bytes [C4, 77] .text ... * 2 .text C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe[3608] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\SearchIndexer.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\LockKey\LockKey.exe[3240] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files\Elantech\ETDCtrlHelper.exe[3404] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[1464] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[3436] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Windows\system32\svchost.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files (x86)\FindRight\bin\FilterApp_C64.exe[2780] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\FindRight\bin\FindRight.BrowserAdapter.exe[2856] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\FindRight\bin\FindRight.BrowserAdapter.exe[2856] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c41465 2 bytes [C4, 77] .text C:\Program Files (x86)\FindRight\bin\FindRight.BrowserAdapter.exe[2856] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c414bb 2 bytes [C4, 77] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[3804] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[3900] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4788] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c41465 2 bytes [C4, 77] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c414bb 2 bytes [C4, 77] .text ... * 2 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ae1360 5 bytes JMP 0000000077c40460 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ae13b0 5 bytes JMP 0000000077c40450 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ae1510 5 bytes JMP 0000000077c40370 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ae1560 5 bytes JMP 0000000077c40470 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ae1570 5 bytes JMP 0000000077c403e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ae1620 5 bytes JMP 0000000077c40320 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ae1650 5 bytes JMP 0000000077c403b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ae1670 5 bytes JMP 0000000077c40390 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ae16b0 5 bytes JMP 0000000077c402e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ae1730 5 bytes JMP 0000000077c402d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ae1750 5 bytes JMP 0000000077c40310 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ae1790 5 bytes JMP 0000000077c403c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ae17e0 5 bytes JMP 0000000077c403f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ae1940 5 bytes JMP 0000000077c40230 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ae1b00 5 bytes JMP 0000000077c40480 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ae1b30 5 bytes JMP 0000000077c403a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ae1c10 5 bytes JMP 0000000077c402f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ae1c20 5 bytes JMP 0000000077c40350 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ae1c80 5 bytes JMP 0000000077c40290 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ae1d10 5 bytes JMP 0000000077c402b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ae1d30 5 bytes JMP 0000000077c403d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ae1d40 5 bytes JMP 0000000077c40330 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ae1db0 5 bytes JMP 0000000077c40410 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ae1de0 5 bytes JMP 0000000077c40240 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ae20a0 5 bytes JMP 0000000077c401e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ae2160 5 bytes JMP 0000000077c40250 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ae2190 5 bytes JMP 0000000077c40490 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ae21a0 5 bytes JMP 0000000077c404a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ae21d0 5 bytes JMP 0000000077c40300 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ae21e0 5 bytes JMP 0000000077c40360 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ae2240 5 bytes JMP 0000000077c402a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ae2290 5 bytes JMP 0000000077c402c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ae22c0 5 bytes JMP 0000000077c40380 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ae22d0 5 bytes JMP 0000000077c40340 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ae25c0 5 bytes JMP 0000000077c40440 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ae27c0 5 bytes JMP 0000000077c40260 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ae27d0 5 bytes JMP 0000000077c40270 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ae27e0 5 bytes JMP 0000000077c40400 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ae29a0 5 bytes JMP 0000000077c401f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ae29b0 5 bytes JMP 0000000077c40210 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ae2a20 5 bytes JMP 0000000077c40200 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ae2a80 5 bytes JMP 0000000077c40420 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ae2a90 5 bytes JMP 0000000077c40430 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ae2aa0 5 bytes JMP 0000000077c40220 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3912] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ae2b80 5 bytes JMP 0000000077c40280 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[2956] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Users\Ewa\Downloads\o8fqn03l.exe[2228] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000761aa2fd 1 byte [62] .text C:\Windows\System32\osk.exe[1264] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000778cef8d 1 byte [62] ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [2756:3440] 000007fee5cd9688 ---- Services - GMER 2.1 ---- Service C:\Program Files\AVAST Software\Avast\AvastSvc.exe (*** hidden *** ) [AUTO] avast! Antivirus <-- ROOTKIT !!! ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DisplayName aswFsBlk Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Description Avast! Mini-filter Driver Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Tag 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ImagePath \??\C:\Windows\system32\drivers\aswFsBlk.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances@DefaultInstance aswFsBlk Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude 388400 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ImagePath \??\C:\Windows\system32\drivers\aswMonFlt.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DisplayName aswMonFlt Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Group FSFilter Anti-Virus Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Description avast! mini-filter driver (aswMonFlt) Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ImagePath \??\C:\Windows\system32\drivers\aswRdr2.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DisplayName aswRdr Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Group PNP_TDI Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DependOnService tcpip? Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Description avast! WFP Redirect driver Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@MSIgnoreLSPDefault Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@WSIgnoreLSPDefault nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@DisplayName avast! Revert Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Description avast! Revert Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@BootCounter 298 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@TickCounter 2954544 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@SystemRoot \Device\Harddisk0\Partition2\Windows Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@ImproperShutdown 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@ Commited Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@BootTimeout 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@TickTimeout 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@CreationTime 0x92 0x05 0xAB 0x4D ... Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@SetupOperations MoveFile("\??\c:\program files\avast software\avast\ashwebsv.dll.1382384811","\??\c:\program files\avast software\avast\ashwebsv.dll",TRUE)?MoveFile("\??\c:\program files\avast software\avast\ashwebsv.dll.sum.1382384811","\??\c:\program files\avast software\avast\ashwebsv.dll.sum",TRUE)?MoveFile("\??\c:\program files\avast software\avast\avastui.exe.1382384811","\??\c:\program files\avast software\avast\avastui.exe",TRUE)?MoveFile("\??\c:\program files\avast software\avast\avastui.exe.sum.1382384811","\??\c:\program files\avast software\avast\avastui.exe.sum",TRUE)? Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@StartBootCounter 3 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@StartTickCounter 15321 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1382384811@LastPackageError -1073741766 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@ Commited Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@BootTimeout 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@TickTimeout 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@CreationTime 0xDE 0x30 0x7B 0x51 ... Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@SetupOperations DeleteFile("\??\c:\program files\avast software\avast\setup\inf\x64\aswsp.sys.1383953775")?DeleteFile("\??\c:\windows\system32\drivers\aswsp.sys.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\x64\aswsp.sys.sum.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.inf.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.inf.sum.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.cat.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.cat.sum.1383953775")? Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@StartBootCounter 52 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@StartTickCounter 370250 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1383953775@LastPackageError -1073741766 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@ Commited Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@BootTimeout 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@TickTimeout 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@CreationTime 0x4E 0x4A 0x16 0xC0 ... Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@SetupOperations MoveFile("\??\c:\program files\avast software\avast\setup\instup.dll.1387486571","\??\c:\program files\avast software\avast\setup\instup.dll",TRUE)?MoveFile("\??\c:\program files\avast software\avast\setup\instup.dll.sum.1387486571","\??\c:\program files\avast software\avast\setup\instup.dll.sum",TRUE)? Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@StartBootCounter 138 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@StartTickCounter 1102640 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\1387486571@LastPackageError -1073741766 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DisplayName aswSnx Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Group FSFilter Virtualization Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Description avast! virtualization driver (aswSnx) Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Tag 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ImagePath \??\C:\Windows\system32\drivers\aswSnx.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances@DefaultInstance aswSnx Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Altitude 137600 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@DisplayName aswSP Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Description avast! Self Protection Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@ImagePath \??\C:\Windows\system32\drivers\aswSP.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@BehavShield 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFilesFolder \??\C:\Program Files Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@GadgetFolder \??\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DisplayName aswTdi Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Group PNP_TDI Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DependOnService tcpip? Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Description aswTdi Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Tag 11 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ImagePath \??\C:\Windows\system32\drivers\aswTdi.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@DisplayName avast! VM Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Description avast! VM Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Type 288 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DisplayName avast! Antivirus Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Group ShellSvcGroup Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DependOnService aswMonFlt?RpcSS? Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@WOW64 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ObjectName LocalSystem Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ServiceSidType 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Description Instaluje i zarz?dza us?ugami antywirusowymi programu avast! na tym komputerze, co obejmuje os?ony dzia?aj?ce w czasie rzeczywistym, kwarantann? oraz harmonogram zada?. Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74e5439099b2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DisplayName aswFsBlk Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Description Avast! Mini-filter Driver Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Tag 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ImagePath \??\C:\Windows\system32\drivers\aswFsBlk.sys Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances@DefaultInstance aswFsBlk Instance Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude 388400 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ImagePath \??\C:\Windows\system32\drivers\aswMonFlt.sys Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DisplayName aswMonFlt Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Group FSFilter Anti-Virus Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Description avast! mini-filter driver (aswMonFlt) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@ImagePath \??\C:\Windows\system32\drivers\aswRdr2.sys Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@DisplayName aswRdr Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Group PNP_TDI Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@DependOnService tcpip? Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Description avast! WFP Redirect driver Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@MSIgnoreLSPDefault Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@WSIgnoreLSPDefault nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@DisplayName avast! Revert Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Description avast! Revert Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@BootCounter 298 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@TickCounter 2954544 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@SystemRoot \Device\Harddisk0\Partition2\Windows Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@ImproperShutdown 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@ Commited Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@BootTimeout 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@TickTimeout 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@CreationTime 0x92 0x05 0xAB 0x4D ... Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@SetupOperations MoveFile("\??\c:\program files\avast software\avast\ashwebsv.dll.1382384811","\??\c:\program files\avast software\avast\ashwebsv.dll",TRUE)?MoveFile("\??\c:\program files\avast software\avast\ashwebsv.dll.sum.1382384811","\??\c:\program files\avast software\avast\ashwebsv.dll.sum",TRUE)?MoveFile("\??\c:\program files\avast software\avast\avastui.exe.1382384811","\??\c:\program files\avast software\avast\avastui.exe",TRUE)?MoveFile("\??\c:\program files\avast software\avast\avastui.exe.sum.1382384811","\??\c:\program files\avast software\avast\avastui.exe.sum",TRUE)? Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@StartBootCounter 3 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@StartTickCounter 15321 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1382384811@LastPackageError -1073741766 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@ Commited Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@BootTimeout 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@TickTimeout 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@CreationTime 0xDE 0x30 0x7B 0x51 ... Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@SetupOperations DeleteFile("\??\c:\program files\avast software\avast\setup\inf\x64\aswsp.sys.1383953775")?DeleteFile("\??\c:\windows\system32\drivers\aswsp.sys.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\x64\aswsp.sys.sum.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.inf.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.inf.sum.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.cat.1383953775")?DeleteFile("\??\c:\program files\avast software\avast\setup\inf\aswsp.cat.sum.1383953775")? Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@StartBootCounter 52 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@StartTickCounter 370250 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1383953775@LastPackageError -1073741766 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@ Commited Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@BootTimeout 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@TickTimeout 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@CreationTime 0x4E 0x4A 0x16 0xC0 ... Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@SetupOperations MoveFile("\??\c:\program files\avast software\avast\setup\instup.dll.1387486571","\??\c:\program files\avast software\avast\setup\instup.dll",TRUE)?MoveFile("\??\c:\program files\avast software\avast\setup\instup.dll.sum.1387486571","\??\c:\program files\avast software\avast\setup\instup.dll.sum",TRUE)? Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@StartBootCounter 138 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@StartTickCounter 1102640 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\1387486571@LastPackageError -1073741766 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@DisplayName aswSnx Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Group FSFilter Virtualization Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Description avast! virtualization driver (aswSnx) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Tag 2 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@ImagePath \??\C:\Windows\system32\drivers\aswSnx.sys Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances@DefaultInstance aswSnx Instance Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Altitude 137600 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@DisplayName aswSP Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Description avast! Self Protection Reg HKLM\SYSTEM\ControlSet002\services\aswSP@ImagePath \??\C:\Windows\system32\drivers\aswSP.sys Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@BehavShield 0 Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFolder \??\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@DataFolder \??\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFilesFolder \??\C:\Program Files Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@GadgetFolder \??\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@DisplayName aswTdi Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Group PNP_TDI Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@DependOnService tcpip? Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Description aswTdi Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Tag 11 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@ImagePath \??\C:\Windows\system32\drivers\aswTdi.sys Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@DisplayName avast! VM Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Description avast! VM Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswVmm\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Type 288 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DisplayName avast! Antivirus Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Group ShellSvcGroup Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DependOnService aswMonFlt?RpcSS? Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@WOW64 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ServiceSidType 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Description Instaluje i zarz?dza us?ugami antywirusowymi programu avast! na tym komputerze, co obejmuje os?ony dzia?aj?ce w czasie rzeczywistym, kwarantann? oraz harmonogram zada?. Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74e5439099b2 (not active ControlSet) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer@CleanShutdown 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder@Attributes 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum@ Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2@FavoritesRemovedChanges 6 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband@FavoritesChanges 7 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband@FavoritesRemovedChanges 6 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings@SecureProtocols 160 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1@Flags 323 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@2708 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@2709 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@2402 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@2708 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@2709 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Themes@LastHighContrastTheme %SystemRoot%\resources\Ease of Access Themes\hcblack.theme Reg HKCU\Software\Microsoft\Windows\DWM@CompositionPolicy 0 Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting@LastQueuePesterTime 0x2B 0xAF 0xE0 0x1C ... ---- Files - GMER 2.1 ---- File C:\Program Files\Common Files\mcafee\core 0 bytes File C:\Program Files\Common Files\mcafee\core\mccore.inf 835 bytes File C:\Program Files\Common Files\mcafee\core\mccoreps.dll 115536 bytes executable File C:\Program Files\Common Files\mcafee\core\McEvtBrk.dll 172704 bytes executable File C:\Program Files\Common Files\mcafee\core\mchost.exe 161880 bytes executable File C:\Program Files\Common Files\mcafee\hackerwatch 0 bytes File C:\Program Files\Common Files\mcafee\hackerwatch\HWAPI.dll 728392 bytes executable File C:\Program Files\Common Files\mcafee\hackerwatch\hwapi.inf 3490 bytes File C:\Program Files\Common Files\mcafee\hackerwatch\hwupdchk.exe 562056 bytes File C:\Program Files\Common Files\mcafee\mcproxy 0 bytes File C:\Program Files\Common Files\mcafee\mcproxy\McProxy.dll 531632 bytes executable File C:\Program Files\Common Files\mcafee\mcproxy\McProxy64.inf 10196 bytes File C:\Program Files\Common Files\mcafee\mcproxy\Proxyver.dll 183504 bytes executable File C:\Program Files\Common Files\mcafee\mcproxy\rmoldfile.inf 1971 bytes File C:\Program Files\Common Files\mcafee\mcsvchost 0 bytes File C:\Program Files\Common Files\mcafee\mcsvchost\McSHIns.dll 182480 bytes executable File C:\Program Files\Common Files\mcafee\mcsvchost\McSvcHost64.inf 2085 bytes File C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe 249936 bytes executable File C:\Program Files\Common Files\mcafee\mcsvchost\McSvHVer.dll 248424 bytes executable File C:\Program Files\Common Files\mcafee\mna 0 bytes File C:\Program Files\Common Files\mcafee\mna\McAltHPS.dll 53760 bytes executable File C:\Program Files\Common Files\mcafee\mna\McAltHst.exe 383848 bytes executable File C:\Program Files\Common Files\mcafee\mna\McNaIns.dll 187112 bytes executable File C:\Program Files\Common Files\mcafee\mna\McNAReg.dll 317928 bytes executable File C:\Program Files\Common Files\mcafee\mna\McNARgPS.dll 50688 bytes executable File C:\Program Files\Common Files\mcafee\mna\McNASvc.dll 3974440 bytes File C:\Program Files\Common Files\mcafee\mna\McNASvPS.dll 73312 bytes executable File C:\Program Files\Common Files\mcafee\mna\McNAVer.dll 170656 bytes executable File C:\Program Files\Common Files\mcafee\mna\McTrstPS.dll 52224 bytes executable File C:\Program Files\Common Files\mcafee\mna\mna64.inf 2514 bytes File C:\Program Files\Common Files\mcafee\msc 0 bytes File C:\Program Files\Common Files\mcafee\msc\LangSel.dll 240696 bytes File C:\Program Files\Common Files\mcafee\msc\mcbrwsr2.dll 570296 bytes executable File C:\Program Files\Common Files\mcafee\msc\McDspWrp.dll 1003408 bytes executable File C:\Program Files\Common Files\mcafee\msc\McDspWrp64.inf 966 bytes File C:\Program Files\Common Files\mcafee\msc\McRTMui.dll 644968 bytes executable File C:\Program Files\Common Files\mcafee\msc\mcscrhlp.dll 180944 bytes executable File C:\Program Files\Common Files\mcafee\msc\mcuc64.inf 484 bytes File C:\Program Files\Common Files\mcafee\msc\McUICnt.exe 678928 bytes executable File C:\Program Files\Common Files\mcafee\msc\mcutil 0 bytes File C:\Program Files\Common Files\mcafee\msc\mcutil\11,0,320,0 0 bytes File C:\Program Files\Common Files\mcafee\msc\mcutil\11,0,320,0\mcutil.dll 326168 bytes File C:\Program Files\Common Files\mcafee\msc\mcutil.dll 326168 bytes File C:\Program Files\Common Files\mcafee\msc\misplf.dll 249960 bytes executable File C:\Program Files\Common Files\mcafee\msc\msccmn.inf 842 bytes File C:\Program Files\Common Files\mcafee\msc\sqlite3.dll 606328 bytes executable File C:\Program Files\Common Files\mcafee\nmc 0 bytes File C:\Program Files\Common Files\mcafee\nmc\McDisc.dll 1492640 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McDiscPS.dll 52736 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McHNShim.dll 1402024 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McHNShPS.dll 63024 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McMPFEvt.dll 306080 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNdAtpg.dll 389528 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNDLor.dll 189648 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNDSv.dll 1321672 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNDSVPS.dll 54808 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNMAtpg.dll 360712 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNmcIns.dll 195352 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNmcLor.dll 816424 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNmcShell.exe 201544 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNmcSPS.dll 54296 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNmcSrv.dll 1957176 bytes executable File C:\Program Files\Common Files\mcafee\nmc\McNmcVer.dll 258200 bytes File C:\Program Files\Common Files\mcafee\nmc\nmcdef.inf 3240 bytes File C:\Program Files\Common Files\mcafee\nmc\NMCJsRes.dll 215928 bytes executable File C:\Program Files\Common Files\mcafee\nmc\nmcLI64.inf 5293 bytes File C:\Program Files\Common Files\mcafee\nmc\nmcuicfg.dat 18961 bytes File C:\Program Files\Common Files\mcafee\systemcore\dainstall.exe 73600 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\ftl.dll 79232 bytes File C:\Program Files\Common Files\mcafee\systemcore\fwinfo.exe 193056 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\lockdown.dll 43712 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mcshield.dll 25640 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe 199272 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfeapfa.dll 61216 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfeavfa.dll 80768 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe 208536 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfefwctl.dll 203880 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfehida.dll 77184 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfehidin.exe 472168 bytes File C:\Program Files\Common Files\mcafee\systemcore\mfehidk_messages.dll 70504 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mferkda.dll 34984 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mfevtpa.dll 153416 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mytilus3.dll 100344 bytes File C:\Program Files\Common Files\mcafee\systemcore\mytilus3_server.dll 91080 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\mytilus3_worker.dll 388256 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\naevent.dll 74600 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\naievent.dll 22024 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\rkscan.dll 347544 bytes File C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120723201251.dll 94688 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\scriptsn.dll 94688 bytes executable File C:\Program Files\Common Files\mcafee\systemcore\strings.bin 34663 bytes File C:\Program Files\Common Files\mcafee\systemcore\vscan.bof 110148 bytes File C:\Program Files\Common Files\mcafee\systemcore\vtp_catcache 89140 bytes File C:\Program Files\Common Files\mcafee\vscore 0 bytes File C:\Program Files\Common Files\mcafee\vscore\mfefwctl.dll 203880 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mferkdet.cat 7726 bytes File C:\Program Files\Common Files\mcafee\vscore\av64.inf 19188 bytes File C:\Program Files\Common Files\mcafee\vscore\cfwids.cat 7718 bytes File C:\Program Files\Common Files\mcafee\vscore\cfwids.inf 721 bytes File C:\Program Files\Common Files\mcafee\vscore\cfwids.sys 65264 bytes executable File C:\Program Files\Common Files\mcafee\vscore\DAInstall.exe 73600 bytes executable File C:\Program Files\Common Files\mcafee\vscore\ftl.dll 79232 bytes File C:\Program Files\Common Files\mcafee\vscore\fw64.inf 1086 bytes File C:\Program Files\Common Files\mcafee\vscore\lockdown.dll 43712 bytes executable File C:\Program Files\Common Files\mcafee\vscore\McShield.dll 25640 bytes executable File C:\Program Files\Common Files\mcafee\vscore\Mcshield.exe 199272 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfeapfa.dll 61216 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfeapfk.cat 7722 bytes File C:\Program Files\Common Files\mcafee\vscore\mfeapfk.inf 725 bytes File C:\Program Files\Common Files\mcafee\vscore\mfeapfk.sys 160280 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfeavfa.dll 80768 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfeavfk.cat 7722 bytes File C:\Program Files\Common Files\mcafee\vscore\mfeavfk.inf 725 bytes File C:\Program Files\Common Files\mcafee\vscore\mfeavfk.sys 229528 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfeclnk.cat 7722 bytes File C:\Program Files\Common Files\mcafee\vscore\mfeclnk.inf 725 bytes File C:\Program Files\Common Files\mcafee\vscore\mfeclnk.sys 10248 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfefire.exe 208536 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfefirek.cat 7726 bytes File C:\Program Files\Common Files\mcafee\vscore\mfefirek.inf 729 bytes File C:\Program Files\Common Files\mcafee\vscore\mfefirek.sys 481768 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfehida.dll 77184 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfehidin.exe 472168 bytes File C:\Program Files\Common Files\mcafee\vscore\mfehidk.cat 7722 bytes File C:\Program Files\Common Files\mcafee\vscore\mfehidk.inf 725 bytes File C:\Program Files\Common Files\mcafee\vscore\mfehidk.sys 647080 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfehidk_messages.dll 70504 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfendisk.cat 7726 bytes File C:\Program Files\Common Files\mcafee\vscore\mfendisk.inf 3287 bytes File C:\Program Files\Common Files\mcafee\vscore\mfendisk.sys 101040 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfendisk_m.cat 7281 bytes File C:\Program Files\Common Files\mcafee\vscore\mfendisk_m.inf 1798 bytes File C:\Program Files\Common Files\mcafee\vscore\mfenlfk.cat 7722 bytes File C:\Program Files\Common Files\mcafee\vscore\mfenlfk.inf 2961 bytes File C:\Program Files\Common Files\mcafee\vscore\mfenlfk.sys 75808 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mferkda.dll 34984 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mferkdet.inf 729 bytes File C:\Program Files\Common Files\mcafee\vscore\mferkdet.sys 100912 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfetdi2k.cat 7726 bytes File C:\Program Files\Common Files\mcafee\vscore\mfetdi2k.inf 729 bytes File C:\Program Files\Common Files\mcafee\vscore\mfetdi2k.sys 117008 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfevtpa.dll 153416 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfevtps.exe 161168 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mfewfpk.cat 7722 bytes File C:\Program Files\Common Files\mcafee\vscore\mfewfpk.inf 725 bytes File C:\Program Files\Common Files\mcafee\vscore\mfewfpk.sys 284648 bytes File C:\Program Files\Common Files\mcafee\vscore\mytilus3.dll 100344 bytes File C:\Program Files\Common Files\mcafee\vscore\mytilus3_server.dll 91080 bytes executable File C:\Program Files\Common Files\mcafee\vscore\mytilus3_worker.dll 388256 bytes executable File C:\Program Files\Common Files\mcafee\vscore\NaEvent.dll 74600 bytes executable File C:\Program Files\Common Files\mcafee\vscore\NaiEvent.dll 22024 bytes executable File C:\Program Files\Common Files\mcafee\vscore\RkScan.dll 347544 bytes File C:\Program Files\Common Files\mcafee\vscore\scriptsn.dll 94688 bytes executable File C:\Program Files\Common Files\mcafee\vscore\strings.bin 34663 bytes File C:\Program Files\Common Files\mcafee\vscore\tools 0 bytes File C:\Program Files\Common Files\mcafee\vscore\tools\fwinfo.exe 193056 bytes executable File C:\Program Files\Common Files\mcafee\vscore\vscore.xml 36307 bytes File C:\Program Files\Common Files\mcafee\vscore\vscore64.inf 4177 bytes File C:\Program Files\Common Files\mcafee\vscore\VSCVer.dll 505616 bytes executable File C:\Program Files\Common Files\mcafee\vscore\vtp_catcache 17368 bytes File C:\Program Files\Common Files\mcafee\vscore\x86 0 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\chrome.manifest 111 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\DAInstall.exe 74600 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\install.rdf 817 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\lockdown.dll 39032 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\McShield.dll 385624 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\mfeavfa.dll 66896 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\mfefwctl.dll 154952 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\mfehida.dll 74600 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\mytilus3.dll 84888 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\mytilus3_worker.dll 312560 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\RkScan.dll 287280 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\scriptff.dll 28760 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\scriptff.gif 624 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\scriptff.js 596 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\scriptff.xul 272 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\scriptsn.dll 79744 bytes executable File C:\Program Files\Common Files\mcafee\vscore\x86\strings.bin 34663 bytes File C:\Program Files\Common Files\mcafee\vscore\x86\vtp_catcache 17368 bytes File C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe (size mismatch) 13112/16744 bytes executable File C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.OmnitureSiteCatalyst.dll (size mismatch) 12088/13672 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\OpenPerfomanceTaskManager.exe 6144 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\battery\64\LenovoEmExpandedAPI.dll (size mismatch) 10240/16744 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Business.dll (size mismatch) 217088/334808 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\CriaPerfMonMemory.bat 145 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\32 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\32\diag_memory.dll 1178688 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\32\ldiag_memory_x86.exe 416768 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\64 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\64\diag_memory.dll 521280 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\64\ldiag_memory_x64.exe 491008 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\flex_comm_sample.exe 29184 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_memory_simulation.exe 28672 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_storage_x64.exe 221496 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_storage_x86.exe 187704 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_test.exe 166912 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Entity.dll (size mismatch) 4608/96616 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\EventViewer.dll (size mismatch) 4608/11112 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\fp_smbios.exe (size mismatch) 17920/24936 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Interop.NetFwTypeLib.dll (size mismatch) 19456/25960 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Interop.PlaLibrary.dll (size mismatch) 73728/80232 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Interop.TaskScheduler.dll (size mismatch) 49152/55656 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\KillProcessLSC.exe (size mismatch) 5120/12136 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCController.dll (size mismatch) 49664/67552 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe (size mismatch) 7680/171 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.vshost.exe (size mismatch) 14328/490 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService32.exe (size mismatch) 7680/19424 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService32.vshost.exe 14328 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\MemoryMonitor.exe (size mismatch) 5120/11776 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\PerformanceMonitor.dll (size mismatch) 12288/18792 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\ProcessorMonitor.exe (size mismatch) 5120/11784 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\RunAsAdministrator.exe (size mismatch) 12600/117 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\RunAsAdministrator.vshost.exe 11064 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\RunAsAdministrator.vshost.exe.manifest 1247 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\TaskScheduler.dll (size mismatch) 14336/23912 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Util.dll (size mismatch) 7168/29544 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\WindowsRegistry.dll (size mismatch) 6144/12648 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\WindowWrapper.dll (size mismatch) 7168/13672 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\DiagSuitesBasic.xml 456 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\DiagSuitesBasicResult.xml 705 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\DiagSuitesComprehensive.xml 499 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\hwScan2.jpg 102229 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\Lenovo Solution Center Help.exe (size mismatch) 142848/142336 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupHardwareScanDefTests.html 1534 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupHardwareScanDefTests.html 1711 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScanDefTests.html 1520 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupHardwareScanDefTests.html 1703 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupHardwareScanDefTests.html 1603 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupHardwareScanDefTests.html 1734 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupHardwareScanDefTests.html 1735 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupHardwareScanDefTests.html 1909 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupHardwareScanDefTests.html 1685 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupHardwareScanDefTests.html 1553 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupHardwareScanDefTests.html 1597 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupHardwareScanDefTests.html 1678 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupHardwareScanDefTests.html 1677 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupHardwareScanDefTests.html 1674 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupHardwareScanDefTests.html 2327 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupHardwareScanDefTests.html 1527 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupHardwareScanDefTests.html 1387 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupHardwareScanDefTests.html 1435 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupHardwareScanDefTests.html 1435 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe (size mismatch) 148280/148840 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe.manifest 908 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\btnSettingsDisabled.png 3618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\icnFilePrinter.png 2994 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusgray.png 10100 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusgreen.png 11157 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusred.png 11461 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusyellow.png 9941 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\silverSkin 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\silverSkin\style.css 3327 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\[Content_Types].xml 919 bytes File C:\Program Files\mcafee 0 bytes File C:\Program Files\mcafee\mpf 0 bytes File C:\Program Files\mcafee\mpf\data 0 bytes File C:\Program Files\mcafee\mpf\data\sports 0 bytes File C:\Program Files\mcafee\mpf\data\sports\OEMUpdate 0 bytes File C:\Program Files\mcafee\mpf\data\sports\update 0 bytes File C:\Program Files\mcafee\mpf\data\sports\update\DirServ.cfg 167 bytes File C:\Program Files\mcafee\mpf\data\sports\update\FTPServ.cfg 155 bytes File C:\Program Files\mcafee\mpf\data\sports\update\IMAPServ.cfg 144 bytes File C:\Program Files\mcafee\mpf\data\sports\update\NetBIOS.cfg 165 bytes File C:\Program Files\mcafee\mpf\data\sports\update\NTP.cfg 292 bytes File C:\Program Files\mcafee\mpf\data\sports\update\OS.cfg 165 bytes File C:\Program Files\mcafee\mpf\data\sports\update\Pop3Serv.cfg 144 bytes File C:\Program Files\mcafee\mpf\data\sports\update\RemAsst.cfg 208 bytes File C:\Program Files\mcafee\mpf\data\sports\update\RPCServ.cfg 147 bytes File C:\Program Files\mcafee\mpf\data\sports\update\SecWeb.cfg 150 bytes File C:\Program Files\mcafee\mpf\data\sports\update\SMTPServ.cfg 137 bytes File C:\Program Files\mcafee\mpf\data\sports\update\SQLServ.cfg 158 bytes File C:\Program Files\mcafee\mpf\data\sports\update\UPNP.cfg 182 bytes File C:\Program Files\mcafee\mpf\data\sports\update\WebServ.cfg 138 bytes File C:\Program Files\mcafee\mpf\data\TSClient.crt 900 bytes File C:\Program Files\mcafee\mpf\data\TSClient.key 900 bytes File C:\Program Files\mcafee\mpf\data\TS_CA.crt 942 bytes File C:\Program Files\mcafee\mpf\FWJsRes.dll 266144 bytes executable File C:\Program Files\mcafee\mpf\instLD.inf 2034 bytes File C:\Program Files\mcafee\mpf\L10N.dll 2043400 bytes executable File C:\Program Files\mcafee\mpf\McMPFPPv.dll 244056 bytes executable File C:\Program Files\mcafee\mpf\mpf.dat 4359 bytes File C:\Program Files\mcafee\mpf\MpfAlert.exe 552520 bytes executable File C:\Program Files\mcafee\mpf\MpfAltPS.dll 52488 bytes executable File C:\Program Files\mcafee\mpf\MpfApi.dll 617368 bytes executable File C:\Program Files\mcafee\mpf\MpfApiPS.dll 59168 bytes executable File C:\Program Files\mcafee\mpf\mpfcor.inf 8233 bytes File C:\Program Files\mcafee\mpf\mpfdata.inf 3703 bytes File C:\Program Files\mcafee\mpf\MpfEvt.dll 400080 bytes executable File C:\Program Files\mcafee\mpf\mpfins64.dll 363512 bytes executable File C:\Program Files\mcafee\mpf\mpfinst.dll 275968 bytes File C:\Program Files\mcafee\mpf\mpfLD.inf 2696 bytes File C:\Program Files\mcafee\mpf\mpfLI.inf 3661 bytes File C:\Program Files\mcafee\mpf\MPFOEM.dll 398032 bytes File C:\Program Files\mcafee\mpf\MpfPP.dll 293472 bytes executable File C:\Program Files\mcafee\mpf\MpfShm.dll 473192 bytes executable File C:\Program Files\mcafee\mpf\MpfSvc.dll 3036856 bytes executable File C:\Program Files\mcafee\mpf\MpfSvcPS.dll 56096 bytes executable File C:\Program Files\mcafee\mpf\MPFuc.dll 58944 bytes executable File C:\Program Files\mcafee\mpf\MPFuc.inf 1887 bytes File C:\Program Files\mcafee\mpf\subst.inf 5244 bytes File C:\Program Files\mcafee\mpf\substLI.inf 2648 bytes File C:\Program Files\mcafee\mpf\twerp.dll 6084608 bytes executable File C:\Program Files\mcafee\mps 0 bytes File C:\Program Files\mcafee\mps\checkmps.dll 168560 bytes executable File C:\Program Files\mcafee\mps\instld.inf 902 bytes File C:\Program Files\mcafee\mps\McAlert.exe 247400 bytes executable File C:\Program Files\mcafee\mps\mps.dll 2305816 bytes File C:\Program Files\mcafee\mps\mpscfg.dll 567688 bytes executable File C:\Program Files\mcafee\mps\mpscfg.inf 1261 bytes File C:\Program Files\mcafee\mps\mpscore.inf 16564 bytes File C:\Program Files\mcafee\mps\mpsdeflt.inf 881 bytes File C:\Program Files\mcafee\mps\mpsevh.dll 304032 bytes File C:\Program Files\mcafee\mps\MPSJsRes.dll 159760 bytes executable File C:\Program Files\mcafee\mps\mpsld.inf 1725 bytes File C:\Program Files\mcafee\mps\mpsli.inf 5729 bytes File C:\Program Files\mcafee\mps\MPSMisp.dll 391600 bytes executable File C:\Program Files\mcafee\mps\mpsmisp.inf 2012 bytes File C:\Program Files\mcafee\mps\mpsmspap.dll 282112 bytes executable File C:\Program Files\mcafee\mps\mpsmsppv.inf 1010 bytes File C:\Program Files\mcafee\mps\mpspost.inf 2102 bytes File C:\Program Files\mcafee\mps\MpsRes2.dll 1093632 bytes executable File C:\Program Files\mcafee\mps\MpsShim.dll 447720 bytes executable File C:\Program Files\mcafee\mps\mpsuc.dll 58944 bytes executable File C:\Program Files\mcafee\mps\mpsuc.inf 1852 bytes File C:\Program Files\mcafee\mps\mpsver.dll 187136 bytes executable File C:\Program Files\mcafee\mps\subst.inf 2374 bytes File C:\Program Files\mcafee\mps\substli.inf 1580 bytes File C:\Program Files\mcafee\mqs 0 bytes File C:\Program Files\mcafee\mqs\instLD.inf 2141 bytes File C:\Program Files\mcafee\mqs\McpIns.dll 83864 bytes File C:\Program Files\mcafee\mqs\mcpins.inf 2045 bytes File C:\Program Files\mcafee\mqs\mcpLD.inf 979 bytes File C:\Program Files\mcafee\mqs\mcpLI.inf 2607 bytes File C:\Program Files\mcafee\mqs\mcqc.inf 14180 bytes File C:\Program Files\mcafee\mqs\mcshr.inf 2380 bytes File C:\Program Files\mcafee\mqs\MqsRes.dll 479872 bytes executable File C:\Program Files\mcafee\mqs\mqsuc.dll 58944 bytes executable