<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Digging in</title><link>http://blogs.technet.com/ganand/default.aspx</link><description /><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Unable to move my cluster group from node A to Node B and cluster.log analysis</title><link>http://blogs.technet.com/ganand/archive/2009/03/25/unable-to-move-my-cluster-group-from-node-a-to-node-b-and-cluster-log-analysis.aspx</link><pubDate>Wed, 25 Mar 2009 12:22:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3217812</guid><dc:creator>ganand</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ganand/comments/3217812.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=3217812</wfw:commentRss><description>&lt;p&gt;&amp;nbsp; &lt;p&gt;I have a 2 node MSCS quorum based cluster and was unable to move my cluster group from node 17 to node16 manually from cluadmin. So let’s have a look and the very first thing one will do is look at cluster.log and event logs…we at Microsoft will grab a quick cluster&amp;nbsp; mps reports to see detailed information. So I quickly ran cluster mps on both nodes and that grabbed all the log files in cab file which I can look into now. &lt;p&gt;Link for cluster mps  &lt;p&gt;&lt;a href="http://download.microsoft.com/download/b/b/1/bb139fcb-4aac-4fe5-a579-30b0bd915706/MPSRPT_CLUSTER.EXE"&gt;http://download.microsoft.com/download/b/b/1/bb139fcb-4aac-4fe5-a579-30b0bd915706/MPSRPT_CLUSTER.EXE&lt;/a&gt; &lt;p&gt;now from my cluster mps reports I quickly outlined a few things that will come handy in my analysis &lt;p&gt;ffbc99dc-0432-4bc4-89bc-90c5899b99d1----------Cluster IP Address&amp;nbsp;&amp;nbsp; {IP Address} &lt;p&gt;c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7----------Disk Q:&amp;nbsp;&amp;nbsp; {Physical Disk} &lt;p&gt;3fa17b2e-a365-4c5d-8fde-460c74deaaf6----------Cluster Name&amp;nbsp;&amp;nbsp; {Network Name} &lt;p&gt;========================================================================================== &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cluster Disk Driver Parameters &lt;p&gt;========================================================================================== &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Available Disk Signatures &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------------------- &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current Used Disk Signatures &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---------------------------- &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1. E098B1A3 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2. E098B1A2 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3. C39BA6F5 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4. AF4763FD &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5. 09C073AC &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6. 09C073A8 &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Unabletomovemyclustergroupfr.loganalysis_D127/clip_image002_2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="162" alt="clip_image002" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Unabletomovemyclustergroupfr.loganalysis_D127/clip_image002_thumb.jpg" width="854" border="0"&gt;&lt;/a&gt; &lt;p&gt;Cluster.log Node 17 &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpDoMoveGroup: Entry—&lt;font color="#0000ff"&gt;we moved the cluster group from node 17 to node 16 and whenever&amp;nbsp; we do this we see&amp;nbsp; FmpDoMoveGroup in the cluster.log so you can search for DoMove if you want to check in cluster.log when we moved the group and what happened after that&lt;/font&gt; &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpMoveGroup: Entry &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpPickNodeFromPreferredListAtRandom: Picking node for group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 [Cluster Group1], suggested node 1...&lt;font color="#0000ff"&gt;cluster group was on node 2 originally and here node 1 is being suggested as this is a 2 node cluster&lt;/font&gt; &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpPickNodeFromPreferredListAtRandom: Node 1 for group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 is user preferred...&lt;font color="#0000ff"&gt;this guid belongs to cluster group and as you see ---00000c50.00000c30::2009/01/06-14:06:03.226 OBRENAME "Group" "9d4fae4b-7dba-44f1-992a-0ecf1502e654" "Cluster Group"—I got this information from cluster.oml file&lt;/font&gt; &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpPickNodeFromPreferredListAtRandom: Selected node 1 for group 9d4fae4b-7dba-44f1-992a-0ecf1502e654... &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpMoveGroup: Moving group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 to node 1 (1)—&lt;font color="#0000ff"&gt;we are moving cluster group to node 1&lt;/font&gt; &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpOfflineResource: Cluster Name depends on Cluster IP Address. Shut down first.—&lt;font color="#0000ff"&gt;as cluster IP is dependent on cluster name we need to bring cluster name offline before cluster ip&lt;/font&gt; &lt;p&gt;00000468.00000128::2009/03/18-12:19:10.651 INFO [FM] FmpOfflineResource: Offline resource &amp;lt;Cluster Name&amp;gt; returned pending &lt;p&gt;00000874.00000c04::2009/03/18-12:19:10.651 INFO [RM] RmpSetResourceStatus, Posting state 3 notification for resource &amp;lt;Cluster Name&amp;gt; &lt;p&gt;00000468.00000774::2009/03/18-12:19:10.651 INFO [FM] NotifyCallBackRoutine: enqueuing event &lt;p&gt;00000874.00000c04::2009/03/18-12:19:10.651 INFO Network Name &amp;lt;Cluster Name&amp;gt;: Resource is now offline &lt;p&gt;00000874.00000b80::2009/03/18-12:19:10.651 INFO IP Address &amp;lt;Cluster IP Address&amp;gt;: Taking resource offline... &lt;p&gt;00000874.00000b80::2009/03/18-12:19:10.651 INFO IP Address &amp;lt;Cluster IP Address&amp;gt;: Deleting IP interface 4. &lt;p&gt;00000874.00000b80::2009/03/18-12:19:10.651 INFO IP Address &amp;lt;Cluster IP Address&amp;gt;: Address 172.23.96.221 on adapter Intel(R) PRO/1000 CT Network Connection offline. &lt;p&gt;00000874.00000b80::2009/03/18-12:19:10.651 INFO IP Address &amp;lt;exchange IP Address&amp;gt;: All resources offline - cleaning up &lt;p&gt;00000874.00000b90::2009/03/18-12:19:10.651 ERR&amp;nbsp; IP Address &amp;lt;exchange IP Address&amp;gt;: WorkerThread: GetClusterNotify failed with status 6. &lt;p&gt;&lt;font color="#0000ff"&gt;To check what this function GetClusterNotify do let’s have a look at msdn&lt;/font&gt; &lt;p&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/aa369623(VS.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/aa369623(VS.85).aspx&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Unabletomovemyclustergroupfr.loganalysis_D127/clip_image004_2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="230" alt="clip_image004" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Unabletomovemyclustergroupfr.loganalysis_D127/clip_image004_thumb.jpg" width="842" border="0"&gt;&lt;/a&gt; &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Offline, Dismounting volume \Device\Harddisk1\Partition1.—&lt;font color="#0000ff"&gt;now we are dismounting the quorum&lt;/font&gt; &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 INFO Physical Disk: [PnP] Event GUID_IO_VOLUME_DISMOUNT for Q (Partition1) - Received  &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 INFO Physical Disk: [PnP] Event GUID_IO_VOLUME_DISMOUNT for Q (Partition1) - Processed  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Offline, Dismount complete, volume \Device\Harddisk1\Partition1. &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskCleanup started. &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] StopPersistentReservations is called---&lt;font color="#0000ff"&gt;here cluster node 2 release arbitration on quorum so that other node can reserve it&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;Persistent Reserve refers to a set of Small Computer Systems Interface-3 (SCSI-3) standard commands and command options which provide SCSI initiators with the ability to establish, preempt, query, and reset a reservation policy with a specified target device. The functionality provided by the Persistent Reserve commands is a superset of the reserve/release commands.&lt;/font&gt; &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Stopping reservation thread. &lt;p&gt;00000874.00000a4c::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] CompletionRoutine, status 0. &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [ArbCleanup] Verifying sector size.  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [ArbCleanup] Reading arbitration block.  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful read&amp;nbsp; (sector 12)  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [ArbCleanup] Writing arbitration block.  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful write (sector 12) [:0] (0,00000000:00000000). &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [ArbCleanup] Returning status 0.  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] StopPersistentReservations is complete. &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DisksDismountDrives: letter mask is 00010000. &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskCleanup returning final error 0  &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 INFO Physical Disk: [PnP] Event GUID_IO_VOLUME_UNLOCK for Q (Partition1) - Received  &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 INFO Physical Disk: [PnP] Event GUID_IO_VOLUME_UNLOCK for Q (Partition1) - Processed  &lt;p&gt;00000874.000004c4::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Offline, Returning final error 0.—&lt;font color="#0000ff"&gt;error 0 means successfull&lt;/font&gt; &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [PnP] Stop watching PnP events for disk 9c073a8—&lt;font color="#0000ff"&gt;this is the disk signature of quorum drive&lt;/font&gt; &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 WARN Physical Disk &amp;lt;Disk Q:&amp;gt;: [PnP] RemoveDisk: WatchedList is empty  &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [PnP] Stop watching disk 9c073a8 - processed &lt;p&gt;00000874.00000130::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskCleanup started. &lt;p&gt;00000874.00000130::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] StopPersistentReservations is called. &lt;p&gt;00000874.00000130::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] StopPersistentReservations is complete. &lt;p&gt;00000874.00000130::2009/03/18-12:19:10.666 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskCleanup returning final error 0  &lt;p&gt;00000468.00000ce4::2009/03/18-12:19:10.666 INFO [CP] CppResourceNotify for resource Disk Q: &lt;p&gt;00000468.00000ce4::2009/03/18-12:19:10.666 INFO [FM] RmTerminateResource: c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7 is now offline &lt;p&gt;So here our quorum goes offline for node 2 ---c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7----------Disk Q:&amp;nbsp;&amp;nbsp; {Physical Disk} &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.682 INFO [FM] FmpCompleteMoveGroup: Completing the move for group Cluster Group1 to node 1 (1) &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.682 INFO [FM] FmpCompleteMoveGroup: Take group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 request to remote node 1—&lt;font color="#0000ff"&gt;now we going to node 1 so that it can take over the cluster group&lt;/font&gt; &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.729 WARN [NM] RpcExtErrorInfo: Error info not found. &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.729 INFO [FM] FmpCompleteMoveGroup: Remote node asked us to resend take group request for group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 to another node .. &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.729 INFO [FM] Set membership mask of 0x0 returns status 1 &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Wait for offline thread to complete... &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb]------- DisksArbitrate -------. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Attaching to disk with signature 9c073a8  &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Disk unique id present trying new attach &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Retrieving disk number from ClusDisk registry key  &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Retrieving handle to PhysicalDrive1  &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Returns success. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Arbitration Parameters: ArbAttempts 5,&amp;nbsp; SleepBeforeRetry 500 ms. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Read the partition info to insure the disk is accessible. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Issuing GetPartInfo on signature 9c073a8. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] GetPartInfo completed, status 0. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Arbitrate for ownership of the disk by reading/writing various disk sectors. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful read&amp;nbsp; (sector 12) [:0] (0,00000000:00000000). &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful write (sector 11) [BLR3R07-17:0] (0,be247638:01c9a7c3). &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful read&amp;nbsp; (sector 12) [:0] (0,00000000:00000000). &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful write (sector 12) [BLR3R07-17:0] (0,be247638:01c9a7c3). &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Successful read&amp;nbsp; (sector 11) [BLR3R07-17:0] (0,be247638:01c9a7c3). &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Issuing Reserve on signature 9c073a8. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Reserve completed, status 0. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 WARN Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Assume ownership of the device. &lt;p&gt;00000874.00000a4c::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] CompletionRoutine starts. &lt;p&gt;00000874.000006f4::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Arbitrate returned status 0. &lt;p&gt;00000874.00000a4c::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Posting request to check reserve progress. &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.729 INFO [FM] FmpNotifyGroupStateChangeReason: Notifying group Cluster Group1 [9d4fae4b-7dba-44f1-992a-0ecf1502e654] of state change reason 3... &lt;p&gt;00000874.00000a4c::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] ********* IO_PENDING ********** - Request to insure reserves working is now posted. &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.729 INFO [FM] FmpOnlineResourceList: Previous quorum resource state for c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7 is 2 &lt;p&gt;00000468.00000330::2009/03/18-12:19:10.729 INFO [FM] FmpOnlineResourceList: trying to bring quorum resource c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7 online, state 3 &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Returns success. &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Wait for async cleanup worker thread in ClusDisk to complete.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.729 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Send Offline IOCTL to all existing volumes, then Online IOCTL.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.744 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Recreate volume information from cluster database.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskspCheckPathLite: Volume name &lt;a href="file:///\\%3f\Volume%7b57acdc20-dbdb-11dd-a9a5-00123f25504d%7d\"&gt;\\?\Volume{57acdc20-dbdb-11dd-a9a5-00123f25504d}\&lt;/a&gt; &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DisksMountDrives: calling IsAlive function. &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DriveIsAlive called for Online check &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DriveIsAlive checking quorum drive to insure cluster directory accessible.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskspCheckPath: Open Q:\MSCS\3586de39-46af-4072-9ffc-4c3a32ddf614\00000001.CPT succeeded.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskspCheckPath: Open Q:\MSCS\chkCD1.tmp succeeded.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskspCheckPath: Open Q:\MSCS\clusdbb1 succeeded.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskspCheckPath: Open Q:\MSCS\clusdbb1.LOG succeeded.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DiskspCheckPath: Open Q:\MSCS\quolog.log succeeded.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DriveIsAlive checking that file system is not corrupt.&amp;nbsp; If so, chkdsk may run.  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DisksIsVolumeDirty: Volume is clean  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DisksMountDrives: letter mask is 00010000. &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: DisksMountDrives: creating admin share names. &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Insure mount point information is correct. &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Offset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; String  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: ================&amp;nbsp; ======================================  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: 0000000000007E00&amp;nbsp; \??\Volume{57acdc20-dbdb-11dd-a9a5-00123f25504d}  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: *** End of list ***  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: SetupVolGuids: Processing VolGuid list  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Retrieve and validate the disk serial number. &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Old SerNum (DF600-00A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&amp;nbsp;&amp;nbsp; Old SerNumLen (16)  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, New SerNum (DF600-00A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&amp;nbsp;&amp;nbsp; New SerNumLen (16)  &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.776 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, Trying to get Disk unique ids . &lt;p&gt;00000874.00000090::2009/03/18-12:19:10.791 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: Online, returning final error 0&amp;nbsp;&amp;nbsp; ResourceState 2&amp;nbsp; Valid 1 &lt;p&gt;00000874.00000828::2009/03/18-12:19:10.791 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [PnP] Start watching PnP events for disk 9c073a8 - processed  &lt;p&gt;00000874.000006f4::2009/03/18-12:19:11.291 INFO IP Address &amp;lt;Cluster IP Address&amp;gt;: Bringing resource online... &lt;p&gt;00000468.00000330::2009/03/18-12:19:11.291 INFO [FM] FmpPropagateResourceState: resource ffbc99dc-0432-4bc4-89bc-90c5899b99d1 pending event. &lt;p&gt;00000468.00000330::2009/03/18-12:19:11.291 INFO [FM] FmpRmOnlineResource: Resource ffbc99dc-0432-4bc4-89bc-90c5899b99d1 pending &lt;p&gt;00000468.00000330::2009/03/18-12:19:11.291 INFO [FM] FmpRmOnlineResource: Returning. Resource ffbc99dc-0432-4bc4-89bc-90c5899b99d1, state 129, status 997. &lt;p&gt;00000468.00000330::2009/03/18-12:19:11.291 INFO [FM] FmpOnlineResourceList: Previous resource state for 3fa17b2e-a365-4c5d-8fde-460c74deaaf6 is 2 &lt;p&gt;00000468.00000330::2009/03/18-12:19:11.291 INFO [FM] FmpOnlineResourceList: trying to bring resource 3fa17b2e-a365-4c5d-8fde-460c74deaaf6 online &lt;p&gt;00000468.00000330::2009/03/18-12:19:11.291 INFO [FM] OnlineResource: 3fa17b2e-a365-4c5d-8fde-460c74deaaf6 depends on ffbc99dc-0432-4bc4-89bc-90c5899b99d1. Bring online first. &lt;p&gt;00000874.00000d70::2009/03/18-12:19:11.291 INFO IP Address &amp;lt;Cluster IP Address&amp;gt;: Online: Registered notification for netinterface 2a6976f9-af64-4d00-af1c-62381c96b776. &lt;p&gt;00000874.00000d70::2009/03/18-12:19:13.510 INFO IP Address &amp;lt;Cluster IP Address&amp;gt;: IP Address 172.23.96.221 on adapter Intel(R) PRO/1000 CT Network Connection online &lt;p&gt;00000874.00000eac::2009/03/18-12:19:13.510 INFO Network Name &amp;lt;Cluster Name&amp;gt;: Bringing resource online... &lt;p&gt;00000874.00000eac::2009/03/18-12:19:14.369 INFO Network Name &amp;lt;Cluster Name&amp;gt;: Registered server name CLUS157442 on transport \Device\NetBt_If3. &lt;p&gt;00000874.00000eac::2009/03/18-12:19:14.557 INFO Network Name &amp;lt;Cluster Name&amp;gt;: Registered workstation name CLUS157442 on transport \Device\NetBt_If3. &lt;p&gt;00000874.00000eac::2009/03/18-12:19:14.557 INFO Network Name &amp;lt;Cluster Name&amp;gt;: Network Name CLUS157442 is now online &lt;p&gt;&lt;font color="#0000ff"&gt;Cluster group came back online on node 17 as node 16 was unable to arbitrate the quorum&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;Now let’s see what we see on node 16&lt;/font&gt; &lt;p&gt;Cluster.log Node 16 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] GUM update group 9d4fae4b-7dba-44f1-992a-0ecf1502e654, state 3—this is cluster group &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] New owner of Group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 is 2, state 3, curstate 0. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: completed update seq 3362&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 9 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: dispatching seq 3363&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 11 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: completed update seq 3363&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 11 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: dispatching seq 3364&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 8 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] Gum update resource 3fa17b2e-a365-4c5d-8fde-460c74deaaf6, state 3, current state 2. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: completed update seq 3364&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 8 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: dispatching seq 3365&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 1 context 4099 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [DM] DmWriteToQuorumLog Entry Seq#=3365 Type=4099 Size=162 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [DM] DmUpdateDeleteValue &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [DM] DmWriteToQuorumLog Entry Seq#=3365 Type=4099 Size=162 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: completed update seq 3365&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 1 context 4099 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: dispatching seq 3366&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 8 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] Gum update resource ffbc99dc-0432-4bc4-89bc-90c5899b99d1, state 3, current state 2. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: completed update seq 3366&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 8 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: dispatching seq 3367&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 8 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] Gum update resource c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7, state 130, current state 2. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: completed update seq 3367&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 8 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [GUM] s_GumUpdateNode: dispatching seq 3368&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type 0 context 9 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] GUM update group 9d4fae4b-7dba-44f1-992a-0ecf1502e654, state 1 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.568 INFO [FM] New owner of Group 9d4fae4b-7dba-44f1-992a-0ecf1502e654 is 2, state 1, curstate 0. &lt;p&gt;&lt;font color="#0000ff"&gt;Here we are updating the state of the resource via GUM update&lt;/font&gt;  &lt;p&gt;ffbc99dc-0432-4bc4-89bc-90c5899b99d1----------Cluster IP Address&amp;nbsp;&amp;nbsp; {IP Address} &lt;p&gt;c6b92a6f-6190-4ec2-b34f-c9a834c8b8f7----------Disk Q:&amp;nbsp;&amp;nbsp; {Physical Disk} &lt;p&gt;3fa17b2e-a365-4c5d-8fde-460c74deaaf6----------Cluster Name&amp;nbsp;&amp;nbsp; {Network Name} &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.599 INFO [FM] FmsTakeGroupRequest: To take group '9d4fae4b-7dba-44f1-992a-0ecf1502e654'. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.599 INFO [FM] FmpTakeGroupRequest: To take group '9d4fae4b-7dba-44f1-992a-0ecf1502e654'.—&lt;font color="#0000ff"&gt;node 1 being requested to take cluster group&lt;/font&gt; &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.599 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] Wait for offline thread to complete... &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.599 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb]------- DisksArbitrate &lt;font color="#0000ff"&gt;-------.node 1 trying to arbitrate quorum&lt;/font&gt; &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.599 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Attaching to disk with signature 9c073a8 &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.599 INFO Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] DisksOpenResourceFileHandle: Disk unique id present trying new attach &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.599 ERR&amp;nbsp; Physical Disk &amp;lt;Disk Q:&amp;gt;: [DiskArb] &lt;font color="#0000ff"&gt;Signature of disk has changed or failed to find disk with id, old signature 0x9c073a8 new signature 0x9c073a8, status 2&lt;/font&gt; &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.646 ERR&amp;nbsp; Physical Disk &amp;lt;Disk Q:&amp;gt;: SCSI: Attach, error attaching to signature 9c073a8, error 2.—&lt;font color="#0000ff"&gt;err 2 path not valid&lt;/font&gt; &lt;p&gt;00000e38.00000ab4::2009/03/18-12:19:10.646 ERR&amp;nbsp; Physical Disk &amp;lt;Disk Q:&amp;gt;: Arbitrate: Unable to attach to signature 9c073a8. Error: 2. