Hello Papakid
Here are the reports
GMER 1.0.13.12551 -
http://www.gmer.netRootkit scan 2007-07-22 07:50:58
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys ZwCreateKey
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys ZwCreateSection
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys ZwCreateSymbolicLinkObject
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys ZwMakeTemporaryObject
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys ZwOpenSection
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys ZwSetInformationProcess
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys ZwSetSystemInformation
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- Kernel IAT/EAT - GMER 1.0.13 ----
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisMCoSendComplete] [F8604E20] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisMSetAttributesEx] [F8606A90] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisInitializeWrapper] [F8606670] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisMRegisterMiniport] [F86070C0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisTerminateWrapper] [F8606CA0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\rasl2tp.sys[NDIS.SYS!NdisMCmRegisterAddressFamily] [F86049B0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisClOpenAddressFamily] [F8604880] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisMCoSendComplete] [F8604E20] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisMSetAttributesEx] [F8606A90] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisMCmRegisterAddressFamily] [F86049B0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisInitializeWrapper] [F8606670] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisTerminateWrapper] [F8606CA0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisMRegisterMiniport] [F86070C0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisMSetAttributesEx] [F8606A90] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisTerminateWrapper] [F8606CA0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisMRegisterMiniport] [F86070C0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisInitializeWrapper] [F8606670] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspptp.sys[NDIS.SYS!NdisMSetAttributesEx] [F8606A90] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspptp.sys[NDIS.SYS!NdisInitializeWrapper] [F8606670] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspptp.sys[NDIS.SYS!NdisMRegisterMiniport] [F86070C0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspptp.sys[NDIS.SYS!NdisTerminateWrapper] [F8606CA0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\TDI.SYS[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisTerminateWrapper] [F8606CA0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisIMAssociateMiniport] [F86069C0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisIMRegisterLayeredMiniport] [F8607170] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisInitializeWrapper] [F8606670] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisClOpenAddressFamily] [F8604880] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisMSetAttributesEx] [F8606A90] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisInitializeWrapper] [F8606670] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisMCoSendComplete] [F8604E20] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisMSetAttributesEx] [F8606A90] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisMCmRegisterAddressFamily] [F86049B0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisMRegisterMiniport] [F86070C0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\raspti.sys[NDIS.SYS!NdisTerminateWrapper] [F8606CA0] kmxstart.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCmRegisterAddressFamily] [F8604920] kmxstart.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisClOpenAddressFamily] [F8604880] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisReturnPackets] [F86056D0] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F8606720] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F8606570] kmxstart.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F8605FC0] kmxstart.sys
---- User IAT/EAT - GMER 1.0.13 ----
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [02040640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0203F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [02040640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [02040290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [02040640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0203F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0203F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [02040470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [02040640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [02040290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [0203F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [02040640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [0203F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [0203FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExA] [0203F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [0203FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\System32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [0203FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\System32\svchost.exe[496] @ C:\WINDOWS\System32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [0203F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ c:\windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ c:\windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[840] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\winlogon.exe[1016] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [00940290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [00940470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [00940290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1048] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\services.exe[1156] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [011B0640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [011AF990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [011B0470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [011B0640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [011B0290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [011B0640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [011AF990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [011AF990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [011B0640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [011AF990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [011AFBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExA] [011AF990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [011B0290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [011AF990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [011B0640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [011AFF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [011AF810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\Explorer.EXE[1516] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [011AFDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!CreateProcessW] [10010640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [1000F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [1000FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryW] [1000FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1764] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [00940290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [00940470] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [00940290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [ADVAPI32.dll!CreateProcessAsUserW] [00940290] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!CreateProcessW] [00940640] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExA] [0093F990] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] [0093FBA0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [0093FF30] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ c:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [0093FDB0] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