File C:\Program Files\mcafee\mqs\mqsuc.inf 2197 bytes File C:\Program Files\mcafee\mqs\MRU.ini 20686 bytes File C:\Program Files\mcafee\mqs\QcCons32.exe 169848 bytes executable File C:\Program Files\mcafee\mqs\QcConsol.exe 182232 bytes executable File C:\Program Files\mcafee\mqs\QCJsRes.dll 231112 bytes executable File C:\Program Files\mcafee\mqs\QCLite.dll 804352 bytes executable File C:\Program Files\mcafee\mqs\QcShm.dll 447448 bytes executable File C:\Program Files\mcafee\mqs\ShrCL.exe 129184 bytes executable File C:\Program Files\mcafee\mqs\ShrCore.dll 267240 bytes executable File C:\Program Files\mcafee\mqs\ShredExt.dll 216752 bytes File C:\Program Files\mcafee\mqs\ShredShm.dll 287328 bytes File C:\Program Files\mcafee\mqs\subst.inf 2288 bytes File C:\Program Files\mcafee\msc 0 bytes File C:\Program Files\mcafee\msc\1028 0 bytes File C:\Program Files\mcafee\msc\1028\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1028\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1028\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1029 0 bytes File C:\Program Files\mcafee\msc\1029\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1029\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1029\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1030 0 bytes File C:\Program Files\mcafee\msc\1030\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1030\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1030\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1031 0 bytes File C:\Program Files\mcafee\msc\1031\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1031\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1031\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1032 0 bytes File C:\Program Files\mcafee\msc\1032\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1032\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1032\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1033 0 bytes File C:\Program Files\mcafee\msc\1033\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1033\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1033\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1034 0 bytes File C:\Program Files\mcafee\msc\1034\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1034\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1034\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1035 0 bytes File C:\Program Files\mcafee\msc\1035\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1035\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1035\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1036 0 bytes File C:\Program Files\mcafee\msc\1036\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1036\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1036\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1038 0 bytes File C:\Program Files\mcafee\msc\1038\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1038\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1038\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1040 0 bytes File C:\Program Files\mcafee\msc\1040\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1040\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1040\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1041 0 bytes File C:\Program Files\mcafee\msc\1041\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1041\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1041\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1042 0 bytes File C:\Program Files\mcafee\msc\1042\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1042\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1042\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1043 0 bytes File C:\Program Files\mcafee\msc\1043\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1043\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1043\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1044 0 bytes File C:\Program Files\mcafee\msc\1044\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1044\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1044\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1045 0 bytes File C:\Program Files\mcafee\msc\1045\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1045\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1045\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1046 0 bytes File C:\Program Files\mcafee\msc\1046\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1046\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1046\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1049 0 bytes File C:\Program Files\mcafee\msc\1049\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1049\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1049\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1053 0 bytes File C:\Program Files\mcafee\msc\1053\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1053\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1053\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\1055 0 bytes File C:\Program Files\mcafee\msc\1055\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\1055\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\1055\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\2057 0 bytes File C:\Program Files\mcafee\msc\2057\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\2057\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\2057\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\2058 0 bytes File C:\Program Files\mcafee\msc\2058\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\2058\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\2058\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\2070 0 bytes File C:\Program Files\mcafee\msc\2070\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\2070\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\2070\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\3081 0 bytes File C:\Program Files\mcafee\msc\3081\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\3081\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\3081\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\3084 0 bytes File C:\Program Files\mcafee\msc\3084\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\3084\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\3084\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\4105 0 bytes File C:\Program Files\mcafee\msc\4105\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\4105\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\4105\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall 0 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\actwizld.inf 2338 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocact.inf 1740 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocaw.inf 2982 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocawres.inf 1901 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocawui.inf 3390 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocdis.inf 3531 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocena.inf 3249 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\McOcInstru.inf 4129 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcocrollback.inf 4152 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcoemmgr.inf 1433 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcoobeof.inf 1500 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\mcsetf.inf 3998 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\MPFrgw.inf 1439 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\MPSrgw.inf 1439 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\MQSrgw.inf 1439 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\MSADrgw.inf 1448 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\MSKrgw.inf 1439 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\oemmain.inf 2307 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\oobesvc.inf 3741 bytes File C:\Program Files\mcafee\msc\Custom_Uninstall\VSOrgw.inf 1441 bytes File C:\Program Files\mcafee\msc\eulares.dll 1819608 bytes executable File C:\Program Files\mcafee\msc\help 0 bytes File C:\Program Files\mcafee\msc\help\mcafee.html 1100296 bytes File C:\Program Files\mcafee\msc\instprog.dll 168096 bytes executable File C:\Program Files\mcafee\msc\langmap.dat 46087 bytes File C:\Program Files\mcafee\msc\license.txt 76856 bytes File C:\Program Files\mcafee\msc\McActInst.exe 148496 bytes executable File C:\Program Files\mcafee\msc\mcactui.dll 898336 bytes executable File C:\Program Files\mcafee\msc\mcactwiz.dll 1320648 bytes executable File C:\Program Files\mcafee\msc\mcactwiz.ini 123 bytes File C:\Program Files\mcafee\msc\mcactwiz_ld.dll 2407744 bytes executable File C:\Program Files\mcafee\msc\McAWFwk.exe 225216 bytes executable File C:\Program Files\mcafee\msc\McAWFwk64.inf 663 bytes File C:\Program Files\mcafee\msc\McAWFwkReg64.inf 5359 bytes File C:\Program Files\mcafee\msc\mccontextust.dll 1024808 bytes executable File C:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll 185576 bytes executable File C:\Program Files\mcafee\msc\McDBMgr.dll 353472 bytes executable File C:\Program Files\mcafee\msc\McGsShm.dll 413224 bytes executable File C:\Program Files\mcafee\msc\mcinfo.exe 876176 bytes File C:\Program Files\mcafee\msc\mcinstru.dll 314856 bytes executable File C:\Program Files\mcafee\msc\McInstru.exe 306568 bytes executable File C:\Program Files\mcafee\msc\McIPTShm.dll 365832 bytes executable File C:\Program Files\mcafee\msc\McLogShm.dll 306104 bytes executable File C:\Program Files\mcafee\msc\mcltvers.ini 5163 bytes File C:\Program Files\mcafee\msc\mcmispps.dll 233992 bytes executable File C:\Program Files\mcafee\msc\mcmispps.inf 515 bytes File C:\Program Files\mcafee\msc\mcmschlp.dll 170120 bytes executable File C:\Program Files\mcafee\msc\mcmscins.dll 884680 bytes executable File C:\Program Files\mcafee\msc\McMscShm.dll 1052064 bytes executable File C:\Program Files\mcafee\msc\mcmscsub.dll 780904 bytes executable File C:\Program Files\mcafee\msc\mcmscver.dll 277240 bytes executable File C:\Program Files\mcafee\msc\McOcInstru.inf 4129 bytes File C:\Program Files\mcafee\msc\mcoemmap.ini 22258 bytes File C:\Program Files\mcafee\msc\mcoemmgr.exe 1117208 bytes executable File C:\Program Files\mcafee\msc\mcoemmgr.inf 1433 bytes File C:\Program Files\mcafee\msc\mcoemres.dll 15424 bytes executable File C:\Program Files\mcafee\msc\mcoemres.inf 1361 bytes File C:\Program Files\mcafee\msc\mcoobeof.exe 986904 bytes executable File C:\Program Files\mcafee\msc\McOobeSv.dll 1986552 bytes executable File C:\Program Files\mcafee\msc\mcprlalt.dll 198448 bytes executable File C:\Program Files\mcafee\msc\McPrsShm.dll 906600 bytes File C:\Program Files\mcafee\msc\mcregobj 0 bytes File C:\Program Files\mcafee\msc\mcregobj\11,0,630,0 0 bytes File C:\Program Files\mcafee\msc\mcregobj\11,0,630,0\mcregobj.dll 301960 bytes File C:\Program Files\mcafee\msc\mcscindx.dat 154641 bytes File C:\Program Files\mcafee\msc\McSnIePl64.dll 160344 bytes executable File C:\Program Files\mcafee\msc\mcsubmgr 0 bytes File C:\Program Files\mcafee\msc\mcsubmgr\11,0,630,0 0 bytes File C:\Program Files\mcafee\msc\mcsubmgr\11,0,630,0\mcsubmgr.dll 878784 bytes executable File C:\Program Files\mcafee\msc\mcsvrcnt.exe 1029176 bytes executable File C:\Program Files\mcafee\msc\mcsync.exe 1477472 bytes executable File C:\Program Files\mcafee\msc\mcuicfg.dll 108856 bytes executable File C:\Program Files\mcafee\msc\mcuihost.exe 890048 bytes executable File C:\Program Files\mcafee\msc\mcuinshm.dll 779320 bytes File C:\Program Files\mcafee\msc\mcuninst.exe 1137296 bytes executable File C:\Program Files\mcafee\msc\mcupdmgr.exe 1459168 bytes File C:\Program Files\mcafee\msc\McUpdShm.dll 246328 bytes executable File C:\Program Files\mcafee\msc\mispreg.exe 646480 bytes executable File C:\Program Files\mcafee\msc\msccust.inf 2804 bytes File C:\Program Files\mcafee\msc\mscdfoem.inf 41391 bytes File C:\Program Files\mcafee\msc\mscinres.dll 557104 bytes executable File C:\Program Files\mcafee\msc\mscLD.inf 1136 bytes File C:\Program Files\mcafee\msc\mscLI.inf 11527 bytes File C:\Program Files\mcafee\msc\mscmisc.inf 1329 bytes File C:\Program Files\mcafee\msc\mscoobe.inf 1984 bytes File C:\Program Files\mcafee\msc\mscprmgr.inf 1297 bytes File C:\Program Files\mcafee\msc\mscpstLI.inf 5500 bytes File C:\Program Files\mcafee\msc\mscreg.inf 589 bytes File C:\Program Files\mcafee\msc\mscrem.inf 8806 bytes File C:\Program Files\mcafee\msc\mscres.inf 1250 bytes File C:\Program Files\mcafee\msc\mscshll.inf 621 bytes File C:\Program Files\mcafee\msc\mscsvc.inf 3905 bytes File C:\Program Files\mcafee\msc\mscuicfg.dat 96149 bytes File C:\Program Files\mcafee\msc\mscuild.dll 395912 bytes executable File C:\Program Files\mcafee\msc\mscuimgr.inf 532 bytes File C:\Program Files\mcafee\msc\mscupd.inf 1570 bytes File C:\Program Files\mcafee\msc\MSFix.inf 1111 bytes File C:\Program Files\mcafee\msc\npMcSnFFPl64.dll 127408 bytes executable File C:\Program Files\mcafee\msc\oeminfo 0 bytes File C:\Program Files\mcafee\msc\oeminfo\BAAE831E-69BA-4C7F-9453-7BC7C4A8D43D 0 bytes File C:\Program Files\mcafee\msc\oeminfo\BAAE831E-69BA-4C7F-9453-7BC7C4A8D43D\AWDET.ini 1104 bytes File C:\Program Files\mcafee\msc\oeminfo\mat 0 bytes File C:\Program Files\mcafee\msc\oeminfo\mat\inst_settings.inf 2056 bytes File C:\Program Files\mcafee\msc\oeminfo\mat\inst_settings_oobe.inf 805 bytes File C:\Program Files\mcafee\msc\oeminfo\mpf 0 bytes File C:\Program Files\mcafee\msc\oeminfo\mpf\inst_settings.inf 1965 bytes File C:\Program Files\mcafee\msc\oeminfo\mpf\inst_settings_oobe.inf 1069 bytes File C:\Program Files\mcafee\msc\oeminfo\mpf\mpfUC.cab 309713 bytes File C:\Program Files\mcafee\msc\oeminfo\mps 0 bytes File C:\Program Files\mcafee\msc\oeminfo\mps\inst_settings.inf 2056 bytes File C:\Program Files\mcafee\msc\oeminfo\mps\inst_settings_oobe.inf 805 bytes File C:\Program Files\mcafee\msc\oeminfo\mps\mpsUC.cab 309393 bytes File C:\Program Files\mcafee\msc\oeminfo\mqs 0 bytes File C:\Program Files\mcafee\msc\oeminfo\mqs\inst_settings.inf 2105 bytes File C:\Program Files\mcafee\msc\oeminfo\mqs\inst_settings_oobe.inf 836 bytes File C:\Program Files\mcafee\msc\oeminfo\mqs\mqsUC.cab 32752 bytes File C:\Program Files\mcafee\msc\oeminfo\msad 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\cs 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\cs\714-108 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\cs\714-108\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\da 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\da\714-104 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\da\714-104\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\de 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\de\714-90 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\de\714-90\msaduc.cab 6239 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\el 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\el\714-113 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\el\714-113\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-AU 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-AU\714-97 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-AU\714-97\msaduc.cab 6243 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-CA 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-CA\714-94 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-CA\714-94\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-GB 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-GB\714-89 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-GB\714-89\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-US 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-US\714-88 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\en-US\714-88\msaduc.cab 6237 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\es 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\es\714-93 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\es\714-93\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\es-MX 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\es-MX\714-98 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\es-MX\714-98\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fi 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fi\714-110 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fi\714-110\msaduc.cab 6239 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fr 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fr\714-91 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fr\714-91\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fr-CA 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fr-CA\714-96 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\fr-CA\714-96\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\hu 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\hu\714-114 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\hu\714-114\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\inst_settings.inf 2090 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\inst_settings_oobe.inf 955 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\it 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\it\714-92 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\it\714-92\msaduc.cab 6239 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\jp 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\jp\714-95 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\jp\714-95\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\ko 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\ko\714-109 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\ko\714-109\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\nl 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\nl\714-102 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\nl\714-102\msaduc.cab 6237 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\no 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\no\714-105 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\no\714-105\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pl 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pl\714-107 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pl\714-107\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pt 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pt\714-103 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pt\714-103\msaduc.cab 6239 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pt-BR 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pt-BR\714-99 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\pt-BR\714-99\msaduc.cab 6239 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\ru 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\ru\714-112 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\ru\714-112\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\sainst_settings.inf 2205 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\sainst_settings_oobe.inf 982 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\sv 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\sv\714-106 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\sv\714-106\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\tr 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\tr\714-111 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\tr\714-111\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-CN 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-CN\714-100 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-CN\714-100\2052.inf 767 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-CN\714-100\msaduc.cab 6241 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-TW 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-TW\714-101 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msad\zh-TW\714-101\msaduc.cab 6239 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\cs 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\cs\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\cs\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\cs\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\cs\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\cs\subst64.cab 8581 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\da 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\da\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\da\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\da\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\da\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\da\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\de 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\de\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\de\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\de\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\de\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\de\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\el 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\el\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\el\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\el\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\el\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\el\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-AU 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-AU\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-AU\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-AU\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-AU\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-AU\subst64.cab 8581 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-CA 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-CA\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-CA\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-CA\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-CA\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-CA\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-GB 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-GB\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-GB\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-GB\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-GB\subst.cab 8575 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-GB\subst64.cab 8581 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-US 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-US\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-US\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-US\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-US\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\en-US\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es-MX 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es-MX\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es-MX\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es-MX\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es-MX\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\es-MX\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fi 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fi\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fi\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fi\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fi\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fi\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr\subst64.cab 8575 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr-CA 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr-CA\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr-CA\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr-CA\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr-CA\subst.cab 8573 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\fr-CA\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\hu 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\hu\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\hu\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\hu\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\hu\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\hu\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\inst_settings.inf 2250 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\inst_settings_oobe.inf 836 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\it 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\it\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\it\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\it\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\it\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\it\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\jp 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\jp\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\jp\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\jp\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\jp\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\jp\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ko 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ko\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ko\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ko\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ko\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ko\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\nl 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\nl\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\nl\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\nl\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\nl\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\nl\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\no 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\no\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\no\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\no\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\no\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\no\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pl 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pl\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pl\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pl\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pl\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pl\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt\subst.cab 8567 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt-BR 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt-BR\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt-BR\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt-BR\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt-BR\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\pt-BR\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ru 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ru\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ru\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ru\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ru\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\ru\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\sv 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\sv\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\sv\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\sv\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\sv\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\sv\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\tr 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\tr\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\tr\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\tr\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\tr\subst.cab 8569 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\tr\subst64.cab 8575 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-CN 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-CN\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-CN\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-CN\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-CN\subst.cab 8573 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-CN\subst64.cab 8577 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-TW 0 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-TW\Msccust.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-TW\msccust64.cab 6680 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-TW\mscoem.inf 773 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-TW\subst.cab 8571 bytes File C:\Program Files\mcafee\msc\oeminfo\MSC\zh-TW\subst64.cab 8579 bytes File C:\Program Files\mcafee\msc\oeminfo\msk 0 bytes File C:\Program Files\mcafee\msc\oeminfo\msk\inst_settings.inf 2054 bytes File C:\Program Files\mcafee\msc\oeminfo\msk\inst_settings_oobe.inf 801 bytes File C:\Program Files\mcafee\msc\oeminfo\msk\mskUC.cab 309609 bytes File C:\Program Files\mcafee\msc\oeminfo\nmc 0 bytes File C:\Program Files\mcafee\msc\oeminfo\nmc\nmcuc.cab 6124 bytes File C:\Program Files\mcafee\msc\oeminfo\vso 0 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe 0 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\inst_settings.inf 2314 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\inst_settings_oobe.inf 1037 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\vsodis.cab 7619 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\vsoena.cab 7637 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\vsofs.inf 1774 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\vsooem.inf 448 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\vsoUC.cab 309893 bytes File C:\Program Files\mcafee\msc\oeminfo\vso\oobe\vsous.inf 792 bytes File C:\Program Files\mcafee\msc\oemui.dll 8768 bytes executable File C:\Program Files\mcafee\msc\oemui.inf 1310 bytes File C:\Program Files\mcafee\msc\oemuild.dll 79424 bytes executable File C:\Program Files\mcafee\msc\oemuild.inf 1343 bytes File C:\Program Files\mcafee\msc\OOBE 0 bytes File C:\Program Files\mcafee\msc\OOBE\mcocact.dll 529584 bytes executable File C:\Program Files\mcafee\msc\OOBE\mcocaw.dll 1309312 bytes executable File C:\Program Files\mcafee\msc\OOBE\mcocawres.dll 878760 bytes executable File C:\Program Files\mcafee\msc\OOBE\mcocawui.dll 871544 bytes executable File C:\Program Files\mcafee\msc\OOBE\mcocrollback.exe 459008 bytes executable File C:\Program Files\mcafee\msc\override.inf 659 bytes File C:\Program Files\mcafee\msc\RprtShm.dll 404984 bytes File C:\Program Files\mcafee\msc\subst.inf 3787 bytes File C:\Program Files\mcafee\msc\subst2.inf 2757 bytes File C:\Program Files\mcafee\msc\TskTCShm.dll 469832 bytes executable File C:\Program Files\mcafee\msc\2052 0 bytes File C:\Program Files\mcafee\msc\2052\instLD.inf 2623 bytes File C:\Program Files\mcafee\msc\2052\msclcres.inf 881 bytes File C:\Program Files\mcafee\msc\2052\mscpstLD.inf 1108 bytes File C:\Program Files\mcafee\msc\mclwapi.dll 176312 bytes executable File C:\Program Files\mcafee\msc\mcprlres.dll 4085360 bytes executable File C:\Program Files\mcafee\msc\mscjsres.dll 3831480 bytes executable File C:\Program Files\mcafee\msk 0 bytes File C:\Program Files\mcafee\msk\mskoeplg.dll 189672 bytes executable File C:\Program Files\mcafee\msk\chrome.manifest 407 bytes File C:\Program Files\mcafee\msk\Config 0 bytes File C:\Program Files\mcafee\msk\Config\core 0 bytes File C:\Program Files\mcafee\msk\Config\core\3590 0 bytes File C:\Program Files\mcafee\msk\Config\core\3590\config.lua 1664 bytes File C:\Program Files\mcafee\msk\Config\core\3590\core.lua 1559680 bytes File C:\Program Files\mcafee\msk\Config\core\3590\core.rgx 2164262 bytes File C:\Program Files\mcafee\msk\Config\core\3590\custom.lua 13552 bytes File C:\Program Files\mcafee\msk\Config\core\3590\dometa.lua 1092344 bytes File C:\Program Files\mcafee\msk\Config\core\3590\filter.lua 5240 bytes File C:\Program Files\mcafee\msk\Config\core\3590\main.lua 35144 bytes File C:\Program Files\mcafee\msk\Config\core\3590\manifest 1330 bytes File C:\Program Files\mcafee\msk\Config\core\3590\overrides.lua 888 bytes File C:\Program Files\mcafee\msk\Config\core\3590\phish.lua 2168 bytes File C:\Program Files\mcafee\msk\Config\core\3590\received.lua 29464 bytes File C:\Program Files\mcafee\msk\Config\core\3590\tlds.lua 18496 bytes File C:\Program Files\mcafee\msk\Config\core\3590\utils.lua 8856 bytes File C:\Program Files\mcafee\msk\Config\cstreams 0 bytes File C:\Program Files\mcafee\msk\Config\cstreams\78193 0 bytes File C:\Program Files\mcafee\msk\Config\cstreams\78193\cstreams.lua 4928 bytes File C:\Program Files\mcafee\msk\Config\cstreams\78193\cstreams.rgx 514780 bytes File C:\Program Files\mcafee\msk\Config\cstreams\78193\manifest 294 bytes File C:\Program Files\mcafee\msk\Config\mas_ui_0 561 bytes File C:\Program Files\mcafee\msk\Config\rbl 0 bytes File C:\Program Files\mcafee\msk\Config\rbl\5 0 bytes File C:\Program Files\mcafee\msk\Config\rbl\5\manifest 142 bytes File C:\Program Files\mcafee\msk\Config\rbl\5\rbl.lua 376 bytes File C:\Program Files\mcafee\msk\Config\sentag 0 bytes File C:\Program Files\mcafee\msk\Config\sentag\28000 0 bytes File C:\Program Files\mcafee\msk\Config\sentag\28000\manifest 303 bytes File C:\Program Files\mcafee\msk\Config\sentag\28000\sentag.lua 344 bytes File C:\Program Files\mcafee\msk\Config\sentag\28000\sentence.lut 5568 bytes File C:\Program Files\mcafee\msk\Config\sentag\28000\tags.lut 472 bytes File C:\Program Files\mcafee\msk\IMskTB.xpt 668 bytes File C:\Program Files\mcafee\msk\install.rdf 679 bytes File C:\Program Files\mcafee\msk\masecore64.dll 3208144 bytes executable File C:\Program Files\mcafee\msk\mcabimp.dll 241184 bytes executable File C:\Program Files\mcafee\msk\mskcmcnt.cab 3292548 bytes File C:\Program Files\mcafee\msk\mskcmcnt.inf 2227 bytes File C:\Program Files\mcafee\msk\mskcore64.inf 4548 bytes File C:\Program Files\mcafee\msk\mskcshim.dll 530608 bytes executable File C:\Program Files\mcafee\msk\mskengn.dll 189696 bytes executable File C:\Program Files\mcafee\msk\mskjsres.dll 271536 bytes executable File C:\Program Files\mcafee\msk\mskLI.inf 4105 bytes File C:\Program Files\mcafee\msk\mskmisp.dll 308640 bytes File C:\Program Files\mcafee\msk\mskmisp.inf 2203 bytes File C:\Program Files\mcafee\msk\mskola64.dll 316368 bytes executable File C:\Program Files\mcafee\msk\mskoladd.dll 251960 bytes executable File C:\Program Files\mcafee\msk\mskplg64.inf 3792 bytes File C:\Program Files\mcafee\msk\MskPlgMn.dll 127384 bytes executable File C:\Program Files\mcafee\msk\mskppv.dll 134624 bytes executable File C:\Program Files\mcafee\msk\mskpxplg.dll 136136 bytes executable File C:\Program Files\mcafee\msk\mskres.dll 817960 bytes executable File C:\Program Files\mcafee\msk\MskSet.dll 449744 bytes executable File C:\Program Files\mcafee\msk\MskSet64.dll 578512 bytes executable File C:\Program Files\mcafee\msk\msksrv.inf 3697 bytes File C:\Program Files\mcafee\msk\msksrvr.dll 115536 bytes executable File C:\Program Files\mcafee\msk\msktb.dll 157248 bytes File C:\Program Files\mcafee\msk\msktbird.jar 27637 bytes File C:\Program Files\mcafee\msk\msktbird_3.jar 26796 bytes File C:\Program Files\mcafee\msk\mskuc.dll 58944 bytes executable File C:\Program Files\mcafee\msk\mskuc.inf 1764 bytes File C:\Program Files\mcafee\msk\mskupd.dll 222120 bytes executable File C:\Program Files\mcafee\msk\mskwm.dll 253544 bytes executable File C:\Program Files\mcafee\msk\mskxagnt.exe 137672 bytes executable File C:\Program Files\mcafee\msk\mskxaif.dll 132552 bytes executable File C:\Program Files\mcafee\msk\oemcfg.xml 435 bytes File C:\Program Files\mcafee\msk\rptspam.dll 118096 bytes executable File C:\Program Files\mcafee\msk\rptspm64.dll 128944 bytes executable File C:\Program Files\mcafee\msk\substLI.inf 2762 bytes File C:\Program Files\mcafee\msk\tbirdins.dll 138696 bytes executable File C:\Program Files\mcafee\msm 0 bytes File C:\Program Files\mcafee\msm\McSmpUi.dll 216488 bytes File C:\Program Files\mcafee\msm\McSmtFwk.exe 205152 bytes executable File C:\Program Files\mcafee\msm\McSmtMsg64.inf 2426 bytes File C:\Program Files\mcafee\msm\McSmtStr.dll 259760 bytes executable File C:\Program Files\mcafee\msm\McSmtTsk.dll 206688 bytes executable File C:\Program Files\mcafee\virusscan 0 bytes File C:\Program Files\mcafee\virusscan\McVSPP.dll 285232 bytes executable File C:\Program Files\mcafee\virusscan\DAT 0 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0 0 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0\avvclean.dat 14034429 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0\avvnames.dat 2782677 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0\avvscan.dat 173628997 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0\bootclean.dat 3044333 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0\bootnames.dat 297629 bytes File C:\Program Files\mcafee\virusscan\DAT\6605.0\bootscan.dat 5045101 bytes File C:\Program Files\mcafee\virusscan\Engine 0 bytes File C:\Program Files\mcafee\virusscan\Engine\5400.1158 0 bytes File C:\Program Files\mcafee\virusscan\Engine\5400.1158\aveng.ini 29 bytes File C:\Program Files\mcafee\virusscan\Engine\5400.1158\config.dat 5644 bytes File C:\Program Files\mcafee\virusscan\Engine\5400.1158\mscan64a.dll 4737128 bytes executable File C:\Program Files\mcafee\virusscan\Engine\5400.1158\signlic.txt 7842 bytes File C:\Program Files\mcafee\virusscan\EScnPlug.dll 479632 bytes executable File C:\Program Files\mcafee\virusscan\instLD.inf 1498 bytes File C:\Program Files\mcafee\virusscan\McAvtSub.dll 250472 bytes File C:\Program Files\mcafee\virusscan\mcctxmnu.dll 182744 bytes executable File C:\Program Files\mcafee\virusscan\McInsUpd.exe 316392 bytes executable File C:\Program Files\mcafee\virusscan\McOasShm.dll 481456 bytes executable File C:\Program Files\mcafee\virusscan\mcods.exe 502032 bytes executable File C:\Program Files\mcafee\virusscan\mcodsax.dll 319192 bytes File C:\Program Files\mcafee\virusscan\mcodsps.dll 51464 bytes executable File C:\Program Files\mcafee\virusscan\McOdsShm.dll 430432 bytes executable File C:\Program Files\mcafee\virusscan\mcqtax.dll 345496 bytes executable File C:\Program Files\mcafee\virusscan\McQtLib.dll 220072 bytes executable File C:\Program Files\mcafee\virusscan\McVsMap.exe 193792 bytes executable File C:\Program Files\mcafee\virusscan\mcvsoins.dll 139984 bytes executable File C:\Program Files\mcafee\virusscan\mcvsoins64.dll 165752 bytes File C:\Program Files\mcafee\virusscan\McVsPs.dll 80528 bytes executable File C:\Program Files\mcafee\virusscan\McVsQt.dll 220072 bytes executable File C:\Program Files\mcafee\virusscan\McVsShld.exe 381040 bytes executable File C:\Program Files\mcafee\virusscan\mvsap.dll 261560 bytes executable File C:\Program Files\mcafee\virusscan\MVsCfg.dll 361176 bytes executable File C:\Program Files\mcafee\virusscan\mvsdeflt.dll 10168 bytes executable File C:\Program Files\mcafee\virusscan\MVsInst.exe 206688 bytes executable File C:\Program Files\mcafee\virusscan\mvslog.dll 336232 bytes executable File C:\Program Files\mcafee\virusscan\mvsoem.dll 58944 bytes executable File C:\Program Files\mcafee\virusscan\MVsScan.dll 688776 bytes executable File C:\Program Files\mcafee\virusscan\mvsuicfg.dat 3139 bytes File C:\Program Files\mcafee\virusscan\MVSVer.dll 196400 bytes executable File C:\Program Files\mcafee\virusscan\NaiAnn.dll 715520 bytes executable File C:\Program Files\mcafee\virusscan\NaiAnnPs.dll 53248 bytes File C:\Program Files\mcafee\virusscan\SubAvt.dll 175288 bytes File C:\Program Files\mcafee\virusscan\subst.inf 2598 bytes File C:\Program Files\mcafee\virusscan\vsapi64.inf 5649 bytes File C:\Program Files\mcafee\virusscan\vscan.bof 110148 bytes File C:\Program Files\mcafee\virusscan\VSJsRes.dll 411368 bytes executable File C:\Program Files\mcafee\virusscan\vso64.inf 6986 bytes File C:\Program Files\mcafee\virusscan\vsoLI_CD.inf 2866 bytes File C:\Program Files\mcafee\virusscan\vsomain64.inf 8868 bytes File C:\Program Files\mcafee\virusscan\vsopost.inf 8514 bytes File C:\Program Files\mcafee\virusscan\vsores.dll 1560336 bytes executable File C:\Program Files\mcafee\virusscan\vsores64.inf 1486 bytes File C:\Program Files\mcafee\virusscan\vsouc.inf 2735 bytes File C:\Program Files\mcafee.com 0 bytes File C:\Program Files\mcafee.com\agent 0 bytes File C:\Program Files\mcafee.com\agent\mcagent.exe 1675160 bytes executable File C:\Program Files\mcafee.com\agent\mcagntps.dll 53760 bytes executable File C:\Program Files\mcafee.com\agent\mcscentr.adf 10890 bytes File C:\Program Files\mcafee.com\agent\mcupdate.exe 911720 bytes executable File C:\Program Files\mcafee.com\agent\msclgmis.inf 3204 bytes File C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstaller.exe (size mismatch) 53632/54632 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Esl 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Esl\AiodLite.dll 104344 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\adoberfp.dll 239512 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\cryptocme2.sig 1607 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Onix32.dll 759816 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\A3DUtils.dll 205720 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ACE.dll 818568 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe 296344 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Acrofx32.dll 63384 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.dll 24731544 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe 1480600 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32Info.exe 17824 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRdIF.dll 102808 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroTextExtractor.exe 49064 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Adobe.Reader.Dependencies.manifest 1472 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe 1240992 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeLinguistic.dll 757664 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeXMP.dll 304536 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AGM.dll 5509512 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AGMGPUOptIn.ini 1727 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ahclient.dll 225656 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll 183696 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.POL 8192 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\authplay.dll 6543768 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AXE8SharedExpat.dll 174496 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AXSLE.dll 595344 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\BIB.dll 110472 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\BIBUtils.dll 154520 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll 183696 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.POL 8192 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ccme_base.dll 1785856 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\CoolType.dll 2695064 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\cryptocme2.dll 1839104 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Eula.exe 94608 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ExtendScript.dll 670624 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\icucnv40.dll 721832 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\icudt40.dll 96144 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\AdobeID.pdf 82070 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\DefaultID.pdf 80651 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\AdobeID.pdf 158882 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\DefaultID.pdf 154954 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Javascripts 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Javascripts\JSByteCodeWin.bin 1189004 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\JP2KLib.dll 686464 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\eula.ini 1040 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\license.html 43061 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL\eula.ini 1136 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL\license.html 61600 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\accessibility.POL 44032 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Acroform.POL 427520 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\AdobeCollabSync.POL 7168 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Annots.POL 506368 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\BRdlang32.POL 55296 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Checkers.POL 124928 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\DigSig.POL 130048 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\DVA.POL 18432 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\eBook.POL 7168 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\EScript.POL 40960 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\IA32.POL 3584 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\makeaccessible.POL 74752 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Multimedia.POL 79360 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\pddom.POL 10752 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\PPKLite.POL 521728 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\RdLang32.POL 1379840 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\ReadOutLoud.POL 11264 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\reflow.POL 4608 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\SaveAsRTF.POL 18432 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Search.POL 24064 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\SendMail.POL 15872 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\DEXShare.asfx 32684 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx 614 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Spelling.POL 10240 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\updater.POL 11776 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\WebLink.POL 29184 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\logsession.dll 368096 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\LogTransport2.exe 315872 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\PDFPrevHndlr.dll 88992 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\PDFSigQFormalRep.pdf 468206 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\pe.dll 1629576 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Accessibility.api 519267 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\adobepdf.xdc 45935 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP\AdobePDF417.pmp 109056 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP\DataMatrix.pmp 521216 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP\QRCode.pmp 78848 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm.api 12394595 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroSign.prc 8574 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf 57218 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf 40726 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf 108763 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Dynamic.pdf 