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.646 INFO [MM] MmSetQuorumOwner(0,0), old owner 1. &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.646 INFO [FM] FmpTakeGroupRequest: MM did not select local node 1 as the arbitration winner, Status 2 &lt;p&gt;&lt;font color="#0000ff"&gt;We were not able to arbitrate quorum on node 1 and we failed due to reservation&lt;/font&gt; &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.646 INFO [FM] FmpTakeGroupRequest: MM did not select local node 1 as the arbitration winner, Status 2 &lt;p&gt;00000db8.00000d7c::2009/03/18-12:19:10.646 INFO [FM] FmpTakeGroupRequest: Exit for group &amp;lt;9d4fae4b-7dba-44f1-992a-0ecf1502e654&amp;gt;, Status = 1237... &lt;p&gt;&lt;font color="#0000ff"&gt;What happened here..aah we see some time skew on both nodes as seen in cluster.log…which is as we see following event logs&lt;/font&gt; &lt;p&gt;Type: Error &lt;p&gt;Date: 03/18/2009 &lt;p&gt;Time: 4:59:03 PM &lt;p&gt;Event ID: 29 &lt;p&gt;Source: W32Time &lt;p&gt;User: N/A &lt;p&gt;Type: Information &lt;p&gt;Date: 03/18/2009 &lt;p&gt;Time: 4:59:04 PM &lt;p&gt;Event ID: 37 &lt;p&gt;Source: W32Time &lt;p&gt;Node 16 &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/875424"&gt;http://support.microsoft.com/kb/875424&lt;/a&gt; &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/830092"&gt;http://support.microsoft.com/kb/830092&lt;/a&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;lets search on support.microsoft.com for any known issue..found these 2 kb articles..however none of them applies as I am already on sp2 and we are not using local quorum feature of cluster. Then what’s the issue…we are sure it is something to do on storage side on quorum.  &lt;p&gt;911030&amp;nbsp; A cluster node failover does not work when you use SCSI-3-compliant persistent reservations in Windows Server 2003 SP1 &lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;911030"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;911030&lt;/a&gt; &lt;p&gt;888160&amp;nbsp; Cluster is formed by using a local quorum resource after a cluster setup failure in Windows Server 2003 &lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;888160"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;888160&lt;/a&gt; &lt;p&gt;I went ahead and stopped the cluster service on node 17 and put clusdisk driver on demand in device manager ..so now quorum is not under the control of node 17 but quorum still may have reservation on it which is not getting cleared somehow. Node 16 was still not able to arbitrate quorum and I tried restarting cluster service on node 16 twice but no help. I went back to node 17 ..restored the cluster service and clusdisk driver on demand ….we got our failed cluster online again. &lt;p&gt;I am now more convinced that this is a storage issue …how to fix my cluster now &lt;p&gt;One way I can go on storage and see for issues and troubleshoot there..but I dint want to go down to lab where our underlying san storage is present..so I will just&amp;nbsp; change the destination of our quorum from Q:\ to k:\  &lt;p&gt;I stopped the cluster service on node 16 from cluadmin.&amp;nbsp; I had drive K in another group 1&amp;nbsp; and I moved it to cluster group…..right clicked on cluster name and selected drive k instead of Q for quorum. Restarted cluster service on node 16 and both nodes are up….now I initiated a move group command for cluster group and Bingo!! It moved fine to node 16 . So we know for sure we were having reservation issue on quorum originally and node 16 was unable to clear that reservation. &lt;p&gt;Server 2003 Cluster service uses Reserve/Release SCSI SPC-2 reservations. Problems with reservations may cause problems with the Cluster service's ability to bring a physical disk resource online. In our case looks like quorum has an active persistent reservation even when node 17 was rebooted&amp;nbsp; and that’s why node 16 was unable to clear it. The Cluster service does not manage persistent reservations. Therefore, the Cluster service cannot directly release or manage a persistent reservation. &lt;/p&gt; &lt;p&gt;If you experience a problem with a persistent reservation, you should contact the storage vendor or SAN administrator to help determine whether a problem exists. Generally, storage vendors have tools that you can use to help identify and change the properties of the storage objects. These tools include a tool to change reservations. &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;The information provided here is "AS IS"&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3217812" width="1" height="1"&gt;</description></item><item><title>How to stop Chkdsk from running</title><link>http://blogs.technet.com/ganand/archive/2009/03/17/how-to-stop-chkdsk-from-running.aspx</link><pubDate>Tue, 17 Mar 2009 14:38:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3213931</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/3213931.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=3213931</wfw:commentRss><description>&lt;p&gt;&amp;nbsp; &lt;p&gt;I have seen so many customer requesting how to stop the chkdsk from checking the drive during boot time especially when they have luns in Tera bytes and they cannot afford chkdsk running and hitting the production and uptime of the server. There are 2 ways of stoppng it and another way to do it on cluster volumes. All the ways and related Microsoft support articles are mentioned below. &lt;p&gt;Steps for stopping chkdsk given below: &lt;p&gt;When running the chkdsk /f /r command, Windows prompts the administrator whether chkdsk should be scheduled to run the next time the system starts. To prevent the chkdsk /f /r command from running, follow these steps: &lt;p&gt;1. Start the Registry Editor. &lt;p&gt;2. Locate the following subkey: &lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager &lt;p&gt;3. Change the BootExecute entry from autocheck autochk * /p \??\C: autocheck autochk * to autocheck autochk *. &lt;p&gt;If chkdsk was scheduled to run on multiple volumes, there is an autocheck entry for each volume. Repeat steps two and three of this procedure for each volume that should not be checked. To determine the volumes to be checked during the next startup process, view the entries in the BootExecute registry key. &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;u&gt;Another way&lt;/u&gt;&lt;/em&gt;&lt;/strong&gt; &lt;p&gt;The chkntfs /x command also adds a /k command-line switch before the asterisk. The /k option excludes volumes from being checked for the dirty bit. &lt;p&gt;For example, the command chkntfs /x d: modifies the default registry entry value to autocheck autochk /k:d *. &lt;p&gt;&amp;nbsp; &lt;p&gt;BootExecute Entries &lt;p&gt;Registry Value Function &lt;p&gt;/k:Volume * Excludes chkdsk from running against the volume &lt;p&gt;Command Examples &lt;p&gt;Sample Command Registry Entry Value &lt;p&gt;chkntfs d: e: /x Autocheck AUTOCHK /k:D /k:E * &lt;p&gt;for more information please have a look at the article given below &lt;p&gt;160963&amp;nbsp; CHKNTFS.EXE: What You Can Use It For &lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;160963"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;160963&lt;/a&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;u&gt;the things change a little on cluster volumes&lt;/u&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;u&gt;&lt;/u&gt;&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;u&gt;first way&lt;/u&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;The CHKDSK will be initiated when the clusdisk driver finds any inconsistency on the disk. It is recommended to run CHKDSK if cluster finds any inconsistency. Best procedure to run CHKDSK on the volume is to run in offline mode.  &lt;p&gt;To run CHKDSK in offline mode, please follow the below procedure. &lt;p&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Keep the disk resource on passive node &lt;p&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Stop the cluster service on the node and mark the start-up type of the service to “Manual” &lt;p&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open regedit  &lt;p&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Locate the key “HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Clusdisk” &lt;p&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select “Clusdisk” and will show parameter keys on the right side &lt;p&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Change the value of “Start” key to “4” &lt;p&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Restart the node &lt;p&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Once the system is back run “CHKDSK /f /r” on the disk resource from this node &lt;p&gt;Once the CHKDSK is finished, please follow the below procedure to bring the node back in to the cluster &lt;p&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From the services console mark the start-up type of the cluster service to “Automatic” &lt;p&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open regedit  &lt;p&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Locate the key “HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Clusdisk” &lt;p&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select “Clusdisk” and will show parameter keys on the right side &lt;p&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Change the value of “Start” key to “1” &lt;p&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Restart the node &lt;p&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This will join the node back to the cluster. &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;u&gt;second way&lt;/u&gt;&lt;/em&gt;&lt;/strong&gt; &lt;p&gt;We have an easy way of running chkdsk on a cluster physical disk. Server 2008 and 2003 maintenance mode lets you do it and you &lt;i&gt;need not to create downtime&lt;/i&gt; for whole cluster. &lt;p&gt;C:\Documents and Settings\Administrator&amp;gt;cluster.exe res "disk s:" /maint:1 &lt;p&gt;Setting maintenance mode for resource 'disk s:' &lt;p&gt;Resource&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Node&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status &lt;p&gt;-------------------- -------------------- --------------- ------ &lt;p&gt;disk s:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BLR3R07-16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Online(Maintenance) &lt;p&gt;C:\Documents and Settings\Administrator&amp;gt;chkdsk s: &lt;p&gt;The type of the file system is NTFS. &lt;p&gt;Volume label is New Volume. &lt;p&gt;WARNING!&amp;nbsp; F parameter not specified. &lt;p&gt;Running CHKDSK in read-only mode. &lt;p&gt;CHKDSK is verifying files (stage 1 of 3)... &lt;p&gt;&amp;nbsp; &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;em&gt;&lt;strong&gt;To stop the CHKDSK running on the disk resource&lt;/strong&gt;&lt;/em&gt; till we get the downtime to run the CHKDSK offline, please run the following command. &lt;p&gt;"cluster clustername res "Disk E" /priv Skipchkdsk=1" &lt;p&gt;Once we finish the CHKDSK offline please run the command “cluster clustername res "Disk E" /priv Skipchkdsk=0" to revert back the previous change. &lt;p&gt;For more details on How to run the "chkdsk /f" command on a shared cluster disk : &amp;lt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;176970"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;176970&lt;/a&gt;&amp;gt; &lt;p&gt;223023&amp;nbsp; Enhanced disk resource private properties when using Cluster Server &lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;223023"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;223023&lt;/a&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;The Information provided here is "AS IS" &lt;p&gt; Gaurav Anand&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3213931" width="1" height="1"&gt;</description></item><item><title>Start up for some one who is not familiar with Read only domain controller RODC</title><link>http://blogs.technet.com/ganand/archive/2008/04/26/start-up-for-some-one-who-is-not-familair-with-read-only-domain-controller-rodc.aspx</link><pubDate>Sat, 26 Apr 2008 12:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045267</guid><dc:creator>ganand</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ganand/comments/3045267.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=3045267</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;What&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;=====&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;RODC is a new feature unleashed with windows server 2008. Read-only Domain Controllers differentiate from Domain Controllers with writable AD &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;replica in three basic aspects:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;- Read-only replica of AD database.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;- On-demand replication of account passwords.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;- Ability to delegate administrative rights independently on other read-only domain controllers or writable domain controllers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;Why&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;====&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;It is designed to minimize risks introduced by running Domain Controller in less-secure locations such as branch offices or extranet networks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;No changes to AD database content are possible on RODC. All objects in RODC AD replica are read-only and can change only by means of AD replication from an &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;upstream domain controller.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;The replication partner cannot be: - Pre-Longhorn Domain controller. - Another RODC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;Features&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;=========&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;RODC by default does not replicate passwords of user and computer accounts into its replica of AD database. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;By limiting credential caching to only users who have authenticated to the RODC and are allowed by the Password Replication Policy to have credentials cached, the potential &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;exposure of credentials by a compromise of the RODC is limited&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#1f497d&gt;. This is because, typically, only a small subset of domain accounts has their credentials cached on any given RODC. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;Therefore, in the event that the RODC is stolen, only those credentials that are cached can become subject to any cracking attempt.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;Password replication policy is the list of rules that specify which accounts can have passwords replicated to Read-only Domain controller&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN style="COLOR: #00b050"&gt;. &lt;/SPAN&gt;&lt;FONT color=#1f497d&gt;Every RODC has its own Password &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;Replication policy – it is linked to the computer account of the Domain Controller.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Read-Only Domain Controller offers the possibility to delegate a certain level of access on single machine – without affecting any other domain controller in the domain of forest &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;So the user account who has been delegated authority on RODC wont b able to access other domain controllers in domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;Limitations&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;===========&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;RODC brings additional requirements to forest infrastructure&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color=#1f497d&gt;&lt;SPAN style="FONT-SIZE: 10.5pt; FONT-FAMILY: Segoe; mso-bidi-font-family: Segoe"&gt;. &lt;/SPAN&gt;&lt;FONT size=3&gt;You cannot run RODC in a forest with Windows 2000 domain controllers&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 10.5pt; FONT-FAMILY: Segoe; mso-bidi-font-family: Segoe"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10.5pt; FONT-FAMILY: Segoe; mso-bidi-font-family: Segoe"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;RODC needs at least one full Longhorn DC in the domain.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color=#1f497d&gt;&lt;SPAN style="FONT-SIZE: 10.5pt; FONT-FAMILY: Segoe; mso-bidi-font-family: Segoe"&gt; &lt;/SPAN&gt;&lt;FONT size=3&gt;RODC cannot replicate from Windows 2003 domain controller and cannot bridge client authentication to &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;Windows 2003 domain controller.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="FONT-SIZE: 10.5pt; FONT-FAMILY: Segoe; mso-bidi-font-family: Segoe"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;RODC cannot satisfy any write operations.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color=#1f497d&gt;&lt;SPAN style="FONT-SIZE: 10.5pt; FONT-FAMILY: Segoe; mso-bidi-font-family: Segoe"&gt; &lt;/SPAN&gt;&lt;FONT size=3&gt;All write operations are referred to full DC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;When connection to full Longhorn DC is broken, only users with credentials already cached on RODC are able to log on. Only resources having their passwords cached &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;on RODC will be accessible.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;SPAN style="COLOR: #00b050"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;RODC cannot be a Global Catalog&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;Prerequisites&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;==============&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;- Domain and Forest functional levels must be Windows 2003 or higher.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;- Full Longhorn Domain Controller from the same domain must be a replication partner for RODC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;- PDC emulator FSMO role must be held by Full Longhorn Domain Controller.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;- Longhorn Server ADPrep /rodcprep must be run. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;FONT size=3&gt;&lt;FONT color=#1f497d&gt;&lt;FONT face=Calibri&gt;RODC cannot be deployed in mixed Windows 2000/Windows 2003 environments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3045267" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/RODC/default.aspx">RODC</category></item><item><title>You will not get the option to reset Pin in bitlocker when using TPM+PIN+StartupKey protectors in vista sp1</title><link>http://blogs.technet.com/ganand/archive/2008/04/26/you-will-not-get-the-option-to-reset-pin-in-bitlocker-when-using-tpm-pin-startupkey-protectors-in-vista-sp1.aspx</link><pubDate>Sat, 26 Apr 2008 12:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045259</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/3045259.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=3045259</wfw:commentRss><description>&lt;P&gt;Aah i dont write blogs in such a nice format but this was written for an&amp;nbsp;another document and i am putting same copy-paste here to save time.Hope this helps.&lt;/P&gt;
&lt;P&gt;=======&lt;/P&gt;
&lt;P&gt;SYMPTOMS&lt;BR&gt;&lt;BR&gt;When you are using TPM+PIN+StartupKey protector on vista sp1 bitlocker enabled vista client you will not get the option to reset the pin when you go to Bitlocker drive encryption applet in control panel. The only option you receive when you choose "select keys to manage" is duplicate the recovery passowrd.&lt;BR&gt;&lt;BR&gt;CAUSE&lt;BR&gt;&lt;BR&gt;This is by design. Please use manage-bde.wsf to delete the exiting TPM+PIN+StartupKey protector and then add a new one if you need to reset the PIN. The GUI shows resetting PIN option only when there is a TPM+PIN protector.&lt;BR&gt;&lt;BR&gt;RESOLUTION&lt;BR&gt;&lt;BR&gt;1 Open the command prompt with administrator privilege.&lt;BR&gt;2 Type:- cd c:\windows\system32&lt;BR&gt;3 Type:- cscript manage-bde.wsf -protectors -delete c: (where c: is the volume being protected)&lt;BR&gt;4 This command will remove all key protectors unless you provide additional parameters.&lt;BR&gt;5 Press enter&lt;BR&gt;6 Type :- cscript manage-bde.wsf -protectors -add (volume to be protected, for eg. c: ) -rp -rk (volume to store recovery key, for eg. f:) -tpsk -tp (pin that you want to be set for eg. 1234) -tsk (volume where you want to store the startup key for eg. g:)&lt;BR&gt;7 Finally the command will appear as:- cscript manage-bde.wsf -protectors -add c: -rp -rk f: -tpsk -tp 1234 -tsk g:&lt;BR&gt;8 You have sucessfully reset the pin.&lt;BR&gt;&lt;BR&gt;======&lt;/P&gt;
&lt;P&gt;The Information provided here is "AS IS"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Gaurav Anand&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3045259" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/Bitlocker/default.aspx">Bitlocker</category></item><item><title>What is this Raw File System</title><link>http://blogs.technet.com/ganand/archive/2008/02/22/what-is-this-raw-file-system.aspx</link><pubDate>Fri, 22 Feb 2008 16:15:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2921540</guid><dc:creator>ganand</dc:creator><slash:comments>15</slash:comments><comments>http://blogs.technet.com/ganand/comments/2921540.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2921540</wfw:commentRss><description>&lt;p&gt;&lt;font size="2"&gt;Sometimes a damaged volume may look like it lost its file system and CHKDSK tool will complain that file system is raw&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000" size="2"&gt;The type of the file system is RAW.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;this is a curious issue as seen here&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;=========&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;what the hell is a RAW file system?—&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.microsoft.com/technet/archive/community/columns/inside/techans9.mspx?mfr=true"&gt;&lt;font size="2"&gt;http://www.microsoft.com/technet/archive/community/columns/inside/techans9.mspx?mfr=true&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;what the hell is a RAW file system?—is easy enough to answer. It's simply a disk partition that has not been&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt; formatted with an NT file system, neither FAT nor NTFS.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;=========&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;so what is this raw or as said raw file system, it is nothing but a &lt;font color="#0000ff"&gt;system supplied file system driver that is the&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff" size="2"&gt; "last resort" for all I/O requests requiring file system support. When the I/O manager calls active file systems&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;font color="#0000ff"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;to mount a volume, RAW is always called last because it supports all disk and tape media. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff" size="2"&gt;However, RAW supplies very primitive file handling capabilities. That is, it does not impose any on-disk file &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff" size="2"&gt;structure or metadata structures for the information about the media; it simply allows read/write access &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff" size="2"&gt;to the logical blocks on the physical disk. For example, it treats the whole disk as a single file and supplies &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff" size="2"&gt;physical-disk-level access to the disk.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;If a device is being driven in raw mode, it has no function driver and no upper or lower-level filter drivers.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt; All raw-mode I/O is done by the bus driver and optional bus filter drivers.&lt;/font&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;font size="2"&gt;Note, however, that a bus driver does not handle read and write requests for the devices on its bus.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt; Read and write requests to a device are handled by the device's function driver only. Only if the device&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt; is being used in raw mode does the parent bus driver handle reads and writes for the device.&lt;/font&gt; &lt;p&gt;&lt;i&gt;&lt;font size="2"&gt;ok the above extract is from DDK ...now lets see where can i see this happening&lt;/font&gt;&lt;/i&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/raw2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="687" alt="raw2" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/raw2_thumb.jpg" width="751" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font color="#ff0000" size="2"&gt;here you see that it is for rawtape, rawcdrom, rawdisk (I am using device and driver explorer here )&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/raw.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="644" alt="raw" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/raw_thumb.jpg" width="758" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;so how can i reproduce this issue--raw file system reported by chkdsk --we can use dskprobe from &lt;/font&gt;&lt;a title="http://technet2.microsoft.com/WindowsServer/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx" href="http://technet2.microsoft.com/WindowsServer/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx"&gt;&lt;font size="2"&gt;http://technet2.microsoft.com/WindowsServer/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;and repro this issue ( please do not try this on a production or home machine -you may loose data)&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;There are two places where we store file system information as seen below&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;1 MBR partition Table&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;2 Volumes' boot sector&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;When the file system information provided on these 2 sectors of disk is not good you may see chkdsk reporting raw file&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; system (though the &lt;/font&gt;&lt;font size="2"&gt;data is still there)&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/disk.