1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Checking out pc's stability/security.

Discussion in 'Malware and Virus Removal Archive' started by Forsaken Knight, 2011/04/14.

  1. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    [Inactive] Checking out pc's stability/security.

    Hello, I have been having some odd behavior within my room pc. I have had, in the past month, 2 blue screens of death. On the most recent one, I wrote down what was in the details of this blue screen of death. The following is that information.

    "PAGE_FAULT_IN_NONPAGED_AREA "
    ...
    "STOP:0x00000050 (0xB47D0B30, 0x00000001, 0xB37923A5, 0x00000000) "
    ...
    "kwecyfoc.sys - Address B37923A5 base at B3786000, DateStamp 4cd7b97f "

    The other thing that I noticed is that the "pagefile.sys" can not be read by any scans that I have done.

    Currently, Malwarebytes is having some problems, in the sense that there is an error when I try to run a scan. The error does not happen at the beginning of the program, or when I start the scan, whether full or quick scans. The error happens after some time has past from starting a scan. The following are screen shots of the errors that appear.

    http://img685.imageshack.us/i/errorwithmalwarebyteson.jpg/
    http://img155.imageshack.us/i/errorwithmalwarebyteson.jpg/

    I have run scans, both full and quick, of registry mechanic, Avira antivirus, spybot search and destroy, ad-aware, and Windows Defender.

    I would like help in getting rid of McAfee Security Scan Plus. It was downloaded again after I updated Itunes and other Apple programs on my pc.

    I have zonealarm firewall installed on my pc.

    I have Avira Antivirus installed on my pc. After the advice/instruction of installing avira last time I had a thread open on here, that seemed to have fixed the problems that avast used to give me. With Avira, I was able to select the file, that avast was not able to select. I do not recall what the exact name of the file was that avast could not detect/see that Avira could detect/see, which I had to select the file during the installation of either program.

    I would also like to point out that for Windows Defender, it is not allowing me to update the program. I am getting a error as when I try to update Windows Defender. The error that appears in Windows Defender is "Error Found: Code: 0x80080005 ".

    For some odd reason, Avira routinely has this pop up about upgrading the Avira program. When this pop up occurs, If I am within a game program, there is some lag due to this pop up appearing. Also, more often than not, this pop up window for avira freezes, and I have to end its task through the task manager.

    I've ran TFC, and it removed and ran smoothly 224 mb of files. Malewarebytes has had problems running, as I have previously meantioned. MBRCheck ran without any problems. DDS ran without any problems as well. GMER ran first with eventually giving the second blue screen of death. The second time that I ran GMER, I ended the task of most of the programs on my pc except 36 or so from the task manager. After doing this, GMER ran smoothly.

    Lastly, I've noticed that a program called dllhost.exe and update.exe have shown up in task manager's program tab recently. After doing some google searches on these two, I now know that they are legit programs, but they have never appeared in task manager before. So, thats why I find this strange.
     
  2. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    DDS (Ver_10-12-12.02) - NTFSx86
    Run by Nelson Ramon Arucas at 0:16:31.92 on Thu 04/14/2011
    Internet Explorer: 7.0.5730.13
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.956 [GMT -4:00]

    AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
    FW: ZoneAlarm Firewall *Enabled*

    ============== Running Processes ===============

    D:\Program Files\Avira\AntiVir Desktop\avguard.exe
    D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    D:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    D:\Program Files\Windows Defender\MsMpEng.exe
    D:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\acs.exe
    D:\Program Files\Avira\AntiVir Desktop\sched.exe
    svchost.exe
    D:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
    D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    D:\Program Files\Bonjour\mDNSResponder.exe
    D:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    D:\WINDOWS\system32\nvsvc32.exe
    D:\Program Files\Sandboxie\SbieSvc.exe
    D:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    D:\Program Files\Secunia\PSI\PSIA.exe
    D:\WINDOWS\system32\svchost.exe -k imgsvc
    D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    D:\Program Files\Secunia\PSI\sua.exe
    D:\WINDOWS\system32\wscntfy.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    D:\Program Files\MSN Toolbar\Platform\4.0.0417.0\mswinext.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    D:\Program Files\iTunes\iTunesHelper.exe
    D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    D:\Program Files\Sandboxie\SbieCtrl.exe
    D:\Program Files\Windows Live\Messenger\msnmsgr.exe
    D:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe
    D:\Program Files\FileHippo.com\UpdateChecker.exe
    D:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    D:\Program Files\iPod\bin\iPodService.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    D:\Program Files\Saitek\Software\ProfilerU.exe
    D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
    D:\Program Files\NETGEAR\WN111v2\WN111V2.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
    D:\Program Files\Secunia\PSI\psi_tray.exe
    D:\Program Files\OpenOffice.org 3\program\soffice.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    D:\Program Files\Xfire\xfire.exe
    D:\Program Files\OpenOffice.org 3\program\soffice.bin
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    D:\Documents and Settings\Nelson Ramon Arucas\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.comcast.net/
    uInternet Settings,ProxyOverride = *.local
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - d:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - d:\program files\yahoo!\common\yiesrvc.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - d:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - d:\program files\comcasttb\comcastdx.dll
    BHO: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - No File
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - No File
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\googletoolbar2.dll
    BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - d:\program files\wot\WOT.dll
    BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - d:\program files\msn toolbar\platform\4.0.0417.0\npwinext.dll
    BHO: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - d:\program files\windows live\toolbar\wltcore.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Yahoo! ¤u¨Ã£¦C: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\googletoolbar2.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - d:\program files\windows live\toolbar\wltcore.dll
    TB: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - d:\program files\comcasttb\comcastdx.dll
    TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - d:\program files\msn toolbar\platform\4.0.0417.0\npwinext.dll
    TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - d:\program files\wot\WOT.dll
    TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
    uRun: [Yahoo! Pager] "d:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet
    uRun: [SpybotSD TeaTimer] d:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [SandboxieControl] "d:\program files\sandboxie\SbieCtrl.exe "
    uRun: [msnmsgr] "d:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [ComcastAntispyClient] "d:\program files\comcasttb\comcastspywarescan\ComcastAntispy.exe" /hide
    uRun: [FileHippo.com] "d:\program files\filehippo.com\UpdateChecker.exe" /background
    uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup
    mRun: [HP Software Update] d:\program files\hewlett-packard\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 10.0\reader\Reader_sl.exe "
    mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [MSN Toolbar] "d:\program files\msn toolbar\platform\4.0.0417.0\mswinext.exe "
    mRun: [Microsoft Default Manager] "d:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
    mRun: [jswtrayutil] "d:\program files\netgear\wn111v2\jswtrayutil.exe "
    mRun: [ZoneAlarm Client] "d:\program files\zone labs\zonealarm\zlclient.exe "
    mRun: [QuickTime Task] "d:\program files\quicktime\qttask.exe" -atboottime
    mRun: [avgnt] "d:\program files\avira\antivir desktop\avgnt.exe" /min
    mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe "
    dRun: [DWQueuedReporting] "d:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
    StartupFolder: d:\docume~1\nelson~1\startm~1\programs\startup\openof~1.lnk - d:\program files\openoffice.org 3\program\quickstart.exe
    StartupFolder: d:\docume~1\nelson~1\startm~1\programs\startup\xfire.lnk - d:\program files\xfire\xfire.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - d:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - d:\program files\hewlett-packard\digital imaging\bin\hpobnz08.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk - d:\program files\saitek\software\ProfilerU.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - d:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - d:\program files\mcafee security scan\2.0.181\SSScheduler.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - d:\program files\netgear\wn111v2\WN111V2.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - d:\program files\hewlett-packard\digital imaging\bin\hposol08.exe
    StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - d:\program files\secunia\psi\psi_tray.exe
    uPolicies-explorer: NoInstrumentation = 1 (0x1)
    dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
    dPolicies-explorer: NoInstrumentation = 1 (0x1)
    IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - d:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - d:\program files\yahoo!\common\yiesrvc.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office11\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - d:\windows\system32\Shdocvw.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab
    DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/Dcode/ActiveX/MSDcode.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - d:\program files\yahoo!\common\Yinsthelper.dll
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
    DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1272133539471
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1272133528581
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {88D969C0-F192-11D4-A65F-0040963251E5} - hxxp://ipgweb.cce.hp.com/rdqaio2/downloads/msxml4.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - d:\program files\wot\WOT.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - d:\progra~1\wifd1f~1\MpShHook.dll