36986 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Faces.pdf 33013 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Pointers.pdf 46897 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\SignHere.pdf 327673 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Standard.pdf 115957 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\StandardBusiness.pdf 67699 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\Words.pdf 112498 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annots.api 6103651 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Checkers.api 861283 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\DigSig.api 1461347 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\DVA.api 150115 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\eBook.api 51299 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\EScript.api 1753699 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\IA32.api 99427 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\MakeAccessible.api 2312803 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\Flash.mpp 120832 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\MCIMPP.mpp 93696 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\QuickTime.mpp 278528 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\WindowsMedia.mpp 218112 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\Flash.POL 2560 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\Mcimpp.POL 8192 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\QuickTime.POL 2560 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\WindowsMedia.POL 2560 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia.api 1526883 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\PDDom.api 429667 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\PPKLite.api 7632483 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\ReadOutLoud.api 112227 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\reflow.api 347747 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\SaveAsRTF.api 406627 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Search.api 430691 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\SendMail.api 157795 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Spelling.api 278115 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Updater.api 169571 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\weblink.api 305251 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\2d.x3d 552840 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\3difr.x3d 269712 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\drvDX9.x3d 814992 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\drvSOFT.x3d 218000 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\prc 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\prc\MyriadCAD.otf 78276 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\prcr.x3d 3150224 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\tesselate.x3d 22424 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\pmd.cer 420 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe 35736 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\rt3d.dll 2215312 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\RTC.der 1098 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ScCore.dll 589712 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\DEXShare.spi 1119017 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg 584045 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\SPPlugins 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\SPPlugins\ADMPlugin.apl 1396736 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\sqlite.dll 249232 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\forms_received.gif 615 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviews_sent.gif 909 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\add_reviewer.gif 1338 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\bl.gif 83 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\br.gif 82 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\create_form.gif 1194 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\distribute_form.gif 821 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\email_all.gif 1443 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\email_initiator.gif 1360 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\ended_review_or_form.gif 807 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\end_review.gif 900 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\forms_distributed.gif 613 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\forms_super.gif 552 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\form_responses.gif 969 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\info.gif 578 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\main.css 11930 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\open_original_form.gif 806 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\pdf.gif 480 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviewers.gif 1452 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviews_joined.gif 914 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviews_super.gif 814 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_browser.gif 1151 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_email.gif 1405 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_same_reviewers.gif 962 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_shared.gif 1365 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\rss.gif 222 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\server_issue.gif 576 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\server_lg.gif 1255 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\server_ok.gif 225 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\stop_collection_data.gif 915 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\submission_history.gif 906 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\tl.gif 85 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\tr.gif 85 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\trash.gif 1161 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOffNotificationInAcrobat.gif 824 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOffNotificationInTray.gif 995 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOnNotificationInAcrobat.gif 831 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOnNotificationInTray.gif 1002 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\warning.gif 369 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ViewerPS.dll 17304 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\wow_helper.exe 73624 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\ReadMe.htm 16758 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\ReadMePOL.htm 17476 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CMap 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CMap\Identity-H 8228 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CMap\Identity-V 2761 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\ENUtxt.pdf 7582 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\AdobePiStd.otf 89660 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd-Bold.otf 37524 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd-BoldOblique.otf 38984 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd-Oblique.otf 39332 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd.otf 37860 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-Bold.otf 217028 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-BoldIt.otf 257148 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-It.otf 258056 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-Regular.otf 217280 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-Bold.otf 98056 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-BoldIt.otf 101744 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-It.otf 100396 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-Regular.otf 96560 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\SY______.PFM 672 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\zx______.pfm 683 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\zy______.pfm 684 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\SY______.PFB 34705 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\ZX______.PFB 75573 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\ZY______.PFB 96418 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2\DisplayLanguageNames.pl.txt 28246 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2\DisplayLanguageNames.pl_PL.txt 28246 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol.fca 972 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol.hyp 118784 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol103.hsp 720111 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol32.clx 32766 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\SaslPrep 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\SaslPrep\SaslPrepProfile_norm_bidi.spp 13724 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\ICU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\ICU\icudt26l.dat 214512 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe\symbol.txt 10381 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe\zdingbat.txt 11932 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CENTEURO.TXT 12948 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CORPCHAR.TXT 18952 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CROATIAN.TXT 13552 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CYRILLIC.TXT 13432 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\GREEK.TXT 13355 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ICELAND.TXT 14204 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMAN.TXT 14423 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMANIAN.TXT 14792 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\SYMBOL.TXT 15731 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\TURKISH.TXT 12825 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\UKRAINE.TXT 4634 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1250.TXT 9828 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1251.TXT 9503 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1252.TXT 9653 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1253.TXT 9236 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1254.TXT 9644 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1257.TXT 9516 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1258.TXT 9506 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Setup Files 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Setup Files\{AC76BA86-7AD7-1045-7B44-AA1000000001} 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (size mismatch) 64928/72336 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (size mismatch) 63912/60568 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.POL (size mismatch) 312320/314368 bytes executable File C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AcrobatUpdater.exe 319400 bytes executable File C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeExtractFiles.dll 70584 bytes executable File C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\ReaderUpdater.exe 319400 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Help\en_us 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader\X 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader\X\using 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader\X\using\helpmap.txt 721 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader\X 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader\X\using 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader\X\using\helpmap.txt 548 bytes File C:\Program Files (x86)\Common Files\Adobe\HelpCfg\en_US\Reader_10.0.helpcfg 344 bytes File C:\Program Files (x86)\Common Files\Adobe\HelpCfg\pl_PL\Reader_10.0.helpcfg 349 bytes File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe (size mismatch) 129408/130408 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll (size mismatch) 13413248/19633000 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe (size mismatch) 102272/103272 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\AdobeCP.dll 5497216 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\adobecp.vch 639919 bytes File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\AdobeCP15.dll (size mismatch) 3507584/3508584 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\airappinstaller.exe (size mismatch) 53632/54632 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll (size mismatch) 8797056/16287592 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\WebKit.dll (size mismatch) 4771200/4791656 bytes executable File C:\Program Files (x86)\Common Files\mcafee\Installer 0 bytes File C:\Program Files (x86)\Common Files\mcafee\Installer\cleanup.ini 3485 bytes File C:\Program Files (x86)\Common Files\mcafee\Installer\mcinst.exe 827456 bytes executable File C:\Program Files (x86)\Common Files\mcafee\msc 0 bytes File C:\Program Files (x86)\Common Files\mcafee\msc\coreps.dll 93688 bytes executable File C:\Program Files (x86)\Common Files\mcafee\msc\LangSel.dll 194840 bytes File C:\Program Files (x86)\Common Files\mcafee\msc\mcbr3264.dll 109856 bytes executable File C:\Program Files (x86)\Common Files\mcafee\msc\McRTMui.dll 464176 bytes executable File C:\Program Files (x86)\Common Files\mcafee\msc\mispps.dll 171432 bytes executable File C:\Program Files (x86)\Common Files\mcafee\msc\submgr.dll 645648 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\chrome.manifest 111 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\components 0 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\components\ScriptFF.gif 624 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\components\scriptff.js 596 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\components\ScriptFF.xul 272 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\dainstall.exe 74600 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\install.rdf 803 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\lockdown.dll 39032 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\mcshield.dll 385624 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\mfeavfa.dll 66896 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\mfefwctl.dll 154952 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\mfehida.dll 74600 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\mytilus3.dll 84888 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\mytilus3_worker.dll 312560 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\rkscan.dll 287280 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\scriptff.dll 28760 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptFF.gif 624 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptFF.js 596 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptFF.xul 272 bytes File C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120723201251.dll 79744 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\scriptsn.dll 79744 bytes executable File C:\Program Files (x86)\Common Files\mcafee\SystemCore\Strings.bin 34663 bytes File C:\Program Files (x86)\Common Files\microsoft shared\VC\msdia80.dll (size mismatch) 625152/641536 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\avcodec-52.dll 1846344 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\avformat-52.dll 203848 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\avutil-50.dll 104520 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome.dll 25917496 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome_frame_helper.dll 55864 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome_frame_helper.exe 89144 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome_launcher.exe 92216 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\d3dcompiler_43.dll 2106216 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\d3dx9_43.dll 1998168 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Extensions 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Extensions\external_extensions.json 99 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\flashplayercplapp.cpl 404640 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\gcswf32.dll 6333088 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\icudt.dll 9075768 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Installer 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Installer\chrome.7z 83850019 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Installer\setup.exe 1271352 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\libegl.dll 106552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\libglesv2.dll 496184 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\hi.dll 371256 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\am.dll 298552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ar.dll 308792 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\bg.dll 366136 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\bn.dll 366648 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ca.dll 332856 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\cs.dll 321080 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\da.dll 311352 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\de.dll 298552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\el.dll 394808 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\en-GB.dll 294968 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\en-US.dll 294456 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\es-419.dll 332856 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\es.dll 338488 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\et.dll 298552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fa.dll 324152 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fi.dll 309304 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fil.dll 341560 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fr.dll 343096 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\gu.dll 356920 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\he.dll 279608 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\hr.dll 312376 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\hu.dll 331320 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\id.dll 310328 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\it.dll 329272 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ja.dll 242744 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\kn.dll 384568 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ko.dll 228920 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\lt.dll 318520 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\lv.dll 316472 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ml.dll 447544 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\mr.dll 360504 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\nb.dll 309304 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\nl.dll 327224 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\pl.dll 332856 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\pt-BR.dll 322616 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\pt-PT.dll 329272 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ro.dll 334904 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ru.dll 358456 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sk.dll 331832 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sl.dll 308280 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sr.dll 345144 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sv.dll 307256 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sw.dll 282168 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ta.dll 411704 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\te.dll 376376 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\th.dll 355384 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\tr.dll 318008 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\uk.dll 348216 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\vi.dll 322104 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\zh-CN.dll 194104 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\zh-TW.dll 193080 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\nacl64.dll 2452536 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\nacl64.exe 1476664 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\npchrome_frame.dll 6212152 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\pdf.dll 3649592 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\plugin.vch 498627 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\ppgooglenaclpluginchrome.dll 329272 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\resources.pak 2439126 bytes File C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (size mismatch) 1012792/859976 bytes executable File C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (size mismatch) 182768/194032 bytes executable <-- ROOTKIT !!! File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_zh-CN_64_AFEA62AEFC56F445.dll 707248 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_bg_4074563322A92B86.dll 554672 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ca_48758D4284E1CF09.dll 541872 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_cs_0F04F96F707F23F4.dll 540848 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_da_97D33C0C858471F9.dll 531120 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_de_8251A7D27AF3323C.dll 525488 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_el_F41C324996B886C6.dll 589488 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en-GB_A7584E1CF049BD7B.dll 523952 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll 2013360 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_es_2BE8A68F55B395DD.dll 542384 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_fil_0071BC6018071578.dll 547504 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_fi_78E90CBF86D1F6EA.dll 535728 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_fr_9DEC13D2629B5A08.dll 550064 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_hi_67E1FE88C4333F7B.dll 592560 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_hr_988409DD50190882.dll 532144 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_hu_18A7006EF2B488CA.dll 544944 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_id_98364288BBB09CC5.dll 531632 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_is_60A4F5F49ACB6000.dll 537776 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_it_A82B711CFC49E9DD.dll 538288 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ja_823F21A18D628A46.dll 549040 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleCld_26623DE26D4DBD2D.dll 1206960 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleQuickSearchBoxSetup_F8DB49E787CC0771.exe 2938352 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar.7.1.1821.1806.manifest.xml 16985 bytes File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_D1B8F90352BD52A9.dll 3082416 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_64_136C3706C4509D97.dll 4663472 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_ja_32_D7397CC65FA11CF0.dll 317616 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_ja_64_21276A3BC060C732.dll 416944 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_zh-CN_32_A5B37DD91AFCF7CD.dll 555184 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_et_E78F15F19B24A4D5.dll 530608 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ko_D905A071ABFF1B7B.dll 515760 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sl_52DDAFE99637F72B.dll 535216 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_lt_C404E000E80AB3DF.dll 540336 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_lv_EA1628B75E1094DC.dll 537264 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_nl_3AAC294F9909F6B2.dll 536240 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_no_BB2DD1B0E5F85CDE.dll 532144 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_pl_BFB5E9018AAD2B4D.dll 543408 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_pt-BR_14B054AF84DB147F.dll 543408 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_pt-PT_94ACE028001DE37F.dll 547504 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ro_806BC80260FF2B38.dll 549040 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ru_67B78656D7BF50B9.dll 580272 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sk_8E484E435DB524A5.dll 546992 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sr_90B923AEEB433763.dll 560816 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sv_C2D96AA6195FD1BC.dll 533680 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_th_7735E13BE92FAF8E.dll 587952 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_tr_C1231F6B5AF97FA1.dll 536752 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_uk_0F7FD6DA968F6862.dll 569520 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_vi_37252089E2D4FAD9.dll 551600 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_zh-CN_10E08B6D7CB47AFE.dll 924848 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_zh-TW_1965F9F500EFCFCD.dll 491696 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_EAA6E347FFC35CC8.exe 1053872 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_32_8AD791F283771CB0.exe 307376 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_64_851D90A00F31A295.exe 399024 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar_32_79A4E6A8AACC0F12.dll 305328 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar_64_9F1D475DC3704B46.dll 410288 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdaterService_5898FABCFA121C11.exe 182768 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdateSetup_90698EA083D01143.exe 568472 bytes File C:\Program Files (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_86D23231A3A85F4A.exe 1706552 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (size mismatch) 307376/309704 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe (size mismatch) 399024/400840 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (size mismatch) 305328/194504 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (size mismatch) 410288/256456 bytes executable File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642 0 bytes File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\gth.dll 49208 bytes executable File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\gtn.dll 150072 bytes executable File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\Readme.url 133 bytes File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll 1007160 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57 0 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_am.dll 22680 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ar.dll 24728 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_bg.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_bn.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ca.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_cs.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_da.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_de.dll 28824 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_el.dll 28824 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_en-GB.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_en.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_es-419.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_es.dll 28824 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_et.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fa.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fi.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fr.dll 28312 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_gu.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_hi.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_hr.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_hu.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_id.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_is.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_it.dll 28312 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_iw.dll 24216 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ja.dll 22680 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_kn.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ko.dll 22168 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_lt.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_lv.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ml.dll 29336 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_mr.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleCrashHandler.exe 140952 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdate.exe 136176 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdateBroker.exe 59032 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdateHelper.msi 25088 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdateOnDemand.exe 59032 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_nl.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_no.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_pl.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_pt-BR.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_pt-PT.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ro.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ru.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sk.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sl.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sr.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sv.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sw.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ta.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_te.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_th.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_tr.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_uk.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ur.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_vi.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_zh-CN.dll 20120 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_zh-TW.dll 20120 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll 235672 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\psmachine.dll 138904 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\psuser.dll 138904 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdate.dll 798872 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fil.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ms.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\12.0.742.112 0 bytes File C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\12.0.742.112\chrome_installer.exe 22267448 bytes executable File C:\Program Files (x86)\Google\Update\Offline 0 bytes File C:\Program Files (x86)\McAfee\msc 0 bytes File C:\Program Files (x86)\McAfee\msc\mchlp32.exe 574368 bytes executable File C:\Program Files (x86)\McAfee\msc\mcshell.exe 429144 bytes executable File C:\Program Files (x86)\McAfee\msc\McSnIePl.dll 141840 bytes File C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll 111416 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor 0 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\ActUtil.exe 191008 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\chr.inf 881 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\chrome.manifest 145 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\contents.rdf 632 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\default.txt 548 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Download 0 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\install.rdf 916 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\mcbrwctl.dll 388208 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx 92212 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll 281600 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\McPlgUI.dll 184792 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe 103440 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\McSACorePS.dll 59168 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll 231648 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Oem.txt 140 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll 20032 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saOemMgr.exe 53464 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saplugin.dll 155464 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\sares.dll 1899736 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saSets.ini 1518 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\sasshmod.dll 2301960 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saSubMgr.dll 206928 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe 282648 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saUpd.exe 331064 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\saupkeep.dll 421728 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\SA_indep.inf 6806 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\SA_main.inf 5467 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\SA_x64.inf 1410 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts 0 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon.html 14666 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_logo.gif 2121 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\balloon_logo_plus.gif 2143 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\blackpixel.gif 35 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\bullet.gif 68 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_black_lock.gif 1122 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_disabled.gif 1408 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_green.gif 1273 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_green_lock.gif 1273 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_grey.gif 1467 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_grey_lock.gif 1467 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_hs.gif 1192 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_hs_lock.gif 1192 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_red.gif 1276 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_red_lock.gif 1276 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_yellow.gif 1321 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_yellow_lock.gif 1321 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\corner-solid.gif 86 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cornersm-hollow.gif 147 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\cornersm-solid.gif 70 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\download_careful.gif 8162 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\download_unsafe.gif 6984 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\down_arrow.gif 60 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\empty.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\error-icon.gif 269 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\favicon.ico 894 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\gleftarrow.gif 143 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\green.gif 1072 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\grightarrow.gif 145 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_c.gif 297 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_l.gif 1719 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_r.gif 1622 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_banner_sep.gif 512 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_c.gif 875 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_l.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_r.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_bottom_sep.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_facet.gif 300 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_footer_c.gif 90 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_footer_l.gif 497 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_footer_r.gif 497 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_header_c.gif 164 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_header_l.gif 490 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_header_r.gif 970 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_icon.gif 727 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\g_upsell_border.gif 50 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_facet.gif 284 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_footer_c.gif 65 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_footer_l.gif 186 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_footer_r.gif 288 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_c.gif 162 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_l.gif 489 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_r.gif 961 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_header_r_nox.gif 458 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\button_black.gif 1122 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\common.js 11419 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\hackersafe.gif 1552 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif 2662 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_black.gif 1069 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protectedmode.gif 3749 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_icon.gif 873 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small-buttonC.gif 147 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\unselected_tab.gif 1066 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_header_c.gif 164 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_c.gif 284 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\hs.gif 915 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\hs_icon.gif 3750 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-background.gif 294 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-top.gif 357 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\inst-xup.gif 2352 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\large-buttonC.gif 181 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\large-buttonL.gif 263 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\large-buttonR.gif 264 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\main.js 8182 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafeesiteadvisor.gif 504 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_logo.gif 1356 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcafee_logo_shield.png 3986 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\mcwedge.gif 4259 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_arrow_down.gif 418 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_arrow_up.gif 418 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_black_lock.gif 1069 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_disabled.gif 1315 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_green.gif 1230 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_green_lock.gif 1230 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_grey.gif 1392 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_grey_lock.gif 1392 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_hs.gif 1337 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_hs_lock.gif 1337 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_red.gif 1246 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_red_lock.gif 1246 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_yellow.gif 1241 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\nb_button_yellow_lock.gif 1241 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protection.gif 1053 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protmode-off.gif 2123 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\protmode-on.gif 2168 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\question-icon.gif 555 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\red.gif 1064 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\redarrow.gif 49 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\rleftarrow.gif 145 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\rrightarrow.gif 144 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_c.gif 309 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_l.gif 1899 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_r.gif 1870 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_banner_sep.gif 514 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_blocked.png 2867 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_c.gif 875 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_l.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_r.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_bottom_sep.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_upsell_border.gif 50 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\r_x_icon.gif 2551 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-logo-plus.gif 1637 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-logo-white.gif 4076 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sa-logo.gif 1353 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\sachplg.js 8084 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safe.xul 759 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_green.gif 1314 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_grey.gif 1306 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_red.gif 1316 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\safeshare_yellow.gif 1320 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\saffplg.js 23161 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SAPlus-graphic.gif 4644 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\searchglass.gif 355 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\selected_tab.gif 1227 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\siteadvisor.gif 624 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA1.gif 1649 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA2.gif 1643 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA3.gif 1638 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderA4.gif 1652 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD1.gif 437 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD2.gif 562 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD3.gif 563 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\SliderD4.gif 433 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small-buttonL.gif 242 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\small-buttonR.gif 234 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_bottom_c.gif 328 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_bottom_l.gif 41 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_bottom_r.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_copylink_off.gif 4172 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_copylink_on.gif 3997 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_facebook_off.gif 3241 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_facebook_on.gif 3235 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_footer_c.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_footer_l.gif 44 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_footer_r.gif 35 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_header_c.gif 269 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_header_l.gif 595 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_header_r.gif 1353 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_twitter_off.gif 3286 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ss_twitter_on.gif 3101 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\untested.gif 676 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\vertical_divider.png 361 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\vertical_divider_live.png 1055 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\warning.html 19124 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\warning.js 375 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wleftarrow.gif 145 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\wrightarrow.gif 145 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_c.gif 289 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_l.gif 1436 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_r.gif 1794 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_banner_sep.gif 301 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_c.gif 875 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_l.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_r.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_bottom_sep.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_footer_c.gif 42 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_footer_l.gif 169 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_footer_r.gif 172 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_header_l.gif 495 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_header_r.gif 981 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_icon.gif 756 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\w_upsell_border.gif 50 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\xdown.gif 1234 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\xup.gif 77 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\xup_light.png 1086 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yellow.gif 659 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yleftarrow.gif 144 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\yrightarrow.gif 144 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\ytri.gif 279 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_l.gif 1797 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_r.gif 1781 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_banner_sep.gif 493 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_c.gif 875 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_l.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_r.