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="545" alt="disk" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/disk_thumb.jpg" width="616" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/disk2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="397" alt="disk2" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/disk2_thumb.jpg" width="700" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/disk4.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="347" alt="disk4" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/disk4_thumb.jpg" width="721" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;A Raw volume is a volume that was never formatted and does not contain a File System&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;a title="http://support.microsoft.com/kb/929662" href="http://support.microsoft.com/kb/929662"&gt;&lt;font size="2"&gt;http://support.microsoft.com/kb/929662&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;so just to play i did same on my test machine and removed OEM ID string on D drives Volume boot sector and yes this is&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; my production machine containing lots of data, Now when i try to access D drive it asks do you want to format it...&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;..Of course NOT&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;As if we format we will lose all the data on D drive.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;I tried running Chkdsk and you can see results below. It says, type of File System is raw. Chkdsk is not available for raw drives.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;I reversed my changes using dskprobe again (added NTFS IN OEM ID string) and Yes my data is back and D drive is&amp;nbsp; accessible.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/image_2.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="683" alt="image" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatisthisRawFileSystem_1077C/image_thumb.png" width="715" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;===========================&lt;/p&gt; &lt;p&gt;Gaurav Anand  &lt;p&gt;This posting is provided "AS IS" with no warranties, and confers no rights.  &lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2921540" width="1" height="1"&gt;</description></item><item><title>NTFS Time Stamps --file created in 1601, modified in 1801 and accessed in 2008!!</title><link>http://blogs.technet.com/ganand/archive/2008/02/19/ntfs-time-stamps-file-created-in-1601-modified-in-1801-and-accessed-in-2008.aspx</link><pubDate>Tue, 19 Feb 2008 21:12:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2911445</guid><dc:creator>ganand</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.technet.com/ganand/comments/2911445.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2911445</wfw:commentRss><description>&lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:31d72914-c8de-4144-ac69-12e339a89ab9" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/NTFS" rel="tag"&gt;NTFS&lt;/a&gt;&lt;/div&gt; &lt;p&gt;&lt;font size="2"&gt;So many times we have seen Server Admins asking how to figure out whether someone accessed there&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; files or not or is it possible to play with NTFS time stamps or how exactly time stamps change and under&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; what scenarios. I have heard of this issue a lot and seen people enquiring on same, so i though lets play&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; with a test notepad file and see what Time stamps i can change and then what really happens in MFT.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;To read more about Time stamps please refer the following public links. &lt;/p&gt; &lt;p&gt;========================&lt;/p&gt; &lt;p&gt;"How NTFS Works" (&lt;a href="http://technet2.microsoft.com/WindowsServer/en/library/8cc5891d-bf8e-4164-862d-dac5418c59481033.mspx?mfr=true"&gt;http://technet2.microsoft.com/WindowsServer/en/library/8cc5891d-bf8e-4164-862d-dac5418c59481033.mspx?mfr=true&lt;/a&gt;) &lt;p&gt;&lt;a href="http://technet2.microsoft.com/WindowsServer/en/Library/80dc5066-7f13-4ac3-8da8-48ebd60b44471033.mspx?mfr=true"&gt;http://technet2.microsoft.com/WindowsServer/en/Library/80dc5066-7f13-4ac3-8da8-48ebd60b44471033.mspx?mfr=true&lt;/a&gt; &lt;p&gt;Description of NTFS date and time stamps for files and folders&lt;/p&gt; &lt;p&gt;&lt;a title="http://support.microsoft.com/kb/299648" href="http://support.microsoft.com/kb/299648"&gt;http://support.microsoft.com/kb/299648&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Time Stamps Change When Copying From NTFS to FAT&lt;/p&gt; &lt;p&gt;&lt;a title="http://support.microsoft.com/kb/127830" href="http://support.microsoft.com/kb/127830"&gt;http://support.microsoft.com/kb/127830&lt;/a&gt;&lt;/p&gt; &lt;p&gt;========================&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;In quick short words&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;Last modified time relates to the last time an application modified the unnamed data attribute—what we &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;normally think of as “the file.”&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;Last entry modified stamp relates to an update or modification of any attribute—data, metadata, named streams, etc.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;Last access is updated by activity involving a file, but the stamp is not updated unless the last access occurs &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;after a certain amount of time from the last update of the last access stamp.&amp;nbsp; &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;Two metadata attributes of interest to investigators in the NTFS file system are the Master File Table (MFT) &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;$STANDARD_INFO and $FILE_NAME. Both attributes contain their own entry last modified timestamps. The &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;MFT $STANDARD_INFO attribute contains general information about a file such as flags, last accessed, &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;written, created times, owner, and security ID. The MFT $FILE_NAME attribute contains file name in Unicode, &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;and also the last accessed, written and created times. &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;We have four time stamps…M MODIFIED….A ACESSED…….C CREATED…E ENTRY MODIFED…known as&amp;nbsp; MACE too sometimes.&lt;/font&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/NTFSTimeStampsfilecreatedin1601modifiedi_14D40/clip_image002_2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="167" alt="clip_image002" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/NTFSTimeStampsfilecreatedin1601modifiedi_14D40/clip_image002_thumb.jpg" width="716" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;so I created a test notepad file with the name ntfs.txt and i used a 3rd party utility timestomp.exe (from &lt;/font&gt;&lt;a title="http://www.metasploit.com/projects/antiforensics/" href="http://www.metasploit.com/projects/antiforensics/"&gt;&lt;font size="2"&gt;http://www.metasploit.com/projects/antiforensics/&lt;/font&gt;&lt;/a&gt;&amp;nbsp;&lt;font size="2"&gt;) to change the attributes of my file which was otherwise&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; created today i.e. 19th feb, 2008. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\&amp;gt;TimeStomp ntfs.txt -c "Monday 7/25/1601 5:15:55 AM"&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\&amp;gt;TimeStomp ntfs.txt -m "Monday 7/25/1701 5:15:55 AM"&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\&amp;gt;TimeStomp ntfs.txt -a "Monday 7/25/1801 5:15:55 AM"&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;------------------------------------------------&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;now i checked in explorer and to my surprise I have a file which was created in year 1601 (much before i was born,NTFS&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; file system was born, computers were born) wow!!&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;Now i used another tool named NFI ( &lt;/font&gt;&lt;a title="http://support.microsoft.com/kb/q253066/" href="http://support.microsoft.com/kb/q253066/"&gt;&lt;font size="2"&gt;http://support.microsoft.com/kb/q253066/&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; ) to see the attributes and grab the &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;file record segment of the file ntfs.txt&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;------------------------------------&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\Documents and Settings\ganand\Desktop\mike\ntfs\tools&amp;gt;nfi c:\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;NTFS File Sector Information Utility.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;Copyright (C) Microsoft Corporation 1999. All rights reserved.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $STANDARD_INFORMATION (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $FILE_NAME (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $DATA (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;/font&gt;&amp;nbsp; &lt;p&gt;&lt;font size="2"&gt;I haven't wrote anything in the ntfs.txt till now and that why i don't see an $OBJECT_ID entry..so i wrote some garbage&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt; text in it and saved it.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\Documents and Settings\ganand\Desktop\mike\ntfs\tools&amp;gt;nfi c:\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;NTFS File Sector Information Utility.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;Copyright (C) Microsoft Corporation 1999. All rights reserved.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $STANDARD_INFORMATION (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $FILE_NAME (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $OBJECT_ID (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $DATA (resident)&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;aaaah now i see&amp;nbsp;&amp;nbsp; $OBJECT_ID attribue too (The $OBJECT_ID attribute has a type identifier of 64 and stores a file's&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; 128-bit global object identifier that can be used to address the file instead of its name. This allows a file to be found &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;even when its name is changed.)&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;but the problem is i need to find out where on disk (on which sector) this file is being written to and NFI is not giving&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt; me any output for same....what to do????&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;ohh i figured out that all the attributes and specially data attribute is resident..so i filled lot of garbage data in ntfs.txt and save it.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;tried NFI again and finally got what i was looking for---------------&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\Documents and Settings\ganand\Desktop\mike\ntfs\tools&amp;gt;nfi c:\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;NTFS File Sector Information Utility.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;Copyright (C) Microsoft Corporation 1999. All rights reserved.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $STANDARD_INFORMATION (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $FILE_NAME (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $OBJECT_ID (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $DATA (nonresident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; logical sectors 88364256-88364263 (0x54454e0-0x54454e7)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; logical sectors 115305560-115305567 (0x6df6c58-0x6df6c5f)&lt;/font&gt; &lt;p&gt;------------------------------&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;now from sector I can get the File record segment of this file-------------------&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\Documents and Settings\ganand\Desktop\mike\ntfs\tools&amp;gt;nfi c: 88364256&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;NTFS File Sector Information Utility.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;Copyright (C) Microsoft Corporation 1999. All rights reserved.&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;***Logical sector 88364256 (0x54454e0) on drive C is in file number 44650.------------&lt;font size="2"&gt;converting into hexa decimal &lt;/font&gt;&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;------------AE6A------44650&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;\ntfs.txt&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $STANDARD_INFORMATION (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $FILE_NAME (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $OBJECT_ID (resident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; $DATA (nonresident)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; logical sectors 88364256-88364263 (0x54454e0-0x54454e7)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; logical sectors 115305560-115305567 (0x6df6c58-0x6df6c5f)&lt;/font&gt; &lt;p&gt;----------------------------&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;Now i wanted to look at the attributes using another NTFS utility------------------------------&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;font color="#0000ff"&gt;STANDARD_INFORMATION {&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CreationTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000a114ff05fb80 07/24/1601 23:45:55.0000-------------------though this makes sense&lt;/font&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp; LastModificationTime&amp;nbsp; :0x01c872de3753158f 02/19/2008 10:00:11.0655&lt;font size="2"&gt;-----------------why this --aaah because&lt;/font&gt;&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;font size="2"&gt; i have added data into ntfs.txt after using timestomp so it again changed the modification time stamp-----now makes sense&lt;/font&gt;&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastChangeTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x01c872de3753158f 02/19/2008 10:00:11.0655--------------&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastAccessTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x01c872de3753158f 02/19/2008 10:00:11.0655---------------&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FileAttributes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000020&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MaximumVersions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VersionNumber&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ClassId&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OwnerId&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SecurityId&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x000002fd&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; QuotaCharged&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000000000000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Usn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x000000004a5e3e78&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;_ATTRIBUTE_RECORD_HEADER {&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ATTRIBUTE_TYPE_CODE TypeCode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000030 ($FILE_NAME)&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ULONG RecordLength&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000070&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UCHAR FormCode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UCHAR NameLength&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; USHORT NameOffset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ""&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; USHORT Flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; USHORT Instance&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0004&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RESIDENT_FORM {&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ULONG ValueLength&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0052&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; USHORT ValueOffset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0018&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UCHAR ResidentFlags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0001&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UCHAR Reserved&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;}&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; FILE_NAME {&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ParentDirectory Frs, Seq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; 5 , 5 &amp;gt;&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DUPLICATED_INFORMATION Info {&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CreationTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :01c872da933c2514 02/19/2008 09:34:07.0868&lt;strong&gt;&lt;font size="2"&gt;--------------------//////this never changed////&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastModificationTime :01c872da933c2514 02/19/2008 09:34:07.0868&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastChangeTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :01c872da933c2514 02/19/2008 09:34:07.0868&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastAccessTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :01c872da933c2514 02/19/2008 09:34:07.0868&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AllocatedLength&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0000000000000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FileSize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0000000000000000&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FileAttributes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :00000020&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;--------------------------------------------------&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff" size="2"&gt;lets do once again&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\&amp;gt;TimeStomp ntfs.txt -a "Monday 7/25/1801 5:15:55 AM"&lt;/font&gt; &lt;p&gt;&lt;font color="#0000ff"&gt;C:\&amp;gt;TimeStomp ntfs.txt -m "Monday 7/25/1801 5:15:55 AM"&lt;/font&gt; &lt;p&gt;----------------------&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/NTFSTimeStampsfilecreatedin1601modifiedi_14D40/ntfs%20(2).jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="692" alt="ntfs (2)" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/NTFSTimeStampsfilecreatedin1601modifiedi_14D40/ntfs%20(2)_thumb.jpg" width="770" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;font color="#ff0000"&gt;STANDARD_INFORMATION {&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CreationTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000a114ff05fb80 07/24/1601 23:45:55.0000----------------------------&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastModificationTime&amp;nbsp; :0x00e0da734e1ffb80 07/24/1801 23:45:55.0000---------------------------&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastChangeTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x01c872de3753158f 02/19/2008 10:00:11.0655----------------------------&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastAccessTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00e0da734e1ffb80 07/24/1801 23:45:55.0000-----------------------&lt;/font&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FileAttributes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000020 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MaximumVersions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VersionNumber&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ClassId&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OwnerId&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x00000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SecurityId&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x000002fd &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; QuotaCharged&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x0000000000000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Usn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0x000000004a5e8828 &lt;p&gt;&amp;nbsp;&amp;nbsp; &lt;p&gt;&amp;nbsp; &lt;font color="#ff0000"&gt;&amp;nbsp; FILE_NAME {&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ParentDirectory Frs, Seq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; 5 , 5 &amp;gt;&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DUPLICATED_INFORMATION Info {&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CreationTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :01c872da933c2514 02/19/2008 09:34:07.0868--------------------------------THEY NEVER CHANGED&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastModificationTime :01c872da933c2514 02/19/2008 09:34:07.0868----------------------------------&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastChangeTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :01c872da933c2514 02/19/2008 09:34:07.0868------------------------------&lt;/font&gt; &lt;p&gt;&lt;font color="#ff0000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LastAccessTime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :01c872da933c2514 02/19/2008 09:34:07.0868-----------------------------------&lt;/font&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AllocatedLength&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0000000000000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FileSize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :0000000000000000 &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FileAttributes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :00000020 &lt;p&gt;============&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;If I undesrtand right FN mace values should be older than SIA mace values or same depending on different scenarios. But how easy it was to play with these time stamps on ntfs.txt file!!&lt;/font&gt; &lt;p&gt;===========================&lt;/p&gt; &lt;p&gt;Gaurav Anand &lt;p&gt;This posting is provided "AS IS" with no warranties, and confers no rights. &lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2911445" width="1" height="1"&gt;</description></item><item><title>What happens and parameters passed when a new process is created</title><link>http://blogs.technet.com/ganand/archive/2008/02/15/what-happens-and-parameters-passed-when-a-new-process-is-created.aspx</link><pubDate>Fri, 15 Feb 2008 17:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2895363</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/2895363.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2895363</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Via this blog I have just tried to show What exactly happens when a new process is created and what all structures are required and parameters&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;passed to that process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;What ever mentioned below is all extracted from different places of windows SDK and I have tried to forward a easy picture for understanding&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;purpose. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;The &lt;B&gt;CreateProcessAsUser&lt;/B&gt; function creates a new process and its primary thread. The new process then runs the specified executable file.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #1f497d; FONT-FAMILY: 'Verdana','sans-serif'; mso-themecolor: dark2"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;There are other functions also for creating process like &lt;B style="mso-bidi-font-weight: normal"&gt;CreateProcess&lt;/B&gt; and &lt;B style="mso-bidi-font-weight: normal"&gt;CreateprocessWithLogonW&lt;/B&gt; but I have chosen&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;B&gt;CreateProcessAsUser&lt;/B&gt; one to explain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;BOOL&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt; &lt;B&gt;CreateProcessAsUser(&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;HANDLE&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;hToken&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPCTSTR&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpApplicationName&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPTSTR&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpCommandLine&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPSECURITY_ATTRIBUTES&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpProcessAttributes&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPSECURITY_ATTRIBUTES&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpThreadAttributes&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;BOOL&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;bInheritHandles&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;DWORD&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;dwCreationFlags&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPVOID&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpEnvironment&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPCTSTR&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpCurrentDirectory&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPSTARTUPINFO&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpStartupInfo&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPPROCESS_INFORMATION&lt;/B&gt; &lt;/SPAN&gt;&lt;U&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;lpProcessInformation&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT face=Calibri&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Now a little explained version in regards to all the parameters passed to the function &lt;B&gt;CreateProcessAsUser&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;BOOL&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt; &lt;B&gt;CreateProcessAsUser(&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;HANDLE&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;hToken&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,--------------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; Handle to a primary token that represents a user.