IAT C:\WINDOWS\system32\svchost.exe[1976] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [0093F810] C:\Program Files\CA\SharedComponents\PPRT\bin\CACheck.dll
---- Devices - GMER 1.0.13 ----
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F88DC439] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F88DC669] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F88DC4F5] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F88DC564] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F88DC620] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F88DC6BB] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F841CDEC] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F841D4C6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F841C892] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F841C810] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F841C800] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F841C790] VET-REC.SYS
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F6E76900] kmxfw.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F6E76A60] kmxfw.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F6E77500] kmxfw.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F6E774C0] kmxfw.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F6E76AC0] kmxfw.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F6E76900] kmxfw.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F6E76A60] kmxfw.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F6E77500] kmxfw.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F6E774C0] kmxfw.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F6E76AC0] kmxfw.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F6E76900] kmxfw.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F6E76A60] kmxfw.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F6E77500] kmxfw.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F6E774C0] kmxfw.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F6E76AC0] kmxfw.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F6E76900] kmxfw.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F6E76A60] kmxfw.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F6E77500] kmxfw.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F6E774C0] kmxfw.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F6E76AC0] kmxfw.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F6E76900] kmxfw.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F6E76A60] kmxfw.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F6E77500] kmxfw.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F6E774C0] kmxfw.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F6E76AC0] kmxfw.sys
Device \Driver\AFD \Device\Afd IRP_MJ_CREATE [F4EAA850] KmxCF.sys
Device \Driver\AFD \Device\Afd IRP_MJ_CLOSE [F4EAB010] KmxCF.sys
Device \Driver\AFD \Device\Afd IRP_MJ_READ [F4EAB290] KmxCF.sys
Device \Driver\AFD \Device\Afd IRP_MJ_WRITE [F4EAB070] KmxCF.sys
Device \Driver\AFD \Device\Afd IRP_MJ_DEVICE_CONTROL [F4EAB2E0] KmxCF.sys
Device \Driver\AFD \Device\Afd IRP_MJ_INTERNAL_DEVICE_CONTROL [F4EAA890] KmxCF.sys
Device \Driver\AFD \Device\Afd IRP_MJ_CLEANUP [F4EAB040] KmxCF.sys
Device \Driver\AFD \Device\Afd FastIoDeviceControl [F4EAB3E0] KmxCF.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F6EE031A] kmxagent.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F88DC439] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F88DC669] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F88DC4F5] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F88DC564] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F88DC620] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F88DC6BB] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F88DC3A4] KmxFile.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F841CDEC] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F841D4C6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F841C892] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F841C810] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F841C800] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F841C790] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F841C790] VET-REC.SYS
---- EOF - GMER 1.0.13 ----
Here is the awf report
Find AWF report by noahdfear ©2006
bak folders found
~~~~~~~~~~~
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
end of report
And the Registrar report
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Plugin]
"DisplayName"="Adobe Flash Player Plugin"
"DisplayVersion"="9.0.47.0"
"Publisher"="Adobe Systems Incorporated"
"URLInfoAbout"="http://www.adobe.com/go/getflashplayer"
"DisplayIcon"="C:\\WINDOWS\\system32\\Macromed\\Flash\\uninstall_plugin.exe"
"UninstallString"="C:\\WINDOWS\\system32\\Macromed\\Flash\\uninstall_plugin.exe"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVGantiRootkit]
"DisplayName"="AVG Anti-Rootkit Free"
"UninstallString"="C:\\Program Files\\GRISOFT\\AVG Anti-Rootkit Free\\Uninstall.exe"
"InstallLocation"="C:\\Program Files\\GRISOFT\\AVG Anti-Rootkit Free"
"DisplayIcon"="C:\\Program Files\\GRISOFT\\AVG Anti-Rootkit Free\\avgarkt.exe"
"Publisher"="GRISOFT"
"HelpLink"="http://www.grisoft.com"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner]
"DisplayName"="CCleaner (remove only)"
"UninstallString"="\"C:\\Program Files\\CCleaner\\uninst.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ERUNT_is1]
"Inno Setup: Setup Version"="4.2.7"
"Inno Setup: App Path"="C:\\Program Files\\ERUNT"
"InstallLocation"="C:\\Program Files\\ERUNT\\"
"Inno Setup: Icon Group"="ERUNT"
"Inno Setup: User"="Matthew"
"Inno Setup: Selected Tasks"="eruntdesktopicon,ntregoptdesktopicon"
"Inno Setup: Deselected Tasks"="eruntquicklaunchicon,ntregoptquicklaunchicon,installgermanlanguagefiles"
"DisplayName"="ERUNT 1.1j"
"UninstallString"="\"C:\\Program Files\\ERUNT\\unins000.exe\""
"QuietUninstallString"="\"C:\\Program Files\\ERUNT\\unins000.exe\" /SILENT"
"Publisher"="Lars Hederer"
"URLInfoAbout"="http://www.larshederer.homepage.t-online.de"
"HelpLink"="http://www.larshederer.homepage.t-online.de/erunt"
"URLUpdateInfo"="http://www.larshederer.homepage.t-online.de/erunt"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal]
"DisplayName"="CA Internet Security Suite"
"UninstallString"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe\" /u"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="CA, Inc."