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_bottom_sep.gif 43 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_facet.gif 287 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_footer_c.gif 65 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_footer_l.gif 186 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_footer_r.gif 288 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_c.gif 162 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_l.gif 489 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_r.gif 968 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_header_r_nox.gif 454 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_icon.gif 769 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\Scripts\y_upsell_border.gif 50 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\uninstall.exe 171384 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\x64 0 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McBrwCtl.dll 485064 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll 348592 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McPlgUI.dll 218800 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McSACorePS.dll 60728 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\saHook.dll 18984 bytes executable File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\saPlugin.dll 175552 bytes File C:\Program Files (x86)\McAfee\SiteAdvisor\x64\saSets.ini 1518 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE2 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE2\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5274 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5274\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5CFD 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5CFD\MPFrgwoem.inf 935 bytes File C:\Program Files (x86)\McAfee\Temp\qxz1BF8 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz1BF8\mscoobe.inf 1984 bytes File C:\Program Files (x86)\McAfee\Temp\qxz3BD7 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz3BD7\registerbridge.inf 1007 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\actwizui.inf 1509 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\avap.inf 1021 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\extra.rul 8763 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\HWAPI.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\langmap.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mcactui.inf 1509 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mcactwiz.inf 2530 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mcagntps.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mcawlang.inf 1654 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McDspWrp.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mclangmap.inf 679 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McLib.lib 4148192 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McNARgPS.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McNmcIns.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mcocdisable.inf 351 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mcocenable.inf 1621 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McSmtTsk.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McSvHost.exe 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\McUICnt.exe 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\mscLI_cd.inf 10322 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\vscan.bof 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\vscore_fresh.inf 1394 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\vscore_pre.inf 5589 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\vscore_update.inf 1225 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\win32 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\win32\mcoemres.dll 15424 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz42D9\win32\oemui.dll 8256 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz42D9\win32\oemuild.dll 128576 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz42D9\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\x64\mcactui.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\x64\mcactwiz.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\x64\mcactwiz_ld.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\x64\McInstru.exe 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz42D9\x64\mcoemmgr.exe 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\CDOnly 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\install.ini 330 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\langmap.inf 1152 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\langsel.dll 194840 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcmisc.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocact.cab 309100 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocact.dll 420928 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocaw.cab 435586 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocaw.dll 1136248 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocawres.cab 464304 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocawres.dll 880296 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocawui.cab 174873 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocawui.dll 873080 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocrollback.cab 315569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcocrollback.exe 353960 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcoemcpy.exe 140576 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcoemmap.inf 783 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcoemmgr.exe 1029640 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\mcoobeof.exe 937976 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz47B9\McOOBEOffer.cab 601445 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\McUtil.dll 267952 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\BAAE831E-69BA-4C7F-9453-7BC7C4A8D43D 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\BAAE831E-69BA-4C7F-9453-7BC7C4A8D43D\AWDET.ini 1104 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mat\inst_settings.inf 2056 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mat\inst_settings_oobe.inf 805 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mpf 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mpf\inst_settings.inf 1965 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mpf\inst_settings_oobe.inf 1069 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mpf\mpfUC.cab 309713 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mps 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mps\inst_settings.inf 2056 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mps\inst_settings_oobe.inf 805 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mps\mpsUC.cab 309393 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mqs 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mqs\inst_settings.inf 2105 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mqs\inst_settings_oobe.inf 836 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\mqs\mqsUC.cab 32752 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\cs 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\cs\714-108 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\cs\714-108\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\da 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\da\714-104 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\da\714-104\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\de 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\de\714-90 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\de\714-90\msaduc.cab 6239 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\el 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\el\714-113 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\el\714-113\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-AU 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-AU\714-97 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-AU\714-97\msaduc.cab 6243 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-CA 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-CA\714-94 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-CA\714-94\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-GB 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-GB\714-89 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-GB\714-89\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-US 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-US\714-88 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\en-US\714-88\msaduc.cab 6237 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\es 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\es\714-93 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\es\714-93\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\es-MX 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\es-MX\714-98 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\es-MX\714-98\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fi 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fi\714-110 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fi\714-110\msaduc.cab 6239 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fr 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fr\714-91 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fr\714-91\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fr-CA 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fr-CA\714-96 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\fr-CA\714-96\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\hu 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\hu\714-114 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\hu\714-114\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\inst_settings.inf 2090 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\inst_settings_oobe.inf 955 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\it 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\it\714-92 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\it\714-92\msaduc.cab 6239 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\jp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\jp\714-95 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\jp\714-95\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\ko 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\ko\714-109 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\ko\714-109\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\nl 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\nl\714-102 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\nl\714-102\msaduc.cab 6237 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\no 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\no\714-105 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\no\714-105\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pl 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pl\714-107 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pl\714-107\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pt 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pt\714-103 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pt\714-103\msaduc.cab 6239 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pt-BR 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pt-BR\714-99 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\pt-BR\714-99\msaduc.cab 6239 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\ru 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\ru\714-112 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\ru\714-112\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\sainst_settings.inf 2205 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\sainst_settings_oobe.inf 982 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\sv 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\sv\714-106 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\sv\714-106\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\tr 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\tr\714-111 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\tr\714-111\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-CN 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-CN\714-100 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-CN\714-100\2052.inf 767 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-CN\714-100\msaduc.cab 6241 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-TW 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-TW\714-101 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msad\zh-TW\714-101\msaduc.cab 6239 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\cs 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\cs\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\cs\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\cs\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\cs\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\cs\subst64.cab 8581 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\da 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\da\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\da\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\da\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\da\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\da\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\de 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\de\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\de\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\de\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\de\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\de\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\el 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\el\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\el\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\el\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\el\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\el\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-AU 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-AU\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-AU\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-AU\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-AU\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-AU\subst64.cab 8581 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-CA 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-CA\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-CA\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-CA\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-CA\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-CA\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-GB 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-GB\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-GB\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-GB\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-GB\subst.cab 8575 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-GB\subst64.cab 8581 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-US 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-US\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-US\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-US\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-US\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\en-US\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es-MX 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es-MX\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es-MX\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es-MX\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es-MX\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\es-MX\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fi 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fi\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fi\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fi\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fi\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fi\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr\subst64.cab 8575 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr-CA 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr-CA\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr-CA\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr-CA\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr-CA\subst.cab 8573 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\fr-CA\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\hu 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\hu\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\hu\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\hu\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\hu\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\hu\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\inst_settings.inf 2250 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\inst_settings_oobe.inf 836 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\it 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\it\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\it\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\it\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\it\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\it\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\jp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\jp\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\jp\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\jp\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\jp\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\jp\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ko 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ko\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ko\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ko\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ko\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ko\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\nl 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\nl\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\nl\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\nl\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\nl\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\nl\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\no 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\no\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\no\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\no\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\no\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\no\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pl 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pl\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pl\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pl\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pl\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pl\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt\subst.cab 8567 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt-BR 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt-BR\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt-BR\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt-BR\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt-BR\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\pt-BR\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ru 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ru\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ru\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ru\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ru\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\ru\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\sv 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\sv\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\sv\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\sv\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\sv\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\sv\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\tr 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\tr\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\tr\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\tr\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\tr\subst.cab 8569 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\tr\subst64.cab 8575 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-CN 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-CN\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-CN\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-CN\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-CN\subst.cab 8573 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-CN\subst64.cab 8577 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-TW 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-TW\Msccust.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-TW\msccust64.cab 6680 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-TW\mscoem.inf 773 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-TW\subst.cab 8571 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\MSC\zh-TW\subst64.cab 8579 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msk 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msk\inst_settings.inf 2054 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msk\inst_settings_oobe.inf 801 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\msk\mskUC.cab 309609 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\nmc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\nmc\nmcuc.cab 6124 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\inst_settings.inf 2314 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\inst_settings_oobe.inf 1037 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\vsodis.cab 7619 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\vsoena.cab 7637 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\vsofs.inf 1774 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\vsooem.inf 448 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\vsoUC.cab 309893 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\oeminfo\vso\oobe\vsous.inf 792 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\ptfiles.inf 386 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz47B9\x64\langsel.dll 240696 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4930 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4930\mscLD_cd.inf 1833 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4941 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4941\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4941\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4941\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4941\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4B9D 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4B9D\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BA0 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BA0\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BA0\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BA0\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BA0\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BF9 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4BF9\override.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C0B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C0B\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C0B\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C0B\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C0B\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C45 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C45\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C58 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C58\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C58\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C58\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C58\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\actwizui.inf 1509 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcactini.inf 1247 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcactui.dll 899872 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcactui.inf 1509 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcactwiz.dll 1245416 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcactwiz.inf 2530 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcactwiz_ld.dll 2407744 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz4C99\mcawlang.inf 1654 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4C99\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA1 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA1\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA4 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA4\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA4\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA4\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CA4\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CEE 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CEE\override.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CF1 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CF1\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CF1\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CF1\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4CF1\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D3A 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D3A\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D4D 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D4D\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D4D\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D4D\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D4D\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D86 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D86\override.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D99 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D99\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D99\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D99\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4D99\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DC1 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DC1\inst_settings.inf 2250 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE5 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE5\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE5\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE5\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4DE5\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\inst_settings.inf 2314 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\mvsoem.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\Temp\vsouc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\vsodis.inf 839 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\vsolockdown.inf 265 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E0F\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E2F 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E2F\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E41 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E41\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E41\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E41\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E41\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E7B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E7B\override.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E8E 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E8E\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E8E\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E8E\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4E8E\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4ED7 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4ED7\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4EDA 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4EDA\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4EDA\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4EDA\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4EDA\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F24 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F24\override.inf 721 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F27 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F27\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F27\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F27\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F27\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F70 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F70\override.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F83 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F83\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F83\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F83\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4F83\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FBC 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FBC\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FCF 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FCF\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FCF\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FCF\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz4FCF\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5018 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5018\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz501B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz501B\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz501B\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz501B\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz501B\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5074 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5074\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5087 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5087\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5087\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5087\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5087\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517C 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517C\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517F 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517F\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517F\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517F\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz517F\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5287 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5287\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5287\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5287\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5287\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz532E 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz532E\override.inf 665 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5340 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5340\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5340\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5340\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5340\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53D8 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53D8\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53DB 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53DB\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53DB\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53DB\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz53DB\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5434 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5434\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5437 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5437\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5437\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5437\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5437\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5490 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5490\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5493 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5493\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5493\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5493\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5493\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54DC 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54DC\override.inf 721 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54EF 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54EF\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54EF\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54EF\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz54EF\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5528 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5528\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz553B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz553B\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz553B\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5584 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5584\override.inf 763 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5587 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5587\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5587\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5587\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5587\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55D1 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55D1\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55E3 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55E3\mclgtmpl.inf 872 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55E3\msc 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55E3\mscuicfg.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz55E3\settings.dat 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz562D 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz562D\override.inf 659 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5BE5 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5BE5\vsorgwoem.inf 935 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5C81 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5C81\inst_settings.inf 1965 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5C81\mpfuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5C81\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5C81\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5C81\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5C81\Temp\mpfuc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5C81\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5D5B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\inst_settings.inf 2056 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\mpsuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\Temp\mpsuc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5D5B\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5DB9 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5DB9\MPSrgwoem.inf 935 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5E35 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5E35\inst_settings.inf 2054 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5E35\mskuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5E35\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5E35\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5E35\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz5E35\Temp\mskuc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5E35\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5EB2 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5EB2\MSKrgwoem.inf 935 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5F1F 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5F1F\inst_settings.inf 2090 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5F1F\msaduc.inf 475 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5F5E 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5F5E\MSADrgwoem.inf 940 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5FDB 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5FDB\inst_settings.inf 2105 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5FDB\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz5FDB\x64\mqsuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxz6019 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz6019\MQSrgwoem.inf 935 bytes File C:\Program Files (x86)\McAfee\Temp\qxz6096 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz9494 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxz9494\av64.inf 19188 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\mcappcfg.exe 1051776 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzA19B\mvsdeflt.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\mvsdeflt.xml 3701 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\substLI.inf 1132 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\vscore_cfg.inf 7413 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\vsodft.inf 1193 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\vsodft64.inf 1193 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\vsouc.xml 297 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA19B\x64\mvsoem.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA1BA 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA1BA\mpfLI_cd.inf 3825 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA1BA\MpfSvc.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA1BA\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA1BA\x64\mpfuc.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA257 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA257\vsoCD_LD.inf 1117 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA258 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\checkmps64.dll 190208 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzA295\McAlert.exe 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\mcdndb.txt 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\mpsLI_cd.inf 5727 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\mpsmspap.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\psupgd.exe 69216 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzA295\rmoldmpsfile.inf 2866 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\Temp\mcappcfg.exe 985344 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzA295\Temp\mpsdeflt.xml 72 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\Temp\mpsuc.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA295\Temp\mpsuc.xml 1425 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A4 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A4\msaduc.inf 485 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A4\SA_main.inf 5467 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A4\SA_win32.inf 1007 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A4\ssearch.gif 2894 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A4\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\mskcmcnt.cab 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\mskengn.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\mskLI_Cd.inf 4133 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\mskmisp.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\mskro.dll 173752 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\MskSet.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2A5\mskuc.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2B4 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2B4\mcpLI_Cd.inf 2619 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2B4\mqsuc.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2B4\MRU.ini 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2B4\ShrCore.dll 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2F3 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA2F3\mpfLD.inf 2696 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA304 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA3BE 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA3BE\mcpLD.inf 979 bytes File C:\Program Files (x86)\McAfee\Temp\qxzA3CF 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzAF2B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzAF3B 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzAF3B\instLD.inf 902 bytes File C:\Program Files (x86)\McAfee\Temp\qxzAF3B\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDA66 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDA66\inst_settings_oobe.inf 1069 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDA66\mpfuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzDA66\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDA66\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzDA66\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzDA66\Temp\mpfuc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDA66\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDD63 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDD63\inst_settings_oobe.inf 805 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDD63\mpsuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzDD63\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDD63\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzDD63\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzDD63\Temp\mpsuc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxzDD63\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE511 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE511\inst_settings_oobe.inf 836 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE511\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE511\x64\mqsuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE6D5 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE6D5\inst_settings_oobe.inf 955 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE6D5\msaduc.inf 475 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE754 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE7CF 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE7CF\inst_settings_oobe.inf 836 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE8A9 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\inst_settings_oobe.inf 801 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\mskuc.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\Temp\mskuc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE8A9\x64 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\disdefend.inf 651 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\inst_settings_oobe.inf 1037 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\mvsoem.dll 58944 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\Temp 0 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\Temp\McAppCfg.exe 978496 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\Temp\McAppCfg64.exe 1044544 bytes executable File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\Temp\vsouc.xml 62 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\vsoena.inf 689 bytes File C:\Program Files (x86)\McAfee\Temp\qxzE9E1\x64 0 bytes File C:\Program Files (x86)\mcafee.com 0 bytes File C:\Program Files (x86)\mcafee.com\agent 0 bytes File C:\Program Files (x86)\mcafee.com\agent\mcagent.exe 429144 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1025\OOBEIntl.dll (size mismatch) 20848/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1026\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1028\OOBEIntl.dll (size mismatch) 19312/19048 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1029\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1030\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1031\OOBEIntl.dll (size mismatch) 21872/21096 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1032\OOBEIntl.dll (size mismatch) 22384/21096 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1033\OOBEIntl.dll (size mismatch) 19824/19048 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1035\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1036\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1037\OOBEIntl.dll (size mismatch) 20848/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1038\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1040\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1041\OOBEIntl.dll (size mismatch) 20336/19560 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1042\OOBEIntl.dll (size mismatch) 19824/19560 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1043\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1044\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1045\OOBEIntl.dll (size mismatch) 22384/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1046\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1048\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1049\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1050\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1051\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1053\OOBEIntl.dll (size mismatch) 21360/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1054\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1055\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1058\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1060\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1061\OOBEIntl.dll (size mismatch) 21360/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1062\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1063\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1081\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1087\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\2052\OOBEIntl.dll (size mismatch) 19312/19048 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\2070\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\2074\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\3082\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\OOBESTUB.EXE (size mismatch) 81792/82560 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\agcore.dll 5921792 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\agcp.exe 15688 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\coreclr.dll 3516928 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\coregen.exe 73552 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\system.resources.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\Microsoft.VisualBasic.dll 253952 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\mscorlib.dll 1589248 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\mscorlib.ni.dll 6186496 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll 1013248 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll 760832 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\Silverlight.Configuration.exe 348528 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\Silverlight.ConfigurationUI.dll 747520 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\SLMSPRBootstrap.dll 426336 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\slr.dll.managed_manifest 5587 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Core.dll 536576 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Core.ni.dll 2364928 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\system.dll 233472 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Net.dll 225280 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Net.ni.dll 650240 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ni.dll 664576 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Runtime.Serialization.dll 413696 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Runtime.Serialization.ni.dll 1186304 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.dll 520192 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.ni.dll 1598464 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.Web.dll 73728 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.Web.ni.dll 137728 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.Browser.dll 143360 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.Browser.ni.dll 373760 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.dll 1462272 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.ni.dll 4453888 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Xml.dll 319488 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Xml.ni.dll 843776 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\mscorrc.