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPCTSTR&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpApplicationName&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,------------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; Pointer to a null-terminated string that specifies the module to execute.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #1f497d; FONT-FAMILY: 'Verdana','sans-serif'; mso-themecolor: dark2"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; The specified module can be a Windows-based application.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPTSTR&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpCommandLine&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;, --------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Pointer to a null-terminated string that specifies the command line to execute.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;If both &lt;I&gt;lpApplicationName&lt;/I&gt; and &lt;I&gt;lpCommandLine&lt;/I&gt; are non-NULL, *&lt;I&gt;lpApplicationName&lt;/I&gt; specifies the module to execute, &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;and *&lt;I&gt;lpCommandLine&lt;/I&gt; specifies the command line.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT face="Courier New"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPSECURITY_ATTRIBUTES&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpProcessAttributes&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,-------------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; Pointer to a &lt;B&gt;SECURITY_ATTRIBUTES&lt;/B&gt; structure that specifies&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; a security descriptor &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;for the new process and determines whether child processes can inherit the returned handle. If &lt;I&gt;lpProcessAttributes&lt;/I&gt; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;is NULL or &lt;B&gt;lpSecurityDescriptor &lt;/B&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; is NULL, &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;the process gets a default security descriptor and the handle cannot be inherited. &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #1f497d; FONT-FAMILY: 'Verdana','sans-serif'; mso-themecolor: dark2"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;The default security descriptor is that of the user referenced in the &lt;I&gt;hToken&lt;/I&gt; parameter. This security descriptor may not allow access for the caller, &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;in which case the process may not be opened again after it is run. The process handle is valid and will continue to have full access rights.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0.1in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&lt;B&gt;&lt;SPAN style="COLOR: black"&gt;lpSecurityDescriptor&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: black"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;A pointer to a security descriptor for the object that controls the sharing of it. If NULL is specified for this member, the object&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;is assigned the default security descriptor of the calling process. This is not the same as granting access to everyone by&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;assigning a NULL&amp;nbsp;&lt;I&gt;discretionary access control list&lt;/I&gt; (DACL). The default security descriptor is based on the default DACL of&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;the &lt;I&gt;access token&lt;/I&gt; belonging to the calling process. By default, the default DACL in the access token of a process allows access&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;only to the user represented by the access token. If other users must access the object, you can either create a security&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: white; MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;descriptor with the appropriate access, or add ACEs to the DACL that grants access to a group of users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd" face="Courier New"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT face="Courier New"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPSECURITY_ATTRIBUTES&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpThreadAttributes&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;, ---&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Pointer to a &lt;B&gt;SECURITY_ATTRIBUTES&lt;/B&gt; structure that specifies a security descriptor&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; for the new process and determines whether child processes can inherit the returned handle. If &lt;I&gt;lpThreadAttributes&lt;/I&gt; is NULL or&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; &lt;B&gt;lpSecurityDescriptor &lt;/B&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;is NULL,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; the thread gets a default security descriptor and the handle cannot be inherited. The default security&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; descriptor is that of the user referenced &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;in the &lt;I&gt;hToken&lt;/I&gt; parameter. This security descriptor may not allow access for the caller.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;BOOL&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;bInheritHandles&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,-----&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; If this parameter is TRUE, each inheritable handle in the calling process is inherited by the new process. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;If the parameter is FALSE, the handles are not inherited. Note that inherited handles have the same value and access rights as the original handles.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;DWORD&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;dwCreationFlags&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,---&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; control the priority class and the creation of the process. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P style="BACKGROUND: white"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;The &lt;B&gt;GetPriorityClass&lt;/B&gt; function retrieves the priority class for the specified process. This value, together with the priority value of each thread&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="BACKGROUND: white"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;of the process, determines each thread's base priority level. The operating system uses the base priority level of all executable threads to &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="BACKGROUND: white"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;determine which thread gets the next slice of CPU time. Threads are scheduled in a round-robin fashion at each priority level, and only when&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="BACKGROUND: white"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;there are no executable threads at a higher level will scheduling of threads at a lower level take place.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd" face="Courier New"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPVOID&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpEnvironment&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; Pointer to an environment block for the new process. If this parameter is NULL, the new process uses&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; the environment of the calling process.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPCTSTR&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpCurrentDirectory&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,------------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; Pointer to a null-terminated string that specifies the full path to the current directory for&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt; the process. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;If this parameter is NULL, the new process will have the same current drive and directory as the calling process.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT face="Courier New"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPSTARTUPINFO&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpStartupInfo&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;,----------&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; Pointer to a &lt;/FONT&gt;&lt;A href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/startupinfo_str.htm" mce_href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/startupinfo_str.htm"&gt;&lt;B&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd" color=#0000ff&gt;STARTUPINFO&lt;/FONT&gt;&lt;/B&gt;&lt;/A&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; structure that specifies the window station, desktop, standard&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; handles,&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; and appearance of the main window for the new process.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;For graphical user interface (GUI) processes, this information affects the first window created by the &lt;B&gt;CreateWindow&lt;/B&gt; function and &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;shown by the &lt;B&gt;ShowWindow&lt;/B&gt; function. For console processes, this information affects the console window if a new console is created&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; for the process. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; A process can use the &lt;/FONT&gt;&lt;A href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/getstartupinfo.htm" mce_href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/getstartupinfo.htm"&gt;&lt;B&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd" color=#0000ff&gt;GetStartupInfo&lt;/FONT&gt;&lt;/B&gt;&lt;/A&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; function to retrieve the &lt;B&gt;STARTUPINFO&lt;/B&gt; structure specified when the process&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; was created.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd" face="Courier New"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT face="Courier New"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; &lt;B&gt;LPPROCESS_INFORMATION&lt;/B&gt; &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;lpProcessInformation&lt;/U&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;-----------&lt;/SPAN&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;Pointer to a &lt;/FONT&gt;&lt;A href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/process_information_str.htm" mce_href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/process_information_str.htm"&gt;&lt;B&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd" color=#0000ff&gt;PROCESS_INFORMATION&lt;/FONT&gt;&lt;/B&gt;&lt;/A&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; structure that receives identification &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;information about the new process. This structure contains information about the newly created process and its primary thread.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;typedef struct _PROCESS_INFORMATION {&lt;BR style="mso-special-character: line-break"&gt;
&lt;BR style="mso-special-character: line-break"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; HANDLE &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;hProcess&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;;&lt;BR style="mso-special-character: line-break"&gt;
&lt;BR style="mso-special-character: line-break"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; HANDLE &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;hThread&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;;&lt;BR style="mso-special-character: line-break"&gt;
&lt;BR style="mso-special-character: line-break"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; DWORD &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;dwProcessId&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;;&lt;BR style="mso-special-character: line-break"&gt;
&lt;BR style="mso-special-character: line-break"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&amp;nbsp; DWORD &lt;/SPAN&gt;&lt;SPAN class=MsoHyperlink&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: #0040ff; TEXT-DECORATION: none; text-underline: none"&gt;&lt;U&gt;dwThreadId&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;} PROCESS_INFORMATION, &lt;BR style="mso-special-character: line-break"&gt;
&lt;BR style="mso-special-character: line-break"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;&lt;FONT face="Courier New"&gt;*LPPROCESS_INFORMATION;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;If the function succeeds, be sure to call the &lt;B&gt;CloseHandle&lt;/B&gt; function to close the &lt;B&gt;hProcess&lt;/B&gt; and &lt;B&gt;hThread&lt;/B&gt; handles when you are finished with them. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;Otherwise, when the child process exits, the system cannot clean up these handles because the parent process did not close them. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;FONT style="BACKGROUND-COLOR: #dddddd"&gt;However, the system will close these handles when the parent process terminates, so they would be cleaned up at this point.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;FONT face=Calibri&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;By default, &lt;B&gt;CreateProcessAsUser&lt;/B&gt; creates the new process on a noninteractive window station with a desktop that is not visible and cannot&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;receive user input. To enable user interaction with the new process, you must specify the name of the default interactive window station and&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;desktop, "winsta0\default",&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;in the &lt;B&gt;lpDesktop&lt;/B&gt; member of the &lt;A href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/startupinfo_str.htm" mce_href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/startupinfo_str.htm"&gt;&lt;B&gt;&lt;FONT color=#0000ff&gt;STARTUPINFO&lt;/FONT&gt;&lt;/B&gt;&lt;/A&gt; structure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;The preferred way to shut down a process is by using the &lt;A href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/exitprocess.htm" mce_href="ms-help://MS.PSDKSVR2003SP1.1033/dllproc/base/exitprocess.htm"&gt;&lt;B&gt;&lt;FONT color=#0000ff&gt;ExitProcess&lt;/FONT&gt;&lt;/B&gt;&lt;/A&gt; function, because this function sends notification of approaching &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;termination to all DLLs attached to the process. Other means of shutting down a process do not notify the attached DLLs. Note that when&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;a thread calls &lt;B&gt;ExitProcess&lt;/B&gt;, other threads of the process are terminated without an opportunity to execute any additional code (including &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;the thread termination code of attached DLLs).&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;PLEASE LEVEAGE THE WINDOWS SDK FOR MORE ON SAME.&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;===========================&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;Gaurav Anand&lt;/P&gt;
&lt;P minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/P&gt;&lt;o:p minmax_bound="true"&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2895363" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/When+a+new+process+is+created/default.aspx">When a new process is created</category></item><item><title>Few public links giving an insight on Windows Internal Architecture.</title><link>http://blogs.technet.com/ganand/archive/2008/01/26/few-public-links-giving-an-insight-on-windows-internal-architecture.aspx</link><pubDate>Sat, 26 Jan 2008 15:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2783526</guid><dc:creator>ganand</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ganand/comments/2783526.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2783526</wfw:commentRss><description>&lt;P&gt;&amp;nbsp;A few favorite links of mine on Windows Architecture..Hope you will like reading them..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="http://www.osronline.com/"&gt;&lt;FONT face=Calibri size=3&gt;http://www.osronline.com/&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;U&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: 'MS Shell Dlg'"&gt;&lt;A href="http://www.windowsitlibrary.com/Documents/Book.cfm?DocumentID=356"&gt;http://www.windowsitlibrary.com/Documents/Book.cfm?DocumentID=356&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://www.jps.at/dev/kurs/3-23.html"&gt;&lt;FONT face=Calibri size=3&gt;http://www.jps.at/dev/kurs/3-23.html&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://blogs.msdn.com/ntdebugging/archive/tags/Debugging/default.aspx"&gt;&lt;FONT face=Calibri size=3&gt;http://blogs.msdn.com/ntdebugging/archive/tags/Debugging/default.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://bcs.wiley.com/he-bcs/Books?action=resource&amp;amp;bcsId=2217&amp;amp;itemId=0471694665&amp;amp;resourceId=5004"&gt;&lt;FONT face=Calibri size=3&gt;http://bcs.wiley.com/he-bcs/Books?action=resource&amp;amp;bcsId=2217&amp;amp;itemId=0471694665&amp;amp;resourceId=5004&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri color=#1f497d size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://uninformed.org/index.cgi?v=8&amp;amp;a=5&amp;amp;p=1"&gt;&lt;FONT face=Calibri size=3&gt;http://uninformed.org/index.cgi?v=8&amp;amp;a=5&amp;amp;p=1&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;===========================&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;Gaurav Anand&lt;/P&gt;
&lt;P minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/P&gt;&lt;o:p minmax_bound="true"&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2783526" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/Windows+Internal+Architecture/default.aspx">Windows Internal Architecture</category></item><item><title>Internal structures of the Windows Registry</title><link>http://blogs.technet.com/ganand/archive/2008/01/05/internal-structures-of-the-windows-registry.aspx</link><pubDate>Sat, 05 Jan 2008 20:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2713339</guid><dc:creator>ganand</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/ganand/comments/2713339.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2713339</wfw:commentRss><description>&lt;P&gt;One of the best public document which talks about Registry internals is by Mark Russinovich and I will recommend same before you go ahead with this article. &lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/technet/archive/winntas/tips/winntmag/inreg.mspx?mfr=true"&gt;http://www.microsoft.com/technet/archive/winntas/tips/winntmag/inreg.mspx?mfr=true&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Make sure before proceeding ahead you go through Mark's Article.&lt;/P&gt;
&lt;P&gt;Ok..so now as you have read that article..you know how registry is broken into blocks,&amp;nbsp;bins, cells&amp;nbsp;and stored in memory or disk. &lt;/P&gt;
&lt;P&gt;&lt;IMG title="Cell directory and tables for regisrty" style="WIDTH: 524px; HEIGHT: 274px" height=229 alt="Cell directory and tables for regisrty" src="http://www.microsoft.com/library/media/1033/technet/images/archive/winntas/tips/winntmag/inreg02_big.gif" width=461 align=middle mce_src="http://www.microsoft.com/library/media/1033/technet/images/archive/winntas/tips/winntmag/inreg02_big.gif"&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now lets see the same via Live debugger and see the same structures.....&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; !reg hivelist&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-------------------------------------------------------------------------------------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| HiveAddr |Stable Length|Stable Map|Volatile Length|Volatile Map|MappedViews|PinnedViews|U(Cnt&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;)| BaseBlock | FileName&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-------------------------------------------------------------------------------------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e1008950 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp; | e10089b0 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e1008aec&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e1014000&amp;nbsp; | &amp;lt;NONAME&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;| e1019458 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 364000&amp;nbsp; | e1021000 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e10195f4&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 166&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;| e101e000&amp;nbsp; | SYSTEM&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e1392008 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b000&amp;nbsp; | e1392068 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e13921a4&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e1393000&amp;nbsp; | &amp;lt;NONAME&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e2081a80 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; f000&amp;nbsp; | e2081ae0 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e2081c1c&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e2063000&amp;nbsp; | emRoot\System32\Config\SECURITY&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e1626a80 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3b000&amp;nbsp; | e1626ae0 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e1626c1c&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e205b000&amp;nbsp; | temRoot\System32\Config\DEFAULT&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e1484008 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8000&amp;nbsp; | e1484068 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; 00000000&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e1669000&amp;nbsp; | \SystemRoot\System32\Config\SAM&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e162fa80 |&amp;nbsp;&amp;nbsp;&amp;nbsp; 1d9a000&amp;nbsp; | e1666000 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1d000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e162fc1c&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e1ff9000&amp;nbsp; | emRoot\System32\Config\SOFTWARE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e24cc830 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 35000&amp;nbsp; | e24cc890 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e24cc9cc&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e251d000&amp;nbsp; | tings\NetworkService\ntuser.dat&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e24c81a8 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp; | e24c8208 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; 00000000&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e2523000&amp;nbsp; | \Microsoft\Windows\UsrClass.dat&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e253d798 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 35000&amp;nbsp; | e253d7f8 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e253d934&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e254c000&amp;nbsp; | ettings\LocalService\ntuser.dat&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e2551008 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000&amp;nbsp; | e2551068 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; 00000000&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e2552000&amp;nbsp; | \Microsoft\Windows\UsrClass.dat&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e24fd0c0 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2cb000&amp;nbsp; | e2ff8000 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2000&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; e24fd25c&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 159&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e24f9000&amp;nbsp; |&amp;nbsp; and Settings\ganand\ntuser.dat&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;| e302e008 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9000&amp;nbsp; | e302e068 |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp; 00000000&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0| e309d000&amp;nbsp; | \Microsoft\Windows\UsrClass.dat&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-------------------------------------------------------------------------------------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;I dumped out the hive lists on my machine..as registry is maintained as hives and not what we see when we open regedit..thats only visual registry. we see the address of the system hive right now loaded in kernel mode as you can figure out from address. 