"URLInfoAbout"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=PN&app=inclient&lang=en&date=1184267626&link_id=1&dest=homepage&lic=4CZT1ECJGYXKWJLRIRIK&ver=5.1.17.0"
"HelpLink"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=PN&app=inclient&lang=en&date=1184267626&link_id=1&dest=main_support&lic=4CZT1ECJGYXKWJLRIRIK&ver=5.1.17.0"
"DisplayVersion"="3.2.1.14"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite"
"DisplayIcon"="C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe,-0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\as]
"DisplayIcon"="C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe,-0"
"UninstallString"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe\" /u"
"DisplayName"="CA Anti-Spam"
"Publisher"="CA, Inc."
"HelpLink"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=PN&app=inclient&lang=en&date=1184267664&link_id=1&dest=main_support&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=5.1.17.0"
"URLInfoAbout"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=PN&app=inclient&lang=en&date=1184267664&link_id=1&dest=homepage&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=5.1.17.0"
"DisplayVersion"="5.1.17.0"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Spam\\QSP-5.1.17.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\av]
"DisplayName"="CA Anti-Virus"
"UninstallProduct"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\unvet32.exe"
"UninstallString"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe\" /u"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="CA, Inc."
"URLInfoAbout"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=SS&app=inclient&lang=en&date=1184253124&link_id=1&dest=homepage&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=3.2.1.14"
"HelpLink"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=SS&app=inclient&lang=en&date=1184253124&link_id=1&dest=main_support&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=3.2.1.14"
"DisplayVersion"="8.4.0.24"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus"
"DisplayIcon"="C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe,-0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\pfw]
"DisplayName"="CA Personal Firewall"
"UninstallProduct"="MsiExec.exe /X{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}"
"UninstallString"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe\" /u"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="CA, Inc."
"URLInfoAbout"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=SS&app=inclient&lang=en&date=1184253153&link_id=1&dest=homepage&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=3.2.1.14"
"HelpLink"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=SS&app=inclient&lang=en&date=1184253153&link_id=1&dest=main_support&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=3.2.1.14"
"DisplayVersion"="9.1.0.33"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Personal Firewall"
"DisplayIcon"="C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe,-0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eTrust Suite Personal\pp]
"DisplayName"="CA Anti-Spyware"
"UninstallProduct"="MsiExec.exe /X{609B0E8F-0E98-46BF-85F9-7123D1022D84}"
"UninstallString"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe\" /u"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="CA, Inc."
"URLInfoAbout"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=SS&app=inclient&lang=en&date=1184253122&link_id=1&dest=homepage&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=3.2.1.14"
"HelpLink"="http://www.my-etrust.com/Redirect/router.aspx?OEM= &prod=SS&app=inclient&lang=en&date=1184253122&link_id=1&dest=main_support&lic=4CZT1-ECJGY-XKWJL-RIRIK&ver=3.2.1.14"
"DisplayVersion"="9.1.0.18"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Spyware"
"DisplayIcon"="C:\\Program Files\\CA\\CA Internet Security Suite\\caunst.exe,-0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis]
"DisplayName"="HijackThis 2.0.2"
"UninstallString"="\"C:\\Documents and Settings\\Matthew\\Desktop\\HijackThis.exe\" /uninstall"
"DisplayIcon"="C:\\Documents and Settings\\Matthew\\Desktop\\HijackThis.exe"
"DisplayVersion"="2.0.2"
"Publisher"="TrendMicro"