    ============= SERVICES / DRIVERS ===============

    R1 avgio;avgio;d:\program files\avira\antivir desktop\avgio.sys [2011-3-9 11608]
    R1 vsdatant;vsdatant;d:\windows\system32\vsdatant.sys [2011-1-28 532224]
    R2 aawservice;Lavasoft Ad-Aware Service;d:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
    R2 AntiSpywareService;Comcast AntiSpyware;d:\program files\comcasttb\comcastspywarescan\ComcastAntiSpyService.exe [2009-6-17 616408]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\avira\antivir desktop\sched.exe [2011-3-9 135336]
    R2 AntiVirService;Avira AntiVir Guard;d:\program files\avira\antivir desktop\avguard.exe [2011-3-9 269480]
    R2 avgntflt;avgntflt;d:\windows\system32\drivers\avgntflt.sys [2011-3-9 61960]
    R2 fssfltr;FssFltr;d:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-22 54752]
    R2 PEDRV;P&E Microcomputer System PCI Driver.;d:\windows\system32\drivers\pedrv.sys [2000-8-3 23296]
    R2 Secunia PSI Agent;Secunia PSI Agent;d:\program files\secunia\psi\psia.exe [2011-1-5 988216]
    R2 Secunia Update Agent;Secunia Update Agent;d:\program files\secunia\psi\sua.exe [2011-1-5 399416]
    R2 vsmon;TrueVector Internet Monitor;d:\windows\system32\zonelabs\vsmon.exe -service --> d:\windows\system32\zonelabs\vsmon.exe -service [?]
    R2 WinDefend;Windows Defender;d:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;d:\windows\system32\DNINDIS5.sys [2003-7-24 17149]
    R3 JSWSCIMD;jswscimd Service;d:\windows\system32\drivers\jswscimd.sys [2008-10-1 57440]
    R3 PSI;PSI;d:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
    R3 SaiH5F0D;SaiH5F0D;d:\windows\system32\drivers\SaiH5F0D.sys [2008-4-4 176640]
    R3 SaiU5F0D;SaiU5F0D;d:\windows\system32\drivers\SaiU5F0D.sys [2008-4-4 27264]
    R3 SbieDrv;SbieDrv;d:\program files\sandboxie\SbieDrv.sys [2011-1-12 125672]
    R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;d:\windows\system32\drivers\WN111v2.sys [2009-1-14 458752]
    S2 gupdate;Google Update Service (gupdate);d:\program files\google\update\GoogleUpdate.exe [2011-1-10 136176]
    S3 EagleXNt;EagleXNt;\??\d:\windows\system32\drivers\eaglexnt.sys --> d:\windows\system32\drivers\EagleXNt.sys [?]
    S3 fsssvc;Windows Live Family Safety Service;d:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
    S3 jswpsapi;Jumpstart Wifi Protected Setup;d:\program files\netgear\wn111v2\jswpsapi.exe [2008-2-27 360547]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;d:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
    S3 nosGetPlusHelper;getPlus(R) Helper 3004;d:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-3 14336]

    =============== Created Last 30 ================

    2011-04-08 11:28:58 41872 ----a-w- d:\windows\system32\xfcodec.dll
    2011-03-27 17:16:26 -------- d-----w- d:\program files\iPod
    2011-03-27 17:16:19 -------- d-----w- d:\program files\iTunes

    ==================== Find3M ====================

    2011-02-03 02:40:23 472808 ----a-w- d:\windows\system32\deployJava1.dll
    2011-02-03 00:19:39 73728 ----a-w- d:\windows\system32\javacpl.cpl
    2011-02-02 22:11:20 222080 ------w- d:\windows\system32\MpSigStub.exe
    2004-09-11 01:18:54 5923328 ------r- d:\program files\PRO11.MSI
    2004-09-11 01:18:18 604672 ------r- d:\program files\OWC11.MSI
    2004-09-11 01:18:18 560128 ------r- d:\program files\OWC10.MSI

    ============= FINISH: 0:18:58.65 ===============
     

  3. to hide this advert.