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\system.resources.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\mscorrc.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\xapauthenticodesip.dll (size mismatch) 19808/61608 bytes executable File C:\ProgramData\Adobe\Acrobat\10.0 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0\Replicate 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0\Replicate\Security 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0\Replicate\Security\directories.acrodata 479 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001} 0 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\ABCPY.INI 1729 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\AcroRead.msi 2328576 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\Data1.cab 124461271 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\setup.exe 1560520 bytes executable File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\Setup.ini 292 bytes File C:\ProgramData\McAfee\hackerwatch 0 bytes File C:\ProgramData\McAfee\hackerwatch\data 0 bytes File C:\ProgramData\McAfee\hackerwatch\data\HwLocal.xdb 4480000 bytes File C:\ProgramData\McAfee\MCLOGS 0 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam 0 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam\mcinst 0 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam\mcinst\mcinst000.log 882 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam\McSvHost\McSvHost000.log 354 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam\Mskxagnt 0 bytes File C:\ProgramData\McAfee\MCLOGS\Anti-Spam\Mskxagnt\Mskxagnt000.log 190 bytes File C:\ProgramData\McAfee\MCLOGS\Common 0 bytes File C:\ProgramData\McAfee\MCLOGS\Common\install 0 bytes File C:\ProgramData\McAfee\MCLOGS\Common\install\install000.log 878 bytes File C:\ProgramData\McAfee\MCLOGS\Common\mcagent 0 bytes File C:\ProgramData\McAfee\MCLOGS\Common\mcagent\mcagent000.log 148248 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech 0 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\mcagent 0 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\mcagent\mcagent000.log 674 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\mcalert 0 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\mcalert\mcalert000.log 698 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\mcinsspt 0 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\mcinsspt\mcinsspt000.log 698 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\McUpdate 0 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\McUpdate\McUpdate000.log 698 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\regsvr32 0 bytes File C:\ProgramData\McAfee\MCLOGS\CoreTech\regsvr32\regsvr32000.log 1394 bytes File C:\ProgramData\McAfee\MCLOGS\DetectMPSdll 0 bytes File C:\ProgramData\McAfee\MCLOGS\DetectMPSdll\mcinst 0 bytes File C:\ProgramData\McAfee\MCLOGS\DetectMPSdll\mcinst\mcinst000.log 210 bytes File C:\ProgramData\McAfee\MCLOGS\HomeNet 0 bytes File C:\ProgramData\McAfee\MCLOGS\HomeNet\McNmcShell 0 bytes File C:\ProgramData\McAfee\MCLOGS\HomeNet\McNmcShell\McNmcShell000.log 232 bytes File C:\ProgramData\McAfee\MCLOGS\HomeNet\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\HomeNet\McSvHost\McSvHost000.log 750 bytes File C:\ProgramData\McAfee\MCLOGS\HWAPI 0 bytes File C:\ProgramData\McAfee\MCLOGS\HWAPI\regsvr32 0 bytes File C:\ProgramData\McAfee\MCLOGS\HWAPI\regsvr32\regsvr32000.log 356 bytes File C:\ProgramData\McAfee\MCLOGS\MasterInstaller 0 bytes File C:\ProgramData\McAfee\MCLOGS\MasterInstaller\install 0 bytes File C:\ProgramData\McAfee\MCLOGS\MasterInstaller\install\install000.log 394 bytes File C:\ProgramData\McAfee\MCLOGS\mcappcfg 0 bytes File C:\ProgramData\McAfee\MCLOGS\mcappcfg\mcappcfg 0 bytes File C:\ProgramData\McAfee\MCLOGS\mcappcfg\mcappcfg\mcappcfg000.log 234 bytes File C:\ProgramData\McAfee\MCLOGS\mcinsspt 0 bytes File C:\ProgramData\McAfee\MCLOGS\mcinsspt\mcinsspt 0 bytes File C:\ProgramData\McAfee\MCLOGS\mcinsspt\mcinsspt\mcinsspt000.log 660 bytes File C:\ProgramData\McAfee\MCLOGS\McInst 0 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\2052.inf000.log 269 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\Common000.log 792 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\langsel.inf000.log 210 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\mcpLI_Cd.inf000.log 244 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\MPFrgw.inf000.log 201 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\mpsmisp.inf000.log 124 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\MPSrgw.inf000.log 201 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\MQSrgw.inf000.log 201 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\MSADrgw.inf000.log 202 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\msccmn.inf000.log 111 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\mscmisc.inf000.log 100 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\mscreg.inf000.log 100 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\mskLI_Cd.inf000.log 138 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\MSKrgw.inf000.log 201 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\rmoldfile.inf000.log 427 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\rmoldmpsfile.inf000.log 121 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\sa_main.inf000.log 190 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\subst.inf000.log 226 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\vsopost.inf000.log 132 bytes File C:\ProgramData\McAfee\MCLOGS\McInst\VSOrgw.inf000.log 201 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns 0 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns\install 0 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns\install\install000.log 7166 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns\mcupdate 0 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns\mcupdate\mcupdate000.log 614 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns\rundll32 0 bytes File C:\ProgramData\McAfee\MCLOGS\McMSCIns\rundll32\rundll32000.log 128304 bytes File C:\ProgramData\McAfee\MCLOGS\mcoemmgr 0 bytes File C:\ProgramData\McAfee\MCLOGS\mcoemmgr\McOEMMGr 0 bytes File C:\ProgramData\McAfee\MCLOGS\mcoemmgr\McOEMMGr\McOEMMGr000.log 10248 bytes File C:\ProgramData\McAfee\MCLOGS\McSync 0 bytes File C:\ProgramData\McAfee\MCLOGS\McSync\mcsync 0 bytes File C:\ProgramData\McAfee\MCLOGS\McSync\mcsync\mcsync000.log 40078 bytes File C:\ProgramData\McAfee\MCLOGS\mfehidin.log 311905 bytes File C:\ProgramData\McAfee\MCLOGS\MISP 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcagent 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcagent\log.ini 121 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcagent\mcagent000.log 153644 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcagent\mcagent001.log 72392 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcappcfg 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcappcfg\mcappcfg000.log 268 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mchost 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mchost\mchost000.log 46278 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcinsspt 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcinsspt\mcinsspt000.log 528 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\McSvHost\log.ini 121 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\McSvHost\McSvHost000.log 153678 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\McSvHost\McSvHost001.log 24660 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcsvrcnt 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcsvrcnt\mcsvrcnt000.log 388 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcsync 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcsync\mcsync000.log 482 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\McUpdate 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\McUpdate\McUpdate000.log 3834 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcupdmgr 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr000.log 718 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mispreg 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\mispreg\mispreg000.log 2008 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\OOBESVC 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\OOBESVC\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\OOBESVC\McSvHost\McSvHost000.log 14292 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\regsvr32 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\regsvr32\regsvr32000.log 550 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\rundll32 0 bytes File C:\ProgramData\McAfee\MCLOGS\MISP\rundll32\rundll32000.log 854 bytes File C:\ProgramData\McAfee\MCLOGS\MPF 0 bytes File C:\ProgramData\McAfee\MCLOGS\MPF\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\MPF\McSvHost\McSvHost000.log 31990 bytes File C:\ProgramData\McAfee\MCLOGS\MPF\mpfalert 0 bytes File C:\ProgramData\McAfee\MCLOGS\MPF\mpfalert\mpfalert000.log 45678 bytes File C:\ProgramData\McAfee\MCLOGS\MPF\regsvr32 0 bytes File C:\ProgramData\McAfee\MCLOGS\MPF\regsvr32\regsvr32000.log 498 bytes File C:\ProgramData\McAfee\MCLOGS\Mps 0 bytes File C:\ProgramData\McAfee\MCLOGS\Mps\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\Mps\McSvHost\McSvHost000.log 478 bytes File C:\ProgramData\McAfee\MCLOGS\MpsConfig 0 bytes File C:\ProgramData\McAfee\MCLOGS\MpsConfig\mcagent 0 bytes File C:\ProgramData\McAfee\MCLOGS\MpsConfig\mcagent\mcagent000.log 226 bytes File C:\ProgramData\McAfee\MCLOGS\MpsEventHandler 0 bytes File C:\ProgramData\McAfee\MCLOGS\MpsEventHandler\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\MpsEventHandler\McSvHost\McSvHost000.log 302 bytes File C:\ProgramData\McAfee\MCLOGS\MpsMISP 0 bytes File C:\ProgramData\McAfee\MCLOGS\MpsMISP\mcagent 0 bytes File C:\ProgramData\McAfee\MCLOGS\MpsMISP\mcagent\mcagent000.log 4734 bytes File C:\ProgramData\McAfee\MCLOGS\Pearl 0 bytes File C:\ProgramData\McAfee\MCLOGS\Pearl\mcagent 0 bytes File C:\ProgramData\McAfee\MCLOGS\Pearl\mcagent\mcagent000.log 294 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan 0 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan\McInsUpd 0 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan\McInsUpd\McInsUpd000.log 5214 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan\McSvHost 0 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan\McSvHost\McSvHost000.log 2960 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan\regsvr32 0 bytes File C:\ProgramData\McAfee\MCLOGS\VirusScan\regsvr32\regsvr32000.log 374 bytes File C:\ProgramData\McAfee\MNA 0 bytes File C:\ProgramData\McAfee\MNA\NAData 19456 bytes File C:\ProgramData\McAfee\MNM 0 bytes File C:\ProgramData\McAfee\MNM\NDData 11264 bytes File C:\ProgramData\McAfee\MPF 0 bytes File C:\ProgramData\McAfee\MPF\mpf.dat 17865 bytes File C:\ProgramData\McAfee\MPS 0 bytes File C:\ProgramData\McAfee\MPS\mcdndb.dat 5632 bytes File C:\ProgramData\McAfee\MPS\mcdndb.txt 0 bytes File C:\ProgramData\McAfee\MPS\nomon 0 bytes File C:\ProgramData\McAfee\MPS\nomon\sacore 0 bytes File C:\ProgramData\McAfee\MPS\nomon\sacore\sacore.db 242688 bytes File C:\ProgramData\McAfee\MPS\nomon\sacore\sacoredata 0 bytes File C:\ProgramData\McAfee\MPS\nomon\sacore\sacoredata\uds_filetypes.txt 38 bytes File C:\ProgramData\McAfee\MPS\nomon\sacore\sacoredata\uds_hosting.txt 137 bytes File C:\ProgramData\McAfee\MPS\nomon\sacore\sacoredata\uds_tlds.txt 25680 bytes File C:\ProgramData\McAfee\MPS\searchengines.ini 31193 bytes File C:\ProgramData\McAfee\msc 0 bytes File C:\ProgramData\McAfee\msc\logs 0 bytes File C:\ProgramData\McAfee\msc\logs\Events.dat 4096 bytes File C:\ProgramData\McAfee\msc\logs\settings.dat 40960 bytes File C:\ProgramData\McAfee\msc\McConfig.dat 1269 bytes File C:\ProgramData\McAfee\msc\McSubDB.Dat 2697 bytes File C:\ProgramData\McAfee\msc\McUsers.dat 2048 bytes File C:\ProgramData\McAfee\msc\RegWiz 0 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp 0 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp\MPF.ini 195 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp\MPS.ini 194 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp\MQS.ini 194 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp\MSAD.ini 196 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp\MSK.ini 194 bytes File C:\ProgramData\McAfee\msc\RegWiz\RegApp\VSO.ini 194 bytes File C:\ProgramData\McAfee\msk 0 bytes File C:\ProgramData\McAfee\msk\MSKWMDB.dat 3072 bytes File C:\ProgramData\McAfee\msk\settingsdb.dat 3072 bytes File C:\ProgramData\McAfee\SiteAdvisor 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\mcbrwctl.dll 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\mcsacore.exe 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\SA.dat 6144 bytes File C:\ProgramData\McAfee\SiteAdvisor\SACore 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\SACore\sacore.db 237568 bytes File C:\ProgramData\McAfee\SiteAdvisor\SACore\sacore_priv.db 5120 bytes File C:\ProgramData\McAfee\SiteAdvisor\sasshmod.dll 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\sasshmod.dll\log.txt 269 bytes File C:\ProgramData\McAfee\SiteAdvisor\sasubmgr.dll 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\saUpd.exe 0 bytes File C:\ProgramData\McAfee\SiteAdvisor\saupkeep.dll 0 bytes File C:\ProgramData\McAfee\VirusScan 0 bytes File C:\ProgramData\McAfee\VirusScan\Logs 0 bytes File C:\ProgramData\McAfee\VirusScan\Logs\OAS.Log 3 bytes File C:\ProgramData\McAfee\VirusScan\Quarantine 0 bytes File C:\ProgramData\McAfee\WinCore 0 bytes File C:\ProgramData\McAfee\WinCore\persist.mtk 242 bytes File C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll (size mismatch) 17816/22240 bytes executable File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr 15660 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000A.log 1048576 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wsb 65536 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\CiAD0002.000 240 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\CiAD0002.001 65536 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\CiAD0002.002 65536 bytes File C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000002e.db 191120 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2441 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Odinstaluj Google Chrome.lnk 2433 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Solution Center 0 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Solution Center\Lenovo Solution Center.lnk 2024 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 0 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee\McAfee Internet Security.lnk 1857 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\CBS.log 2575926 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\CbsPersist_20130712131055.cab 1060065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\CbsPersist_20130815214227.cab 1663206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\CbsPersist_20130816213502.cab 1665853 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\CbsPersist_20130910175558.cab 2089816 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\CbsPersist_20130911233004.cab 1228234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\FilterList.log 444 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\poqexec.log 1640 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\Report.wer 7364 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\SCM.EVM 425984 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\Sessions.xml 3289101 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\WER35D2.tmp.hdmp 2722264 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_2a5fb3bf817395522cf5199fe3ef9e4be70d3e5_cab_05b43cf3\WER3C67.tmp.mdmp 827428 bytes File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863} 0 bytes File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863}\mpasbase.vdm 11628944 bytes executable File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863}\mpasdlta.vdm 339344 bytes executable File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863}\mpengine.dll 8199504 bytes executable File C:\ProgramData\OneKey Reminder 0 bytes File C:\ProgramData\OneKey Reminder\OneKeyReminder.oki 23 bytes File C:\ProgramData\Partner\Partner.dll 433648 bytes executable File C:\ProgramData\Partner\Partner.exe 332272 bytes executable File C:\ProgramData\Partner\Partner64.dll 750064 bytes executable File C:\SWTOOLS\SimpleTap DeskBand 0 bytes File C:\SWTOOLS\SimpleTap DeskBand\DeskBand32.dll 559416 bytes File C:\SWTOOLS\SimpleTap DeskBand\DeskBand64.dll 760120 bytes executable File C:\SWTOOLS\SimpleTap DeskBand\MsgCheck.exe 13624 bytes executable File C:\SWTOOLS\SimpleTap DeskBand\ShowBand.exe 155960 bytes executable File C:\SysPart\Boot? 0 bytes File C:\SysPart\Default\BackF? 156 bytes File indowsPart\Default\BackF? 0 bytes File ystem32art\Default\BackF? 0 bytes File rivers2art\Default\BackF? 0 bytes File rivers2art\Default\BackF? 647080 bytes executable File rivers2art\Default\BackF? 284648 bytes File C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe (size mismatch) 53632/54632 bytes executable File C:\Users\Ewa\AppData\Local\Microsoft\Feeds Cache\2U6SK5ZK\fwlink[1] 0 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Feeds Cache\index.dat 32768 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 16384 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6I705CDS 0 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6I705CDS\desktop.ini 67 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8GVTKH3W 0 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8GVTKH3W\continue[1].htm 7 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8GVTKH3W\desktop.ini 67 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BMER8VH1 0 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BMER8VH1\desktop.ini 67 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LYOQFQD6 0 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LYOQFQD6\desktop.ini 67 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MO3KXB2B 0 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MO3KXB2B\desktop.ini 67 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XRI0JGHZ\continue[1].htm 7 bytes File C:\Users\Ewa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XRI0JGHZ\continue[2].htm 7 bytes File C:\Users\Ewa\AppData\Local\Temp\CLUpdater.ini 300 bytes File C:\Users\Ewa\AppData\Local\Temp\CLUpdater0.ini 300 bytes File C:\Users\Ewa\AppData\Local\Temp\CLUpdater1.ini 300 bytes File C:\Users\Ewa\AppData\Local\Temp\CLUpdater2.ini 300 bytes File C:\Users\Ewa\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe (size mismatch) 53632/54632 bytes executable File C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Cookies\CM7QRTA2.txt 95 bytes File C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Cookies\index.dat 32768 bytes File C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Cookies\KLG2NDDG.txt 96 bytes File C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Cookies\YOQSXYN6.txt 95 bytes File C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat 262144 bytes File C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 1432 bytes File C:\Users\Public\Desktop\Adobe Reader X.lnk 2030 bytes File C:\Users\Public\Desktop\McAfee Internet Security.lnk 1839 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9859a6e0562f64eacfb8ad76f260a2d6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9859a6e0562f64eacfb8ad76f260a2d6\Accessibility.ni.dll 25600 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\2823d3be9334fea94dce8001b247589b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\2823d3be9334fea94dce8001b247589b\BDATunePIA.ni.dll 621568 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\5f1a06c0108b2c81cde1dc491d74043d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\5f1a06c0108b2c81cde1dc491d74043d\ComSvcConfig.ni.exe 410112 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll 220672 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\2c3e7fda8de40e45e7f5e004094dc7c9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\2c3e7fda8de40e45e7f5e004094dc7c9\dfsvc.ni.exe 14336 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\c899de3549784161aa66610d5735e4f0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\c899de3549784161aa66610d5735e4f0\ehExtHost32.ni.exe 254464 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiExtens 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\7b6de29c99674df526ccf9d4937828fe 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\7b6de29c99674df526ccf9d4937828fe\ehiExtens.ni.dll 161280 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiProxy 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\5cd902459c588bb0ac608d4cbc8b5e4c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\5cd902459c588bb0ac608d4cbc8b5e4c\ehiProxy.ni.dll 442880 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\f09ce1eab0d18a4bbd53ab2a67a5c909 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\f09ce1eab0d18a4bbd53ab2a67a5c909\ehiUserXp.ni.dll 60416 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\e05e6f6ef788b8973bbedf258216c972 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\e05e6f6ef788b8973bbedf258216c972\ehiVidCtl.ni.dll 875520 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\EventViewer 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\EventViewer\654c5baca16d72756296ab1d927ea4a8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\EventViewer\654c5baca16d72756296ab1d927ea4a8\EventViewer.ni.dll 553472 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ca11c3c4c5560bf7aafa094599128200 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ca11c3c4c5560bf7aafa094599128200\IAStorCommon.ni.dll 14336 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\1428876b9bee0b7d7ced9462111719b8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\1428876b9bee0b7d7ced9462111719b8\IAStorDataMgr.ni.dll 225280 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\51694f36a8a968fb3d8ca98152caf4ef 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\51694f36a8a968fb3d8ca98152caf4ef\IAStorDataMgrSvc.ni.exe 19968 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\f1f0231b32dee581dcab0b26d83b02ca 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\f1f0231b32dee581dcab0b26d83b02ca\IAStorUtil.ni.dll 487424 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\index11f.dat 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\index120.dat 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.CxHDAudioAP# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.CxHDAudioAP#\c534da8afa812956f594f98fc9ff5998 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.CxHDAudioAP#\c534da8afa812956f594f98fc9ff5998\Interop.CxHDAudioAPILib.ni.dll 283648 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\a21ece5c049c9f429756fd1a3fe55ccd 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\a21ece5c049c9f429756fd1a3fe55ccd\IsdiInterop.ni.dll 172032 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcepg 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcepg\38e4b4d4c4cf98e359438769fae66149 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcepg\38e4b4d4c4cf98e359438769fae66149\mcepg.ni.dll 3025920 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstore 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstore\740a64a316ada107a23dd34f35ae3b94 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstore\740a64a316ada107a23dd34f35ae3b94\mcstore.ni.dll 2035712 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstoredb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\c359669d601990310a6b30ab5992ffa8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\c359669d601990310a6b30ab5992ffa8\mcstoredb.ni.dll 364032 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\14afe54e24cf09fe6c371fc47cfabf0e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\14afe54e24cf09fe6c371fc47cfabf0e\Microsoft.Build.Engine.ni.dll 839680 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\e4031bd0b7706fd0a686e9bb6353aa2a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\e4031bd0b7706fd0a686e9bb6353aa2a\Microsoft.Build.Engine.ni.dll 1888768 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4c0fa9d495ac562afcb136f3e9a87cb9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4c0fa9d495ac562afcb136f3e9a87cb9\Microsoft.Build.Framework.ni.dll 74752 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\84b83e7639310b35b5ce150df62a2843 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\84b83e7639310b35b5ce150df62a2843\Microsoft.Build.Framework.ni.dll 65024 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\880a680b2160130c8cf858a7d2a9067d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\880a680b2160130c8cf858a7d2a9067d\Microsoft.Build.Tasks.ni.dll 1620992 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d7245402b9853a8e390552ba45b3a6b4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d7245402b9853a8e390552ba45b3a6b4\Microsoft.Build.Tasks.v3.5.ni.dll 1970176 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\30f8865f88bb953486fd20650b54177c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\30f8865f88bb953486fd20650b54177c\Microsoft.Build.Utilities.ni.dll 144384 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\dfb5532e4cf07b7324280988a3e1cca4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\dfb5532e4cf07b7324280988a3e1cca4\Microsoft.Build.Utilities.v3.5.ni.dll 175104 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\b0d0daea6a1d9a111a0f33a9a868bcf7 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\b0d0daea6a1d9a111a0f33a9a868bcf7\Microsoft.Ink.ni.dll 1361408 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b3fde69f9642ab464bd3389f1fe3c5bd 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b3fde69f9642ab464bd3389f1fe3c5bd\Microsoft.JScript.ni.dll 2335744 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\630257a0b042768c2e3104a36559c1a9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\630257a0b042768c2e3104a36559c1a9\Microsoft.ManagementConsole.ni.dll 561664 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\d22ec1c367b915c4028867244c6a1623 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\d22ec1c367b915c4028867244c6a1623\Microsoft.MediaCenter.ni.dll 1009664 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e7b8df5d803bb9bd27f63f0074775aaf 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e7b8df5d803bb9bd27f63f0074775aaf\Microsoft.MediaCenter.UI.ni.dll 6499840 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\2ba6bf6e9258afde91ab81fad2d37469 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\2ba6bf6e9258afde91ab81fad2d37469\Microsoft.PowerShell.GPowerShell.ni.dll 1704960 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\3008a05e2928e2c1d856cc34e0422c17 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\3008a05e2928e2c1d856cc34e0422c17\Microsoft.PowerShell.Commands.Utility.ni.dll 1681920 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4f68cd04686e5dc5a55070d112d44bdf 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4f68cd04686e5dc5a55070d112d44bdf\Microsoft.PowerShell.Commands.Diagnostics.ni.dll 291328 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6cc1334749f85cce651642f0a8260892 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6cc1334749f85cce651642f0a8260892\Microsoft.PowerShell.Editor.ni.dll 3724288 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\8ce205027e30804d1b2deaffa0582735 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\8ce205027e30804d1b2deaffa0582735\Microsoft.PowerShell.Security.ni.dll 167424 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\8df695fb80187f65208d87229e81e8a2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\8df695fb80187f65208d87229e81e8a2\Microsoft.PowerShell.Commands.Management.ni.dll 786432 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b1c511d8fad78ad3c5213b2b4fb02b8b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b1c511d8fad78ad3c5213b2b4fb02b8b\Microsoft.PowerShell.ConsoleHost.ni.dll 515584 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\e998eeb1548ffd53b39dcde50d196ab7 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\e998eeb1548ffd53b39dcde50d196ab7\Microsoft.PowerShell.GraphicalHost.ni.dll 729088 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4a235e617ad0a4c3aecd3982f0e3c48a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4a235e617ad0a4c3aecd3982f0e3c48a\Microsoft.Transactions.Bridge.Dtc.ni.dll 386560 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\af058f98427f47670e70468a36d84ee4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\af058f98427f47670e70468a36d84ee4\Microsoft.Transactions.Bridge.ni.dll 1093120 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll 1670144 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\4bfa36696bef033cf7e33b1a092c8a0f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\4bfa36696bef033cf7e33b1a092c8a0f\Microsoft.VisualC.ni.dll 15872 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\a415a146afc72f13f691f69a11ab5609 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\a415a146afc72f13f691f69a11ab5609\Microsoft.Vsa.ni.dll 55296 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\0a5d39e601d2512b483a56408c3cec05 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\0a5d39e601d2512b483a56408c3cec05\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll 19968 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\90cd177df2fc13d88c401b6b53a121b8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\90cd177df2fc13d88c401b6b53a121b8\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll 86528 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\aa3fa7748881ce0969396eba0be3c6c3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\aa3fa7748881ce0969396eba0be3c6c3\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll 23040 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\b5e6aa065d13e30c27219186f8e02689 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\b5e6aa065d13e30c27219186f8e02689\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll 25088 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\de64901e4cd2074f5c70733ab5d7787a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\de64901e4cd2074f5c70733ab5d7787a\Microsoft.Windows.Diagnosis.SDHost.ni.dll 32256 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\e7904d77bcee77868d534546ed2a61b6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\e7904d77bcee77868d534546ed2a61b6\Microsoft.Windows.Diagnosis.SDEngine.ni.dll 21504 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\ee8ed3c8e7f0281a9e29c7cdf050b69d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\ee8ed3c8e7f0281a9e29c7cdf050b69d\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll 27136 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\ee28a075665b6bc23b6dae56903d431d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\ee28a075665b6bc23b6dae56903d431d\Microsoft.WSMan.Management.ni.dll 531968 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCEx 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCEx\6d4bacfd54e8f79763945bee5a50711d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCEx\6d4bacfd54e8f79763945bee5a50711d\MMCEx.ni.dll 1545216 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\18e41c018ceff36c2512d12f570f0be7 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\18e41c018ceff36c2512d12f570f0be7\MMCFxCommon.ni.dll 287232 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\MSBuild 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MSBuild\af28543d9b3e7d9f110448ecce53cd72 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MSBuild\af28543d9b3e7d9f110448ecce53cd72\MSBuild.ni.exe 133632 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll 11490304 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\napcrypt 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\napcrypt\09b65f9c3f78e6ef3e259af945e937b9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\napcrypt\09b65f9c3f78e6ef3e259af945e937b9\napcrypt.ni.dll 79872 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\naphlpr 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\naphlpr\3905ee11acabb6d202a69b8bfa3c91a0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\naphlpr\3905ee11acabb6d202a69b8bfa3c91a0\naphlpr.ni.dll 114176 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\napinit 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\napinit\6a657f2f518f97b282702fce20033459 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\napinit\6a657f2f518f97b282702fce20033459\napinit.ni.dll 117760 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\napsnap 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\napsnap\f64692e58aa1a7116024bf3c3cbd1352 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\napsnap\f64692e58aa1a7116024bf3c3cbd1352\napsnap.ni.dll 723456 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Narrator 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Narrator\0bae62c3fc6c327ed24989263988173d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Narrator\0bae62c3fc6c327ed24989263988173d\Narrator.ni.exe 2623488 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\c0a8f3f379d7a62a032783cc4e04a4dd 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\c0a8f3f379d7a62a032783cc4e04a4dd\PresentationBuildTasks.ni.dll 1451520 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3e357e76593a8cc5346dc0431f4cdaa9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3e357e76593a8cc5346dc0431f4cdaa9\PresentationCFFRasterizer.ni.dll 39424 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\2ad23de8284d4594aa658dfb5e667d97 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\2ad23de8284d4594aa658dfb5e667d97\PresentationCore.ni.dll 12234752 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\b3ade8d5c0d4bb5d4940bcafd3453642 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\b3ade8d5c0d4bb5d4940bcafd3453642\PresentationFontCache.ni.exe 47104 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0e5bae8f265fbbbf53e8ca79d159cd6d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0e5bae8f265fbbbf53e8ca79d159cd6d\PresentationFramework.Luna.ni.dll 539648 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\17ab5131ab854c98847ad70236435924 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\17ab5131ab854c98847ad70236435924\PresentationFramework.Royale.ni.dll 258048 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2897c35bf2bc4ef171004bfc2909aaf3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2897c35bf2bc4ef171004bfc2909aaf3\PresentationFramework.Classic.ni.dll 226816 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\299d0b38053fd7cbd84bac2178c3703b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\299d0b38053fd7cbd84bac2178c3703b\PresentationFramework.Aero.ni.dll 368128 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bfaf8f86e69928fb2f67987c0203f603 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bfaf8f86e69928fb2f67987c0203f603\PresentationFramework.ni.dll 14339072 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehRecObj 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\6e35ba22c9762646d5294dd919175c69 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\6e35ba22c9762646d5294dd919175c69\ehRecObj.ni.dll 693248 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\942c10614a6f8c8a22d1f74e217a11d6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\942c10614a6f8c8a22d1f74e217a11d6\Microsoft.Build.Conversion.v3.5.ni.dll 222720 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\86550fdda6994a9c192d7a0b9b59ee5b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\86550fdda6994a9c192d7a0b9b59ee5b\Microsoft.WSMan.Runtime.ni.dll 17920 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\569e273efda8306ec7e22143d5285476 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\569e273efda8306ec7e22143d5285476\MIGUIControls.ni.dll 6438912 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationUI 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6f4c8aeb8f066adf5cafedbec0cac415 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6f4c8aeb8f066adf5cafedbec0cac415\PresentationUI.ni.dll 1658368 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll 971264 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\5490e4be56d6b1a80586439ac8b09b77 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\5490e4be56d6b1a80586439ac8b09b77\System.IdentityModel.Selectors.ni.dll 212992 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\da5da08245467818759aa44c4eb948e1 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\da5da08245467818759aa44c4eb948e1\System.Web.ni.dll 11819520 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\ReachFramework 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\7073e12b4c349a6ad94522e465e4f4ed 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\7073e12b4c349a6ad94522e465e4f4ed\ReachFramework.ni.dll 2157056 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\SmartAudio 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\SmartAudio\1c301df37d78b555739f4881e69b9170 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\SmartAudio\1c301df37d78b555739f4881e69b9170\SmartAudio.ni.exe 1869312 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8218dc4808b77f3585fb048c61597af1 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8218dc4808b77f3585fb048c61597af1\SMDiagnostics.ni.dll 256000 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1bc1ee3c3aa45d28dcf4657bceb2fcb4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1bc1ee3c3aa45d28dcf4657bceb2fcb4\SMSvcHost.ni.exe 366080 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\sysglobl 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\sysglobl\8abe9d895b3e9efe741b9162cb9206fc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\sysglobl\8abe9d895b3e9efe741b9162cb9206fc\sysglobl.ni.dll 232448 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll 7963136 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\29c55874e34f9d5cd3ea739262f48adc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\29c55874e34f9d5cd3ea739262f48adc\System.AddIn.ni.dll 633344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\78ce3fd89c50ab2d8d0ffc42ad838644 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\78ce3fd89c50ab2d8d0ffc42ad838644\System.AddIn.Contract.ni.dll 82944 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\221fa10bd3cb407e43b7476af5039090 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\221fa10bd3cb407e43b7476af5039090\System.ComponentModel.DataAnnotations.ni.dll 94208 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f02737c83305687a68c088927a6c5a98 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f02737c83305687a68c088927a6c5a98\System.Configuration.Install.ni.dll 141312 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll 2297856 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\1e85062785e286cd9eae9c26d2c61f73 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\1e85062785e286cd9eae9c26d2c61f73\System.Data.ni.dll 6611456 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\eae18653a1b39fe484b49963d43480ce 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\eae18653a1b39fe484b49963d43480ce\System.Data.DataSetExtensions.ni.dll 135680 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a5947a9c77b884b9e06c54f38ff3c4d7 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a5947a9c77b884b9e06c54f38ff3c4d7\System.Data.Entity.ni.dll 9921536 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\32088676b4c08d192aae910cac1dade4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\32088676b4c08d192aae910cac1dade4\System.Data.Entity.Design.ni.dll 763392 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\748de10ea72fad908022d9507c7304fc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\748de10ea72fad908022d9507c7304fc\System.Data.Linq.ni.dll 2516992 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\907f5045e26c39e1ae48024201b6334d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\907f5045e26c39e1ae48024201b6334d\System.Data.OracleClient.ni.dll 1116672 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\5d0f494f1be2367fb0a634956f719965 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\5d0f494f1be2367fb0a634956f719965\System.Data.Services.Design.ni.dll 462336 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a933cd1241698e4d13d80c8cb31d7055 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a933cd1241698e4d13d80c8cb31d7055\System.Data.Services.Client.ni.dll 1378816 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\c335a6ef5339fa917518475c286c8ca4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\c335a6ef5339fa917518475c286c8ca4\System.Data.Services.ni.dll 2029568 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\4308c2310ca6f08c6e0068172e5b709f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\4308c2310ca6f08c6e0068172e5b709f\System.Data.SqlXml.ni.dll 2508288 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\be74d258a0daa0e11197e1dcb1b3b0b9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\be74d258a0daa0e11197e1dcb1b3b0b9\System.Deployment.ni.dll 1806848 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Design 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Design\52873358b397c328168f0a5be7f3b9ae 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Design\52873358b397c328168f0a5be7f3b9ae\System.Design.ni.dll 10580480 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\45ec12795950a7d54691591c615a9e3c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\45ec12795950a7d54691591c615a9e3c\System.DirectoryServices.ni.dll 1117184 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\bcad898b90aee666da2f81b0a87a91ee 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\bcad898b90aee666da2f81b0a87a91ee\System.DirectoryServices.AccountManagement.ni.dll 888320 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ced847eb933ffee8e1a2e738205916ce 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ced847eb933ffee8e1a2e738205916ce\System.DirectoryServices.Protocols.ni.dll 455680 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll 1587200 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\fac6392e83ef7e777b78933e057c9546 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\fac6392e83ef7e777b78933e057c9546\System.Drawing.Design.ni.dll 208384 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\887ef2648686aad19feff405eddbffd2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\887ef2648686aad19feff405eddbffd2\System.EnterpriseServices.ni.dll 628224 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\887ef2648686aad19feff405eddbffd2\System.EnterpriseServices.Wrapper.dll 280064 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\b4c60dd01be760ee0452df2c040de8fc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\b4c60dd01be760ee0452df2c040de8fc\System.IdentityModel.ni.dll 1083392 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\19837bdc62b7667aba81364142e3565a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\19837bdc62b7667aba81364142e3565a\System.IO.Log.ni.dll 381440 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll 1051136 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.A# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\4436815b432c313255af322f4ec3560d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\4436815b432c313255af322f4ec3560d\System.Management.Automation.ni.dll 8872960 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.I# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\17e443d6c643b83137beb310adee3c48 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\17e443d6c643b83137beb310adee3c48\System.Management.Instrumentation.ni.dll 330240 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Messaging 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\9c17882ea083259c36cfd691f7c0835b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\9c17882ea083259c36cfd691f7c0835b\System.Messaging.ni.dll 593408 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Net 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Net\964a515210f3bad01949e9ae4f83c7b2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Net\964a515210f3bad01949e9ae4f83c7b2\System.Net.ni.dll 624128 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Printing 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Printing\aac5817d96d0ddcffebc1c45000e9008 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Printing\aac5817d96d0ddcffebc1c45000e9008\System.Printing.ni.dll 1044480 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820\System.Runtime.Remoting.ni.dll 771584 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\0728af1479c3388cadf85ccfc2b12582 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\0728af1479c3388cadf85ccfc2b12582\System.Runtime.Serialization.Formatters.Soap.ni.dll 310784 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\4a984a9ad59d14063bc6ae64a0c8f62a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\4a984a9ad59d14063bc6ae64a0c8f62a\System.Runtime.Serialization.ni.dll 2347008 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll 680448 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e2642bff810609f64343e53dddb6b59c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e2642bff810609f64343e53dddb6b59c\System.ServiceModel.ni.dll 17478656 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\4782a5d2bc7d86895faf404a3470aacb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\4782a5d2bc7d86895faf404a3470aacb\System.ServiceModel.Web.ni.dll 1707008 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8\System.ServiceProcess.ni.dll 212992 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Speech 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Speech\6935e1dad6ec5de21658f8d38999099a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Speech\6935e1dad6ec5de21658f8d38999099a\System.Speech.ni.dll 1917952 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\ad18f93fc713db2c4b29b25116c13bd8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\ad18f93fc713db2c4b29b25116c13bd8\System.Transactions.ni.dll 