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Now we dumped the system hive &lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt nt!hhive e1019458&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;nt!HHIVE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x000 Signature&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xbee0bee0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x004 GetCellRoutine&amp;nbsp;&amp;nbsp; : 0x8092d3ef&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!HvpGetCellMapped+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x008 ReleaseCellRoutine : 0x8093db9d&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!HvpReleaseCellMapped+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x00c Allocate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x8091f642&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!CmpAllocate+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x010 Free&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x8091f68d&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!CmpFree+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x014 FileSetSize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x8091e608&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!CmpFileSetSize+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x018 FileWrite&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x8092798f&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!CmpFileWrite+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x01c FileRead&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x808f6320&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!CmpFileRead+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x020 FileFlush&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x80927615&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nt!CmpFileFlush+0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x024 BaseBlock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xe101e000 _HBASE_BLOCK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x028 DirtyVector&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;: _RTL_BITMAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x030 DirtyCount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x034 DirtyAlloc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x364&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x038 BaseBlockAlloc&amp;nbsp;&amp;nbsp; : 0x1000&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x03c Cluster&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x040 Flat&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0 ''&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x041 ReadOnly&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0 ''&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x042 Log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x1 ''&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x043 DirtyFlag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x1 ''&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x044 HiveFlags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x048 LogSize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x400&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x04c RefreshCount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x050 StorageTypeCount : 2&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x054 Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x058 Storage&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : [2] _DUAL&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt nt!cmhive e1019458&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;nt!CMHIVE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x000 Hive&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _HHIVE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2d0 FileHandles&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : [3] 0x8000031c&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;--------------------------------------handles to the hive&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2dc NotifyList&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _LIST_ENTRY [ 0xe139b678 - 0x0 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2e4 HiveList&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _LIST_ENTRY [ 0xe13922ec - 0xe1008c34 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2ec HiveLock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _EX_PUSH_LOCK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2f0 ViewLock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x89b8f1a8 _KGUARDED_MUTEX&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2f4 WriterLock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _EX_PUSH_LOCK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2f8 FlusherLock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _EX_PUSH_LOCK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x2fc SecurityLock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _EX_PUSH_LOCK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x300 LRUViewListHead&amp;nbsp; : _LIST_ENTRY [ 0xe34b4598 - 0xe359d690 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x308 PinViewListHead&amp;nbsp; : _LIST_ENTRY [ 0xe1019760 - 0xe1019760 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x310 FileObject&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x89835df8 _FILE_OBJECT&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;--------------------address of the file object&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x314 FileFullPath&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _UNICODE_STRING "\Device\HarddiskVolume1\WINNT\system32\config\system"&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;------------------path on disk&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x31c FileUserName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : _UNICODE_STRING ""&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x324 MappedViews&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xa6&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x326 PinnedViews&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x328 UseCount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x32c SecurityCount&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x5b&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x330 SecurityCacheSize : 0x60&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x334 SecurityHitHint&amp;nbsp; : 13&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x338 SecurityCache&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xe1391d00 _CM_KEY_SECURITY_CACHE_ENTRY&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x33c SecurityHash&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : [64] _LIST_ENTRY [ 0xe1020138 - 0xe1020138 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x53c UnloadEvent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x540 RootKcb&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x544 Frozen&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0 ''&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x548 UnloadWorkItem&amp;nbsp;&amp;nbsp; : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x54c GrowOnlyMode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0 ''&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x550 GrowOffset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x554 KcbConvertListHead : _LIST_ENTRY [ 0xe10199ac - 0xe10199ac ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x55c KnodeConvertListHead : _LIST_ENTRY [ 0xe10199b4 - 0xe10199b4 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x564 CellRemapArray&amp;nbsp;&amp;nbsp; : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x568 Flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x56c TrustClassEntry&amp;nbsp; : _LIST_ENTRY [ 0xe10199c4 - 0xe10199c4 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x574 FlushCount&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x5a1&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x578 CreatorOwner&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Now lets go to the storage...&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt nt!hhive e1019458 storage.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;nt!HHIVE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Cannot find specified field members.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt nt!hhive e1019458 Storage.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;nt!HHIVE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x050 StorageTypeCount : 2&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x058 Storage&amp;nbsp; : [2]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +0x000 Length&amp;nbsp;&amp;nbsp; : 0x364000&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;+0x004 Map&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xe1021000 _HMAP_DIRECTORY&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;---map directory used by configuration manager..this is equivalent to PDE in terms of memory management&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +0x008 SmallDir : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +0x00c Guard&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xffffffff&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +0x010 FreeDisplay : [24] _FREE_DISPLAY&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +0x130 FreeSummary : 0x100a5f&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;+0x134 FreeBins : _LIST_ENTRY [ 0xe10195e4 - 0xe10195e4 ]&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;---free bins for this hive&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt 0xe1021000 _&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;HMAP_DIRECTORY&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x000 Directory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : [1024] 0xe1022000 _HMAP_TABLE&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;---so first we went to hive directory address and from there we figured out hive table address and from there we got block offset&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;. In this case cell index in configuration manager&amp;nbsp;is equivalent to PFN in case of memory manager.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt&amp;nbsp; 0xe1022000 _&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;HMAP_TABLE&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x000 Table &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: [512] _HMAP_ENTRY&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; dt 0xe1021000 _&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;HMAP_ENTRY&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;+0x000 BlockAddress&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xe1022000&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;-----------------&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;&amp;nbsp;&amp;nbsp; +0x004 BinAddress&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0xe1024000&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;---------------------------&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x008 CmView&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : (null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; +0x00c MemAlloc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;So now we have reached to the block and inside the block we have reached to the bin….from here we will go to that cell…&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Now just to prove that we are on right track..let me achieve the same via debugger ….for that we have !reg cellindex &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; !reg baseblock e1019458&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;FileName :&amp;nbsp; SYSTEM&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Signature:&amp;nbsp; HBASE_BLOCK_SIGNATURE&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Sequence1:&amp;nbsp; 1a0f&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Sequence2:&amp;nbsp; 1a0f&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;TimeStamp:&amp;nbsp; 1c84fa5 ac4d292c&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Major&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp; 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Minor&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp; 5&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp; HFILE_TYPE_PRIMARY&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Format&amp;nbsp;&amp;nbsp; :&amp;nbsp; HBASE_FORMAT_MEMORY&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;RootCell :&amp;nbsp; 20&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Length&amp;nbsp;&amp;nbsp; :&amp;nbsp; 364000&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Cluster&amp;nbsp; :&amp;nbsp; 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;CheckSum :&amp;nbsp; 346bbc65&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;0: kd&amp;gt; !reg cellindex e1019458 20&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Map = e1021000 Type = 0 Table = 0 Block = 0 Offset = 20&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;MapTable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = e1022000&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;pcell:&amp;nbsp; de441024&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;--------------this is the address of the cell&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2"&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;==========&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;Gaurav Anand&lt;/P&gt;
&lt;P minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/P&gt;&lt;o:p minmax_bound="true"&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2713339" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/Internal+structures+of+the+Windows+Registry/default.aspx">Internal structures of the Windows Registry</category></item><item><title>Windows Vista Address Space Load Randomization - The way vista loads DLL's</title><link>http://blogs.technet.com/ganand/archive/2008/01/04/windows-vista-address-space-load-randomization-the-way-vista-loads-dll-s.aspx</link><pubDate>Fri, 04 Jan 2008 23:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2710354</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/2710354.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2710354</wfw:commentRss><description>&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;
&lt;P&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Lets talk about what is a Dll and why we need it first&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt; ... &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;dynamic-link library (DLL) is shared code and data that an application can load and call at run time. A DLL typically exports a set of routines for applications to use and contains other routines for internal use. This technique enables code reuse by allowing multiple applications to share common functionality in a library and load it on demand. Advantages of using DLLs include reduced code footprint, lower memory utilization due to single-copy-sharing and much more.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;The original purpose for DLLs was saving both disk space and memory required for Windows applications by sharing a single library between two loaded programs. In a conventional non-shared library, sections of code are simply added to the calling program when its executable is built at the linking phase; if two programs use the same routine, the code has to be included in both. Instead, code which multiple applications share can be separated into a DLL which only exists as a single, separate file, loaded only once into memory during usage. Extensive use of DLLs allowed early versions of Windows to work under tight memory conditions, in an environment in which all programs shared the same address space,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;How these Dll's and exe files are loaded?&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;This is done by Loader. Loader&amp;nbsp;is the part of an operating system that is responsible for loading programs from executables (i.e., executable files) into memory, preparing them for execution and then executing them. The loader is usually a part of the&amp;nbsp;Operating system's kernel&amp;nbsp;and usually is loaded at system boot time and stays in memory until the system is rebooted, shut down, or powered off.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;A href="http://support.microsoft.com/kb/100635" mce_href="http://support.microsoft.com/kb/100635"&gt;http://support.microsoft.com/kb/100635&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Now what is the change in vista and what is this Address space load randomization?&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;Let’s&amp;nbsp;see it practically&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-themecolor: dark2; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;I attached debugger with msiexec.exe and&amp;nbsp;we see the loaded modules below.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; COLOR: #1f497d; mso-themecolor: dark2"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Before reboot In windows vista&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;CommandLine: C:\Windows\System32\msiexec.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Symbol search path is: SRV*C:\WINDOWS\Symbols*\\symbols\symbols&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Executable search path is: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;00ab0000 00ac4000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; msiexec.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;772c0000 773de000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; ntdll.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;771e0000 772b8000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\Windows\system32\kernel32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;768e0000 7699f000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\Windows\system32\ADVAPI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;769a0000 76a63000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\Windows\system32\RPCRT4.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;76ed0000 76f6e000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\Windows\system32\USER32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 76a70000 76abb000&amp;nbsp;&amp;nbsp; C:\Windows\system32\GDI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 76f70000 7701a000&amp;nbsp;&amp;nbsp; C:\Windows\system32\msvcrt.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 76790000 768d4000&amp;nbsp;&amp;nbsp; C:\Windows\system32\ole32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;72950000 72b54000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\Windows\System32\msi.dll&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;-----------------------------In legacy OS scenario …if I want to write a bad code…or want to modify something on your machine..i know that msi.dll is going to load here every time + even if I am not going to use this dll &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;later, I m going to keep this address for msi.dll once it is loaded but in vista due to address space load randomization, I will unload/reload it later at some other address…and when I am not using this dll..i need not to reserve the address for it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;BENEFIT:----the same address can be used by next dll which is going to load… creating larger regions of free memory for contiguous memory allocations, reducing the number of page tables the memory manager allocates to keep track of address-space layout.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;After reboot&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;=========&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Executable search path is: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 005b0000 005c4000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;msiexec.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77540000 7765e000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ntdll.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 763e0000 764b8000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\kernel32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 776c0000 7777f000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\ADVAPI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 75ed0000 75f93000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\RPCRT4.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 769d0000 76a6e000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\USER32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 764c0000 7650b000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\GDI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 767c0000 7686a000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\msvcrt.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 76290000 763d4000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\system32\ole32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: lime; COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-highlight: lime"&gt;ModLoad: 72c40000 72e44000&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;C:\Windows\System32\msi.dll-----------------------------------address have changed--dynamically loaded&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-bidi-theme-font: minor-bidi; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #17365d; FONT-FAMILY: 'Microsoft Sans Serif','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-themecolor: text2; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes; mso-themeshade: 191"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;Later I did similar test on win2k3 machine for notepad.exe&amp;nbsp;and we see dll load at same address even after reboot&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Before reboot&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Executable search path is: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 01000000 01014000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\notepad.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 7c800000 7c8c0000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\ntdll.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77e40000 77f42000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\kernel32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 762b0000 762f9000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\comdlg32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77ba0000 77bfa000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\msvcrt.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77da0000 77df2000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\SHLWAPI.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77c00000 77c48000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\GDI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77380000 77411000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\USER32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77f50000 77feb000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\ADVAPI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77c50000 77cef000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\RPCRT4.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 76f50000 76f63000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\Secur32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 77420000 77523000&amp;nbsp;&amp;nbsp; C:\WINNT\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.3959_x-ww_D8713E55\COMCTL32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 7c8d0000 7d0cf000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\SHELL32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 73070000 73097000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\WINSPOOL.DRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 4b3c0000 4b410000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\MSCTF.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="BACKGROUND: red; COLOR: #1f497d; mso-highlight: red"&gt;ModLoad: 71b70000 71ba6000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\UxTheme.dll&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;After reboot&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;==============&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Executable search path is: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;01000000 01014000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\notepad.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;7c800000 7c8c0000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\ntdll.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;77e40000 77f42000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\kernel32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;762b0000 762f9000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\comdlg32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;77ba0000 77bfa000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\msvcrt.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;: 77da0000 77df2000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\SHLWAPI.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;77c00000 77c48000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\GDI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;: 77380000 77411000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\USER32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;77f50000 77feb000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\ADVAPI32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;77c50000 77cef000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\RPCRT4.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;76f50000 76f63000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\system32\Secur32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: &lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;77420000 77523000&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; C:\WINNT\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.3959_x-ww_D8713E55\COMCTL32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 7c8d0000 7d0cf000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\SHELL32.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 73070000 73097000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\WINSPOOL.DRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 4b3c0000 4b410000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\MSCTF.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ModLoad: 71b70000 71ba6000&amp;nbsp;&amp;nbsp; C:\WINNT\system32\UxTheme.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;now i wanted to see that whats the change in msi.dll on win2k3 and vista so i dumped both of them using following command...i knew that there is a new flag on vista msi.dll ......&lt;SPAN style="FONT-SIZE: 11pt; BACKGROUND: fuchsia; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-highlight: fuchsia; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;dynamic relocation flag in the header of the msi.dll...but i guess i was not able to see it because link.exe that i was using was not from vista SDK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;o:p&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;STRONG&gt;C:\Users\ganand\Desktop\internals\TOOLS&amp;gt;link.exe -dump -headers c:\windows\system32\msi.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Microsoft (R) COFF/PE Dumper Version 7.10.2179&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Copyright (C) Microsoft Corporation.&amp;nbsp; All rights reserved.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Dump of file c:\windows\system32\msi.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;PE signature found&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;File Type: DLL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;FILE HEADER VALUES&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14C machine (x86)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 number of sections&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4549BD89 time date stamp Thu Nov 02 15:12:33 2006&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;0 file pointer to symbol table&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 number of symbols&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E0 size of optional header&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2102 characteristics&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Executable&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32 bit word machine&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DLL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;OPTIONAL HEADER VALUES&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10B magic # (PE32)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.00 linker version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1DAE00 size of code&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 25200 size of initialized data&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 size of uninitialized data&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7B2D entry point (751F7B2D)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 12pt; LINE-HEIGHT: 18pt"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 base of code&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;For more information refer to &lt;A href="http://www.microsoft.com/technet/technetmag/issues/2007/04/VistaKernel/default.aspx" mce_href="http://www.microsoft.com/technet/technetmag/issues/2007/04/VistaKernel/default.aspx"&gt;http://www.microsoft.com/technet/technetmag/issues/2007/04/VistaKernel/default.