  4. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-12-12.02)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/3/2008 8:55:25 AM
    System Uptime: 4/13/2011 11:53:52 PM (1 hours ago)

    Motherboard: MSI | | MS-7309
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4000+ | CPU 1 | 2109/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (FAT32) - 5 GiB total, 0.031 GiB free.
    D: is FIXED (NTFS) - 51 GiB total, 20.886 GiB free.
    E: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP20: 4/14/2011 12:12:27 AM - System Checkpoint

    ==== Installed Programs ======================

    Ad-Aware
    Adobe AIR
    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Adobe Reader X
    AiO_Scan_CDA
    AiOSoftwareNPI
    AirRivals 1.0.0.26
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Ask Toolbar
    Avira AntiVir Personal - Free Antivirus
    Bonjour
    BufferChm
    CA Pest Patrol Realtime Protection
    CodeWarrior Development Studio for S12(X) V5.0
    Comcast High-Speed Internet Install Wizard
    Comcast Toolbar 3.0
    Compatibility Pack for the 2007 Office system
    CP_Package_Variety1
    CP_Package_Variety2
    CP_Package_Variety3
    Destinations
    DeviceManagementQFolder
    DFOLauncher
    DMI Browse
    DocProc
    ESET Online Scanner v3
    eSupportQFolder
    F300
    F300_Help
    F300Trb
    Fax_CDA
    FileHippo.com Update Checker
    Foxit Reader
    Google Chrome
    Google Toolbar for Internet Explorer
    Google Update Helper
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB954708)
    Hotfix for Windows XP (KB961118)
    HP Driver Diagnostics
    HP Imaging Device Functions 6.1
    HP Photo and Imaging 1.0 - HP PSC - HP OfficeJet
    HP Photo and Imaging 1.0 - HP PSC - HP OfficeJet Drivers
    HP Photosmart Essential
    HP Print Diagnostic Utility
    HP PSC & OfficeJet 6.1.A
    HP Software Update
    HP Solution Center and Imaging Support Tools 6.1
    HPProductAssistant
    i-Speeder
    ImgBurn
    InfoView
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 24
    Java(TM) 6 Update 7
    Junk Mail filter update
    Logitech Desktop Messenger
    Logitech IM Video Companion
    Logitech ImageStudio
    Logitech Print Service
    Malwarebytes' Anti-Malware
    McAfee Security Scan Plus
    MGI PhotoSuite 4 (Remove Only)
    MGI VideoWave 4
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Default Manager
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Professional Edition 2003
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Move Media Player
    MSN Toolbar
    MSN Toolbar Platform
    MSVCRT
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MyScribe
    NewCopy_CDA
    NVIDIA DDS Utilities
    NVIDIA Drivers
    NVIDIA Photoshop Plug-ins
    OpenOffice.org 3.0
    Pando Media Booster
    Philips Firmware Manager
    ProductContextNPI
    QuickTime
    RangeMax Wireless-N USB Adapter WN111v2
    Readiris 7.5
    Readme
    RealPlayer 7 Basic
    Realtek High Definition Audio Driver
    Registry Mechanic 5.2
    Rhapsody Player Engine
    Saitek SST Programming Software
    Sandboxie 3.52
    Scan
    ScannerCopy
    Secunia PSI (2.0.0.2001)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    Segoe UI
    SolutionCenter
    Spybot - Search & Destroy
    Status
    Steam
    TeamSpeak 3 Client
    Toolbox
    TrayApp
    Unload
    Unreal Anthology
    UnrealKeyChanger
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB973815)
    UT2004Mi v2.00
    Ventrilo Client
    WebFldrs XP
    WebReg
    Winamp
    Windows Defender
    Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
    Windows Driver Package - SofTec Microsystems (sft02) SofTecUSBDevices (02/07/2007 2.40.0.0)
    Windows Internet Explorer 7
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live ID Sign-in Assistant
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Service Pack 3
    WinRAR archiver
    WMIinfo
    WN111v2
    WOT for Internet Explorer
    WOT Services
    Xfire (remove only)
    Xirrus Wi-Fi Inspector
    Yahoo! Browser Services
    Yahoo! Install Manager
    Yahoo! Internet Mail
    Yahoo! Messenger
    Yahoo! ¤u¨Ã£¦C
    ZoneAlarm
    ZoneAlarm Spy Blocker

    ==== Event Viewer Messages From Past Week ========

    4/14/2011 12:18:45 AM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
    4/13/2011 2:50:08 AM, error: VolSnap [14] - The shadow copy of volume D: was aborted because of an IO failure.
    4/13/2011 2:23:38 AM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
    4/13/2011 11:47:03 PM, error: Sr [1] - The System Restore filter encountered the unexpected error '0xC000007F' while processing the file 'DESKTOP.INI' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    4/13/2011 11:45:36 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
    4/13/2011 11:45:36 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    4/13/2011 11:45:36 PM, error: Service Control Manager [7034] - The Atheros Configuration Service service terminated unexpectedly. It has done this 1 time(s).
    4/13/2011 11:45:36 PM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
    4/13/2011 11:45:36 PM, error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
    4/13/2011 11:44:38 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 4 time(s).
    4/13/2011 11:41:05 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 3 time(s).
    4/13/2011 11:40:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COM+ System Application service to connect.
    4/13/2011 11:40:38 PM, error: Service Control Manager [7000] - The COM+ System Application service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    4/13/2011 11:40:12 PM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
    4/13/2011 11:37:28 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 2 time(s).
    4/13/2011 11:37:28 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
    4/13/2011 11:37:28 PM, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    4/13/2011 11:36:35 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 2 time(s).
    4/11/2011 11:32:58 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    4/11/2011 11:32:14 PM, error: Service Control Manager [7034] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 3 time(s).
    4/11/2011 11:32:01 PM, error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
    4/11/2011 11:31:52 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    4/11/2011 11:31:45 PM, error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
    4/11/2011 11:31:42 PM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:31:26 PM, error: Service Control Manager [7034] - The Secunia Update Agent service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:31:21 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:31:18 PM, error: Service Control Manager [7034] - The Sandboxie Service service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:31:16 PM, error: Service Control Manager [7034] - The Secunia PSI Agent service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:31:08 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:31:02 PM, error: Service Control Manager [7034] - The CA Pest Patrol Realtime Protection Service service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:30:59 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:30:49 PM, error: Service Control Manager [7034] - The Comcast AntiSpyware service terminated unexpectedly. It has done this 1 time(s).
    4/11/2011 11:30:44 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    4/11/2011 11:10:40 PM, error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    4/11/2011 11:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Google Update Service (gupdate) service to connect.
    4/11/2011 11:09:44 PM, error: ParVdm [2] - Unable to get device object pointer for port object.