627200 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\3112fe15b1994ff59b169cf7ce997e71 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\3112fe15b1994ff59b169cf7ce997e71\System.Web.Abstractions.ni.dll 141312 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ec2acb1a563ecfce8396babd4a3b25 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ec2acb1a563ecfce8396babd4a3b25\System.Web.DynamicData.Design.ni.dll 36864 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a16dd65d2bfab6a019ac8a05337a5c24 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a16dd65d2bfab6a019ac8a05337a5c24\System.Web.DynamicData.ni.dll 547328 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\9a3ab1594cf5cd52f0794b0a93a14b57 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\9a3ab1594cf5cd52f0794b0a93a14b57\System.Web.Entity.ni.dll 328192 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\a63e76cc86c8958f0f3e9741c0d89f14 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\a63e76cc86c8958f0f3e9741c0d89f14\System.Web.Entity.Design.ni.dll 301568 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\0b5071ee1d40266575a7ac53b9b299d4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\0b5071ee1d40266575a7ac53b9b299d4\System.Web.Extensions.Design.ni.dll 860160 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\70823ac0d6e6631a11d443bf38987cc9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\70823ac0d6e6631a11d443bf38987cc9\System.Web.Extensions.ni.dll 2403328 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\9abec9ee3dab00d67b395d1994a60776 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\9abec9ee3dab00d67b395d1994a60776\System.Web.Mobile.ni.dll 2209792 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\c72ccbd1fef598dd897fdf0d2e49195b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\c72ccbd1fef598dd897fdf0d2e49195b\System.Web.RegularExpressions.ni.dll 202240 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\165d0873203da280298bfcfa50567a0b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\165d0873203da280298bfcfa50567a0b\System.Web.Routing.ni.dll 129536 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\02d5be8209f0eac6f7725f8d83b87df6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\02d5be8209f0eac6f7725f8d83b87df6\System.Web.Services.ni.dll 1840640 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll 12432896 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\fee2bbfe0b8f5988a3ab7a9db85c7a30 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\fee2bbfe0b8f5988a3ab7a9db85c7a30\System.Windows.Presentation.ni.dll 37888 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\b2a2c534c407bbe46e8536445d0ada50 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\b2a2c534c407bbe46e8536445d0ada50\System.Workflow.Activities.ni.dll 2995200 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\e1a68d2a01e132ebc60a5565a771902b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\e1a68d2a01e132ebc60a5565a771902b\System.Workflow.ComponentModel.ni.dll 4515840 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\2101dbd9fa083a2ed0cc112636260070 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\2101dbd9fa083a2ed0cc112636260070\System.Workflow.Runtime.ni.dll 1917952 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\f0f10d0591d11a36ee2aa8ee2fbdb2bf 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\f0f10d0591d11a36ee2aa8ee2fbdb2bf\System.WorkflowServices.ni.dll 1358336 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll 5453312 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\70aac9dff3bdde548962557151c1ff49 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\70aac9dff3bdde548962557151c1ff49\System.Xml.Linq.ni.dll 401408 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\99797e9500ed7bfa6b06063e7f017313 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\99797e9500ed7bfa6b06063e7f017313\TaskScheduler.ni.dll 245248 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPAC93.tmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\eca4310274a7a6ce651b33cd4278610c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\eca4310274a7a6ce651b33cd4278610c\UIAutomationClient.ni.dll 452096 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\56780b4bd164787631d4317d0556c3c0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\56780b4bd164787631d4317d0556c3c0\UIAutomationClientsideProviders.ni.dll 1047552 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ab8ac659d9525c6a0cd22c6f3734862f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ab8ac659d9525c6a0cd22c6f3734862f\UIAutomationProvider.ni.dll 60928 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\6820836e29efa97200d3fcfb4d0f170b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\6820836e29efa97200d3fcfb4d0f170b\UIAutomationTypes.ni.dll 185344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf293040f3a93afa1ea782487acae816 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf293040f3a93afa1ea782487acae816\WindowsBase.ni.dll 3347968 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\30b1d86571495ea86b9a19b13498aad3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\30b1d86571495ea86b9a19b13498aad3\WindowsFormsIntegration.ni.dll 240128 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_32\WsatConfig 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\96a8bdafba9f9d3e33cd974bfaa67e58 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\96a8bdafba9f9d3e33cd974bfaa67e58\WsatConfig.ni.exe 321024 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Accessibility 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Accessibility\b03641c39929ad202f0c3a9a64b93d86 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Accessibility\b03641c39929ad202f0c3a9a64b93d86\Accessibility.ni.dll 78848 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\13385391832b7c36af9306baeb570e57 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\13385391832b7c36af9306baeb570e57\BDATunePIA.ni.dll 971264 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\d632b7434f821829827657e23ac98589 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\d632b7434f821829827657e23ac98589\ComSvcConfig.ni.exe 640000 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\e41fccd68a6543f2528f6f6118f5f7e2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\e41fccd68a6543f2528f6f6118f5f7e2\CustomMarshalers.ni.dll 348672 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\dfsvc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\dfsvc\9bc0d921859b039d6e9f642148333949 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\dfsvc\9bc0d921859b039d6e9f642148333949\dfsvc.ni.exe 28672 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehCIR 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehCIR\b648e07269decc9d5a2d8aeba1d48cbb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehCIR\b648e07269decc9d5a2d8aeba1d48cbb\ehCIR.ni.dll 313856 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehExtHost 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\ad37b6e3a1cb1081592f1c5797ae9dad 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\ad37b6e3a1cb1081592f1c5797ae9dad\ehExtHost.ni.exe 389120 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\56a7faf970109dc1dc6b76f643d93c5f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\56a7faf970109dc1dc6b76f643d93c5f\ehiActivScp.ni.dll 125440 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\99c61751c71078d92ff372495bc38fc3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\99c61751c71078d92ff372495bc38fc3\ehiBmlDataCarousel.ni.dll 110080 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiExtens 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\d122f8c71cdd586e76d9617f80a0297f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\d122f8c71cdd586e76d9617f80a0297f\ehiExtens.ni.dll 397824 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiProxy 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\50691bdee045a2df00f00ac461844c5f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\50691bdee045a2df00f00ac461844c5f\ehiProxy.ni.dll 1201664 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\32c163c5b3420fb95f4bc8b5a365a6bd 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\32c163c5b3420fb95f4bc8b5a365a6bd\ehiTVMSMusic.ni.dll 93184 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\8b58e86c1211cac8bb344ec05015055b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\8b58e86c1211cac8bb344ec05015055b\ehiUPnP.ni.dll 49664 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\a6dc826bf08c95bd5fe459a02bbfd33c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\a6dc826bf08c95bd5fe459a02bbfd33c\ehiUserXp.ni.dll 145408 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\005810b5e7d8802575d07878997d434d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\005810b5e7d8802575d07878997d434d\ehiVidCtl.ni.dll 2165248 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiwmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\9f570489c98c93a79f0fd793586afdc6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\9f570489c98c93a79f0fd793586afdc6\ehiwmp.ni.dll 933888 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\b253aa4b8000e29b2fb725e4f7b8bc7c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\b253aa4b8000e29b2fb725e4f7b8bc7c\ehiWUapi.ni.dll 661504 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehRecObj 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\dd75e74b3a7686f661129df07fdeadf1 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\dd75e74b3a7686f661129df07fdeadf1\ehRecObj.ni.dll 969216 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehshell 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehshell\a1e624126e0db648f3b8ea24d0f13f84 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehshell\a1e624126e0db648f3b8ea24d0f13f84\ehshell.ni.dll 25470976 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\EventViewer 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\EventViewer\21464de9aa1dce17c1f42044129a986e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\EventViewer\21464de9aa1dce17c1f42044129a986e\EventViewer.ni.dll 659456 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\index134.dat 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\index135.dat 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\LoadMxf 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\d09b54cd68bc772b3be3832926e940d4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\d09b54cd68bc772b3be3832926e940d4\LoadMxf.ni.exe 40960 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcepg 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcepg\13b4ad00d1167ff3ed7d2a8e4994f1ff 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcepg\13b4ad00d1167ff3ed7d2a8e4994f1ff\mcepg.ni.dll 4088320 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\f04b0488328a68d57953149b31a85065 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\f04b0488328a68d57953149b31a85065\MCESidebarCtrl.ni.dll 156672 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\18aae97d7e56a28acf9d642ad23ab413 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\18aae97d7e56a28acf9d642ad23ab413\mcGlidHostObj.ni.dll 696320 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\f7a93626b76fe66f217c19426cc5b02a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\f7a93626b76fe66f217c19426cc5b02a\mcplayerinterop.ni.dll 549376 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstore 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstore\67c2902f53638a9056174f6130a8bde7 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstore\67c2902f53638a9056174f6130a8bde7\mcstore.ni.dll 2801664 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstoredb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\e049a1a3948a031aed69690fc102ea6c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\e049a1a3948a031aed69690fc102ea6c\mcstoredb.ni.dll 533504 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcupdate 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcupdate\f30beba36940b5a2b55a32ea7f42d694 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mcupdate\f30beba36940b5a2b55a32ea7f42d694\mcupdate.ni.exe 547328 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\53fddfded025faba07fdd8b69fef6bd6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\53fddfded025faba07fdd8b69fef6bd6\Mcx2Dvcs.ni.dll 380928 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\ba0cf5858766f7bc9413b1d4af6d69bd 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\ba0cf5858766f7bc9413b1d4af6d69bd\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll 107008 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\8d64f031cf429f4ce79642e8be267d2d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\8d64f031cf429f4ce79642e8be267d2d\Microsoft.Build.Conversion.v3.5.ni.dll 294912 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\2e1dbe90bc10ba70f147a249adfc7f64 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\2e1dbe90bc10ba70f147a249adfc7f64\Microsoft.Build.Engine.ni.dll 1137152 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\8c4abd55a6b822e3efbbc649c5c01a3e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\8c4abd55a6b822e3efbbc649c5c01a3e\Microsoft.Build.Engine.ni.dll 2544640 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\89815091ad8cb6d7b4c48d84ff1021e0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\89815091ad8cb6d7b4c48d84ff1021e0\Microsoft.Build.Framework.ni.dll 142336 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\a71fda14114136e528b310f41dce7915 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\a71fda14114136e528b310f41dce7915\Microsoft.Build.Framework.ni.dll 121344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\3cf3740de20740208d614d330aa4416c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\3cf3740de20740208d614d330aa4416c\Microsoft.Build.Tasks.v3.5.ni.dll 2682880 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\ca72594c581d8024d629f931f0e312d7 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\ca72594c581d8024d629f931f0e312d7\Microsoft.Build.Tasks.ni.dll 2218496 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\8ce46e3ffce2d37b9c50762a641c57ee 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\8ce46e3ffce2d37b9c50762a641c57ee\Microsoft.Build.Utilities.ni.dll 198656 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\97d05b893a063bbb5b56c7b3d20c5245 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\97d05b893a063bbb5b56c7b3d20c5245\Microsoft.Build.Utilities.v3.5.ni.dll 244736 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\3d4632e11d04d8db85c98485b1622bae 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\3d4632e11d04d8db85c98485b1622bae\Microsoft.Ink.ni.dll 2365952 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\71e40c479d779f2bf55bb925834e3cd3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\71e40c479d779f2bf55bb925834e3cd3\Microsoft.JScript.ni.dll 3213312 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\e72886c96b63be364c0205b6c4ff4413 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\e72886c96b63be364c0205b6c4ff4413\Microsoft.ManagementConsole.ni.dll 798720 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\140714964f3afbcea38cb33d548c5d3c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\140714964f3afbcea38cb33d548c5d3c\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll 1170432 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\1e99a9d1dc792d81f86b5de451cf9f3d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\1e99a9d1dc792d81f86b5de451cf9f3d\Microsoft.MediaCenter.Interop.ni.dll 522240 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\4e9468fdc6937145e65c6434787e2fa5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\4e9468fdc6937145e65c6434787e2fa5\Microsoft.MediaCenter.iTv.Media.ni.dll 219648 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5b9c2eae674609a3d84010c9906e0bf8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5b9c2eae674609a3d84010c9906e0bf8\Microsoft.MediaCenter.iTv.Hosting.ni.dll 65536 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\618ab8996b43e841efdcfb273393fc02 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\618ab8996b43e841efdcfb273393fc02\Microsoft.MediaCenter.UI.ni.dll 8979456 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\91d1761a767975dc100e4e05e48cc9a3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\91d1761a767975dc100e4e05e48cc9a3\Microsoft.MediaCenter.Shell.ni.dll 1142784 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\9ae837dc03e8519b40fe2c35c8752146 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\9ae837dc03e8519b40fe2c35c8752146\Microsoft.MediaCenter.ni.dll 1516544 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\a9f43923aab0d83b93cbf10ac1dfd0b5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\a9f43923aab0d83b93cbf10ac1dfd0b5\Microsoft.MediaCenter.iTv.ni.dll 312320 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b883b83d1f72f1fcaf4acdef3c9c381f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b883b83d1f72f1fcaf4acdef3c9c381f\Microsoft.MediaCenter.Bml.ni.dll 1508864 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ce17670e5d6d33a85e64766e340a2176 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ce17670e5d6d33a85e64766e340a2176\Microsoft.MediaCenter.Playback.ni.dll 370176 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\dc34242bf840d340e94d2657c7c33371 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\dc34242bf840d340e94d2657c7c33371\Microsoft.MediaCenter.Sports.ni.dll 965632 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ef44c6dfcb60c7b8bc8c26847048d6e5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ef44c6dfcb60c7b8bc8c26847048d6e5\Microsoft.MediaCenter.ITVVM.ni.dll 152576 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f1f58d6720098d7c1d51faf7f326d72d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f1f58d6720098d7c1d51faf7f326d72d\Microsoft.MediaCenter.Mheg.ni.dll 164864 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\22b5364c10d315a7f0a1fbd23f671c5a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\22b5364c10d315a7f0a1fbd23f671c5a\Microsoft.Transactions.Bridge.Dtc.ni.dll 584192 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\a04be0cabc675da23c6cdd970b50e3c5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\a04be0cabc675da23c6cdd970b50e3c5\Microsoft.Transactions.Bridge.ni.dll 1598976 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\684eae3bcd28cb6d1e6997e6497056e2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\684eae3bcd28cb6d1e6997e6497056e2\Microsoft.VisualBasic.ni.dll 2131968 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\692d1ed105277febf1550c93d00cd202 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\692d1ed105277febf1550c93d00cd202\Microsoft.VisualC.ni.dll 32256 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\bb235aa98e8e876f0f641c4d486f9151 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\bb235aa98e8e876f0f641c4d486f9151\Microsoft.Vsa.ni.dll 105984 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\03ab7eafba7f39a47e9e50e59551395a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\03ab7eafba7f39a47e9e50e59551395a\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll 45056 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\1dd37db07c93d0d49379838760970302 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\1dd37db07c93d0d49379838760970302\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll 40448 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\5efdf2ce3570caddc09eeae943f71cee 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\5efdf2ce3570caddc09eeae943f71cee\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll 122368 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\a178c0607d3809c8334a450b9b839b43 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\a178c0607d3809c8334a450b9b839b43\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll 36864 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\a5daafd496ae30928b7ac626037af53c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\a5daafd496ae30928b7ac626037af53c\Microsoft.Windows.Diagnosis.SDEngine.ni.dll 70144 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\dcc11202188c9fa2ba06359a04d4b43a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\dcc11202188c9fa2ba06359a04d4b43a\Microsoft.Windows.Diagnosis.SDHost.ni.dll 59904 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\e97b40597db13e8a8151b30b9c59007e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\e97b40597db13e8a8151b30b9c59007e\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll 43520 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\8cd73e65058ef6f77f36b62a74ec3344 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\8cd73e65058ef6f77f36b62a74ec3344\Microsoft.WSMan.Management.ni.dll 681984 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\4582b654b68ad17b90714875bd8c3fa2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\4582b654b68ad17b90714875bd8c3fa2\Microsoft.WSMan.Runtime.ni.dll 33792 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\5d7e85e3ad81826e2e1d7131284c63fe 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\5d7e85e3ad81826e2e1d7131284c63fe\MIGUIControls.ni.dll 7970304 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCEx 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCEx\b46af15d2e2ae2782f384bfc4a4c2c03 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCEx\b46af15d2e2ae2782f384bfc4a4c2c03\MMCEx.ni.dll 2327552 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\98b1fc37038b59eb1fcb89ce6284190e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\98b1fc37038b59eb1fcb89ce6284190e\MMCFxCommon.ni.dll 417792 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\MSBuild 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MSBuild\1a154709cdfe214029ea88c51ab2b579 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\MSBuild\1a154709cdfe214029ea88c51ab2b579\MSBuild.ni.exe 184320 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll 15568384 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\napcrypt 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\napcrypt\d95f343677c556b67e99818cc02f4214 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\napcrypt\d95f343677c556b67e99818cc02f4214\napcrypt.ni.dll 127488 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\naphlpr 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\naphlpr\03d99e593bc94e308005a972667d7ca9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\naphlpr\03d99e593bc94e308005a972667d7ca9\naphlpr.ni.dll 175104 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\napinit 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\napinit\a64d6cb9f99621449821066eca9291e9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\napinit\a64d6cb9f99621449821066eca9291e9\napinit.ni.dll 162816 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\napsnap 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\napsnap\46a2e8958905ea98cb6e91b38449c58a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\napsnap\46a2e8958905ea98cb6e91b38449c58a\napsnap.ni.dll 855040 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiiTv 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\4a7ec1155d9e9e4b40889b171d16a577 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\4a7ec1155d9e9e4b40889b171d16a577\ehiiTv.ni.dll 196096 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\7a9c26f21641112fcacd6f087b42133a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\7a9c26f21641112fcacd6f087b42133a\Microsoft.PowerShell.GPowerShell.ni.dll 2105344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\9206dc8156588e608d405729c833edc5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\9206dc8156588e608d405729c833edc5\Microsoft.PowerShell.Commands.Management.ni.dll 1131008 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\997418025a2c73d8088b0f59264a6f2b 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\997418025a2c73d8088b0f59264a6f2b\Microsoft.PowerShell.Editor.ni.dll 5350912 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b023321bc53c20c10ccbbd8f78c82c82 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b023321bc53c20c10ccbbd8f78c82c82\Microsoft.PowerShell.ConsoleHost.ni.dll 713216 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b5a6a5ce3cd3d4dd2b151315c612aeff 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b5a6a5ce3cd3d4dd2b151315c612aeff\Microsoft.PowerShell.Security.ni.dll 237056 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\cdf48153115fc0bb466f37b7dcad9ac5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\cdf48153115fc0bb466f37b7dcad9ac5\Microsoft.PowerShell.Commands.Utility.ni.dll 2176512 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\dcf1d740ffae84572215588047a59861 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\dcf1d740ffae84572215588047a59861\Microsoft.PowerShell.GraphicalHost.ni.dll 999936 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\ec50af274bf7a15fb59ac1f0d353b7ea 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\ec50af274bf7a15fb59ac1f0d353b7ea\Microsoft.PowerShell.Commands.Diagnostics.ni.dll 416768 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Narrator 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Narrator\4cc02fad33053737088d4c18267ca0a0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Narrator\4cc02fad33053737088d4c18267ca0a0\Narrator.ni.exe 3601920 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\1e96bc85441d7719ea6f7e63c4c3e287 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\1e96bc85441d7719ea6f7e63c4c3e287\System.Data.Services.Design.ni.dll 629760 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\5d81c3e6fa9f3f78cd8d06d8cf2caff0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\5d81c3e6fa9f3f78cd8d06d8cf2caff0\System.Data.Services.Client.ni.dll 1868288 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Printing 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Printing\8a2376658a24628765d359a0fafb3339 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Printing\8a2376658a24628765d359a0fafb3339\System.Printing.ni.dll 1463808 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\b9977dd97ed7006f1d7968495c594bc5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\b9977dd97ed7006f1d7968495c594bc5\System.Web.Routing.ni.dll 187392 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\08ccd030c85c817c0a889196955a49a4 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\08ccd030c85c817c0a889196955a49a4\PresentationBuildTasks.ni.dll 1884160 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\c0ad9f95f88a6678d9ab2a648f0f2eae 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\c0ad9f95f88a6678d9ab2a648f0f2eae\PresentationCFFRasterizer.ni.dll 61952 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCore 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\e097881a6e1956a4c3f6b8dbb81cb4ee 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\e097881a6e1956a4c3f6b8dbb81cb4ee\PresentationCore.ni.dll 16540160 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\0246845f487e5f33d3564eff578665a3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\0246845f487e5f33d3564eff578665a3\PresentationFontCache.ni.exe 72192 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\09ca6fe45ec9d8c535413b0dfa7d2075 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\09ca6fe45ec9d8c535413b0dfa7d2075\PresentationFramework.ni.dll 19195392 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\1badf57680aebab32f17bc080876b61d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\1badf57680aebab32f17bc080876b61d\PresentationFramework.Classic.ni.dll 282624 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\4260e87dc94e25052b34ea78873dfedb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\4260e87dc94e25052b34ea78873dfedb\PresentationFramework.Aero.ni.dll 463360 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\495f263cbca8e7d0462ee309a634e115 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\495f263cbca8e7d0462ee309a634e115\PresentationFramework.Luna.ni.dll 620544 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\c462be068987b2b4fac3a700f265fc77 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\c462be068987b2b4fac3a700f265fc77\PresentationFramework.Royale.ni.dll 317440 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationUI 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\d7c71f43e6d6e92221717345e6156044 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\d7c71f43e6d6e92221717345e6156044\PresentationUI.ni.dll 2109952 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\ReachFramework 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\34177215bbd2e05eb6d59d40a0a98f96 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\34177215bbd2e05eb6d59d40a0a98f96\ReachFramework.ni.dll 3116032 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\4b5adb098f8ce2890826195454a777b2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\4b5adb098f8ce2890826195454a777b2\SMDiagnostics.ni.dll 349184 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\04d794428d635f6a82ac57dd3d6f3628 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\04d794428d635f6a82ac57dd3d6f3628\SMSvcHost.ni.exe 525824 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\sysglobl 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\sysglobl\857fbc76bdd79711e5228e5b075ade49 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\sysglobl\857fbc76bdd79711e5228e5b075ade49\sysglobl.ni.dll 297984 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll 10617344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\ed852e32514b415cfb4ac81aef9ac0fd 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\ed852e32514b415cfb4ac81aef9ac0fd\System.AddIn.ni.dll 889344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\eadb7dd5fe85da92b491154484bc40e3 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\eadb7dd5fe85da92b491154484bc40e3\System.AddIn.Contract.ni.dll 156672 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\560cb6a2e8f4877877b11de7c1f07d42 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\560cb6a2e8f4877877b11de7c1f07d42\System.ComponentModel.DataAnnotations.ni.dll 132096 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\fcf35536476614410e0b0bd0e412199e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\fcf35536476614410e0b0bd0e412199e\System.Configuration.Install.ni.dll 192000 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll 1308160 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\83e2f6909980da7347e7806d8c26670e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\83e2f6909980da7347e7806d8c26670e\System.Core.ni.dll 3315200 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\accc3a5269658c8c47fe3e402ac4ac1c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\accc3a5269658c8c47fe3e402ac4ac1c\System.Data.ni.dll 8681472 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\56ccdabce54219b23bc4b6477d98b45c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\56ccdabce54219b23bc4b6477d98b45c\System.Data.DataSetExtensions.ni.dll 194560 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\84467aa24019da88d4aece177e51a223 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\84467aa24019da88d4aece177e51a223\System.Data.Entity.ni.dll 13760000 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\8f1dcb9771b151969c5afdae76376d5c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\8f1dcb9771b151969c5afdae76376d5c\System.Data.Entity.Design.ni.dll 1080320 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\b357f35e860204c5b74e1388f97db058 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\b357f35e860204c5b74e1388f97db058\System.Data.Linq.ni.dll 3480576 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\89eae0aa2c0c6d4678ccffdc84fcc410 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\89eae0aa2c0c6d4678ccffdc84fcc410\System.Data.OracleClient.ni.dll 1506816 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0765c6422b48cd504d2fba3765c78c79 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0765c6422b48cd504d2fba3765c78c79\System.Data.Services.ni.dll 2805760 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7111bf18edb7bf9d986782131f797acb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7111bf18edb7bf9d986782131f797acb\System.Data.SqlXml.ni.dll 3463680 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Deployment 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\413d36d1d35aabadf1c9d6f0a56cfab8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\413d36d1d35aabadf1c9d6f0a56cfab8\System.Deployment.ni.dll 2444288 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Design 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Design\d42a48a3e73b472a80d0d44038af89b0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Design\d42a48a3e73b472a80d0d44038af89b0\System.Design.ni.dll 13609472 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\6ed2b26c49820b85b9f78ac7abceefa9 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\6ed2b26c49820b85b9f78ac7abceefa9\System.DirectoryServices.AccountManagement.ni.dll 1230848 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\c1cdea55f62c9e8b9b9c1ae4c23b1c1f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\c1cdea55f62c9e8b9b9c1ae4c23b1c1f\System.DirectoryServices.ni.dll 1640448 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\e883ac4543d94e67abd1c33191633865 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\e883ac4543d94e67abd1c33191633865\System.DirectoryServices.Protocols.ni.dll 649728 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\5910828a337dbe848dc90c7ae0a7dee2 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\5910828a337dbe848dc90c7ae0a7dee2\System.Drawing.ni.dll 2311168 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\aa8854bd55fca246dd3226a671092bfa 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\aa8854bd55fca246dd3226a671092bfa\System.Drawing.Design.ni.dll 288768 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\a6155c70b3df6c860303ffee7b560ade 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\a6155c70b3df6c860303ffee7b560ade\System.EnterpriseServices.ni.dll 1081344 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\a6155c70b3df6c860303ffee7b560ade\System.EnterpriseServices.Wrapper.dll 446464 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\559a3dee015d005c199f3867b10f5bbc 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\559a3dee015d005c199f3867b10f5bbc\System.IdentityModel.Selectors.ni.dll 294400 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\9b1d7533105a793af14b7b51cd5443af 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\9b1d7533105a793af14b7b51cd5443af\System.IdentityModel.ni.dll 1444352 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\85b543fd18ce71c8bc95c49abf8ceb66 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\85b543fd18ce71c8bc95c49abf8ceb66\System.IO.Log.ni.dll 569856 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c44929bde355680c886f8a52f5e22b81 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c44929bde355680c886f8a52f5e22b81\System.Management.ni.dll 1472000 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.A# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\009a09f5b2322bb8c5520dc5ddbb28bb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\009a09f5b2322bb8c5520dc5ddbb28bb\System.Management.Automation.ni.dll 11900928 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.I# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\8b62ac3a8cfd55c530052c79253d25c8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\8b62ac3a8cfd55c530052c79253d25c8\System.Management.Instrumentation.ni.dll 534016 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Messaging 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\ee9a323861b378713f17421b0d98adb5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\ee9a323861b378713f17421b0d98adb5\System.Messaging.ni.dll 783360 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Net 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Net\d567624f1206028ff852c689416d6b58 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Net\d567624f1206028ff852c689416d6b58\System.Net.ni.dll 916480 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\0fde44651bdf14a3988b955dd94aa318 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\0fde44651bdf14a3988b955dd94aa318\System.Runtime.Remoting.ni.dll 1022976 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\52bdf474b237d949c5b2b407ebec8f1e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\52bdf474b237d949c5b2b407ebec8f1e\System.Runtime.Serialization.ni.dll 3073536 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\8ad0e1382ab6565741bbb64b965f2748 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\8ad0e1382ab6565741bbb64b965f2748\System.Runtime.Serialization.Formatters.Soap.ni.dll 396288 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Security 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Security\821d4406efa3556465e6244fae26b536 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Security\821d4406efa3556465e6244fae26b536\System.Security.ni.dll 928768 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\ac74a0642981011a441823a762bfb3d8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\ac74a0642981011a441823a762bfb3d8\System.ServiceModel.ni.dll 23913984 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\bde9665f643d6e82b36b401d38f07fc8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\bde9665f643d6e82b36b401d38f07fc8\System.ServiceModel.Web.ni.dll 2312704 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\df4cc33bfe326b259eeef086451a2528 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\df4cc33bfe326b259eeef086451a2528\System.ServiceProcess.ni.dll 295424 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Speech 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Speech\0dc049d2993f3d0e2651581533093e17 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Speech\0dc049d2993f3d0e2651581533093e17\System.Speech.ni.dll 2727936 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\051655963f24f9ade08486084c570086 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\051655963f24f9ade08486084c570086\System.Transactions.ni.dll 921600 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web\ea5a0e7af3956d40caeffaab3bb8b753 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web\ea5a0e7af3956d40caeffaab3bb8b753\System.Web.ni.dll 15249408 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\e66285eb011e4864314f3e4e4d6d8e40 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\e66285eb011e4864314f3e4e4d6d8e40\System.Web.Abstractions.ni.dll 204800 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\98acb62493655ab4e5cad815e8df664d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\98acb62493655ab4e5cad815e8df664d\System.Web.DynamicData.Design.ni.dll 54784 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\bef47cfaf8928e35b99d8deb0eeb6b08 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\bef47cfaf8928e35b99d8deb0eeb6b08\System.Web.DynamicData.ni.dll 753664 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\d3aaf07a1d6356d9edf7c3c9f4b7dd0d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\d3aaf07a1d6356d9edf7c3c9f4b7dd0d\System.Web.Entity.ni.dll 449024 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\86fd874752b7cca432941e9f482c3590 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\86fd874752b7cca432941e9f482c3590\System.Web.Entity.Design.ni.dll 398848 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\47da05ff5ddd7d25ab9df88e6d79bb39 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\47da05ff5ddd7d25ab9df88e6d79bb39\System.Web.Extensions.Design.ni.dll 1155072 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\e2d043bbce0d8d303dadd068037c3ffb 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\e2d043bbce0d8d303dadd068037c3ffb\System.Web.Extensions.ni.dll 3042304 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\5ea81699d36a1938a0ff618380506f11 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\5ea81699d36a1938a0ff618380506f11\System.Web.Mobile.ni.dll 3336704 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\fc4fb8a45f4e2115c1290af5ffe5ace0 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\fc4fb8a45f4e2115c1290af5ffe5ace0\System.Web.RegularExpressions.ni.dll 261120 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\2f157d250a738f7a6074e0f29b298998 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\2f157d250a738f7a6074e0f29b298998\System.Web.Services.ni.dll 2292224 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5\System.Windows.Forms.ni.dll 17379328 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\93ee0d8b03d20f6b2d9875add13e23e8 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\93ee0d8b03d20f6b2d9875add13e23e8\System.Windows.Presentation.ni.dll 60416 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\a53a2767e448aef90b345af1339d4c9a 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\a53a2767e448aef90b345af1339d4c9a\System.Workflow.Activities.ni.dll 3895296 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\20e46d1d15a9eaee80b1d16dafef4017 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\20e46d1d15a9eaee80b1d16dafef4017\System.Workflow.ComponentModel.ni.dll 5957632 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\462293b97f4b8f084192a7fbae47269f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\462293b97f4b8f084192a7fbae47269f\System.Workflow.Runtime.ni.dll 2711040 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\7f1f91903e297c234f177743d94c318e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\7f1f91903e297c234f177743d94c318e\System.WorkflowServices.ni.dll 1818112 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll 6948864 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\164d9beb2bf9b6160593f915a2d9aa6d 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\164d9beb2bf9b6160593f915a2d9aa6d\System.Xml.Linq.ni.dll 529920 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\a3883e7fc1bd0fbc54761b26c2bc5483 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\a3883e7fc1bd0fbc54761b26c2bc5483\TaskScheduler.ni.dll 304128 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5CDE.tmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP6B8E.tmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\60fa801c6b0c236ddeb6e93364ec5705 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\60fa801c6b0c236ddeb6e93364ec5705\UIAutomationClient.ni.dll 653312 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\1820fd86357ea33153927f127e6c5d3f 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\1820fd86357ea33153927f127e6c5d3f\UIAutomationClientsideProviders.ni.dll 1459712 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\0445defa66af3e3548dd3052e8752079 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\0445defa66af3e3548dd3052e8752079\UIAutomationProvider.ni.dll 120832 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\69e6acc80dfb71c3ebeac12584ea008c 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\69e6acc80dfb71c3ebeac12584ea008c\UIAutomationTypes.ni.dll 253952 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsBase 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\40864f42b00635e6fa6ce8da88d9ab83 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\40864f42b00635e6fa6ce8da88d9ab83\WindowsBase.ni.dll 4962816 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra# 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\0cb1830849e0ce11c8985339523d5b63 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\0cb1830849e0ce11c8985339523d5b63\WindowsFormsIntegration.ni.dll 329216 bytes executable File C:\Windows\assembly\NativeImages_v2.0.50727_64\WsatConfig 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\36ca2928b2191011831ab673861c6ac6 0 bytes File C:\Windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\36ca2928b2191011831ab673861c6ac6\WsatConfig.ni.exe 468992 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\01254caa0efc15b5cd48fb3178018701 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\01254caa0efc15b5cd48fb3178018701\Accessibility.ni.dll 44544 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\d2574c8ae333ff959be2e0d83121ad10 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\d2574c8ae333ff959be2e0d83121ad10\CustomMarshalers.ni.dll 193024 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\dfsvc 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\dfsvc\b9b6069e6da06eb57e89cc544397f735 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\dfsvc\b9b6069e6da06eb57e89cc544397f735\dfsvc.ni.exe 9728 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\index50.dat 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\index56.dat 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\05503f37aef5261d80ccca19f8078679 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\05503f37aef5261d80ccca19f8078679\Microsoft.CSharp.ni.dll 1612288 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\08b2c2639708ab20748653185d6b67be 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\08b2c2639708ab20748653185d6b67be\Microsoft.JScript.ni.dll 2441728 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\5f595338c63c2fdb5a171760c29d5bcf 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\5f595338c63c2fdb5a171760c29d5bcf\Microsoft.Transactions.Bridge.Dtc.ni.dll 418304 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\9952f66fc592ffc21b024803c8c955fd 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\9952f66fc592ffc21b024803c8c955fd\Microsoft.Transactions.Bridge.ni.dll 1079808 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2eef2f34c0295f1fe5d6d4441f9e790b 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2eef2f34c0295f1fe5d6d4441f9e790b\Microsoft.VisualBasic.Activities.Compiler.ni.dll 1167872 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a7b5a07abe981fc8d777ff40a0e45102 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a7b5a07abe981fc8d777ff40a0e45102\Microsoft.VisualBasic.Compatibility.ni.dll 1134080 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\e8ab3b63bade82c3522613f2b1240c0d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\e8ab3b63bade82c3522613f2b1240c0d\Microsoft.VisualBasic.ni.dll 1819648 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\edcde6e8ccca7996c2e1ad40bd0f2758 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\edcde6e8ccca7996c2e1ad40bd0f2758\Microsoft.VisualBasic.Compatibility.Data.ni.dll 219136 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\552a460a8bcf608aecc6418db0d40216 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\552a460a8bcf608aecc6418db0d40216\Microsoft.VisualC.ni.dll 11776 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll 14415872 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\3963e9ce8d44f50e8367e92a8e3e42e6 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\3963e9ce8d44f50e8367e92a8e3e42e6\PresentationCore.ni.dll 