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;===============================&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;Gaurav Anand&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" minmax_bound="true"&gt;&lt;SPAN class=a minmax_bound="true"&gt;&lt;FONT color=#008000 minmax_bound="true"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2710354" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/Windows+Vista+Address+Space+Load+Randomization/default.aspx">Windows Vista Address Space Load Randomization</category></item><item><title>How to isolate a service in its own scvhost.exe </title><link>http://blogs.technet.com/ganand/archive/2007/12/23/how-to-isolate-a-service-in-its-own-scvhost-exe.aspx</link><pubDate>Sun, 23 Dec 2007 17:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2673035</guid><dc:creator>ganand</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/ganand/comments/2673035.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2673035</wfw:commentRss><description>&lt;P&gt;&lt;SPAN class=a&gt;&lt;FONT color=#008000&gt;This is a very good public link to read about service control manager internals and how to manage services. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=a&gt;&lt;SPAN class=a&gt;&lt;FONT color=#008000&gt;download.&lt;B&gt;microsoft&lt;/B&gt;.com/download/f/&lt;WBR&gt;3/9/f3900e1e-a45c-45a4-b716-740e553e1f62/SPTCF_SYS.doc&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=a&gt;&lt;SPAN class=a&gt;Description of svchost.exe &lt;A href="http://support.microsoft.com/kb/314056"&gt;http://support.microsoft.com/kb/314056&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN class=a&gt;&lt;SPAN class=a&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;C:\Documents and Settings\ganand&amp;gt;tasklist /svc&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;As you see right now my bits service is running under svchost along with other services…&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Image Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PID Services&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;========================= ======== ============================================&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;System Idle Process&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;System&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;smss.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 312 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;csrss.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 360 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;winlogon.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 384 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;services.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 432 Eventlog, PlugPlay&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;lsass.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 444 HTTPFilter, Netlogon, PolicyAgent,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProtectedStorage, SamSs&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 632 DcomLaunch&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 704 RpcSs&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 780 Dhcp, Dnscache&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 828 Alerter, LmHosts, W32Time,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WinHttpAutoProxySvc&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 848 AeLookupSvc, AudioSrv, BITS, CryptSvc,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dmserver, EventSystem, helpsvc,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; lanmanserver, lanmanworkstation, Netman,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Nla, RasMan, Schedule, seclogon, SENS,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ShellHWDetection, TrkWks, winmgmt,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: yellow; mso-highlight: yellow"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; wuauserv, WZCSVC&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;spoolsv.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1024 Spooler&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;msdtc.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1052 MSDTC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1172 ERSvc&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;FwcAgent.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1216 FwcAgent&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;inetinfo.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1280 IISADMIN&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;InoRpc.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;1332 InoRPC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;InoRT.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1384 InoRT&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;InoTask.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1420 InoTask&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1528 Pml Driver HPZ12&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1552 RemoteRegistry&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;SMAgent.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1584 SoundMAX Agent Service (default)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1652 TermService&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;vmh.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1824 vmh&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;searchindexer.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1912 WSearch&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;CcmExec.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2052 CcmExec&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;vssrvc.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2160 Virtual Server&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2180 W3SVC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2636 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2716 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;explorer.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3276 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;GrooveMonitor.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3560 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;igfxtray.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3568 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;hkcmd.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3580 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;SMTray.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3588 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;VM_STI.EXE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3596 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3780 TapiSrv&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;ctfmon.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3768 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;communicator.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3856 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Skype.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4076 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;FwcMgmt.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2644 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;WindowsSearch.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2672 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;ONENOTEM.EXE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2864 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3260 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;VisualKB.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3720 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;dexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1660 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;hh.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3020 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;hh.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3864 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1316 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;dllhost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3204 COMSysApp&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;OUTLOOK.EXE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3904 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;AcroRd32.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 792 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4072 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3944 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2944 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;cmd.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2084 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;regedit.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3916 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 816 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;tasklist.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3492 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;for troubleshooting purposes if we want to isolate any one service running under svchost---we can do that using sc config&amp;nbsp; bits type= own&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;o:p&gt;&lt;SPAN style="TEXT-DECORATION: none"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;now as you see bits is running under its own scvhost&amp;nbsp; process&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;C:\Documents and Settings\ganand&amp;gt;tasklist /svc&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Image Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PID Services&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;========================= ======== ============================================&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;System Idle Process&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;System&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;smss.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 312 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;csrss.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 360 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;winlogon.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 384 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;services.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 432 Eventlog, PlugPlay&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;lsass.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 444 HTTPFilter, Netlogon, PolicyAgent,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProtectedStorage, SamSs&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 632 DcomLaunch&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 704 RpcSs&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 780 Dhcp, Dnscache&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 828 Alerter, LmHosts, W32Time&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 848 AeLookupSvc, AudioSrv, CryptSvc, dmserver,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EventSystem, helpsvc, lanmanserver,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; lanmanworkstation, Netman, Nla, RasMan,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Schedule, seclogon, SENS, ShellHWDetection,&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;TrkWks, winmgmt, wuauserv, WZCSVC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;spoolsv.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1024 Spooler&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;msdtc.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1052 MSDTC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1172 ERSvc&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;FwcAgent.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1216 FwcAgent&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;inetinfo.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1280 IISADMIN&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;InoRpc.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332 InoRPC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;InoRT.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1384 InoRT&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;InoTask.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1420 InoTask&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1528 Pml Driver HPZ12&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1552 RemoteRegistry&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;SMAgent.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1584 SoundMAX Agent Service (default)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1652 TermService&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;vmh.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1824 vmh&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;searchindexer.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1912 WSearch&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;CcmExec.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2052 CcmExec&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;vssrvc.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2160 Virtual Server&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2180 W3SVC&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2636 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2716 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;explorer.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3276 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;GrooveMonitor.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3560 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;igfxtray.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3568 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;hkcmd.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3580 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;SMTray.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3588 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;VM_STI.EXE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3596 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3780 TapiSrv&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;ctfmon.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3768 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;communicator.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;3856 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Skype.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4076 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;FwcMgmt.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2644 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;WindowsSearch.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2672 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;ONENOTEM.EXE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2864 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3260 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;VisualKB.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3720 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;dexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1660 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;hh.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3020 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;hh.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3864 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1316 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;dllhost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3204 COMSysApp&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;OUTLOOK.EXE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3904 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;AcroRd32.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 792 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4072 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3944 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;iexplore.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2944 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;cmd.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2084 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;regedit.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3916 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;wmiprvse.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;816 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="BACKGROUND: red; mso-highlight: red"&gt;&lt;FONT face=Calibri size=3&gt;svchost.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1780 BITS&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;tasklist.exe&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 608 N/A&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=a&gt;&lt;FONT color=#008000&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN" minmax_bound="true"&gt;&lt;FONT size=3 minmax_bound="true"&gt;&lt;FONT face=Calibri minmax_bound="true"&gt;Gaurav Anand&lt;/P&gt;
&lt;P minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/P&gt;&lt;o:p minmax_bound="true"&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2673035" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ganand/archive/tags/services/default.aspx">services</category></item><item><title>How do transition from user mode to kernel mode takes place</title><link>http://blogs.technet.com/ganand/archive/2007/12/23/how-do-transition-from-user-mode-to-kernel-mode-takes-place.aspx</link><pubDate>Sun, 23 Dec 2007 17:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2672855</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/2672855.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2672855</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;NTDLL is used to call into the operating system, which is (generally) in the address range (0x80000000-0xFFFFFFFF). &amp;nbsp;The operating system addresses are not accessible in user-mode; therefore a special protected mechanism (using a CPU instruction which is sysenter..earlier it used to be Int 2e) is used to control the transition from user-mode to kernel-mode. NTDLL loads the system service number into the EAX register, then copies the address the processor-specific kernel-mode transition code on the Kernel-User shared page (0x7FFE0000 + 0x300) into the EDX register, then calls through the EDX register. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;MOV &amp;nbsp; &amp;nbsp;EAX, Service Number &lt;BR&gt;MOV &amp;nbsp; &amp;nbsp;EDX, MM_SHARED_USER_DATA_VA + UsSystemCall &lt;BR&gt;CALL &amp;nbsp; &amp;nbsp;EDX &lt;BR&gt;RET &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;n &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The processor-specific kernel-mode transition code depends upon whether the CPU is Intel, AMD or Pentium2 and earlier (Win2K and earlier). &amp;nbsp;INT 2E vectors through the IDT (entry number 0x2E), while &lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;SYSCALL and SYSENTER vector through model-specific registers that are initialized at system boot time.&lt;/SPAN&gt; –these are better explained at &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;U&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: 'MS Shell Dlg','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;http://www.codeguru.com/Cpp/W-P/system/devicedriverdevelopment/article.php/c8223/&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="BACKGROUND: red; COLOR: black; mso-ansi-language: EN-IN; mso-highlight: red"&gt;&lt;FONT face=Calibri size=3&gt;Win2K and earlier: &lt;BR&gt;LEA &amp;nbsp; &amp;nbsp;EDX, [ESP+4] &lt;BR&gt;INT &amp;nbsp; &amp;nbsp;2E &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;; Ends up calling KiSystemService&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;BR&gt;RET &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;WinXP and later (Intel): &lt;BR&gt;MOV &amp;nbsp; &amp;nbsp;EDX, ESP &lt;BR&gt;&lt;SPAN style="BACKGROUND: lime; mso-highlight: lime"&gt;SYSENTER &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;; Ends up calling KiFastCallEntry,&lt;/SPAN&gt; which then calls &lt;BR&gt;KiSystemService &lt;BR&gt;RET &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;AMD K6 and later &lt;BR&gt;MOV &amp;nbsp; &amp;nbsp;EDX, ESP &lt;BR&gt;SYSCALL &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;; Ends up calling KiSystemCall, which then calls &lt;BR&gt;KiSystemService &lt;BR&gt;RET &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;KiSystemService uses the system service number(in EAX) &amp;nbsp;as an index into the system service dispatch table, which contains the address of the routine in the operating system to call. &amp;nbsp;This prevents an application from calling any random address in the system; an application can only call those routines that are listed in the system service dispatch table. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;During the initialization of NTOSKRNL, it creates a function table, hereafter referred to as the System Service Dispatch Table (SSDT), for different services provided by NTOSKRNL. Each entry in the table contains the address of the function to be executed for a given service ID. The handler looks up this table based on the service ID passed in EAX register and calls the corresponding system service. The code for each function resides in the kernel. Similarly, another table called the System Service Parameter Table [SSPT]) provides the handler with the number of parameter bytes to expect from a particular service. The handler refers to the first entry in the Service Descriptor Table for service IDs less than 0x1000 and refers to the second entry of the table for service IDs greater than or equal to 0x1000. The handler checks the validity of service IDs. If a service ID is valid, the handler extracts the addresses of the SSDT and SSPT. The handler copies the number of bytes (equal to the total number of bytes of the parameter list) described by the SSPT for the service–from user-mode stack to kernel-mode stack–and then calls the function pointed to by the SSDT for that service.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN lang=EN-IN style="COLOR: black; mso-ansi-language: EN-IN"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;
&lt;P minmax_bound="true"&gt;Gaurav Anand&lt;/P&gt;
&lt;P minmax_bound="true"&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/P&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2672855" width="1" height="1"&gt;</description></item><item><title>Dumping out notepad.exe and ntdll.dll</title><link>http://blogs.technet.com/ganand/archive/2007/12/23/dumping-out-notepad-exe-and-ntdll-dll.aspx</link><pubDate>Sun, 23 Dec 2007 16:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2672848</guid><dc:creator>ganand</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ganand/comments/2672848.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2672848</wfw:commentRss><description>&lt;P&gt;&lt;EM&gt;&lt;U&gt;&amp;nbsp;I tried to dump out the headers and data sections of notepad.exe and ntdll.dll to figure out what are their dependents and what are the functions and services provided by ntdll.dll along with service numbers which are used in kernel mode.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Microsoft (R) COFF/PE Dumper Version 7.10.2179&lt;BR&gt;Copyright (C) Microsoft Corporation.&amp;nbsp; All rights reserved.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Dump of file c:\windows\system32\notepad.exe---&lt;EM&gt;&lt;U&gt;this is what you see when you dump the notepad.exe using link tool from sdk..these are all the dll's that notepad.exe may use and use along with all their functions.&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;File Type: EXECUTABLE IMAGE&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Section contains the following imports:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ADVAPI32.dll---&lt;U&gt;&lt;EM&gt;these are the functions of advapi32.dll that notepad.exe image uses.&lt;BR&gt;&lt;/EM&gt;&lt;/U&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001000 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1008DC8 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77CD632E&amp;nbsp;&amp;nbsp;&amp;nbsp; 268 RegQueryValueExW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77CD64CC&amp;nbsp;&amp;nbsp;&amp;nbsp; 22A RegCloseKey&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77CA8229&amp;nbsp;&amp;nbsp;&amp;nbsp; 236 RegCreateKeyW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77CBE8F0&amp;nbsp;&amp;nbsp;&amp;nbsp; 17A IsTextUnicode&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77CC802D&amp;nbsp;&amp;nbsp;&amp;nbsp; 278 RegSetValueExW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; KERNEL32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001018 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1008DE0 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E1D22A&amp;nbsp;&amp;nbsp;&amp;nbsp; 1D0 GetFileInformationByHandle&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E5280F&amp;nbsp;&amp;nbsp;&amp;nbsp; 12B FindNLSString&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2068A&amp;nbsp;&amp;nbsp;&amp;nbsp; 285 GlobalAlloc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2087D&amp;nbsp;&amp;nbsp;&amp;nbsp; 297 GlobalUnlock&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E207CB&amp;nbsp;&amp;nbsp;&amp;nbsp; 290 GlobalLock&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2444D&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7C CreateFileMappingW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E45CBB&amp;nbsp;&amp;nbsp;&amp;nbsp; 1B0 GetDateFormatW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E1EDBA&amp;nbsp;&amp;nbsp;&amp;nbsp; 1E7 GetLocalTime&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E23672&amp;nbsp;&amp;nbsp;&amp;nbsp; 303 LocalUnlock&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2737E&amp;nbsp;&amp;nbsp;&amp;nbsp; 30A MapViewOfFile&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E442A7&amp;nbsp;&amp;nbsp;&amp;nbsp; 31A MultiByteToWideChar&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E48DB6&amp;nbsp;&amp;nbsp;&amp;nbsp; 441 UnmapViewOfFile&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47CEE&amp;nbsp;&amp;nbsp;&amp;nbsp; 300 LocalReAlloc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E29BEE&amp;nbsp;&amp;nbsp;&amp;nbsp; 152 GetACP&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E1AD23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C3 DeleteFileW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E1644C&amp;nbsp;&amp;nbsp;&amp;nbsp; 3CD SetEndOfFile&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2373F&amp;nbsp;&amp;nbsp;&amp;nbsp; 2FF LocalLock&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E45358&amp;nbsp;&amp;nbsp;&amp;nbsp; 148 FormatMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E48A32&amp;nbsp;&amp;nbsp;&amp;nbsp; 47A WideCharToMultiByte&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47940&amp;nbsp;&amp;nbsp;&amp;nbsp; 3EC SetLastError&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E483D2&amp;nbsp;&amp;nbsp;&amp;nbsp; 48D WriteFile&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E48129&amp;nbsp;&amp;nbsp;&amp;nbsp; 1E6 GetLastError&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E23842&amp;nbsp;&amp;nbsp;&amp;nbsp; 302 LocalSize&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4464E&amp;nbsp;&amp;nbsp;&amp;nbsp; 1DF GetFullPathNameW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E473C0&amp;nbsp;&amp;nbsp;&amp;nbsp; 319 MulDiv&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2AA46&amp;nbsp;&amp;nbsp;&amp;nbsp; 170 GetCommandLineW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2D36B&amp;nbsp;&amp;nbsp;&amp;nbsp; 2A5 HeapSetInformation&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47B0D&amp;nbsp;&amp;nbsp;&amp;nbsp; 1AA GetCurrentProcessId&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E5614A&amp;nbsp;&amp;nbsp;&amp;nbsp; 146 FoldStringW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4337B&amp;nbsp;&amp;nbsp;&amp;nbsp; 4AA lstrcmpW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E449CA&amp;nbsp;&amp;nbsp;&amp;nbsp; 1CE GetFileAttributesW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E44E2A&amp;nbsp;&amp;nbsp;&amp;nbsp; 124 FindFirstFileW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E44EBF&amp;nbsp;&amp;nbsp;&amp;nbsp; 119 FindClose&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4B29A&amp;nbsp;&amp;nbsp;&amp;nbsp; 26A GetTimeFormatW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E29145&amp;nbsp;&amp;nbsp;&amp;nbsp; 1A9 GetCurrentProcess&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E018E0&amp;nbsp;&amp;nbsp;&amp;nbsp; 42D TerminateProcess&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E01890&amp;nbsp;&amp;nbsp;&amp;nbsp; 24F GetSystemTimeAsFileTime&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47A1D&amp;nbsp;&amp;nbsp;&amp;nbsp; 1AD GetCurrentThreadId&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47652&amp;nbsp;&amp;nbsp;&amp;nbsp; 266 GetTickCount&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E482B0&amp;nbsp;&amp;nbsp;&amp;nbsp; 354 QueryPerformanceCounter&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4427B&amp;nbsp;&amp;nbsp;&amp;nbsp; 1F6 GetModuleHandleA&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E2D187&amp;nbsp;&amp;nbsp;&amp;nbsp; 415 SetUnhandledExceptionFilter&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E019B8&amp;nbsp;&amp;nbsp;&amp;nbsp; 239 GetStartupInfoA&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4739C&amp;nbsp;&amp;nbsp;&amp;nbsp; 2BA InterlockedCompareExchange&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E01D91&amp;nbsp;&amp;nbsp;&amp;nbsp; 421 Sleep&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47388&amp;nbsp;&amp;nbsp;&amp;nbsp; 2BD InterlockedExchange&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E49D35&amp;nbsp;&amp;nbsp;&amp;nbsp; 4B6 lstrlenW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E44801&amp;nbsp;&amp;nbsp;&amp;nbsp; 1EA GetLocaleInfoW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E20725&amp;nbsp;&amp;nbsp;&amp;nbsp; 28C GlobalFree&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E44572&amp;nbsp;&amp;nbsp;&amp;nbsp; 4AD lstrcmpiW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E44A49&amp;nbsp;&amp;nbsp;&amp;nbsp; 3D2 SetErrorMode&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4866C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7F