    ==== End Of File ===========================
     
  5. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000001d

    Kernel Drivers (total 138):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806E4000 \WINDOWS\system32\hal.dll
    0xBADA8000 \WINDOWS\system32\KDCOM.DLL
    0xBACB8000 \WINDOWS\system32\BOOTVID.dll
    0xBA779000 ACPI.sys
    0xBADAA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xBA768000 pci.sys
    0xBA8A8000 isapnp.sys
    0xBAE70000 pciide.sys
    0xBAB28000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xBA8B8000 MountMgr.sys
    0xBA749000 ftdisk.sys
    0xBADAC000 dmload.sys
    0xBA723000 dmio.sys
    0xBAB30000 PartMgr.sys
    0xBA8C8000 VolSnap.sys
    0xBA70B000 atapi.sys
    0xBA6F1000 nvata.sys
    0xBA8D8000 disk.sys
    0xBA8E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xBA6D1000 fltmgr.sys
    0xBA6BF000 sr.sys
    0xBA8F8000 PxHelp20.sys
    0xBA6A8000 KSecDD.sys
    0xBA61B000 Ntfs.sys
    0xBA5EE000 NDIS.sys
    0xBA5D4000 Mup.sys
    0xBAAC8000 \SystemRoot\system32\DRIVERS\AmdK8.sys
    0xBAAD8000 \SystemRoot\system32\DRIVERS\serial.sys
    0xBAD60000 \SystemRoot\system32\DRIVERS\serenum.sys
    0xBABE0000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xBA578000 \SystemRoot\system32\DRIVERS\parport.sys
    0xBAAE8000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xBABE8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBABF0000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xBABF8000 \SystemRoot\system32\DRIVERS\usbohci.sys
    0xBA554000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xBAC00000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xBA52C000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xBAAF8000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xBAB08000 \SystemRoot\System32\Drivers\AFS2K.SYS
    0xBAB18000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xBA928000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xBA509000 \SystemRoot\system32\DRIVERS\ks.sys
    0xBAC08000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
    0xBA938000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
    0xBA41F000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
    0xB9E45000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
    0xB9E31000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xBA948000 \SystemRoot\system32\DRIVERS\jswscimd.sys
    0xB9E08000 \SystemRoot\system32\drivers\windrvr6.sys
    0xBADCE000 \SystemRoot\system32\drivers\USBD.SYS
    0xBAF49000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xBA9B8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xBAD6C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB9DA0000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xBA9C8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xBA9D8000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xBAC10000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xB9D8F000 \SystemRoot\system32\DRIVERS\psched.sys
    0xBA9E8000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xBAC18000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xBAC20000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xB9CBF000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xBA9F8000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xBAA08000 \SystemRoot\system32\drivers\SaiBus.sys
    0xBADD0000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB9C39000 \SystemRoot\system32\DRIVERS\update.sys
    0xBAD84000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xBAA18000 \SystemRoot\system32\DRIVERS\wsimd.sys
    0xBAA28000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xBA5B0000 \SystemRoot\system32\DRIVERS\SaiMini.sys
    0xBAA38000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xBAC28000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xBA5AC000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xBA5A8000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xBAA48000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xBAA58000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
    0xB71A1000 \SystemRoot\system32\drivers\RtkHDAud.sys
    0xB717D000 \SystemRoot\system32\drivers\portcls.sys
    0xBAA78000 \SystemRoot\system32\drivers\drmk.sys
    0xBAC38000 \SystemRoot\system32\DRIVERS\flpydisk.sys
    0xBADD4000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xBAEC3000 \SystemRoot\System32\Drivers\Null.SYS
    0xBADD6000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBAC48000 \SystemRoot\System32\drivers\vga.sys
    0xBADD8000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBADDA000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xBAC50000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xBAC58000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xB9CAF000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xB7028000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xB6FCF000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xB6FA7000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xB6F81000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xB6F00000 \SystemRoot\System32\vsdatant.sys
    0xBA958000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xB6EDE000 \SystemRoot\System32\drivers\afd.sys
    0xBA968000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xBAC60000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
    0xB6EB3000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xB6E43000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xBA988000 \SystemRoot\System32\Drivers\Fips.SYS
    0xBAC68000 \SystemRoot\system32\DRIVERS\SaiU5F0D.sys
    0xB9C35000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xBAC70000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xB6CD3000 \SystemRoot\system32\DRIVERS\WN111v2.sys
    0xB6CAD000 \SystemRoot\system32\DRIVERS\avipbb.sys
    0xB6023000 \SystemRoot\system32\DRIVERS\SaiH5F0D.sys
    0xBAE16000 \??\D:\Program Files\Avira\AntiVir Desktop\avgio.sys
    0xBA9A8000 \SystemRoot\system32\drivers\LVUSBSta.sys
    0xB5F1E000 \SystemRoot\system32\DRIVERS\Camdrl.sys
    0xB9D7F000 \SystemRoot\system32\drivers\usbaudio.sys
    0xB5E32000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xB5E1A000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xBADB8000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xB7097000 \SystemRoot\System32\drivers\Dxapi.sys
    0xBAC78000 \SystemRoot\System32\watchdog.sys
    0xBF9C3000 \SystemRoot\System32\drivers\dxg.sys
    0xBAF2A000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF9D5000 \SystemRoot\System32\nv4_disp.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xB5764000 \SystemRoot\system32\DRIVERS\avgntflt.sys
    0xB56B4000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
    0xB56C8000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xB5327000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xBAEC7000 \SystemRoot\System32\Drivers\GIVEIO.SYS
    0xBAE0C000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xB5195000 \SystemRoot\system32\DRIVERS\srv.sys
    0xB5207000 \SystemRoot\System32\Drivers\PEDRV.SYS
    0xB4FBC000 \??\D:\Program Files\Sandboxie\SbieDrv.sys
    0xB4E84000 \SystemRoot\system32\DRIVERS\psi_mf.sys
    0xB4B4E000 \SystemRoot\system32\drivers\wdmaud.sys
    0xB4CE3000 \SystemRoot\system32\drivers\sysaudio.sys
    0xB4D13000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xB52F3000 \??\D:\WINDOWS\system32\DNINDIS5.SYS
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 67):
    0 System Idle Process
    4 System
    1364 D:\WINDOWS\system32\smss.exe
    1460 csrss.exe
    1484 D:\WINDOWS\system32\winlogon.exe
    1528 D:\WINDOWS\system32\services.exe
    1540 D:\WINDOWS\system32\lsass.exe
    1692 D:\Program Files\Avira\AntiVir Desktop\avguard.exe
    1724 D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    1876 D:\WINDOWS\system32\svchost.exe
    1924 svchost.exe
    1964 D:\Program Files\Windows Defender\MsMpEng.exe
    2004 D:\WINDOWS\system32\svchost.exe
    216 svchost.exe
    376 svchost.exe
    424 D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    1016 D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    1224 D:\WINDOWS\system32\spoolsv.exe
    1264 D:\WINDOWS\system32\acs.exe
    1288 D:\Program Files\Avira\AntiVir Desktop\sched.exe
    1324 svchost.exe
    1448 D:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
    1504 D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1976 D:\Program Files\Bonjour\mDNSResponder.exe
    228 D:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    264 D:\Program Files\Java\jre6\bin\jqs.exe
    296 D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    172 D:\WINDOWS\system32\nvsvc32.exe
    536 D:\Program Files\Sandboxie\SbieSvc.exe
    612 D:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    648 D:\Program Files\Secunia\PSI\psia.exe
    752 D:\WINDOWS\system32\svchost.exe
    808 wdfmgr.exe
    972 D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    4020 D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    2480 alg.exe
    2152 D:\Program Files\Secunia\PSI\sua.exe
    2472 D:\WINDOWS\system32\wscntfy.exe
    2608 D:\WINDOWS\system32\ctfmon.exe
    2696 D:\WINDOWS\explorer.exe
    3496 D:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
    2976 D:\Program Files\MSN Toolbar\Platform\4.0.0417.0\mswinext.exe
    3556 D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    708 D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    3932 D:\Program Files\iTunes\iTunesHelper.exe
    3096 D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    3128 D:\Program Files\Sandboxie\SbieCtrl.exe
    3964 D:\Program Files\Windows Live\Messenger\msnmsgr.exe
    3004 D:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
    3116 D:\Program Files\FileHippo.com\UpdateChecker.exe
    3532 D:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
    2288 D:\Program Files\iPod\bin\iPodService.exe
    2540 D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    3080 D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    3916 D:\Program Files\Saitek\Software\ProfilerU.exe
    2680 D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
    3408 D:\Program Files\NETGEAR\WN111v2\WN111V2.exe
    3548 D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
    3900 D:\Program Files\Secunia\PSI\psi_tray.exe
    344 D:\Program Files\OpenOffice.org 3\program\soffice.exe
    2604 D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    3592 D:\Program Files\Xfire\xfire.exe
    3892 D:\Program Files\OpenOffice.org 3\program\soffice.bin
    416 D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
    2572 D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
    1972 wmiprvse.exe
    2496 D:\Documents and Settings\Nelson Ramon Arucas\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000001`4589ae00 (NTFS)