11057664 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationUI 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\15578874ee1464dc6a3545d4be842e59 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\15578874ee1464dc6a3545d4be842e59\PresentationUI.ni.dll 1622528 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\ReachFramework 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\42f0e1a4e3081c50503d74ebc0540a60 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\42f0e1a4e3081c50503d74ebc0540a60\ReachFramework.ni.dll 2842624 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4d2a51c03b27e615ff9f1c430f2014ba 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4d2a51c03b27e615ff9f1c430f2014ba\SMDiagnostics.ni.dll 142336 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\38f0d77629891e7808424103aaef0728 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\38f0d77629891e7808424103aaef0728\SMSvcHost.ni.exe 316928 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll 9000960 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities\931ad0783c03deb967760d5c2387274a 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities\931ad0783c03deb967760d5c2387274a\System.Activities.ni.dll 4103168 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\607df7a11c3334146664bc74130bc38f 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\607df7a11c3334146664bc74130bc38f\System.Activities.Core.Presentation.ni.dll 1506304 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\8594d07d18330843968d649ed6ef6166 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\8594d07d18330843968d649ed6ef6166\System.Activities.DurableInstancing.ni.dll 402944 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\a57e34a36f38a007aa24f1bd07a167ab 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\a57e34a36f38a007aa24f1bd07a167ab\System.Activities.Presentation.ni.dll 3691520 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\767e70aec1ffb52f95c2b07c08fa0781 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\767e70aec1ffb52f95c2b07c08fa0781\System.AddIn.ni.dll 613888 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\5c87f21925d5a61059ee68cef72841f4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\5c87f21925d5a61059ee68cef72841f4\System.AddIn.Contract.ni.dll 78848 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\aea1d325200e1a7b1ee7ec86fba33db4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\aea1d325200e1a7b1ee7ec86fba33db4\System.Configuration.Install.ni.dll 145920 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716\System.Configuration.ni.dll 973312 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll 7025664 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\92cccedc7cda413ff6fc6492cb256b58 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\92cccedc7cda413ff6fc6492cb256b58\System.Data.ni.dll 6754816 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\caecc65b5c0ede0fe0d55b9f48ada80f 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\caecc65b5c0ede0fe0d55b9f48ada80f\System.Data.DataSetExtensions.ni.dll 134656 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\642a7b3d47828fb0070a55cfeb58f42b 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\642a7b3d47828fb0070a55cfeb58f42b\System.Data.Entity.ni.dll 13273600 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\87a713cee613d08ee04ae9483a9d4716 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\87a713cee613d08ee04ae9483a9d4716\System.Data.Linq.ni.dll 2499072 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\685c7df1332a74aaa899f2bdb3beabc3 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\685c7df1332a74aaa899f2bdb3beabc3\System.Data.Services.Client.ni.dll 1332736 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\1fdd0961d8d07ef4d1fcaf30f0050c0a 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\1fdd0961d8d07ef4d1fcaf30f0050c0a\System.Data.SqlXml.ni.dll 2538496 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Deployment 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\90fd7fc9fbf5f4eed9135996b515a38a 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\90fd7fc9fbf5f4eed9135996b515a38a\System.Deployment.ni.dll 1872384 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Device 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Device\36342e6024e2844502d0bdaa9d30971a 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Device\36342e6024e2844502d0bdaa9d30971a\System.Device.ni.dll 112128 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\46a7f51ef1a9d917598b96f7a758a459 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\46a7f51ef1a9d917598b96f7a758a459\System.DirectoryServices.AccountManagement.ni.dll 911872 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\5166bf93ac5239837c9c92b58d183ea6 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\5166bf93ac5239837c9c92b58d183ea6\System.DirectoryServices.ni.dll 1151488 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\7f4419b6f829a2485d83b3c3e7b26a97 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\7f4419b6f829a2485d83b3c3e7b26a97\System.DirectoryServices.Protocols.ni.dll 461824 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll 1651200 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\1331ee3a7146218388537aa7e41303af 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\1331ee3a7146218388537aa7e41303af\System.Dynamic.ni.dll 373248 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\8b6e9d6171aad3561263ce2cd05c57df 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\8b6e9d6171aad3561263ce2cd05c57df\System.EnterpriseServices.ni.dll 784896 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\8b6e9d6171aad3561263ce2cd05c57df\System.EnterpriseServices.Wrapper.dll 230912 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\386f41f744eedacd1517c8a15750a48b 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\386f41f744eedacd1517c8a15750a48b\System.IdentityModel.Selectors.ni.dll 228352 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\016f9a150fce0e0a4c93532d8fa4c749 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\016f9a150fce0e0a4c93532d8fa4c749\PresentationFramework.Luna.ni.dll 656896 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\040571d65dc822e5df020d5e084f4b45 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\040571d65dc822e5df020d5e084f4b45\PresentationFramework.Royale.ni.dll 327168 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3555f5f74c56fa92c0ab7a635af91bfa 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3555f5f74c56fa92c0ab7a635af91bfa\PresentationFramework.Aero.ni.dll 450048 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7f91eecda3ff7ce478146b6458580c98 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7f91eecda3ff7ce478146b6458580c98\PresentationFramework.ni.dll 17629184 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f5e029e2215c95ab38a1eefef7b32ac9 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f5e029e2215c95ab38a1eefef7b32ac9\PresentationFramework.Classic.ni.dll 283648 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\4a518b841f06ee4f07320159cf918a2c 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\4a518b841f06ee4f07320159cf918a2c\System.ComponentModel.Composition.ni.dll 690176 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\7d8e51e92fede804332703770695afdb 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\7d8e51e92fede804332703770695afdb\System.ComponentModel.DataAnnotations.ni.dll 193536 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817\System.IdentityModel.ni.dll 1065984 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\150da10324f2811a48da58d3496bbe10 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\150da10324f2811a48da58d3496bbe10\System.IO.Log.ni.dll 405504 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\6a6f4be744ed5bc5273cbcf0fcf303e3 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\6a6f4be744ed5bc5273cbcf0fcf303e3\System.Management.ni.dll 1159168 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management.I# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\8b5fe7aff54a7aed07287257a9b8e420 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\8b5fe7aff54a7aed07287257a9b8e420\System.Management.Instrumentation.ni.dll 392704 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Messaging 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\3ab3e80af8e5e95a5a62092cc9293c91 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\3ab3e80af8e5e95a5a62092cc9293c91\System.Messaging.ni.dll 625152 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net\dd5c866d2462dd913ed0a0287396aa50 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net\dd5c866d2462dd913ed0a0287396aa50\System.Net.ni.dll 651264 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\b07f0d26a34ad53fc369248f289d1126 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\b07f0d26a34ad53fc369248f289d1126\System.Numerics.ni.dll 144896 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Printing 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Printing\eb9369fc9393d29afe51e45cb49aa4be 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Printing\eb9369fc9393d29afe51e45cb49aa4be\System.Printing.ni.dll 1047040 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1\System.Runtime.DurableInstancing.ni.dll 1011200 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\e30ded9b9c19a264a974b1cc40d7d2cc 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\e30ded9b9c19a264a974b1cc40d7d2cc\System.Runtime.Remoting.ni.dll 758784 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0ff3383438d688a0118d0fa19ed1dc4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0ff3383438d688a0118d0fa19ed1dc4\System.Runtime.Serialization.Formatters.Soap.ni.dll 310272 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll 2625024 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\09a97525ae5583cc2685e2c39a3078bd 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\09a97525ae5583cc2685e2c39a3078bd\System.Security.ni.dll 721920 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766\System.ServiceModel.ni.dll 17919488 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\52481fccddb053768631c640d5059d4b 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\52481fccddb053768631c640d5059d4b\System.ServiceModel.Activities.ni.dll 1388032 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\76a5d670ce969c0c65a905b7303d4bbf 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\76a5d670ce969c0c65a905b7303d4bbf\System.ServiceModel.Routing.ni.dll 365056 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c3831eb95ccf3904bab81a97a9b08ed3 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c3831eb95ccf3904bab81a97a9b08ed3\System.ServiceModel.Channels.ni.dll 82432 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dbf07cb14b4dcc210cdf8b5d90a12a56 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dbf07cb14b4dcc210cdf8b5d90a12a56\System.ServiceModel.Discovery.ni.dll 1127424 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\6e7f1bdc845816dfc797f8002b76b5e8 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\6e7f1bdc845816dfc797f8002b76b5e8\System.ServiceProcess.ni.dll 220672 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Speech 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Speech\61a931da70f8078539a51cef3888d02d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Speech\61a931da70f8078539a51cef3888d02d\System.Speech.ni.dll 1992192 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\dd9dbf82e44454689976a49a9e4ddb6d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\dd9dbf82e44454689976a49a9e4ddb6d\System.Transactions.ni.dll 645632 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\02068ef9dafba3308b13444b8f4e5940 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\02068ef9dafba3308b13444b8f4e5940\System.Web.ApplicationServices.ni.dll 71680 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\87e09dfbe3a44d6b00d3a5895f5a21a6 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\87e09dfbe3a44d6b00d3a5895f5a21a6\System.Web.Services.ni.dll 1828352 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\9cf13572472dc2efe8f3b7c2ab6198d3 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\9cf13572472dc2efe8f3b7c2ab6198d3\System.Windows.Forms.DataVisualization.ni.dll 4496384 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0\System.Windows.Forms.ni.dll 13006336 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\18419dd13ced512c5f8dc15a79a601eb 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\18419dd13ced512c5f8dc15a79a601eb\System.Windows.Input.Manipulations.ni.dll 187904 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\9bbefd2263d8f2169ab3695798208293 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\9bbefd2263d8f2169ab3695798208293\System.Windows.Presentation.ni.dll 35328 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll 1776640 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll 5571584 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8eca92a64c232f34b5b559625b022369 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8eca92a64c232f34b5b559625b022369\System.Xml.Linq.ni.dll 391680 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\Temp 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\ece129234f9ba9ad856d0e77e4849137 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\ece129234f9ba9ad856d0e77e4849137\UIAutomationClient.ni.dll 481792 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\5904383f7c86f1374a14198872dfa7d8 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\5904383f7c86f1374a14198872dfa7d8\UIAutomationClientsideProviders.ni.dll 1055744 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\0eb3c18ec758534395684f3ca286a201 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\0eb3c18ec758534395684f3ca286a201\UIAutomationProvider.ni.dll 96768 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\5786f917a7b62d63ca8dd5b47aaf9610 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\5786f917a7b62d63ca8dd5b47aaf9610\UIAutomationTypes.ni.dll 195584 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\d17606e813f01376bd0def23726ecc62 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\d17606e813f01376bd0def23726ecc62\WindowsBase.ni.dll 3779072 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\cc063533b04f9420d1aa571a36d1fabd 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\cc063533b04f9420d1aa571a36d1fabd\WindowsFormsIntegration.ni.dll 245760 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Accessibility 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Accessibility\dea86a81aacc28e408507e311da6d2fa 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Accessibility\dea86a81aacc28e408507e311da6d2fa\Accessibility.ni.dll 57856 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\484c3c0ed451c906dec30445553d8fc1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\484c3c0ed451c906dec30445553d8fc1\CustomMarshalers.ni.dll 276992 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\dfsvc 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\dfsvc\a354197a45ffa73be93177ed5b0ce377 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\dfsvc\a354197a45ffa73be93177ed5b0ce377\dfsvc.ni.exe 10752 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\index50.dat 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\index56.dat 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\4e7049d81f575a6e0652f7af80040a17 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\4e7049d81f575a6e0652f7af80040a17\Microsoft.CSharp.ni.dll 1968640 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\0ec582085325e7acf33b004c484be1de 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\0ec582085325e7acf33b004c484be1de\Microsoft.JScript.ni.dll 3288064 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\0fb7cbd4c3fcf73f8860bd91497e8f66 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\0fb7cbd4c3fcf73f8860bd91497e8f66\Microsoft.Transactions.Bridge.ni.dll 1490944 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\a4381928c37d4cf483070269f48326d2 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\a4381928c37d4cf483070269f48326d2\Microsoft.Transactions.Bridge.Dtc.ni.dll 595456 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\227517fd5a11539b8ed1fbe6a8c10f79 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\227517fd5a11539b8ed1fbe6a8c10f79\Microsoft.VisualBasic.Compatibility.Data.ni.dll 287232 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\af08f116e2c31d2c65bd492804fb2fef 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\af08f116e2c31d2c65bd492804fb2fef\Microsoft.VisualBasic.ni.dll 2269696 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\b37e1ae66271b1dd2b7879febc9eac93 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\b37e1ae66271b1dd2b7879febc9eac93\Microsoft.VisualBasic.Activities.Compiler.ni.dll 1612800 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\f989c78736b186c8cc9ff2d1ca06217e 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\f989c78736b186c8cc9ff2d1ca06217e\Microsoft.VisualBasic.Compatibility.ni.dll 1831424 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\35566e921b6dc6f070408594e730faaa 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\35566e921b6dc6f070408594e730faaa\Microsoft.VisualC.ni.dll 14336 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\bc19222db4406c472d9aa1f8b6e0f470 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\bc19222db4406c472d9aa1f8b6e0f470\mscorlib.ni.dll 19348992 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationCore 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\f3bf2b87e57d986369366c34f520a41b 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\f3bf2b87e57d986369366c34f520a41b\PresentationCore.ni.dll 14810112 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationUI 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\b3fcf4290c9ba947d8dcb293442eacb1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\b3fcf4290c9ba947d8dcb293442eacb1\PresentationUI.ni.dll 1987584 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\ReachFramework 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\c8777929815906c78c1cd0fd6003eb9c 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\c8777929815906c78c1cd0fd6003eb9c\ReachFramework.ni.dll 3910656 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\ac74a156499a8303d5788ab299881d5d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\ac74a156499a8303d5788ab299881d5d\SMDiagnostics.ni.dll 182272 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\ef022a4092ef0a271b4dd7d12264dae8 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\ef022a4092ef0a271b4dd7d12264dae8\SMSvcHost.ni.exe 424960 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System\0f8f78b729ce16dd078f5d5f734a1110 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System\0f8f78b729ce16dd078f5d5f734a1110\System.ni.dll 11722240 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities\8a7112ce783f048fabd7c0ae1102f282 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities\8a7112ce783f048fabd7c0ae1102f282\System.Activities.ni.dll 5633536 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\8ec6b52230006060fd8e0ae4ee5a6078 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\8ec6b52230006060fd8e0ae4ee5a6078\System.Activities.Core.Presentation.ni.dll 1948160 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\17de1d19c3443b70236762a493b51aa4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\17de1d19c3443b70236762a493b51aa4\System.Activities.DurableInstancing.ni.dll 537600 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\d6f957aff5d1d2adbae373ba2c895fc7 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\d6f957aff5d1d2adbae373ba2c895fc7\System.Activities.Presentation.ni.dll 4817408 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\fb44540b59b268b7a681165b000da009 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\fb44540b59b268b7a681165b000da009\System.AddIn.ni.dll 827392 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\47d59056ac291cf639edc1499ad22e84 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\47d59056ac291cf639edc1499ad22e84\System.AddIn.Contract.ni.dll 97280 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c080a9ed31f78466f2400bba623af2f8 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c080a9ed31f78466f2400bba623af2f8\System.Configuration.Install.ni.dll 179712 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\11581b5eba4b3ff58441c638ab66c742 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\11581b5eba4b3ff58441c638ab66c742\System.Configuration.ni.dll 1247232 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\7a93c267da35a5f16b6fa5a10482eb4e 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\7a93c267da35a5f16b6fa5a10482eb4e\System.Core.ni.dll 10199552 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data\5a47dfd0b200a502a4d5d27ee99bcc3c 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data\5a47dfd0b200a502a4d5d27ee99bcc3c\System.Data.ni.dll 8485376 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\e21ef3f0466f3b32573b2054a8ec2756 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\e21ef3f0466f3b32573b2054a8ec2756\System.Data.DataSetExtensions.ni.dll 175104 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\c41b30de7215a62c8ca5bfe6e04ea763 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\c41b30de7215a62c8ca5bfe6e04ea763\System.Data.Entity.ni.dll 18089472 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\8b5e92d8d715887140ae692251667d2a 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\8b5e92d8d715887140ae692251667d2a\System.Data.Linq.ni.dll 3320832 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\5ac492f703d6d741140f7cd45ef3c746 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\5ac492f703d6d741140f7cd45ef3c746\System.Data.Services.Client.ni.dll 1750016 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\eda698e4f33bbc7f6824512b1af768b4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\eda698e4f33bbc7f6824512b1af768b4\System.Data.SqlXml.ni.dll 3323392 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Deployment 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\b02f2fc896c45ef188c8fcc62bb78622 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\b02f2fc896c45ef188c8fcc62bb78622\System.Deployment.ni.dll 2353152 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Device 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Device\355f9ad8b3a2820986085f8194e46afd 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Device\355f9ad8b3a2820986085f8194e46afd\System.Device.ni.dll 141824 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\1e6d600cb8881ea39ba9321e27665bcd 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\1e6d600cb8881ea39ba9321e27665bcd\System.DirectoryServices.ni.dll 1587200 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\4e646b87f86fb1349f132c16106281ee 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\4e646b87f86fb1349f132c16106281ee\System.DirectoryServices.AccountManagement.ni.dll 1193472 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\c2e9871975b94235b9e6ab192ecd1bf7 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\c2e9871975b94235b9e6ab192ecd1bf7\System.DirectoryServices.Protocols.ni.dll 623104 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\1266d26c7b7843d308e2705cb8239d55 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\1266d26c7b7843d308e2705cb8239d55\System.Drawing.ni.dll 2248192 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\898b578693d64daac6e604c9cc44fcea 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\898b578693d64daac6e604c9cc44fcea\System.Dynamic.ni.dll 489984 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\48264d6ad04173a3a82cc06b70c5cd28 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\48264d6ad04173a3a82cc06b70c5cd28\System.EnterpriseServices.ni.dll 1051136 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\48264d6ad04173a3a82cc06b70c5cd28\System.EnterpriseServices.Wrapper.dll 338944 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\2db9efed85653059a279145d180bc535 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\2db9efed85653059a279145d180bc535\System.IdentityModel.Selectors.ni.dll 288256 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\27fcc0e27b29a6518808712035f60f71 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\27fcc0e27b29a6518808712035f60f71\PresentationFramework.Aero.ni.dll 553984 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\33e1103724b1b63ae539a292b56355fe 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\33e1103724b1b63ae539a292b56355fe\PresentationFramework.ni.dll 22967808 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\8b726992b3b59fd5fb396feaa5697ee0 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\8b726992b3b59fd5fb396feaa5697ee0\PresentationFramework.Luna.ni.dll 745472 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a63e7b9a489aaa79e0708cd669469c72 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a63e7b9a489aaa79e0708cd669469c72\PresentationFramework.Royale.ni.dll 387072 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\d63d1aeda73031944cb04496577630e3 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\d63d1aeda73031944cb04496577630e3\PresentationFramework.Classic.ni.dll 330240 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\041944016e311af997be348fdf7bf101 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\041944016e311af997be348fdf7bf101\System.ComponentModel.Composition.ni.dll 997888 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\209765cffc4869810e3dac2a63356adb 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\209765cffc4869810e3dac2a63356adb\System.ComponentModel.DataAnnotations.ni.dll 252416 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\33ac21194152cf9a89b82d9cd38b398d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\33ac21194152cf9a89b82d9cd38b398d\System.IdentityModel.ni.dll 1401856 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\858fcb90269ce9231b39c3c8fd773d18 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\858fcb90269ce9231b39c3c8fd773d18\System.IO.Log.ni.dll 520192 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\da51604aa808b94c181181b37c727078 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\da51604aa808b94c181181b37c727078\System.Management.ni.dll 1438720 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management.I# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\0ed484f6ac7e052feab93c030580fe83 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\0ed484f6ac7e052feab93c030580fe83\System.Management.Instrumentation.ni.dll 509952 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Messaging 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\e00e9887726be6523c6766d97563a5ce 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\e00e9887726be6523c6766d97563a5ce\System.Messaging.ni.dll 767488 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net\e12639aa1d12f14e08d88dabb7d7aec2 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net\e12639aa1d12f14e08d88dabb7d7aec2\System.Net.ni.dll 904704 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Numerics 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\215d813343ba0950ad6e148e2098018b 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\215d813343ba0950ad6e148e2098018b\System.Numerics.ni.dll 176128 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Printing 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Printing\0b4141cd5f9a1f9b5db2ed0d53c2aafa 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Printing\0b4141cd5f9a1f9b5db2ed0d53c2aafa\System.Printing.ni.dll 1396224 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\2f02efd9ddb7417ffd5c06cfe6e865ca 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\2f02efd9ddb7417ffd5c06cfe6e865ca\System.Runtime.DurableInstancing.ni.dll 1327616 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\bfcee391af3b055588839ed4dcd0a93c 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\bfcee391af3b055588839ed4dcd0a93c\System.Runtime.Remoting.ni.dll 976896 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\08fba6b56d838ad48b4451c82e5728d4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\08fba6b56d838ad48b4451c82e5728d4\System.Runtime.Serialization.ni.dll 3375616 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\b468f9d8655e91b7a6aa11473eca4a97 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\b468f9d8655e91b7a6aa11473eca4a97\System.Runtime.Serialization.Formatters.Soap.ni.dll 374272 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Security 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Security\1a32460874cc4452c740b86ff22ecdf1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Security\1a32460874cc4452c740b86ff22ecdf1\System.Security.ni.dll 928768 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\d072039db89cac96d9e0b1ae9b3a94f4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\d072039db89cac96d9e0b1ae9b3a94f4\System.ServiceModel.ni.dll 24146944 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\3d4a4c37891be698e4a6da84c70f9f74 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\3d4a4c37891be698e4a6da84c70f9f74\System.ServiceModel.Discovery.ni.dll 1547776 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\50c0039fed2761ebedbf30436cb26d4e 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\50c0039fed2761ebedbf30436cb26d4e\System.ServiceModel.Channels.ni.dll 108032 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\71433975df10aad7d60d14f2a2e59ade 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\71433975df10aad7d60d14f2a2e59ade\System.ServiceModel.Routing.ni.dll 504832 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\ab64e8f7c3bcb8d217c80c6b24a6e2d1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\ab64e8f7c3bcb8d217c80c6b24a6e2d1\System.ServiceModel.Activities.ni.dll 1885184 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\7b167f31f23d4aed19dfa65ad3d29480 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\7b167f31f23d4aed19dfa65ad3d29480\System.ServiceProcess.ni.dll 275456 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Speech 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Speech\56deb12b13d969b72e250df440b3cd5f 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Speech\56deb12b13d969b72e250df440b3cd5f\System.Speech.ni.dll 2653696 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\122cea70c5d0d591f9af1f4316848fd1 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\122cea70c5d0d591f9af1f4316848fd1\System.Transactions.ni.dll 900096 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\cb9aa37454ca42d505366aa421872b49 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\cb9aa37454ca42d505366aa421872b49\System.Web.ApplicationServices.ni.dll 86016 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\f417705d2257cd04cb9d11483ed38be8 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\f417705d2257cd04cb9d11483ed38be8\System.Web.Services.ni.dll 2220032 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\c4b205eb68df08b6c0e3e2645f6653c5 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\c4b205eb68df08b6c0e3e2645f6653c5\System.Windows.Forms.DataVisualization.ni.dll 5587456 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\f0acb5c0e7dc2c42c6c61f3aa1278338 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\f0acb5c0e7dc2c42c6c61f3aa1278338\System.Windows.Forms.ni.dll 17046528 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\63310265c78b84ed848564e7b48fbdb4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\63310265c78b84ed848564e7b48fbdb4\System.Windows.Input.Manipulations.ni.dll 251904 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\ae6799bd4dc4d1a2a65cdcc8a82cea40 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\ae6799bd4dc4d1a2a65cdcc8a82cea40\System.Windows.Presentation.ni.dll 42496 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\535e182d16212c61bc8b22e0309d3362 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\535e182d16212c61bc8b22e0309d3362\System.Xaml.ni.dll 2406400 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\5d9f385419332f14eaf937556199856f 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\5d9f385419332f14eaf937556199856f\System.Xml.ni.dll 6972928 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\9d14b7bc969452800c0456286309d41d 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\9d14b7bc969452800c0456286309d41d\System.Xml.Linq.ni.dll 523264 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\Temp 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\3b9f689c1ba2a1875d5001ade2cc54e2 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\3b9f689c1ba2a1875d5001ade2cc54e2\UIAutomationClient.ni.dll 637952 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\9438a191056a09eab733771508954503 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\9438a191056a09eab733771508954503\UIAutomationClientsideProviders.ni.dll 1424896 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\17f02848e133014dab9270423d9dc916 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\17f02848e133014dab9270423d9dc916\UIAutomationProvider.ni.dll 121344 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\61f2a7b20694daeb02f7de4931261fa4 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\61f2a7b20694daeb02f7de4931261fa4\UIAutomationTypes.ni.dll 231424 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsBase 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\38d48114cb19778e4bfdc338eb8adde2 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\38d48114cb19778e4bfdc338eb8adde2\WindowsBase.ni.dll 5060608 bytes executable File C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra# 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\1c94b0dc0867d4028750c5efc3cb5edf 0 bytes File C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\1c94b0dc0867d4028750c5efc3cb5edf\WindowsFormsIntegration.ni.dll 314368 bytes executable File C:\Windows\assembly\pubpol1.dat 0 bytes File C:\Windows\assembly\pubpol4.dat 0 bytes File C:\Windows\inf\oem30.inf 2961 bytes File C:\Windows\inf\oem30.PNF 8080 bytes File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0 0 bytes File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336 0 bytes File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336\ul_ATL80.dll.97F81AF1_0E47_DC99_FF1F_C8B3B9A1E18E 96256 bytes executable File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336\ul_manifest.9BAE13A2_E7AF_D6C3_FF1F_C8B3B9A1E18E 2371 bytes File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336\ul_mfc80CHS.dll.74FD3CE6_2A8D_0E9C_FF1F_C8B3B9A1E18E 40960 bytes executable File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336\ul_mfcm80.dll.9BAE13A2_E7AF_D6C3_FF1F_C8B3B9A1E18E 69632 bytes File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336\ul_msvcr80.dll.98CB24AD_52FB_DB5F_FF1F_C8B3B9A1E18E 626688 bytes executable File C:\Windows\Installer\$PatchCache$\Managed\b25099274a207264182f8181add555d0\8.0.56336\ul_vcomp.dll.1E507087_0819_45E0_FF1F_C8B3B9A1E18E 65536 bytes executable File C:\Windows\Installer\16981.msi 2328576 bytes File C:\Windows\Installer\16988.msi 41984 bytes File C:\Windows\Installer\16990.msp 20240896 bytes File C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe (size mismatch) 158560/159320 bytes executable File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001} 0 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\APIFile_8.ico 27989 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\FDFFile_8.ico 34295 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\PDFFile_8.ico 292878 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\PDXFile_8.ico 30379 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\SC_Reader.ico 292878 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\SecStoreFile.ico 33752 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\XDPFile_8.ico 38929 bytes File C:\Windows\Installer\{AC76BA86-7AD7-1045-7B44-AA1000000001}\XFDFFile_8.ico 38614 bytes File C:\Windows\Installer\{CA640F1C-BC62-47B4-BAE1-A6467324EB2F} 0 bytes File C:\Windows\Installer\{CA640F1C-BC62-47B4-BAE1-A6467324EB2F}\1033.MST 32768 bytes File C:\Windows\Installer\{CA640F1C-BC62-47B4-BAE1-A6467324EB2F}\ARPPRODUCTICON.exe 128384 bytes executable File C:\Windows\Installer\{CA640F1C-BC62-47B4-BAE1-A6467324EB2F}\NewShortcut11_826E84252D674A43B34790A4A3064AF1.exe 128384 bytes executable File C:\Windows\Installer\{CA640F1C-BC62-47B4-BAE1-A6467324EB2F}\NewShortcut2_26C5DC5011A34F178F25162C256BC0EB.exe 128384 bytes executable File C:\Windows\Installer\25592.msi 1901056 bytes File C:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll 49152 bytes executable File C:\Windows\Installer\16c09.msi 2818048 bytes File C:\Windows\Installer\16c15.msi 25088 bytes File C:\Windows\Installer\16c2e.msi 32256 bytes File C:\Windows\Installer\16c37.msi 14524928 bytes File C:\Windows\SoftwareDistribution\DataStore\Logs\edb00001.log 1310720 bytes File C:\Windows\System32\catroot2\edb004E9.log 65536 bytes File C:\Windows\System32\drivers\cfwids.sys 65264 bytes executable File C:\Windows\System32\drivers\mferkdet.sys 100912 bytes executable File C:\Windows\System32\drivers\mfeapfk.sys 160280 bytes executable File C:\Windows\System32\drivers\mfeavfk.sys 229528 bytes executable File C:\Windows\System32\drivers\mfeclnk.sys 10248 bytes executable File C:\Windows\System32\drivers\mfefirek.sys 481768 bytes executable File C:\Windows\System32\drivers\mfehidk.sys 771096 bytes executable File C:\Windows\System32\drivers\mfenlfk.sys 75808 bytes executable File C:\Windows\System32\drivers\mfewfpk.sys 339776 bytes executable File C:\Windows\System32\DriverStore\FileRepository\mfenlfk.inf_amd64_neutral_acec8c424d80b3f4 0 bytes File C:\Windows\System32\DriverStore\FileRepository\mfenlfk.inf_amd64_neutral_acec8c424d80b3f4\mfenlfk.cat 7722 bytes File C:\Windows\System32\DriverStore\FileRepository\mfenlfk.inf_amd64_neutral_acec8c424d80b3f4\mfenlfk.inf 2961 bytes File C:\Windows\System32\DriverStore\FileRepository\mfenlfk.inf_amd64_neutral_acec8c424d80b3f4\mfenlfk.PNF 8080 bytes File C:\Windows\System32\DriverStore\FileRepository\mfenlfk.inf_amd64_neutral_acec8c424d80b3f4\mfenlfk.sys 75808 bytes executable File C:\Windows\System32\en-US\dfshim.dll.mui (size mismatch) 8552/18520 bytes executable File C:\Windows\System32\LogFiles\Scm\a1d60d55-a6b8-401b-bc05-2938e02df2f2 20 bytes File C:\Windows\System32\MRT.exe (size mismatch) 82896128/90655440 bytes executable File C:\Windows\System32\msvcr100_clr0400.dll (size mismatch) 827744/18000 bytes executable File C:\Windows\System32\NCCount.bin 0 bytes File C:\Windows\System32\mfevtps.exe 161168 bytes executable File C:\Windows\System32\Tasks\Lenovo\Lenovo Solution Center Launcher 3684 bytes File C:\Windows\System32\Tasks\Lenovo\LSC\CreateHardwareScanTask 3746 bytes File C:\Windows\System32\UICommu.bin 228 bytes File C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\SQM\iesqmdata_setup3.sqm 5642 bytes File C:\Windows\SysWOW64\en-US\dfshim.dll.mui (size mismatch) 8552/18520 bytes executable File C:\Windows\SysWOW64\msvcr100_clr0400.dll (size mismatch) 771424/18000 bytes executable File C:\Windows\Temp\0118491356438469mcinst.exe 827456 bytes executable File C:\Windows\Temp\cab_5320_3 46 bytes File C:\Windows\Temp\cab_5572_5 46 bytes File C:\Windows\Temp\cab_7220_4 1308322 bytes File C:\Windows\Temp\cab_5320_4 1017562 bytes File C:\Windows\Temp\cab_5320_5 46 bytes File C:\Windows\Temp\cab_5320_6 8 bytes File C:\Windows\Temp\cab_5400_2 1051923 bytes File C:\Windows\Temp\cab_5400_3 46 bytes File C:\Windows\Temp\cab_5400_4 1051923 bytes File C:\Windows\Temp\cab_5400_5 46 bytes File C:\Windows\Temp\cab_5400_6 8 bytes File C:\Windows\Temp\cab_5572_2 509231 bytes File C:\Windows\Temp\cab_5572_3 46 bytes File C:\Windows\Temp\cab_5572_4 509231 bytes File C:\Windows\Temp\cab_1076_2 627713 bytes File C:\Windows\Temp\cab_1076_3 46 bytes File C:\Windows\Temp\cab_1076_4 627713 bytes File C:\Windows\Temp\cab_1076_5 46 bytes File C:\Windows\Temp\cab_1076_6 8 bytes File C:\Windows\Temp\cab_1204_2 1199572 bytes File C:\Windows\Temp\cab_1204_3 46 bytes File C:\Windows\Temp\cab_1204_4 1199572 bytes File C:\Windows\Temp\cab_1204_5 46 bytes File C:\Windows\Temp\cab_1204_6 8 bytes File C:\Windows\Temp\cab_5572_6 8 bytes File C:\Windows\Temp\cab_5572_7 0 bytes File C:\Windows\Temp\cab_5572_8 0 bytes File C:\Windows\Temp\cab_5628_2 1817794 bytes File C:\Windows\Temp\cab_5628_3 46 bytes File C:\Windows\Temp\cab_5628_4 1817794 bytes File C:\Windows\Temp\cab_5628_5 46 bytes File C:\Windows\Temp\cab_5628_6 8 bytes File C:\Windows\Temp\cab_5804_2 1727473 bytes File C:\Windows\Temp\cab_5804_3 46 bytes File C:\Windows\Temp\cab_5804_4 1727473 bytes File C:\Windows\Temp\cab_5804_5 46 bytes File C:\Windows\Temp\cab_5804_6 8 bytes File C:\Windows\Temp\cab_5896_2 955331 bytes File C:\Windows\Temp\cab_5896_3 46 bytes File C:\Windows\Temp\cab_5896_4 955331 bytes File C:\Windows\Temp\cab_5896_5 46 bytes File C:\Windows\Temp\cab_5896_6 8 bytes File C:\Windows\Temp\cab_7220_2 1308322 bytes File C:\Windows\Temp\cab_7220_3 46 bytes File C:\Windows\Temp\cab_3848_2 648600 bytes File C:\Windows\Temp\cab_3848_3 46 bytes File C:\Windows\Temp\cab_3848_4 648600 bytes File C:\Windows\Temp\cab_3848_5 46 bytes File C:\Windows\Temp\cab_3848_6 8 bytes File C:\Windows\Temp\cab_7220_5 46 bytes File C:\Windows\Temp\cab_7220_6 8 bytes File C:\Windows\Temp\cab_2380_2 1342953 bytes File C:\Windows\Temp\cab_2380_3 46 bytes File C:\Windows\Temp\cab_2380_4 1342953 bytes File C:\Windows\Temp\cab_2380_5 46 bytes File C:\Windows\Temp\cab_2380_6 8 bytes File C:\Windows\Temp\cab_2952_2 961365 bytes File C:\Windows\Temp\cab_2952_3 46 bytes File C:\Windows\Temp\cab_2952_4 961365 bytes File C:\Windows\Temp\cab_2952_5 46 bytes File C:\Windows\Temp\cab_2952_6 8 bytes File C:\Windows\Temp\IE140B9.tmp\SQMAPI.DLL 235216 bytes executable File C:\Windows\Temp\IE1A2C4.tmp\SQMAPI.DLL 235032 bytes executable File C:\Windows\Temp\cab_5252_2 1932638 bytes File C:\Windows\Temp\cab_5252_3 46 bytes File C:\Windows\Temp\cab_5252_4 1932638 bytes File C:\Windows\Temp\cab_5252_5 46 bytes File C:\Windows\Temp\cab_5252_6 8 bytes File C:\Windows\Temp\cab_5320_2 1017562 bytes File C:\Windows\Microsoft.NET\NETFXRepair.1028.dll (size mismatch) 8024/18008 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll (size mismatch) 81248/96880 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll (size mismatch) 78168/72792 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll (size mismatch) 2989456/3105496 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll (size mismatch) 5196112/5214376 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll (size mismatch) 3545952/3226224 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll (size mismatch) 2970968/3208792 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll (size mismatch) 246128/248464 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll (size mismatch) 109568/114688 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll (size mismatch) 334688/342632 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll (size mismatch) 269672/288888 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll (size mismatch) 91488/106608 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll (size mismatch) 94552/73304 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll (size mismatch) 3563408/3715800 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll (size mismatch) 4960080/5151392 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll (size mismatch) 3453792/3207792 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll (size mismatch) 3111768/3237464 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll (size mismatch) 237424/247952 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll (size mismatch) 125440/129024 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll (size mismatch) 335712/342120 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll (size mismatch) 288616/291448 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll (size mismatch) 17240/26704 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll (size mismatch) 505184/483952 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll (size mismatch) 746336/758896 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll (size mismatch) 387960/399008 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll (size mismatch) 661352/642688 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll (size mismatch) 349576/360120 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll (size mismatch) 97680/108752 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll (size mismatch) 12128/21088 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll (size mismatch) 62880/131816 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll (size mismatch) 6346600/6197376 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll (size mismatch) 232304/249496 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll (size mismatch) 167288/181920 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll (size mismatch) 478576/485528 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll (size mismatch) 194424/209056 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll (size mismatch) 832856/847464 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll (size mismatch) 581464/595048 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll (size mismatch) 112976/124496 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll (size mismatch) 3481928/3453000 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll (size mismatch) 1199968/1574000 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll (size mismatch) 525704/718008 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll (size mismatch) 122248/135352 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll (size mismatch) 1462648/2137256 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll (size mismatch) 149848/163424 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll (size mismatch) 39784/52352 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll (size mismatch) 210816/304304 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll (size mismatch) 81800/111296 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll (size mismatch) 409448/393856 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll (size mismatch) 81784/94368 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll (size mismatch) 1339736/1252440 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll (size mismatch) 50552/63648 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll (size mismatch) 683872/698480 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll (size mismatch) 436600/448152 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll (size mismatch) 747360/743544 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll (size mismatch) 829280/842864 