"URLInfoAbout"="http://www.spywareinfo.com/~merijn/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB892130]
"DisplayName"="Windows Genuine Advantage Validation Tool (KB892130)"
"UninstallString"=""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070711"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=892130"
"URLInfoAbout"="http://www.microsoft.com/genuine"
"NoRemove"=dword:00000001
"NoRemoveInitialValue"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB928365.T1_1ToU569_1]
"UninstallString"="C:\\WINDOWS\\system32\\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"
"NoModify"=dword:00000001
"EstimatedSize"=dword:00000000
"RegistryLocation"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Updates\\Microsoft .NET Framework 2.0\\KB928365"
"DisplayIcon"="C:\\WINDOWS\\system32\\msiexec.exe"
"DisplayVersion"="2"
"ParentDisplayName"="Microsoft .NET Framework 2.0"
"NoRepair"=dword:00000001
"DisplayName"="Security Update for Microsoft .NET Framework 2.0 (KB928365)"
"ReleaseType"="Security Update"
"Helplink"="http://support.microsoft.com/kb/928365"
"ParentKeyName"="Microsoft .NET Framework 2.0"
"Publisher"="Microsoft Corporation"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB936357]
"DisplayName"="Update for Windows XP (KB936357)"
"UninstallString"="\"C:\\WINDOWS\\$NtUninstallKB936357$\\spuninst\\spuninst.exe\""
"TSAware"=dword:00000001
"NoModify"=dword:00000001
"InstallDate"="20070711"
"Publisher"="Microsoft Corporation"
"NoRepair"=dword:00000001
"HelpLink"="http://support.microsoft.com?kbid=936357"
"URLInfoAbout"="http://support.microsoft.com"
"DisplayVersion"="1"
"ParentKeyName"="OperatingSystem"
"ParentDisplayName"="Windows XP - Software Updates"
"ReleaseType"="Update"
"RegistryLocation"="HKLM\\SOFTWARE\\Microsoft\\Updates\\Windows XP\\SP3\\KB936357"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (2.0.0.5)]
"Comments"="Mozilla Firefox"
"DisplayIcon"="C:\\PROGRA~1\\Mozilla Firefox\\firefox.exe,0"
"DisplayName"="Mozilla Firefox (2.0.0.5)"
"DisplayVersion"="2.0.0.5 (en-US)"
"InstallLocation"="C:\\PROGRA~1\\Mozilla Firefox"
"Publisher"="Mozilla"
"UninstallString"="C:\\PROGRA~1\\Mozilla Firefox\\uninstall\\helper.exe"
"URLInfoAbout"="http://en-US.www.mozilla.com/en-US/"
"URLUpdateInfo"="http://en-US.www.mozilla.com/en-US/firefox/"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Registrar Lite 2.00]
"DisplayName"="Registrar Lite 2.00"
"UninstallString"="\"C:\\Program Files\\Registrar Lite\\unwise.exe\" C:\\PROGRA~1\\REGIST~1\\INSTALL.LOG"
"DisplayIcon"="\"C:\\Program Files\\Registrar Lite\\rl.exe\""
"URLInfoAbout"="http://www.resplendence.com"
"HelpLink"="http://www.resplendence.com"
"Publisher"="Resplendence Software Projects Sp."
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VETWIN32Vp5]
"DisplayIcon"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\caav.exe,-0"
"Publisher"="CA, Inc."
"ModifyPath"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\caav.exe"
"DisplayVersion"="8.4.0.24"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus"
"EstimatedSize"=dword:00006400
"NoModify"=dword:00000000
"NoRepair"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WGA]
"HelpLink"="http://support.microsoft.com?kbid=892130"
"URLInfoAbout"="http://www.microsoft.com/genuine"
"Publisher"="Microsoft Corporation"
"DisplayName"="Windows Genuine Advantage Validation Tool (KB892130)"
"DisplayVersion"="1.7.0036.0"
"VersionMajor"="1"
"VersionMinor"="0"
"ParentKeyName"="OperatingSystem"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160020}]
"DisplayIcon"="C:\\Program Files\\Java\\jre1.6.0_02\\\\bin\\javaws.exe"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"="http://java.com"
"DisplayVersion"="1.6.0.20"
"HelpLink"=hex(2):68,74,74,70,3a,2f,2f,6a,61,76,61,2e,63,6f,6d,00
"HelpTelephone"=""
"InstallDate"="20070718"
"InstallLocation"=""
"InstallSource"="http://javadl.sun.com/webapps/download/GetFile/1.6.0_02-b06/windows-i586/"
"ModifyPath"=hex(2):4d,73,69,45,78,65,63,2e,65,78,65,20,2f,49,7b,33,32,34,38,\
46,30,41,38,2d,36,38,31,33,2d,31,31,44,36,2d,41,37,37,42,2d,30,30,42,30,44,\
30,31,36,30,30,32,30,7d,00
"NoRepair"=dword:00000001
"Publisher"="Sun Microsystems, Inc."