    PhysicalDrive0 Model Number: SAMSUNGSV0602H, Rev: RH100-09

    Size Device Name MBR Status
    --------------------------------------------
    55 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!
     
  6. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit scan 2011-04-14 11:44:02
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 SAMSUNG_SV0602H rev.RH100-09
    Running: GMER.exe; Driver: D:\DOCUME~1\NELSON~1\LOCALS~1\Temp\kwecyfod.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0xB6F03534]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0xB6EFD782]
    SSDT BAFA54F6 ZwCreateKey
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0xB6F03CC0]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xB6F16EB4]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xB6F172A2]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0xB6F20916]
    SSDT BAFA54EC ZwCreateThread
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xB6F03DF6]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xB6EFE398]
    SSDT BAFA54FB ZwDeleteKey
    SSDT BAFA5505 ZwDeleteValueKey
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xB6F15DF0]
    SSDT BAFA550A ZwLoadKey
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xB6F1EB44]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0xB6EFDFAA]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xB6F191CE]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenThread [0xB6F18DF8]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0xB6F1F8D2]
    SSDT BAFA5514 ZwReplaceKey
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xB6F030F4]
    SSDT BAFA550F ZwRestoreKey
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xB6F037DC]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xB6EFE75C]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xB6F1FE12]
    SSDT BAFA5500 ZwSetValueKey
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xB6F17F0A]
    SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xB6F17C86]

    Code BAF70C9C ZwRequestPort
    Code BAF70D3C ZwRequestWaitReplyPort
    Code BAF70BFC ZwTraceEvent
    Code BAF70C9B NtRequestPort
    Code BAF70D3B NtRequestWaitReplyPort
    Code BAF70BFB NtTraceEvent

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!ZwCallbackReturn + 2C7C 80504518 12 Bytes [C0, 3C, F0, B6, B4, 6E, F1, ...]
    .text ntkrnlpa.exe!ZwCallbackReturn + 2EC5 80504761 7 Bytes [F8, F1, B6, 14, 55, FA, BA]
    .text ntkrnlpa.exe!NtTraceEvent 80535108 5 Bytes JMP BAF70C00
    .text D:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9E45360, 0x32DEFD, 0xE8000020]
    .text win32k.sys!BRUSHOBJ_pvAllocRbrush + 322E BF81E750 5 Bytes JMP BAF70A20
    .text win32k.sys!EngSetLastError + 763E BF828650 5 Bytes JMP BAF705C0
    .text win32k.sys!EngLockSurface + 148C BF834F6F 5 Bytes JMP BAF70700
    .text win32k.sys!EngCreateBitmap + D9A0 BF84582C 5 Bytes JMP BAF70660
    .text win32k.sys!EngMultiByteToWideChar + 2F22 BF85277C 5 Bytes JMP BAF708E0
    .text win32k.sys!PATHOBJ_vGetBounds + 74E1 BF8F004B 5 Bytes JMP BAF70980
    .text win32k.sys!EngCreateClip + 19C1 BF912991 5 Bytes JMP BAF70AC0
    .text win32k.sys!EngCreateClip + 1F51 BF912F21 5 Bytes JMP BAF70B60
    .text win32k.sys!EngCreateClip + 2597 BF913567 5 Bytes JMP BAF70840
    init D:\WINDOWS\System32\Drivers\PEDRV.SYS entry point in "init" section [0xB4F30E00]