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll (size mismatch) 51032/63584 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll (size mismatch) 395120/415888 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll (size mismatch) 285072/297688 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll (size mismatch) 182144/194232 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll (size mismatch) 607064/586856 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll (size mismatch) 120152/125544 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll (size mismatch) 392552/1085056 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll (size mismatch) 125816/136872 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll (size mismatch) 123736/134752 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll (size mismatch) 378720/406128 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll (size mismatch) 134528/146608 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll (size mismatch) 231760/250968 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll (size mismatch) 64352/77416 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll (size mismatch) 349568/164528 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll (size mismatch) 291184/338056 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll (size mismatch) 1026936/1052320 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll (size mismatch) 122264/133344 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll (size mismatch) 261472/280168 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll (size mismatch) 6067048/6367352 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll (size mismatch) 505208/570536 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll (size mismatch) 37240/158880 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll (size mismatch) 390008/309408 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll (size mismatch) 129912/132248 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll (size mismatch) 113512/126080 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll (size mismatch) 675672/686176 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll (size mismatch) 44920/62712 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll (size mismatch) 857960/849528 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll (size mismatch) 4982120/4811392 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll (size mismatch) 1711496/1726152 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll (size mismatch) 58240/68280 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll (size mismatch) 17784/28824 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll (size mismatch) 699224/631896 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll (size mismatch) 2207568/2691672 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll (size mismatch) 138592/154728 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll (size mismatch) 68952/64608 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll (size mismatch) 4464480/4163704 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll (size mismatch) 253280/266864 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll (size mismatch) 163168/179320 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll (size mismatch) 350592/366760 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll (size mismatch) 35688/49280 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll (size mismatch) 93024/106608 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll (size mismatch) 1303896/1239128 bytes executable File C:\Windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll (size mismatch) 87408/103560 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\alinkui.dll (size mismatch) 24400/35400 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll (size mismatch) 182088/203328 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\CvtResUI.dll (size mismatch) 10064/20064 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\Microsoft.VisualBasic.Activities.CompilerUI.dll (size mismatch) 255896/272096 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\vbc7ui.dll (size mismatch) 255304/271432 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Accessibility.dll (size mismatch) 17240/26704 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe (size mismatch) 29016/161 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe (size mismatch) 29528/161 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe (size mismatch) 29008/161 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\AdoNetDiag.dll (size mismatch) 139088/162392 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_dataperfcounters_shared12_neutral.h 444 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_NetworkingPerfCounters.h 1055 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_Networkingperfcounters.ini 173424 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_SMSvcHostPerfCounters.h 702 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_SMSvcHostPerfCounters.ini 133910 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_TransactionBridgePerfCounters.h 705 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_TransactionBridgePerfCounters.ini 135794 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll (size mismatch) 1141592/1299632 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll (size mismatch) 955728/1104544 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.tlb (size mismatch) 29696/30208 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll (size mismatch) 413008/505424 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreeis.dll (size mismatch) 20816/32848 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll (size mismatch) 5196112/5214376 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.tlb (size mismatch) 518144/519680 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll (size mismatch) 145752/143448 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll (size mismatch) 372048/394312 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsecimpl.dll (size mismatch) 110936/108128 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvc.dll (size mismatch) 335184/409168 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (size mismatch) 130384/105144 bytes executable <-- ROOTKIT !!! File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.dll (size mismatch) 1199968/1574000 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.DurableInstancing.dll (size mismatch) 122248/135352 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.Presentation.dll (size mismatch) 1462648/2137256 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.Contract.dll (size mismatch) 39784/52352 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll (size mismatch) 149848/163424 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ComponentModel.Composition.dll (size mismatch) 210816/304304 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ComponentModel.DataAnnotations.dll (size mismatch) 81800/111296 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.configuration.dll (size mismatch) 409448/393856 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Configuration.Install.dll (size mismatch) 81784/94368 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll (size mismatch) 1339736/1252440 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.DataSetExtensions.dll (size mismatch) 50552/63648 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.dll (size mismatch) 2970968/3208792 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Entity.dll (size mismatch) 4464480/4163704 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Linq.dll (size mismatch) 683872/698480 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.SqlXml.dll (size mismatch) 747360/743544 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Deployment.dll (size mismatch) 829280/842864 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Device.dll (size mismatch) 51032/63584 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.AccountManagement.dll (size mismatch) 285072/297688 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.dll (size mismatch) 395120/415888 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.Protocols.dll (size mismatch) 182144/194232 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll (size mismatch) 3481928/3453000 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll (size mismatch) 607064/586856 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.tlb (size mismatch) 7168/7680 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Dynamic.dll (size mismatch) 120152/125544 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.dll (size mismatch) 246128/248464 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.Thunk.dll (size mismatch) 45952/74920 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.Wrapper.dll (size mismatch) 109568/114688 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.IdentityModel.dll (size mismatch) 392552/1085056 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.IdentityModel.Selectors.dll (size mismatch) 125816/136872 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.IO.Log.dll (size mismatch) 123736/134752 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll (size mismatch) 688472/868448 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.Core.Presentation.dll (size mismatch) 525704/718008 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.Client.dll (size mismatch) 436600/448152 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll (size mismatch) 378720/406128 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Routing.dll (size mismatch) 129912/132248 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\_DataPerfCounters.h 829 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.Instrumentation.dll (size mismatch) 134528/146608 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Messaging.dll (size mismatch) 253280/266864 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Net.dll (size mismatch) 231760/250968 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Numerics.dll (size mismatch) 64352/77416 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.DurableInstancing.dll (size mismatch) 349568/164528 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Remoting.dll (size mismatch) 291184/338056 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll (size mismatch) 1026936/1052320 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll (size mismatch) 122264/133344 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Security.dll (size mismatch) 261472/280168 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Activities.dll (size mismatch) 505208/570536 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Channels.dll (size mismatch) 37240/158880 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Discovery.dll (size mismatch) 390008/309408 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.dll (size mismatch) 6067048/6367352 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\sysglobl.dll (size mismatch) 112976/124496 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.CSharp.dll (size mismatch) 505184/483952 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.JScript.dll (size mismatch) 746336/758896 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Transactions.Bridge.dll (size mismatch) 387960/399008 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Activities.Compiler.dll (size mismatch) 2989456/3105496 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Compatibility.Data.dll (size mismatch) 97680/108752 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Compatibility.dll (size mismatch) 349576/360120 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.dll (size mismatch) 661352/642688 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualC.Dll (size mismatch) 12128/21088 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Windows.ApplicationServer.Applications.dll (size mismatch) 62880/131816 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Windows.ApplicationServer.Applications.man 261836 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll (size mismatch) 105288/115264 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe (size mismatch) 105808/281 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe (size mismatch) 95048/368 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll (size mismatch) 6730056/6915216 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll (size mismatch) 385864/511648 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\CORPerfMonExt.dll (size mismatch) 129880/131680 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceProcess.dll (size mismatch) 113512/126080 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Transactions.dll (size mismatch) 269672/288888 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Web.ApplicationServices.dll (size mismatch) 44920/62712 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Services.dll (size mismatch) 857960/849528 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.DataVisualization.dll (size mismatch) 1711496/1726152 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll (size mismatch) 4982120/4811392 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Xaml.dll (size mismatch) 699224/631896 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.XML.dll (size mismatch) 2207568/2691672 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Linq.dll (size mismatch) 138592/154728 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe (size mismatch) 2199880/2380856 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe.config 182 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF 0 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\ReachFramework.dll 581464 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\en-US 0 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\en-US\PresentationHost_v0400.dll.mui 74608 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\Fonts 0 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\Fonts\GlobalMonospace.CompositeFont 26040 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\Fonts\GlobalSansSerif.CompositeFont 26489 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\Fonts\GlobalSerif.CompositeFont 29779 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\Fonts\GlobalUserInterface.CompositeFont 43318 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\NaturalLanguage6.dll 807264 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\NlsData0009.dll 4881752 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\NlsLexicons0009.dll 2650464 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PenIMC.dll 67912 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll 3545952 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Aero.dll 232304 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Classic.dll 167288 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll 6346600 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Luna.dll 478576 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Royale.dll 194424 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll 181096 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll 801136 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationUI.dll 832856 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Printing.dll 334688 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Speech.dll 675672 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Windows.Input.Manipulations.dll 58240 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Windows.Presentation.dll 17784 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationClient.dll 163168 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationClientsideProviders.dll 350592 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationProvider.dll 35688 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationTypes.dll 93024 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll 1303896 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsFormsIntegration.dll 87408 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll 1663320 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\XPThemes.manifest 474 bytes File C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe (size mismatch) 1972552/182 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\Culture.dll (size mismatch) 44368/54856 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\CustomMarshalers.dll (size mismatch) 81248/96880 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe (size mismatch) 31048/281 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfdll.dll (size mismatch) 88904/116800 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe (size mismatch) 11592/167 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\Microsoft.Windows.ApplicationServer.Applications.dll.mui (size mismatch) 52648/99080 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\ServiceModelEvents.dll.mui (size mismatch) 33128/43656 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\ServiceModelInstallRC.dll.mui (size mismatch) 9584/19600 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\ServiceModelPerformanceCounters.dll.mui (size mismatch) 48520/47288 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\ServiceModelRegUI.dll.mui (size mismatch) 27496/37504 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\EventLogMessages.dll (size mismatch) 794464/804464 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll (size mismatch) 42312/63560 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe (size mismatch) 27992/40536 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtilLib.dll (size mismatch) 58200/69736 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ISymWrapper.dll (size mismatch) 78168/72792 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe (size mismatch) 36168/281 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe (size mismatch) 58192/73800 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\SbsNclPerf.dll (size mismatch) 13648/23632 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelEvents.dll (size mismatch) 8032/18040 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll (size mismatch) 8040/18048 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelPerformanceCounters.dll (size mismatch) 42880/65192 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe (size mismatch) 173920/216680 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelRegUI.dll (size mismatch) 8032/18032 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\MUI\0409\mscorsecr.dll (size mismatch) 27984/37968 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe (size mismatch) 150856/137280 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll (size mismatch) 56656/74328 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\PerfCounter.dll (size mismatch) 121688/199256 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe (size mismatch) 52040/281 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe (size mismatch) 32592/223 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMDiagnostics.dll (size mismatch) 68952/64608 bytes executable File C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (size mismatch) 124240/2262 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\1033\alinkui.dll (size mismatch) 24400/35400 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\1033\cscui.dll (size mismatch) 182088/203328 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\1033\CvtResUI.dll (size mismatch) 10064/20064 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\1033\Microsoft.VisualBasic.Activities.CompilerUI.dll (size mismatch) 255896/272096 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\1033\vbc7ui.dll (size mismatch) 255304/271432 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Accessibility.dll (size mismatch) 17240/26704 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe (size mismatch) 29016/161 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess32.exe (size mismatch) 29528/161 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInUtil.exe (size mismatch) 29008/161 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AdoNetDiag.dll (size mismatch) 166224/175192 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\alink.dll (size mismatch) 134984/145984 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AppLaunch.exe (size mismatch) 105296/281 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\CasPol.exe (size mismatch) 94536/368 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll (size mismatch) 9798472/9845392 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll (size mismatch) 1524552/1243296 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_dataperfcounters_shared12_neutral.h 444 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_NetworkingPerfCounters.h 1055 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_Networkingperfcounters.ini 173424 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_SMSvcHostPerfCounters.h 702 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_SMSvcHostPerfCounters.ini 133910 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_TransactionBridgePerfCounters.h 705 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_TransactionBridgePerfCounters.ini 135794 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe (size mismatch) 168776/170048 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll (size mismatch) 67920/84056 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\PerfCounter.dll (size mismatch) 130392/233048 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe (size mismatch) 51528/281 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.JScript.dll (size mismatch) 746336/758896 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Transactions.Bridge.dll (size mismatch) 387960/399008 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.Activities.Compiler.dll (size mismatch) 3563408/3715800 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.Compatibility.Data.dll (size mismatch) 97680/108752 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.Compatibility.dll (size mismatch) 349576/360120 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.dll (size mismatch) 661352/642688 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualC.Dll (size mismatch) 12128/21088 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Windows.ApplicationServer.Applications.dll (size mismatch) 62880/131816 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Windows.ApplicationServer.Applications.man 261836 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.dll (size mismatch) 1199968/1574000 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.DurableInstancing.dll (size mismatch) 122248/135352 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.Presentation.dll (size mismatch) 1462648/2137256 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.Contract.dll (size mismatch) 39784/52352 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll (size mismatch) 149848/163424 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ComponentModel.Composition.dll (size mismatch) 210816/304304 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ComponentModel.DataAnnotations.dll (size mismatch) 81800/111296 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.configuration.dll (size mismatch) 409448/393856 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Configuration.Install.dll (size mismatch) 81784/94368 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Core.dll (size mismatch) 1339736/1252440 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.DataSetExtensions.dll (size mismatch) 50552/63648 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.dll (size mismatch) 3111768/3237464 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Entity.dll (size mismatch) 4464480/4163704 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Linq.dll (size mismatch) 683872/698480 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfdll.dll (size mismatch) 123720/132672 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.CSharp.dll (size mismatch) 505184/483952 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MUI\0409\mscorsecr.dll (size mismatch) 27984/37968 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (size mismatch) 124240/2262 bytes executable <-- ROOTKIT !!! File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.Core.Presentation.dll (size mismatch) 525704/718008 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.Client.dll (size mismatch) 436600/448152 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Management.dll (size mismatch) 378720/406128 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Routing.dll (size mismatch) 129912/132248 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\_DataPerfCounters.h 829 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.SqlXml.dll (size mismatch) 747360/743544 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Deployment.dll (size mismatch) 829280/842864 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Device.dll (size mismatch) 51032/63584 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.AccountManagement.dll (size mismatch) 285072/297688 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.dll (size mismatch) 395120/415888 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.Protocols.dll (size mismatch) 182144/194232 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.dll (size mismatch) 3481928/3453000 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.dll (size mismatch) 607064/586856 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.tlb (size mismatch) 7168/7680 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Dynamic.dll (size mismatch) 120152/125544 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.dll (size mismatch) 237424/247952 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.Wrapper.dll (size mismatch) 125440/129024 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.IdentityModel.dll (size mismatch) 392552/1085056 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.IdentityModel.Selectors.dll (size mismatch) 125816/136872 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.IO.Log.dll (size mismatch) 123736/134752 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Management.Instrumentation.dll (size mismatch) 134528/146608 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Messaging.dll (size mismatch) 253280/266864 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Net.dll (size mismatch) 231760/250968 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Numerics.dll (size mismatch) 64352/77416 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.DurableInstancing.dll (size mismatch) 349568/164528 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Remoting.dll (size mismatch) 291184/338056 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll (size mismatch) 1026936/1052320 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll (size mismatch) 122264/133344 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Security.dll (size mismatch) 261472/280168 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Activities.dll (size mismatch) 505208/570536 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Channels.dll (size mismatch) 37240/158880 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Discovery.dll (size mismatch) 390008/309408 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.dll (size mismatch) 6067048/6367352 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\sysglobl.dll (size mismatch) 112976/124496 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\CORPerfMonExt.dll (size mismatch) 138584/157280 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe (size mismatch) 2492232/182 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Culture.dll (size mismatch) 53072/63560 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\CustomMarshalers.dll (size mismatch) 91488/106608 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe (size mismatch) 35656/281 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceProcess.dll (size mismatch) 113512/126080 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Transactions.dll (size mismatch) 288616/291448 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.ApplicationServices.dll (size mismatch) 44920/62712 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Services.dll (size mismatch) 857960/849528 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.DataVisualization.dll (size mismatch) 1711496/1726152 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll (size mismatch) 4982120/4811392 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xaml.dll (size mismatch) 699224/631896 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.XML.dll (size mismatch) 2207568/2691672 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Linq.dll (size mismatch) 138592/154728 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\vbc.exe (size mismatch) 3170632/3356728 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\vbc.exe.config 182 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll (size mismatch) 39256/47712 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\ReachFramework.dll 581464 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\en-US 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\en-US\PresentationHost_v0400.dll.mui 74608 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\Fonts 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\Fonts\GlobalMonospace.CompositeFont 26040 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\Fonts\GlobalSansSerif.CompositeFont 26489 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\Fonts\GlobalSerif.CompositeFont 29779 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\Fonts\GlobalUserInterface.CompositeFont 43318 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\NaturalLanguage6.dll 1367904 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\NlsData0009.dll 6353752 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\NlsLexicons0009.dll 2650464 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PenIMC.dll 83272 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll 3453792 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Aero.dll 232304 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Classic.dll 167288 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll 6346600 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Luna.dll 478576 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Royale.dll 194424 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll 225640 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationNative_v0400.dll 1098096 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationUI.dll 832856 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Printing.dll 335712 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Speech.dll 675672 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Windows.Input.Manipulations.dll 58240 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Windows.Presentation.dll 17784 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationClient.dll 163168 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationClientsideProviders.dll 350592 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationProvider.dll 35688 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationTypes.dll 93024 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll 1303896 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsFormsIntegration.dll 87408 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll 2153816 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\XPThemes.manifest 474 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll (size mismatch) 597832/785552 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe (size mismatch) 11592/167 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll (size mismatch) 939864/1077344 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\Microsoft.Windows.ApplicationServer.Applications.dll.mui (size mismatch) 52648/99080 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\ServiceModelEvents.dll.mui (size mismatch) 33128/43656 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\ServiceModelInstallRC.dll.mui (size mismatch) 9584/19600 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\ServiceModelPerformanceCounters.dll.mui (size mismatch) 48520/47288 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\ServiceModelRegUI.dll.mui (size mismatch) 27496/37504 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll (size mismatch) 794464/804464 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll (size mismatch) 48456/75336 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe (size mismatch) 27480/40024 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtilLib.dll (size mismatch) 67416/77416 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ISymWrapper.dll (size mismatch) 94552/73304 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\jsc.exe (size mismatch) 36168/281 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll (size mismatch) 1513304/1743024 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll (size mismatch) 1453392/1507496 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoree.tlb (size mismatch) 29696/30208 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll (size mismatch) 578896/613456 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreeis.dll (size mismatch) 20816/32848 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll (size mismatch) 4960080/5151392 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpe.dll (size mismatch) 45904/68680 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll (size mismatch) 183640/173144 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll (size mismatch) 372560/394312 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsecimpl.dll (size mismatch) 114520/129120 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvc.dll (size mismatch) 543056/519760 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (size mismatch) 138576/124088 bytes executable <-- ROOTKIT !!! File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe (size mismatch) 32080/223 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\regtlibv12.exe (size mismatch) 65360/78408 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SbsNclPerf.dll (size mismatch) 14160/24144 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll (size mismatch) 8032/18040 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll (size mismatch) 8040/18048 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelPerformanceCounters.dll (size mismatch) 48512/69800 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe (size mismatch) 235872/248936 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelRegUI.dll (size mismatch) 8032/18032 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1055 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1055\eula.rtf 3859 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1055\LocalizedData.xml 76818 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1055\SetupResources.dll 17752 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1025 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1025\eula.rtf 7567 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1025\LocalizedData.xml 74214 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1025\SetupResources.dll 17240 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1028 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1028\eula.rtf 6309 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1028\LocalizedData.xml 60816 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1028\SetupResources.dll 14168 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1029 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1029\eula.rtf 3726 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1029\LocalizedData.xml 80970 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1029\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1030 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1030\eula.rtf 3314 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1030\LocalizedData.xml 77748 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1030\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1031 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1031\eula.rtf 3419 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1031\LocalizedData.xml 82346 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1031\SetupResources.dll 18776 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1032 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1032\eula.rtf 8876 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1032\LocalizedData.xml 86284 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1032\SetupResources.dll 19288 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1033 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1033\eula.rtf 3188 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1033\LocalizedData.xml 77232 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1033\SetupResources.dll 17240 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1035 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1035\eula.rtf 3702 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1035\LocalizedData.xml 77022 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1035\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1036 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1036\eula.rtf 3526 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1036\LocalizedData.xml 82962 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1036\SetupResources.dll 18776 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1037 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1037\eula.rtf 6851 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1037\LocalizedData.xml 72076 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1037\SetupResources.dll 16728 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1038 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1038\eula.rtf 4254 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1038\LocalizedData.xml 86442 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1038\SetupResources.dll 18776 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1040 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1040\eula.rtf 3643 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1040\LocalizedData.xml 80060 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1040\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1041 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1041\eula.rtf 10125 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1041\LocalizedData.xml 68226 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1041\SetupResources.dll 15704 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1042 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1042\eula.rtf 12687 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1042\LocalizedData.xml 65238 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1042\SetupResources.dll 15192 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1043 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1043\eula.rtf 3546 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1043\LocalizedData.xml 79634 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1043\SetupResources.dll 19288 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1044 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1044\eula.rtf 3046 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1044\LocalizedData.xml 79296 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1044\SetupResources.dll 17752 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1045 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1045\eula.rtf 4040 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1045\LocalizedData.xml 82374 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1045\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1046 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1046\eula.rtf 3683 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1046\LocalizedData.xml 80738 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1046\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1049 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1049\eula.rtf 54456 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1049\LocalizedData.xml 81482 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1049\SetupResources.dll 18264 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1053 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1053\eula.rtf 3865 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1053\LocalizedData.xml 77680 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1053\SetupResources.dll 17752 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2052 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2052\eula.rtf 5827 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2052\LocalizedData.xml 60684 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2052\SetupResources.dll 14168 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2070 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2070\eula.rtf 4015 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2070\LocalizedData.xml 80254 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2070\SetupResources.dll 18776 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3076 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3076\eula.rtf 6309 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3076\LocalizedData.xml 60816 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3076\SetupResources.dll 14168 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3082 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3082\eula.rtf 3069 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3082\LocalizedData.xml 79996 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3082\SetupResources.dll 18776 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Client 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Client\ParameterInfo.xml 201796 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Client\UiInfo.xml 39042 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\DHtmlHeader.html 16118 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\DisplayIcon.ico 88533 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics 0 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Print.ico 1150 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate1.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate2.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate3.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate4.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate5.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate6.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate7.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Rotate8.ico 894 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Save.ico 1150 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\Setup.ico 36710 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\stop.ico 10134 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\SysReqMet.ico 1150 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\SysReqNotMet.ico 1150 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Graphics\warn.ico 10134 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\header.bmp 3628 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core.mzz 181483595 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core_x64.msi 1901056 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe 78152 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupEngine.dll 807256 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupUi.dll 295248 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupUi.xsd 30120 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupUtility.exe 96088 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SplashScreen.bmp 41080 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\sqmapi.dll 144416 bytes executable File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Strings.xml 14084 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\watermark.bmp 104072 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Windows6.1-KB958488-v6001-x64.msu 5091790 bytes File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMDiagnostics.dll (size mismatch) 68952/64608 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1025.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1029.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1030.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1031.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1032.dll (size mismatch) 9048/19032 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1033.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1035.dll (size mismatch) 9048/19032 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1036.dll (size mismatch) 9048/19032 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1037.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1038.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1040.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1041.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1042.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1043.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1044.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1045.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1046.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1049.dll (size mismatch) 9048/19032 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1053.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.1055.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.2052.dll (size mismatch) 8024/18008 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.2070.dll (size mismatch) 8536/19032 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.3076.dll 8536 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.3082.dll (size mismatch) 8536/18520 bytes executable File C:\Windows\Microsoft.NET\NETFXRepair.exe (size mismatch) 114520/131160 bytes executable File C:\Windows\winsxs\amd64_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.1.7600.16385_none_12b230ea15a9e57a\_DataOracleClientPerfCounters_shared12_neutral.h 444 bytes File C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat 243652 bytes ---- Services - GMER 2.1 ---- Service C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [MANUAL] gusvc <-- ROOTKIT !!! Service C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [AUTO] clr_optimization_v4.0.30319_32 <-- ROOTKIT !!! Service C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [DISABLED] NetMsmqActivator <-- ROOTKIT !!! Service C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [AUTO] clr_optimization_v4.0.30319_64 <-- ROOTKIT !!! ---- EOF - GMER 2.1 ----