CreateFileW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E484CC&amp;nbsp;&amp;nbsp;&amp;nbsp; 368 ReadFile&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47A2C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43 CloseHandle&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E43B21&amp;nbsp;&amp;nbsp;&amp;nbsp; 2F9 LocalAlloc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47374&amp;nbsp;&amp;nbsp;&amp;nbsp; 2BC InterlockedDecrement&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E43A9D&amp;nbsp;&amp;nbsp;&amp;nbsp; 2FD LocalFree&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E47360&amp;nbsp;&amp;nbsp;&amp;nbsp; 2C0 InterlockedIncrement&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E4D9BE&amp;nbsp;&amp;nbsp;&amp;nbsp; 270 GetUserDefaultUILanguage&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77E95984&amp;nbsp;&amp;nbsp;&amp;nbsp; 43E UnhandledExceptionFilter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GDI32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100110C Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1008ED4 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B75FC0&amp;nbsp;&amp;nbsp;&amp;nbsp; 25E SelectObject&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B781E7&amp;nbsp;&amp;nbsp;&amp;nbsp; 27B SetMapMode&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B812F2&amp;nbsp;&amp;nbsp;&amp;nbsp; 28F SetViewportExtEx&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B81EA7&amp;nbsp;&amp;nbsp;&amp;nbsp; 293 SetWindowExtEx&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B78600&amp;nbsp;&amp;nbsp;&amp;nbsp; 21B LPtoDP&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B76390&amp;nbsp;&amp;nbsp;&amp;nbsp; 266 SetBkMode&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B7720B&amp;nbsp;&amp;nbsp;&amp;nbsp; 20D GetTextMetricsW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B870AC&amp;nbsp;&amp;nbsp;&amp;nbsp; 260 SetAbortProc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77BA3C3B&amp;nbsp;&amp;nbsp;&amp;nbsp; 297 StartDocW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77BA31C8&amp;nbsp;&amp;nbsp;&amp;nbsp; 299 StartPage&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B87101&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DD EndPage&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77BA2D8C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 AbortDoc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77BA30DD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DB EndDoc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B769A5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CD DeleteDC&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B81550&amp;nbsp;&amp;nbsp;&amp;nbsp; 2A0 TextOutW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B7ABB5&amp;nbsp;&amp;nbsp;&amp;nbsp; 205 GetTextExtentPoint32W&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B7BE99&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 CreateDCW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B7A788&amp;nbsp;&amp;nbsp;&amp;nbsp; 20B GetTextFaceW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B86C04&amp;nbsp;&amp;nbsp;&amp;nbsp; 113 EnumFontsW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B759F0&amp;nbsp;&amp;nbsp;&amp;nbsp; 1F4 GetStockObject&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B765B6&amp;nbsp;&amp;nbsp;&amp;nbsp; 1E4 GetObjectW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B75EA6&amp;nbsp;&amp;nbsp;&amp;nbsp; 1B5 GetDeviceCaps&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B7AE17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3E CreateFontIndirectW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77B75A1F&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D0 DeleteObject&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; USER32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001170 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1008F38 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7B38E&amp;nbsp;&amp;nbsp;&amp;nbsp; 10D GetClientRect&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D8380D&amp;nbsp;&amp;nbsp;&amp;nbsp; 270 SetCursor&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7B8EC&amp;nbsp;&amp;nbsp;&amp;nbsp; 24C ReleaseDC&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7B8D8&amp;nbsp;&amp;nbsp;&amp;nbsp; 11A GetDC&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D9129F&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A6 DialogBoxParamW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D732D3&amp;nbsp;&amp;nbsp;&amp;nbsp; 266 SetActiveWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D78781&amp;nbsp;&amp;nbsp;&amp;nbsp; 132 GetKeyboardLayout&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D721DF&amp;nbsp;&amp;nbsp;&amp;nbsp; 220 PostQuitMessage&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D81D90&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 96 DefWindowProcW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7965E&amp;nbsp;&amp;nbsp;&amp;nbsp; 125 GetForegroundWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7A5A6&amp;nbsp;&amp;nbsp;&amp;nbsp; 1BD IsIconic&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D78C26&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A0 DestroyWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D68A4E&amp;nbsp;&amp;nbsp;&amp;nbsp; 1F7 MessageBeep&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D67B2A&amp;nbsp;&amp;nbsp;&amp;nbsp; 187 GetWindowPlacement&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6D382&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3A CharUpperW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D78671&amp;nbsp;&amp;nbsp;&amp;nbsp; 235 RegisterClassExW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6D3C5&amp;nbsp;&amp;nbsp;&amp;nbsp; 1D9 LoadImageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7862C&amp;nbsp;&amp;nbsp;&amp;nbsp; 1D5 LoadCursorW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D8244A&amp;nbsp;&amp;nbsp;&amp;nbsp; 2A5 SetWindowLongW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D69DE5&amp;nbsp;&amp;nbsp;&amp;nbsp; 1CF LoadAcceleratorsW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D719F6&amp;nbsp;&amp;nbsp;&amp;nbsp; 16E GetSystemMenu&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D674D9&amp;nbsp;&amp;nbsp;&amp;nbsp; 2A6 SetWindowPlacement&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D785F0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 68 CreateWindowExW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6F801&amp;nbsp;&amp;nbsp;&amp;nbsp; 24A RegisterWindowMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6CBB7&amp;nbsp;&amp;nbsp;&amp;nbsp; 28B SetProcessDPIAware&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D9D86E&amp;nbsp;&amp;nbsp;&amp;nbsp; 294 SetScrollPos&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D78B84&amp;nbsp;&amp;nbsp;&amp;nbsp; 2B8 ShowWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D8250E&amp;nbsp;&amp;nbsp;&amp;nbsp; 182 GetWindowLongW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D825BC&amp;nbsp;&amp;nbsp;&amp;nbsp; 21C PeekMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7282F&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D1 EnableWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7BEB6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C7 DrawTextExW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D9A500&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5D CreateDialogParamW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7031A&amp;nbsp;&amp;nbsp;&amp;nbsp; 18F GetWindowTextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6B2CA&amp;nbsp;&amp;nbsp;&amp;nbsp; 205 MoveWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D82DA7&amp;nbsp;&amp;nbsp;&amp;nbsp; 1AA InvalidateRect&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D82B71&amp;nbsp;&amp;nbsp;&amp;nbsp; 263 SendMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6F82E&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2F CharNextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D996E6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3D CheckMenuItem&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D9CA35&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 47 CloseClipboard&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D9CAC8&amp;nbsp;&amp;nbsp;&amp;nbsp; 1B6 IsClipboardFormatAvailable&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D9CA47&amp;nbsp;&amp;nbsp;&amp;nbsp; 20F OpenClipboard&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6BC72&amp;nbsp;&amp;nbsp;&amp;nbsp; 147 GetMenuState&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6BE00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CF EnableMenuItem&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D6B8F9&amp;nbsp;&amp;nbsp;&amp;nbsp; 16B GetSubMenu&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D67B3E&amp;nbsp;&amp;nbsp;&amp;nbsp; 13C GetMenu&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D79C65&amp;nbsp;&amp;nbsp;&amp;nbsp; 2A2 SetWinEventHook&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D819A2&amp;nbsp;&amp;nbsp;&amp;nbsp; 14E GetMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D83915&amp;nbsp;&amp;nbsp;&amp;nbsp; 21F PostMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77DBFBD5&amp;nbsp;&amp;nbsp;&amp;nbsp; 1FF MessageBoxW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D796AB&amp;nbsp;&amp;nbsp;&amp;nbsp; 124 GetFocus&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D911FF&amp;nbsp;&amp;nbsp;&amp;nbsp; 300 WinHelpW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D8340C&amp;nbsp;&amp;nbsp;&amp;nbsp; 11E GetDlgCtrlID&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D73023&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D3 EndDialog&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D70866&amp;nbsp;&amp;nbsp;&amp;nbsp; 18E GetWindowTextLengthW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D786D8&amp;nbsp;&amp;nbsp;&amp;nbsp; 1D7 LoadIconW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7B102&amp;nbsp;&amp;nbsp;&amp;nbsp; 1B9 IsDialogMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7B569&amp;nbsp;&amp;nbsp;&amp;nbsp; 2D3 TranslateAcceleratorW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D82AA1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2D5 TranslateMessage&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D82A89&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A9 DispatchMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D78B98&amp;nbsp;&amp;nbsp;&amp;nbsp; 2E9 UpdateWindow&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D72C64&amp;nbsp;&amp;nbsp;&amp;nbsp; 2D7 UnhookWinEvent&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D8ACBE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41 ChildWindowFromPoint&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D994BD&amp;nbsp;&amp;nbsp;&amp;nbsp; 122 GetDlgItemTextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D993E1&amp;nbsp;&amp;nbsp;&amp;nbsp; 277 SetDlgItemTextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D796B8&amp;nbsp;&amp;nbsp;&amp;nbsp; 279 SetFocus&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D75DF4&amp;nbsp;&amp;nbsp;&amp;nbsp; 2AC SetWindowTextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D82E91&amp;nbsp;&amp;nbsp;&amp;nbsp; 155 GetParent&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7AC9B&amp;nbsp;&amp;nbsp;&amp;nbsp; 1E4 LoadStringW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D91D1C&amp;nbsp;&amp;nbsp;&amp;nbsp; 25A SendDlgItemMessageW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7C65C&amp;nbsp;&amp;nbsp;&amp;nbsp; 119 GetCursorPos&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77D7C1D0&amp;nbsp;&amp;nbsp;&amp;nbsp; 254 ScreenToClient&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; msvcrt.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001290 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1009058 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D65BC2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 37 &lt;A href="mailto:?terminate@@YAXXZ"&gt;?terminate@@YAXXZ&lt;/A&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1E116&amp;nbsp;&amp;nbsp;&amp;nbsp; 127 _controlfp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1C032&amp;nbsp;&amp;nbsp;&amp;nbsp; 3CE _vsnwprintf&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D19860&amp;nbsp;&amp;nbsp;&amp;nbsp; 4EE memset&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1BE1E&amp;nbsp;&amp;nbsp;&amp;nbsp; 46D _wtol&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D198D0&amp;nbsp;&amp;nbsp;&amp;nbsp; 4EA memcpy&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1BA09&amp;nbsp;&amp;nbsp;&amp;nbsp; 4CC iswctype&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D37B87&amp;nbsp;&amp;nbsp;&amp;nbsp; 4DA localtime&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D36599&amp;nbsp;&amp;nbsp;&amp;nbsp; 159 _except_handler4_common&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D223B6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D2 __set_app_type&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D223AB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BE __p__fmode&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D223A0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; B9 __p__commode&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70DB18B4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; F5 _adjust_fdiv&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D7A161&amp;nbsp;&amp;nbsp;&amp;nbsp; 101 _amsg_exit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1BBD2&amp;nbsp;&amp;nbsp;&amp;nbsp; 1D5 _initterm&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70DAE4DC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E7 _acmdln&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D220F7&amp;nbsp;&amp;nbsp;&amp;nbsp; 48F exit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1D39A&amp;nbsp;&amp;nbsp;&amp;nbsp; 534 time&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D234D9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 91 __getmainargs&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D1E342&amp;nbsp;&amp;nbsp;&amp;nbsp; 1F4 _ismbblead&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D74EFE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6A _XcptFilter&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D7A2E3&amp;nbsp;&amp;nbsp;&amp;nbsp; 162 _exit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70D221CC&amp;nbsp;&amp;nbsp;&amp;nbsp; 114 _cexit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70DA5C1D&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D4 __setusermatherr&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; COMDLG32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10012F4 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10090BC Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7181D9D0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E GetSaveFileNameW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71833E86&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 FindTextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71833EBA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17 ReplaceTextW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71839307&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11 PageSetupDlgW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71842EED&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14 PrintDlgExW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 718128DF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C GetOpenFileNameW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71802517&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 CommDlgExtendedError&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71837CD1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 ChooseFontW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 71802E37&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A GetFileTitleW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHELL32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100131C Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10090E4 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7669D635&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1B DragAcceptFiles&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7658A7D3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 DragQueryFileW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 766FB803&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1C DragFinish&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7661AFE6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8D SHCreateItemFromParsingName&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 766EA0A5&amp;nbsp;&amp;nbsp;&amp;nbsp; 110 ShellAboutW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; WINSPOOL.DRV&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001334 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10090FC Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6E19121B&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 85 GetPrinterDriverW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6E199539&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1D ClosePrinter&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6E187359&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8F OpenPrinterW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ole32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001344 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100910C Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72C6D569&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66 CoTaskMemAlloc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72C6DD8F&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 CoCreateInstance&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72C6DE1E&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67 CoTaskMemFree&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72C69BD8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6B CoUninitialize&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72C6885D&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3E CoInitializeEx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHLWAPI.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100135C Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1009124 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6ED6E534&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5D PathIsFileSpecW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6ED7E468&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FD SHStrDupW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; COMCTL32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001368 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1009130 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7493FDC3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C CreateStatusWindowW&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 748B3E05&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ordinal&amp;nbsp;&amp;nbsp; 345&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; OLEAUT32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001374 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100913C Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 702E41AB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ordinal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 702E3DAB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ordinal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ntdll.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001380 Import Address Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1009148 Import Name Table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF time date stamp&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FFFFFFFF Index of first forwarder reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77F0850D&amp;nbsp;&amp;nbsp;&amp;nbsp; 548 WinSqmAddToStream&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Header contains the following bound import information:&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to ADVAPI32.dll [4549BCD2] Thu Nov 02 15:09:30 2006---------------&lt;U&gt;&lt;EM&gt;this refers to when this image was build...this is windows vista thats why showing 2006&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to KERNEL32.dll [4549BD80] Thu Nov 02 15:12:24 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to GDI32.dll [4549BCD3] Thu Nov 02 15:09:31 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to USER32.dll [4549BDE0] Thu Nov 02 15:14:00 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to msvcrt.dll [4549BD61] Thu Nov 02 15:11:53 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to COMDLG32.dll [4549BD09] Thu Nov 02 15:10:25 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to SHELL32.dll [4549BDB4] Thu Nov 02 15:13:16 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to WINSPOOL.DRV [4549BE2A] Thu Nov 02 15:15:14 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to ole32.dll [4549BD92] Thu Nov 02 15:12:42 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to SHLWAPI.dll [4549BDB9] Thu Nov 02 15:13:21 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to COMCTL32.dll [4549BD09] Thu Nov 02 15:10:25 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to OLEAUT32.dll [4549BD95] Thu Nov 02 15:12:45 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bound to ntdll.dll [4549BDC9] Thu Nov 02 15:13:37 2006&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Summary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3000 .data&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 .reloc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1A000 .rsrc&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9000 .text&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;next i dumped out the data section show in summary--------------&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;C:\Users\ganand\Desktop\internals\TOOLS&amp;gt;link.exe -dump -section:".data" -all c:\&lt;BR&gt;windows\system32\notepad.exe &amp;gt;c:\notepaddump2.txt&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Microsoft (R) COFF/PE Dumper Version 7.10.2179&lt;BR&gt;Copyright (C) Microsoft Corporation.&amp;nbsp; All rights reserved.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Dump of file c:\windows\system32\notepad.exe&lt;/P&gt;
&lt;P&gt;PE signature found------&lt;EM&gt;&lt;U&gt;this is windows pe format image&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;File Type: EXECUTABLE IMAGE-----------------------------&lt;/P&gt;
&lt;P&gt;FILE HEADER VALUES&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14C machine (x86)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 number of sections&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4549B0BE time date stamp Thu Nov 02 14:17:58 2006--------------------------when this image was build&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 file pointer to symbol table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 number of symbols&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E0 size of optional header&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 102 characteristics&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Executable&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32 bit word machine&lt;/P&gt;
&lt;P&gt;OPTIONAL HEADER VALUES&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10B magic # (PE32)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.00 linker version&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9000 size of code&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1CC00 size of initialized data&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 size of uninitialized data&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 31F8 entry point (010031F8)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 base of code&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D000 base of data&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000000 image base (01000000 to 01027FFF)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 section alignment&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 200 file alignment&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.00 operating system version---------------------&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.00 image version--------------------------&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.00 subsystem version&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 Win32 version&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 28000 size of image&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 400 size of headers&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2A84B checksum&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 subsystem (Windows GUI)-----------------------------&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8140 DLL characteristics&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RESERVED - UNKNOWN&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RESERVED - UNKNOWN&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Terminal Server Aware----------------------------------------&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40000 size of stack reserve&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11000 size of stack commit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100000 size of heap reserve&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 size of heap commit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 loader flags-------------------------------------------------&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 number of directories&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Export Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8C0C [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 118] RVA [size] of Import Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D000 [&amp;nbsp;&amp;nbsp; 19A10] RVA [size] of Resource Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Exception Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Certificates Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27000 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D20] RVA [size] of Base Relocation Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9EF8 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 38] RVA [size] of Debug Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Architecture Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Global Pointer Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Thread Storage Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5010 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40] RVA [size] of Load Configuration Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 278 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10C] RVA [size] of Bound Import Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 388] RVA [size] of Import Address Table Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Delay Import Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of COM Descriptor Directory&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] RVA [size] of Reserved Directory&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;SECTION HEADER #2&lt;BR&gt;&amp;nbsp;&amp;nbsp; .data name&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2124 virtual size&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; A000 virtual address (0100A000 to 0100C123)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1000 size of raw data&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9400 file pointer to raw data (00009400 to 0000A3FF)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 file pointer to relocation table&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 file pointer to line numbers&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 number of relocations&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 number of line numbers&lt;BR&gt;C0000040 flags&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Initialized Data&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Write&lt;/P&gt;