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [B6F08672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [B6F084C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [B6F08CBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [B6F06C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [B6F06C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [B6F08672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [B6F084C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [B6F08CBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [B6F08672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [B6F06C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [B6F08CBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [B6F084C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [B6F08CBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B6F084C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B6F08672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B6F06C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B6F08672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B6F084C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [B6F08CBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [B6F08672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [B6F06C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [B6F08CBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [B6F084C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [10010380] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[268] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[320] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @
     
  7. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[392] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryExA] [0188FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\Explorer.EXE [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [01890740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0188FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0188FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [01890740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [0188FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [01890380] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [01890560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0188FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [0188FA00]D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0188FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [01890560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [018901B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [0188FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [01890910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [0188FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [0188FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\Explorer.EXE[1004] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [0188F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\winlogon.exe [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @
     
  8. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\winlogon.exe[1484] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\taskmgr.exe[1512] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\services.exe[1528] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @
     
  9. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\REGAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1888] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @
     
  10. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================================

    Uninstall Ask Toolbar, known foistware.

    ====================================================

    Uninstall Registry Mechanic 5.2.
    Registry cleaners/optimizers are not recommended for several reasons:

    • Registry cleaners are extremely powerful applications that can damage the registry by using aggressive cleaning routines and cause your computer to become unbootable.

      The Windows registry is a central repository (database) for storing configuration data, user settings and machine-dependent settings, and options for the operating system. It contains information and settings for all hardware, software, users, and preferences. Whenever a user makes changes to settings, file associations, system policies, or installed software, the changes are reflected and stored in this repository. The registry is a crucial component because it is where Windows "remembers" all this information, how it works together, how Windows boots the system and what files it uses when it does. The registry is also a vulnerable subsystem, in that relatively small changes done incorrectly can render the system inoperable. For a more detailed explanation, read Understanding The Registry.
    • Not all registry cleaners are created equal. There are a number of them available but they do not all work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad entry ". One cleaner may find entries on your system that will not cause problems when removed, another may not find the same entries, and still another may want to remove entries required for a program to work.
    • Not all registry cleaners create a backup of the registry before making changes. If the changes prevent the system from booting up, then there is no backup available to restore it in order to regain functionality. A backup of the registry is essential BEFORE making any changes to the registry.
    • Improperly removing registry entries can hamper malware disinfection and make the removal process more difficult if your computer becomes infected. For example, removing malware related registry entries before the infection is properly identified can contribute to system instability and even make the malware undetectable to removal tools.
    • The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results ".
    Unless you have a particular problem that requires a registry edit to correct it, I would suggest you leave the registry alone. Using registry cleaning tools unnecessarily or incorrectly could lead to disastrous effects on your operating system such as preventing it from ever starting again. For routine use, the benefits to your computer are negligible while the potential risks are great.


    =====================================================

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  11. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[1936] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ d:\windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [10010380] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\System32\svchost.exe[2016] @ D:\WINDOWS\System32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [10010740] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [10010560] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [10010910] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [100101B0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [1000FB40] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [1000FD90] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [1000FFE0] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] [1000FA00] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)
    IAT D:\WINDOWS\system32\svchost.exe[2984] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [1000F890] D:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.)

    ---- Devices - GMER 1.0.15 ----

    Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

    Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
    Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20@RefCount 2

    ---- EOF - GMER 1.0.15 ----
     
  12. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Ooops...keep going with GMER.
     
  13. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK. Continue with my previous reply.
    You're infected.
     
  14. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    One other thing that I should meantion. When I select to access a radio channel from ITunes, or when I restore/minimize the Itunes window, a grind sound happens from my pc tower. This is a very recent event, but I feel that it deserves to be stated. This does not happen all of the time that I open ITunes, but a majority of the time, it does happen.
     
  15. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    Ok, I'll do as you have instructed now.
     
  16. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We'll worry about it later, when your computer is clean.
     
  17. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    how do I uninstall the following, "Uninstall Ask Toolbar, known foistware.
    "?

    I also uninstalled registry mechanic. I have had it for a long time, and its sad to get rid of it, but if it will help my pc, I guess I can get it later on if I need it, as well as get a more updated version of that program when I get some money to spend. The following is the screen shot of a specific part of the uninstallation process of registry mechanic.

    http://img35.imageshack.us/i/regmechuninstallssonwed.jpg/
     
  18. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I can see Ask Toolbar listed in your Ad\Remove.
    Uninstall it from there.

    Did you read my reasoning regarding not using any kind of registry tools?

    As for you screenshot, the safest way is to click "No to all ".
     