"Readme"=hex(2):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,4a,61,76,61,\
5c,6a,72,65,31,2e,36,2e,30,5f,30,32,5c,52,45,41,44,4d,45,2e,74,78,74,00
"Size"=""
"EstimatedSize"=dword:0001bcf2
"UninstallString"=hex(2):4d,73,69,45,78,65,63,2e,65,78,65,20,2f,49,7b,33,32,34,\
38,46,30,41,38,2d,36,38,31,33,2d,31,31,44,36,2d,41,37,37,42,2d,30,30,42,30,\
44,30,31,36,30,30,32,30,7d,00
"URLInfoAbout"="http://java.com"
"URLUpdateInfo"="http://java.sun.com"
"VersionMajor"=dword:00000001
"VersionMinor"=dword:00000006
"WindowsInstaller"=dword:00000001
"Version"=dword:01060000
"Language"=dword:00000000
"DisplayName"="Java 6 Update 2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{609B0E8F-0E98-46BF-85F9-7123D1022D84}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="9.1.0.18"
"HelpLink"=hex(2):68,74,74,70,3a,2f,2f,77,77,77,2e,6d,79,2d,65,74,72,75,73,74,\
2e,63,6f,6d,2f,52,65,64,69,72,65,63,74,2f,72,6f,75,74,65,72,2e,61,73,70,78,\
3f,4f,45,4d,3d,26,70,72,6f,64,3d,50,50,26,61,70,70,3d,69,6e,63,6c,69,65,6e,\
74,26,6c,61,6e,67,3d,65,6e,26,64,61,74,65,3d,2d,31,26,6c,69,6e,6b,5f,69,64,\
3d,31,26,64,65,73,74,3d,6d,61,69,6e,5f,73,75,70,70,6f,72,74,26,6c,69,63,3d,\
26,76,65,72,3d,39,2e,31,2e,30,2e,31,38,00
"HelpTelephone"=""
"InstallDate"="20070712"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Spyware\\"
"InstallSource"="C:\\DOCUME~1\\Matthew\\LOCALS~1\\Temp\\{EE373586-CC8E-4AB6-8A37-37BDB4A3B50E}\\"
"ModifyPath"=hex(2):4d,73,69,45,78,65,63,2e,65,78,65,20,2f,58,7b,36,30,39,42,\
30,45,38,46,2d,30,45,39,38,2d,34,36,42,46,2d,38,35,46,39,2d,37,31,32,33,44,\
31,30,32,32,44,38,34,7d,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="CA"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00003bb3
"URLInfoAbout"="http://www.ca.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000000
"Version"=dword:09010000
"Language"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
"DisplayIcon"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\ndpsetup.ico"
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="2.0.50727"
"HelpLink"=""
"HelpTelephone"=""
"InstallDate"="20070711"
"InstallLocation"=""
"InstallSource"="C:\\DOCUME~1\\Matthew\\LOCALS~1\\Temp\\IXP000.TMP\\"
"NoModify"=dword:00000001
"NoRemove"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="Microsoft Corporation"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00003f24
"SystemComponent"=dword:00000001
"URLInfoAbout"=""
"URLUpdateInfo"=""
"VersionMajor"=dword:00000002
"VersionMinor"=dword:00000000
"WindowsInstaller"=dword:00000001
"Version"=dword:0200c627
"Language"=dword:00000000
"DisplayName"="Microsoft .NET Framework 2.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}]
"AuthorizedCDFPrefix"=""
"Comments"=""
"Contact"=""
"DisplayVersion"="9.1.0.33"
"HelpLink"=hex(2):68,74,74,70,3a,2f,2f,77,77,77,2e,6d,79,2d,65,74,72,75,73,74,\
2e,63,6f,6d,2f,52,65,64,69,72,65,63,74,2f,72,6f,75,74,65,72,2e,61,73,70,78,\
3f,4f,45,4d,3d,26,70,72,6f,64,3d,50,46,26,61,70,70,3d,69,6e,63,6c,69,65,6e,\
74,26,6c,61,6e,67,3d,45,4e,26,64,61,74,65,3d,31,31,38,34,32,35,33,31,33,32,\
26,6c,69,6e,6b,5f,69,64,3d,31,26,64,65,73,74,3d,6d,61,69,6e,5f,73,75,70,70,\
6f,72,74,26,6c,69,63,3d,34,43,5a,54,31,2d,45,43,4a,47,59,2d,58,4b,57,4a,4c,\
2d,52,49,52,49,4b,26,76,65,72,3d,00
"HelpTelephone"=""
"InstallDate"="20070712"
"InstallLocation"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Personal Firewall\\"
"InstallSource"="C:\\WINDOWS\\Installer\\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\\{FF4C8DE2-6DE9-41D5-8747-060EC7506094}\\"
"ModifyPath"=hex(2):4d,73,69,45,78,65,63,2e,65,78,65,20,2f,58,7b,42,44,42,41,\
41,42,31,42,2d,42,33,36,34,2d,34,36,35,45,2d,39,33,31,44,2d,34,45,32,45,32,\
46,30,45,36,30,39,41,7d,00
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"Publisher"="CA"
"Readme"=""
"Size"=""
"EstimatedSize"=dword:00003621
"URLInfoAbout"="http://www.ca.com"
"URLUpdateInfo"=""
"VersionMajor"=dword:00000009
"VersionMinor"=dword:00000001
"WindowsInstaller"=dword:00000000
"Version"=dword:09010000
"Language"=dword:00000000
Thanks again
D_N_M