&lt;P&gt;RAW DATA #2&lt;BR&gt;&amp;nbsp; 0100A000: 00 00 00 00 78 00 00 00 01 00 00 00 FF FF FF FF&amp;nbsp; ....x.......ÿÿÿÿ&lt;BR&gt;&amp;nbsp; 0100A010: 4E E6 40 BB B1 19 BF 44 00 00 00 00 00 00 00 00&amp;nbsp; &lt;A href="mailto:Næ@»±.¿D"&gt;Næ@»±.¿D&lt;/A&gt;........&lt;BR&gt;&amp;nbsp; 0100A020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A200: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A210: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A220: 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A230: 02 00 00 00 03 00 00 00 04 00 00 00 05 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A240: 06 00 00 00 07 00 00 00 08 00 00 00 09 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A250: 0A 00 00 00 0B 00 00 00 0C 00 00 00 0D 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A260: 0E 00 00 00 2F 00 00 00 0F 00 00 00 10 00 00 00&amp;nbsp; ..../...........&lt;BR&gt;&amp;nbsp; 0100A270: 11 00 00 00 12 00 00 00 13 00 00 00 2D 00 00 00&amp;nbsp; ............-...&lt;BR&gt;&amp;nbsp; 0100A280: 14 00 00 00 15 00 00 00 16 00 00 00 17 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A290: 18 00 00 00 19 00 00 00 1A 00 00 00 1B 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A2A0: 1C 00 00 00 1D 00 00 00 1E 00 00 00 1F 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A2B0: 20 00 00 00 21 00 00 00 22 00 00 00 23 00 00 00&amp;nbsp;&amp;nbsp; ...!..."...#...&lt;BR&gt;&amp;nbsp; 0100A2C0: 24 00 00 00 25 00 00 00 26 00 00 00 27 00 00 00&amp;nbsp; $...%...&amp;amp;...'...&lt;BR&gt;&amp;nbsp; 0100A2D0: 28 00 00 00 29 00 00 00 2A 00 00 00 2B 00 00 00&amp;nbsp; (...)...*...+...&lt;BR&gt;&amp;nbsp; 0100A2E0: 2C 00 00 00 2E 00 00 00 CC 2F 00 01 00 00 00 00&amp;nbsp; ,.......Ì/......&lt;BR&gt;&amp;nbsp; 0100A2F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A300: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A310: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A320: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A330: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A340: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A350: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A360: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A370: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A380: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A390: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A3A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A3B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A3C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A3D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A3E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A3F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A410: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A420: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A430: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A440: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A450: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A460: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A470: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A480: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A490: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A4A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A4B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A4C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A4D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A4E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A4F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A500: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A510: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A520: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A530: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A540: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A550: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A560: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A570: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A590: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A5A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A5B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A5C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A5D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A5E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A5F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A600: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A610: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A620: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A630: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A640: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A650: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A660: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A670: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A690: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A6A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A6B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A6C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A6D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A6E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A6F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A710: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A720: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A730: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A740: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A750: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A760: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A770: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A790: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A7A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A7B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A7C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A7D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A7E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A7F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A800: 2C A2 00 01 30 A2 00 01 34 A2 00 01 38 A2 00 01&amp;nbsp; ,¢..0¢..4¢..8¢..&lt;BR&gt;&amp;nbsp; 0100A810: 44 A2 00 01 40 A2 00 01 3C A2 00 01 48 A2 00 01&amp;nbsp; &lt;A href="mailto:D¢..@¢..%3C¢..H¢"&gt;D¢..@¢..&amp;lt;¢..H¢&lt;/A&gt;..&lt;BR&gt;&amp;nbsp; 0100A820: 4C A2 00 01 50 A2 00 01 54 A2 00 01 58 A2 00 01&amp;nbsp; L¢..P¢..T¢..X¢..&lt;BR&gt;&amp;nbsp; 0100A830: 5C A2 00 01 60 A2 00 01 68 A2 00 01 6C A2 00 01&amp;nbsp; \¢..`¢..h¢..l¢..&lt;BR&gt;&amp;nbsp; 0100A840: 70 A2 00 01 80 A2 00 01 84 A2 00 01 88 A2 00 01&amp;nbsp; p¢...¢...¢...¢..&lt;BR&gt;&amp;nbsp; 0100A850: 8C A2 00 01 90 A2 00 01 94 A2 00 01 98 A2 00 01&amp;nbsp; .¢...¢...¢...¢..&lt;BR&gt;&amp;nbsp; 0100A860: 9C A2 00 01 A4 A2 00 01 A0 A2 00 01 A8 A2 00 01&amp;nbsp; .¢..¤¢..&amp;nbsp;¢..¨¢..&lt;BR&gt;&amp;nbsp; 0100A870: AC A2 00 01 B0 A2 00 01 B4 A2 00 01 B8 A2 00 01&amp;nbsp; ¬¢..°¢..´¢..¸¢..&lt;BR&gt;&amp;nbsp; 0100A880: BC A2 00 01 C0 A2 00 01 74 A2 00 01 78 A2 00 01&amp;nbsp; ¼¢..À¢..t¢..x¢..&lt;BR&gt;&amp;nbsp; 0100A890: C4 A2 00 01 C8 A2 00 01 CC A2 00 01 D0 A2 00 01&amp;nbsp; Ä¢..È¢..Ì¢..Ð¢..&lt;BR&gt;&amp;nbsp; 0100A8A0: D4 A2 00 01 D8 A2 00 01 DC A2 00 01 E0 A2 00 01&amp;nbsp; Ô¢..Ø¢..Ü¢..à¢..&lt;BR&gt;&amp;nbsp; 0100A8B0: 7C A2 00 01 E4 A2 00 01 64 A2 00 01 00 00 00 00&amp;nbsp; |¢..ä¢..d¢......&lt;BR&gt;&amp;nbsp; 0100A8C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A8D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A8E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A8F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A900: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A910: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A920: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A930: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A940: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A950: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A960: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A970: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A980: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A990: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A9A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A9B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A9C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A9D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A9E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100A9F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AA90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AAA0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AAB0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AAC0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AAD0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AAE0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AAF0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AB90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ABA0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ABB0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ABC0: 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ABD0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ABE0: 00 00 00 00 00 00 00 00 2D 51 00 01 61 50 00 01&amp;nbsp; ........-Q..aP..&lt;BR&gt;&amp;nbsp; 0100ABF0: 7C 50 00 01 AA 50 00 01 13 51 00 01 B4 50 00 01&amp;nbsp; |P..ªP...Q..´P..&lt;BR&gt;&amp;nbsp; 0100AC00: 71 53 00 01 20 51 00 01 B4 50 00 01 20 51 00 01&amp;nbsp; qS.. Q..´P.. Q..&lt;BR&gt;&amp;nbsp; 0100AC10: BD 51 00 01 C1 50 00 01 DB 50 00 01 F5 50 00 01&amp;nbsp; ½Q..ÁP..ÛP..õP..&lt;BR&gt;&amp;nbsp; 0100AC20: 13 51 00 01 20 51 00 01 13 51 00 01 00 00 00 00&amp;nbsp; .Q.. Q...Q......&lt;BR&gt;&amp;nbsp; 0100AC30: FF FF 00 00 44 A2 00 01 02 00 00 00 50 A2 00 01&amp;nbsp; ÿÿ..D¢......P¢..&lt;BR&gt;&amp;nbsp; 0100AC40: 0A 00 00 00 54 A2 00 01 05 00 00 00 44 A2 00 01&amp;nbsp; ....T¢......D¢..&lt;BR&gt;&amp;nbsp; 0100AC50: 06 00 00 00 44 A2 00 01 04 10 00 00 94 A2 00 01&amp;nbsp; ....D¢.......¢..&lt;BR&gt;&amp;nbsp; 0100AC60: 05 10 00 00 44 A2 00 01 08 10 00 00 E8 A2 00 01&amp;nbsp; ....D¢......è¢..&lt;BR&gt;&amp;nbsp; 0100AC70: EF BB BF 00 FF FE 00 00 FE FF 00 00 00 00 00 00&amp;nbsp; ï»¿.ÿþ..þÿ......&lt;BR&gt;&amp;nbsp; 0100AC80: 59 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; Y...............&lt;BR&gt;&amp;nbsp; 0100AC90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ACA0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ACB0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ACC0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ACD0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ACE0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ACF0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AD90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ADA0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ADB0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ADC0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ADD0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ADE0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100ADF0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AE80: 00 00 00 00 00 00 00 00 59 00 00 00 00 00 00 00&amp;nbsp; ........Y.......&lt;BR&gt;&amp;nbsp; 0100AE90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AEA0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AEB0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AEC0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AED0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AEE0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AEF0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AF90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AFA0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AFB0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AFC0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AFD0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AFE0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;BR&gt;&amp;nbsp; 0100AFF0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00&amp;nbsp; ................&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Summary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3000 .data&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;C:\Users\ganand\Desktop\internals\TOOLS&amp;gt;link.exe -dump -dependents c:\windows\sy&lt;BR&gt;stem32\notepad.exe&lt;BR&gt;Microsoft (R) COFF/PE Dumper Version 7.10.2179&lt;BR&gt;Copyright (C) Microsoft Corporation.&amp;nbsp; All rights reserved.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Dump of file c:\windows\system32\notepad.exe&lt;/P&gt;
&lt;P&gt;File Type: EXECUTABLE IMAGE&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;EM&gt;&lt;U&gt;Image has the following dependencies:&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ADVAPI32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; KERNEL32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GDI32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; USER32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; msvcrt.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; COMDLG32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHELL32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; WINSPOOL.DRV&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ole32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHLWAPI.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; COMCTL32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; OLEAUT32.dll&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ntdll.dll&amp;nbsp;&lt;/P&gt;
&lt;P&gt;====&lt;BR&gt;C:\Users\ganand\Desktop\internals\TOOLS&amp;gt;link.exe -dump -exports&amp;nbsp; c:\windows\syst&lt;BR&gt;em32\ntdll.dll &amp;gt;c:\ntdll.txt&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Dump of file c:\windows\system32\ntdll.dll&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;File Type: DLL&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Section contains the following exports for ntdll.dll&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00000000 characteristics&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4549ACD4 time date stamp Thu Nov 02 14:01:16 2006&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.00 version&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ordinal base&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1902 number of functions&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1902 number of names&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ordinal hint RVA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 000246E0 A_SHAFinal--&lt;EM&gt;&lt;U&gt;this dumps out all the functions of ntdll.dll with their service numbers&lt;/U&gt;&lt;/EM&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 000245D8 A_SHAInit&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 0002462E A_SHAUpdate&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 0000A956 AlpcAdjustCompletionListConcurrencyCount&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 0000B0C0 AlpcFreeCompletionListMessage&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 00097D6D AlpcGetCompletionListLastMessageInformation&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 00097D39 AlpcGetCompletionListMessageAttributes&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp; 7 0006637A AlpcGetHeaderSize&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 18&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 00066343 AlpcGetMessageAttribute&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 0000AF0D AlpcGetMessageFromCompletionList&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&amp;nbsp;&amp;nbsp;&amp;nbsp; A 00070C93 AlpcGetOutstandingCompletionListMessageCount&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&amp;nbsp;&amp;nbsp;&amp;nbsp; B 00022DEB AlpcInitializeMessageAttribute&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 22&amp;nbsp;&amp;nbsp;&amp;nbsp; C 00011135 AlpcMaxAllowedMessageLength&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 23&amp;nbsp;&amp;nbsp;&amp;nbsp; D 0000AD39 AlpcRegisterCompletionList&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24&amp;nbsp;&amp;nbsp;&amp;nbsp; E 0000AE5A AlpcRegisterCompletionListWorkerThread&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 25&amp;nbsp;&amp;nbsp;&amp;nbsp; F 00070CB2 AlpcUnregisterCompletionList&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 26&amp;nbsp;&amp;nbsp; 10 0000AD95 AlpcUnregisterCompletionListWorkerThread&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27&amp;nbsp;&amp;nbsp; 11 0003DCE5 CsrAllocateCaptureBuffer&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 28&amp;nbsp;&amp;nbsp; 12 0003DD78 CsrAllocateMessagePointer&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 29&amp;nbsp;&amp;nbsp; 13 0003EF49 CsrCaptureMessageBuffer&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30&amp;nbsp;&amp;nbsp; 14 00038FFA CsrCaptureMessageMultiUnicodeStringsInPlace&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 31&amp;nbsp;&amp;nbsp; 15 00038F9A CsrCaptureMessageString&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp; 16 0008EC13 CsrCaptureTimeout&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 33&amp;nbsp;&amp;nbsp; 17 00067F66 CsrClientCallServer&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34&amp;nbsp;&amp;nbsp; 18 00034C8C CsrClientConnectToServer&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 35&amp;nbsp;&amp;nbsp; 19 0003DDBE CsrFreeCaptureBuffer&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 36&amp;nbsp;&amp;nbsp; 1A 0008EC08 CsrGetProcessId&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 37&amp;nbsp;&amp;nbsp; 1B 0008EBF3 CsrIdentifyAlertableThread&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 38&amp;nbsp;&amp;nbsp; 1C 0008EBF3 CsrNewThread&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 39&amp;nbsp;&amp;nbsp; 1D 0008EBFB CsrSetPriorityClass&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40&amp;nbsp;&amp;nbsp; 1E 0008EC46 CsrVerifyRegion&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41&amp;nbsp;&amp;nbsp; 1F 00042EA8 DbgBreakPoint&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 42&amp;nbsp;&amp;nbsp; 20 0001544A DbgPrint&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43&amp;nbsp;&amp;nbsp; 21 000214D5 DbgPrintEx&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 44&amp;nbsp;&amp;nbsp; 22 00097ED7 DbgPrintReturnControlC&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45&amp;nbsp;&amp;nbsp; 23 00097E12 DbgPrompt&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 46&amp;nbsp;&amp;nbsp; 24 00097E58 DbgQueryDebugFilterState&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 47&amp;nbsp;&amp;nbsp; 25 00097E68 DbgSetDebugFilterState&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&amp;nbsp;&amp;nbsp; 26 0008EF7E DbgUiConnectToDbg&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 49&amp;nbsp;&amp;nbsp; 27 0008F026 DbgUiContinue&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50&amp;nbsp;&amp;nbsp; 28 0008F158 DbgUiConvertStateChangeStructure&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 51&amp;nbsp;&amp;nbsp; 29 0008F116 DbgUiDebugActiveProcess&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&amp;nbsp;&amp;nbsp; 2A 0008EFD0 DbgUiGetThreadDebugObject&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 53&amp;nbsp;&amp;nbsp; 2B 0008F0D0 DbgUiIssueRemoteBreakin&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 54&amp;nbsp;&amp;nbsp; 2C 0008F06D DbgUiRemoteBreakin&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55&amp;nbsp;&amp;nbsp; 2D 0008EFE2 DbgUiSetThreadDebugObject&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;---long list..................................................................&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2672848" width="1" height="1"&gt;</description></item><item><title>What changed on Disk when I Enabled Bitlocker and configured bitlocker protected data partitions</title><link>http://blogs.technet.com/ganand/archive/2007/10/23/what-changed-on-disk-when-i-enabled-bitlocker-and-configured-bitlocker-protected-data-partitions.aspx</link><pubDate>Tue, 23 Oct 2007 19:09:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2235900</guid><dc:creator>ganand</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ganand/comments/2235900.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2235900</wfw:commentRss><description>&lt;P&gt;I was curious to see what changes Bitlocker make on my raw disk, So i picked my dskprobe and had a quick look and I will like to share a few changes&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i saw. There is lot more which gets changed but not covered below.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/111%20-%20Copy.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/111%20-%20Copy.jpg"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=525 alt="111 - Copy" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/111%20-%20Copy_thumb.jpg" width=568 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/111%20-%20Copy_thumb.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/112.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/112.jpg"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=377 alt=112 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/112_thumb.jpg" width=459 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/112_thumb.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the OS partition i.e. on my C drive, I used dskprobe and opened its NTFS boot sector and i see the OEM ID string saying FVE_FS instead of NTFS.&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I also saw that "clusters to MFT mirror" is not actually pointing to clusters to MFT mirror but to....see below&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/cluster%20mirror%20mft.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/cluster%20mirror%20mft.jpg"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=411 alt="cluster mirror mft" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/cluster%20mirror%20mft_thumb.jpg" width=513 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/cluster%20mirror%20mft_thumb.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;I figured out that this is the start of FVE metadata as visible and also GAUEPSSSET01 is the name of my computer and the the value of "clusters to MFT mirror"&amp;nbsp;is stored in the FVE metadata itself. so FVE_FS is one way to find out backup copies of FVE metadata and better way is to use bitlocker repair tool if ever required.&lt;/P&gt;
&lt;P&gt;For more information about bitlocker repair tool please have a look at article given below.&lt;/P&gt;
&lt;P&gt;928201&amp;nbsp;&amp;nbsp;&amp;nbsp; How to use the BitLocker Repair Tool to help recover data from an encrypted volume in Windows Vista&lt;BR&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;928201" mce_href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;928201"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;928201&lt;/A&gt; 
&lt;P&gt;Now i wanted to see what happens in case of data partitions protected by bitlocker of course on a vista sp1 machine. 
&lt;P&gt;yes with windows vista sp1 (still in beta) you should be able to protect your data partitions as you may see below 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/115.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/115.jpg"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=502 alt=115 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/115_thumb.jpg" width=596 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/115_thumb.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I once again used dskprobe and opened the NTFS boot sector of one of the data partitions. &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/ntfs%20boot%20sector%20of%20data%20partition.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/ntfs%20boot%20sector%20of%20data%20partition.jpg"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=409 alt="ntfs boot sector of data partition" src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/ntfs%20boot%20sector%20of%20data%20partition_thumb.jpg" width=506 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/WhatchangedonDiskwhenIEnabledBitlockeran_13060/ntfs%20boot%20sector%20of%20data%20partition_thumb.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;There is lot more which gets changed but not covered here.&lt;/P&gt;
&lt;P&gt;For more information about dskprobe (part of support tools) see below:&lt;/P&gt;
&lt;P&gt;&lt;A title=http://technet2.microsoft.com/windowsserver/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx?mfr=true href="http://technet2.microsoft.com/windowsserver/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx?mfr=true" mce_href="http://technet2.microsoft.com/windowsserver/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx?mfr=true"&gt;http://technet2.microsoft.com/windowsserver/en/library/006902f1-bae9-4055-9ad2-123ea19006b71033.mspx?mfr=true&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gaurav Anand&lt;/P&gt;
&lt;P&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2235900" width="1" height="1"&gt;</description></item><item><title>Configuring bitlocker</title><link>http://blogs.technet.com/ganand/archive/2007/10/16/configuring-bitlocker.aspx</link><pubDate>Tue, 16 Oct 2007 18:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2183609</guid><dc:creator>ganand</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/ganand/comments/2183609.aspx</comments><wfw:commentRss>http://blogs.technet.com/ganand/commentrss.aspx?PostID=2183609</wfw:commentRss><description>&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;I thought of giving everyone feel of how easy it is to configure bitlocker on your machine. I picked a test Lenovo T60p machine and &lt;/FONT&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;opened bitlocker drive encryption applet from control panel. You will get option to turn on bitlocker but before you do that you first need to prepare your machine for bitlocker i.e. it should have a separate system partition which has to be NTFS and at least 1.5GB. For this you will get bitlocker drive preparation tool by calling Microsoft PSS. You may also do it manually but it is easier from the tool.&lt;/FONT&gt; 
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;Once you get this tool and extract it on desktop and run it you will see what is shown in pic 1. It will shrink your C drive if there is no unallocated space on hard drive and then create a new active system partition and prepare it for bitlocker.&lt;/FONT&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/1.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/1.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=377 alt=1 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/1_thumb.jpg" width=386 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/1_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;Once that is done… open bitlocker drive encryption applet from control panel and if you turn on bitlocker then you will see option as shown in pic2. You can also see that it says machine does not have TPM. Actually till now I have not turned on TPM from bios. &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/2.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/2.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=454 alt=2 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/2_thumb.jpg" width=702 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/2_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 2&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;So I went to TPM.msc and I see what is shown in pic3 …it does not detect my TPM as expected. &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/3.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/3.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=310 alt=3 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/3_thumb.jpg" width=575 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/3_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 3&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;I went to bios and turned on my TPM device…once I booted back to OS and opened TPM.msc, it asks me to initialize my TPM. You can see that in pic 4&lt;/FONT&gt; 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/4.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/4.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=445 alt=4 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/4_thumb.jpg" width=897 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/4_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 4&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;I tried to initialize and got error message as shown in pic 5..reason I am not on network and unable to communicate with AD. This group policy is enabled by default as I mentioned last time that it tries to backup TPM owner password information. &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001_2.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001_2.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=420 alt=clip_image001 src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001_thumb.jpg" width=399 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 5&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;I connected to network and was able to initialize. Now as you see in pic 6 it says TPM is on and ownership has been taken...it will allow you to backup TPM password too. It also gives you the option to reset the TPM in GUI interface as shown.&lt;/FONT&gt; 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B6%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B6%5D.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=289 alt=clip_image001[6] src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B6%5D_thumb.jpg" width=579 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B6%5D_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 6&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;Now I went back to bitlocker drive encryption control panel applet and turned it on…and it started encrypting my C drive. You may turn off your machine and it will resume conversion process as soon as you start next time. You may pause conversion too. Generally the conversion rate is 1GB/min but it varies depending on various factors including the hardware. Pic 7 shows same.&lt;/FONT&gt; 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B8%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B8%5D.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=218 alt=clip_image001[8] src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B8%5D_thumb.jpg" width=580 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B8%5D_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 7&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;On the same window if you click on “manage bitlocker keys” you will get an option to reset the pin (if you have configured) and also to duplicate your recovery password I.e. save password as shown in pic 8 &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;You can save it on a non bitlocker encrypted partition or USB or print it.&lt;/FONT&gt; 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B10%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B10%5D.jpg"&gt;&lt;FONT face="Microsoft Sans Serif" color=#000000 size=2&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=337 alt=clip_image001[10] src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B10%5D_thumb.jpg" width=379 border=0 mce_src="http://blogs.technet.com/blogfiles/ganand/WindowsLiveWriter/Configuringbitlocker_11E30/clip_image001%5B10%5D_thumb.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pic 8&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;Gaurav Anand&lt;/FONT&gt; 
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;------------------------------&lt;/FONT&gt; 
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/FONT&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face="Microsoft Sans Serif" size=2&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2183609" width="1" height="1"&gt;</description></item></channel></rss>