  19. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
  20. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    ComboFix 11-04-13.06 - Nelson Ramon Arucas 04/14/2011 13:16:31.3.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1124 [GMT -4:00]
    Running from: d:\documents and settings\Nelson Ramon Arucas\Desktop\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
    FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    d:\windows\system32\SysInfo.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-03-14 to 2011-04-14 )))))))))))))))))))))))))))))))
    .
    .
    2011-04-14 04:52 . 2011-04-14 04:52 33810 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
    2011-04-14 04:52 . 2011-04-14 04:52 20719 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
    2011-04-14 04:52 . 2011-04-14 04:52 23327 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
    2011-04-14 04:52 . 2011-04-14 04:52 7271 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
    2011-04-14 04:52 . 2011-04-14 04:52 8782 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
    2011-04-08 11:28 . 2011-04-08 11:28 41872 ----a-w- d:\windows\system32\xfcodec.dll
    2011-03-27 17:16 . 2011-03-27 17:16 -------- d-----w- d:\program files\iPod
    2011-03-27 17:16 . 2011-03-27 17:17 -------- d-----w- d:\program files\iTunes
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-16 16:02 . 2011-03-09 19:03 137656 ----a-w- d:\windows\system32\drivers\avipbb.sys
    2011-02-11 06:54 . 2011-03-08 07:17 5943120 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{FF781BAE-3C6F-43EB-8538-183714CF6758}\mpengine.dll
    2011-02-11 06:54 . 2008-04-03 19:33 5943120 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
    2011-02-03 02:40 . 2011-01-10 07:34 472808 ----a-w- d:\windows\system32\deployJava1.dll
    2011-02-03 00:19 . 2008-04-04 04:14 73728 ----a-w- d:\windows\system32\javacpl.cpl
    2011-02-02 22:11 . 2009-10-03 06:06 222080 ------w- d:\windows\system32\MpSigStub.exe
    2004-09-11 01:18 . 2004-09-11 01:18 5923328 ------r- d:\program files\PRO11.MSI
    2004-09-11 01:18 . 2004-09-11 01:18 604672 ------r- d:\program files\OWC11.MSI
    2004-09-11 01:18 . 2004-09-11 01:18 560128 ------r- d:\program files\OWC10.MSI
    .
    .
    ((((((((((((((((((((((((((((( SnapShot_2011-03-05_19.07.24 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-07-12 05:02 . 2009-07-12 05:02 51008 d:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 59728 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 42832 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 43344 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 61264 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 62800 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 61760 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 61776 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 53568 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 63296 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 36688 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 35648 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
    + 2009-07-12 05:05 . 2009-07-12 05:05 59904 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
    + 2009-07-12 05:05 . 2009-07-12 05:05 59904 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
    + 2011-04-14 04:36 . 2011-04-14 04:36 16384 d:\windows\Temp\Perflib_Perfdata_518.dat
    + 2004-08-04 00:07 . 2011-03-18 16:50 67864 d:\windows\system32\perfc009.dat
    - 2004-08-04 00:07 . 2010-11-10 06:26 67864 d:\windows\system32\perfc009.dat
    + 2011-03-27 17:10 . 2011-02-18 20:36 41984 d:\windows\system32\DRVSTORE\usbaapl_05A32DBD3911A2EF4222EF5BE7BB535FAB37D6C4\usbaapl.sys
    + 2011-03-09 19:03 . 2010-06-17 19:27 28520 d:\windows\system32\drivers\ssmdrv.sys
    + 2011-03-09 19:03 . 2010-06-17 19:27 22360 d:\windows\system32\drivers\avgntmgr.sys
    + 2011-03-09 19:03 . 2011-01-10 19:23 61960 d:\windows\system32\drivers\avgntflt.sys
    + 2011-03-09 19:03 . 2010-06-17 19:27 45416 d:\windows\system32\drivers\avgntdd.sys
    + 2008-09-12 23:22 . 2007-04-02 18:26 19456 d:\windows\system32\dllcache\agt040d.dll
    + 2008-09-12 23:22 . 2007-04-02 18:25 19456 d:\windows\system32\dllcache\agt0401.dll
    + 2008-09-12 23:22 . 2007-04-02 18:26 19456 d:\windows\msagent\intl\agt040d.dll
    + 2008-09-12 23:22 . 2007-04-02 18:25 19456 d:\windows\msagent\intl\agt0401.dll
    + 2008-09-12 23:23 . 2008-04-14 00:09 6144 d:\windows\system32\dllcache\kbdpash.dll
    + 2008-09-12 23:23 . 2008-04-14 00:09 6144 d:\windows\system32\dllcache\kbdnepr.dll
    + 2004-08-04 00:07 . 2008-04-14 00:09 6656 d:\windows\system32\dllcache\kbdinmal.dll
    + 2004-08-04 00:07 . 2008-04-14 00:09 6144 d:\windows\system32\dllcache\kbdinben.dll
    + 2004-08-04 00:07 . 2008-04-14 00:09 6144 d:\windows\system32\dllcache\kbdinbe1.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 653120 d:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 569664 d:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
    + 2009-07-12 05:05 . 2009-07-12 05:05 225280 d:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 159032 d:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
    + 2004-08-04 00:07 . 2011-03-18 16:50 433018 d:\windows\system32\perfh009.dat
    - 2004-08-04 00:07 . 2010-11-10 06:26 433018 d:\windows\system32\perfh009.dat
    + 2011-03-09 19:02 . 2011-03-09 19:02 219648 d:\windows\Installer\2d8789.msi
    + 2011-03-27 17:08 . 2011-03-27 17:08 811520 d:\windows\Installer\1d7c06.msi
    + 2011-03-27 17:17 . 2011-03-27 17:17 380928 d:\windows\Installer\{2A697B53-0DE3-42DA-B41D-C3F804B1C538}\iTunesIco.exe
    + 2009-07-12 05:02 . 2009-07-12 05:02 3780424 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 3765048 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
    + 2011-03-27 17:10 . 2011-02-18 20:36 4184352 d:\windows\system32\DRVSTORE\usbaapl_05A32DBD3911A2EF4222EF5BE7BB535FAB37D6C4\usbaaplrc.dll
    + 2011-03-27 17:17 . 2011-03-27 17:17 5448704 d:\windows\Installer\1d84f8.msi
    + 2011-03-27 17:10 . 2011-03-27 17:10 3085312 d:\windows\Installer\1d7c53.msi
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer "= "d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "SandboxieControl "= "d:\program files\Sandboxie\SbieCtrl.exe" [2011-01-12 405736]
    "msnmsgr "= "d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    "ComcastAntispyClient "= "d:\program files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" [2009-08-19 1589208]
    "FileHippo.com "= "d:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon "= "d:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
    "HP Software Update "= "d:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-12-15 49152]
    "Adobe Reader Speed Launcher "= "d:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
    "Adobe ARM "= "d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
    "MSN Toolbar "= "d:\program files\MSN Toolbar\Platform\4.0.0417.0\mswinext.exe" [2010-07-06 240480]
    "Microsoft Default Manager "= "d:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
    "jswtrayutil "= "d:\program files\NETGEAR\WN111v2\jswtrayutil.exe" [BU]
    "ZoneAlarm Client "= "d:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
    "QuickTime Task "= "d:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "avgnt "= "d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
    "iTunesHelper "= "d:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting "= "d:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "nltide_3 "= "advpack.dll" [2009-06-29 124928]
    .
    d:\documents and settings\Nelson Ramon Arucas\Start Menu\Programs\Startup\
    OpenOffice.org 3.0.lnk - d:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
    Xfire.lnk - d:\program files\Xfire\xfire.exe [2011-4-8 3510160]
    .
    d:\documents and settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
    hp psc 2000 Series.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-6-27 323646]
    Launch Profile Launcher.lnk - d:\program files\Saitek\Software\ProfilerU.exe [2008-4-8 163840]
    Logitech Desktop Messenger.lnk - d:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-4-3 169472]
    McAfee Security Scan Plus.lnk - d:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
    NETGEAR WN111v2 Smart Wizard.lnk - d:\program files\NETGEAR\WN111v2\WN111V2.exe [2009-11-4 1507431]
    officejet 6100.lnk - d:\program files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-6-27 147456]
    Secunia PSI Tray.lnk - d:\program files\Secunia\PSI\psi_tray.exe [2011-1-5 291896]
    .
    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel "= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
    "NoAutoUpdate "= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
    @= "Service "
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring "=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)
    "DisableUnicastResponsesToMulticastBroadcast "= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "d:\program files\Gameforge4D\AirRivals\Launcher.atm "= d:\program files\Gameforge4D\AirRivals\Launcher.atm:Enabled:GameExe2
    "d:\program files\Gameforge4D\AirRivals\Res-Voip\SCVoIP.exe "= d:\program files\Gameforge4D\AirRivals\Res-Voip\SCVoIP.exe:Enabled:GameVoIP
    "d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "d:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe "=
    "d:\\WINDOWS\\system32\\sessmgr.exe "=
    "d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "d:\\Program Files\\Xfire\\xfire.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe "=
    "d:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe "=
    "d:\\Program Files\\Ventrilo\\Ventrilo.exe "=
    "d:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe "=
    "d:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe "=
    "d:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe "=
    "d:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "d:\\Program Files\\iTunes\\iTunes.exe "=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "56143:TCP "= 56143:TCP:pando Media Booster
    "56143:UDP "= 56143:UDP:pando Media Booster
    .
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [3/9/2011 3:03 PM 135336]
    R2 PEDRV;P&E Microcomputer System PCI Driver.;d:\windows\system32\drivers\pedrv.sys [8/3/2000 2:25 PM 23296]
    R2 WinDefend;Windows Defender;d:\program files\Windows Defender\MsMpEng.exe [11/3/2006 11:19 PM 13592]
    R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;d:\windows\system32\DNINDIS5.sys [7/24/2003 1:10 PM 17149]
    R3 JSWSCIMD;jswscimd Service;d:\windows\system32\drivers\jswscimd.sys [10/1/2008 5:45 PM 57440]
    R3 PSI;PSI;d:\windows\system32\drivers\psi_mf.sys [9/1/2010 4:30 AM 15544]
    R3 SaiH5F0D;SaiH5F0D;d:\windows\system32\drivers\SaiH5F0D.sys [4/4/2008 2:15 AM 176640]
    R3 SaiU5F0D;SaiU5F0D;d:\windows\system32\drivers\SaiU5F0D.sys [4/4/2008 2:15 AM 27264]
    R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;d:\windows\system32\drivers\WN111v2.sys [1/14/2009 3:23 AM 458752]
    S2 AntiSpywareService;Comcast AntiSpyware;d:\program files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [6/17/2009 1:49 PM 616408]
    S2 gupdate;Google Update Service (gupdate);d:\program files\Google\Update\GoogleUpdate.exe [1/10/2011 2:51 AM 136176]
    S2 Secunia PSI Agent;Secunia PSI Agent;d:\program files\Secunia\PSI\psia.exe [1/5/2011 6:31 AM 988216]
    S2 Secunia Update Agent;Secunia Update Agent;d:\program files\Secunia\PSI\sua.exe [1/5/2011 6:31 AM 399416]
    S3 EagleXNt;EagleXNt;\??\d:\windows\system32\drivers\EagleXNt.sys --> d:\windows\system32\drivers\EagleXNt.sys [?]
    S3 jswpsapi;Jumpstart Wifi Protected Setup;d:\program files\NETGEAR\WN111v2\jswpsapi.exe [2/27/2008 12:54 PM 360547]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;d:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232]
    S3 nosGetPlusHelper;getPlus(R) Helper 3004;d:\windows\System32\svchost.exe -k nosGetPlusHelper [8/3/2004 8:07 PM 14336]
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - kwecyfod
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
    nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-12 d:\windows\Tasks\AppleSoftwareUpdate.job
    - d:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
    .
    2008-07-08 d:\windows\Tasks\FRU Task 2002-06-27 08:46ewlett-Packard2002-06-27 08:46p psc 2200 seriesF56855811176EC24C9B302F94878AD886AF77CFF207566146.job
    - d:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-06-27 08:46]
    .
    2011-04-14 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - d:\program files\Google\Update\GoogleUpdate.exe [2011-01-10 06:51]
    .
    2011-04-14 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - d:\program files\Google\Update\GoogleUpdate.exe [2011-01-10 06:51]
    .
    2011-04-14 d:\windows\Tasks\MP Scheduled Scan.job
    - d:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 03:20]
    .
    2011-04-14 d:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - d:\program files\Ask.com\UpdateTask.exe [2010-09-29 03:44]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.comcast.net/
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file)
    BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-04-14 13:28
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-343818398-813497703-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @= "d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker4 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(1484)
    d:\program files\CA\PPRT\bin\CACheck.dll
    d:\program files\CA\PPRT\bin\CAHook.dll
    d:\program files\CA\PPRT\bin\CAServer.dll
    .
    Completion time: 2011-04-14 13:33:21
    ComboFix-quarantined-files.txt 2011-04-14 17:33
    ComboFix2.txt 2011-03-05 19:11
    ComboFix3.txt 2011-01-08 18:44
    .
    Pre-Run: 22,446,022,656 bytes free
    Post-Run: 22,428,438,528 bytes free
    .
    - - End Of File - - 4F1F20E33C2EC6C167C14CFB406C8911
     
  21. 2011/04/14
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0

    Ok, I looking in my view tab of my IE window, and under the tools section of that tab, there is no "Ask Toolbar ". I also looked in the "Add or Remove Programs" under the control panel, and did not find the Ask Toolbar. Could you please give me details on how to remove this specific toolbar?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.