Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 27

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 28

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 29

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 30

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 31

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 32

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 33

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 35

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 36

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 37

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 38

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 39

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 40

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 41

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 42

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 43

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 44

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 45

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 47

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 48

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 49

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 50

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 51

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 52

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 53

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 54

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 55

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 56

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 80

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 81

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 82

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 83

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 84

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 85

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 86

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 87

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 88

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 89

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 90

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 91

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 92

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 93

Deprecated: Function eregi() is deprecated in /home/mati/domains/forum.programosy.pl/public_html/includes/functions_gfxua.php on line 94

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
Bardzo powolny komputer, prosze o sprawdzenie loga • programosy.pl

  • Ogłoszenie:

Bardzo powolny komputer, prosze o sprawdzenie loga

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez hugo91 30 Lis 2014, 19:06

reklama
witam, jak wyżej, komputer mojej dziewczyny jest bardzo powolny, na dodatek w przegladarce wyskakuja jej czesto jakies dziwne okna, pomimo ze ma adblocker-a, avast czasem widzi jakies wirusy.

proszę o sprawdznie loga, uprzedzajac pytania - z gmerem w trybie awaryjnym mam problemy, wyskakuje taki komunikat, na zwyklym windowsie jest to samo.

Kod: Zaznacz wszystko
OTL Extras logfile created on: 2014-11-30 17:24:55 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 53,07% Memory free
4,20 Gb Paging File | 2,40 Gb Available in Paging File | 57,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,63 Gb Free Space | 77,30% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{030F16B3-AC3F-4B85-AC18-6EF3E5F4F36C}" = rport=138 | protocol=17 | dir=out | app=system |
"{0E408148-2463-493C-974D-9831F0585CEE}" = lport=9996 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcsystemtray.exe |
"{199E3C84-2FDE-45F8-9913-CEF74D8D3499}" = lport=1900 | protocol=17 | dir=in | app=%programfiles%\zune\zune.exe |
"{19AFECAE-A699-4CCD-B7D2-172015BF52AA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BA398D1-E360-4F0D-9A98-5EAB8B6CB86B}" = rport=445 | protocol=6 | dir=out | app=system |
"{31113462-1629-4950-917E-0BF2DAA24DD8}" = lport=138 | protocol=17 | dir=in | app=system |
"{3B656BEE-00F6-450C-8B2A-B8B6EA1052A1}" = lport=445 | protocol=6 | dir=in | app=system |
"{3DE59B36-AF3E-4A20-8268-BF907CEF1972}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4CF0A1A0-996D-404B-BEB9-9ED8531E56BD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D06C62A-FF0C-4F4C-A019-9FCA8B50AAE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{538335E5-13F7-47F7-AE49-8A22B0E73D97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{550A699B-3CDF-49AB-A293-25E8A6ABAA81}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{55A8CA9F-00E5-4CAB-95E8-C51B169A51F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5FDD1F6D-898C-4865-8569-C10751DFED61}" = lport=2869 | protocol=6 | dir=in | app=system |
"{68243D58-392D-41F5-8FE7-E6151EDCF778}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6E23CD0C-702C-4253-A384-C9DB53797B8F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{747A8562-F3A7-4A9C-A2E8-DE0E0E2584A0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7A4A8B49-C91E-4D16-B17A-C7E940954444}" = lport=139 | protocol=6 | dir=in | app=system |
"{898FB1AB-3DFC-4CC1-81F1-084A319F3C00}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A921310-5D00-44ED-9AAF-40780C05A99E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9B997EBD-66BE-4CE7-BB01-81F7CFC56AB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{A04A87E8-DA87-47B1-A0F1-914AD3757D53}" = lport=9997 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vaioshell.exe |
"{AAB83954-A7FE-468B-8A89-95CF1163699A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B01E4F72-CD19-480B-A104-A4C349D3C314}" = lport=9999 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe |
"{B4688510-2513-4F34-8332-47DAB553E0A1}" = lport=9998 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcadmin.exe |
"{BA8646D0-E0D5-420F-92F4-D99D5B2B2C8B}" = lport=137 | protocol=17 | dir=in | app=system |
"{D95F677C-FE69-4D9C-A800-B512F493DBAC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FAE44678-023C-46B8-862D-59FEB9CF75C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FB6C0575-99EB-41D6-AD97-40511D65DC77}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FC9FD662-EA31-42C0-A9A0-AEADD0F29594}" = rport=137 | protocol=17 | dir=out | app=system |
"{FE0B0C3F-A187-41CA-90E8-A3AE57FBF8F9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001464FC-E3E9-4828-BC6F-628A59D79CE4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.315_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{02A0F843-9E76-4C52-A0EE-7C02CE119ADC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{02A6CE20-3CE5-4935-804F-AF1CFCC01946}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{06773AF9-A653-4505-9AF2-878617C09D4A}" = dir=in | name=taptiles |
"{08DD2950-9786-49FC-9B3B-45DE06576044}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{093A6F4D-638C-49E3-BB66-0F338B51A334}" = dir=in | name=microsoft solitaire collection |
"{0D9B20DA-20EC-43B7-AB43-6E400C3EB4A7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{124BE3DC-93D9-4D46-8FB3-94980959F22A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{153DDAFE-7284-48EB-BB8E-2780F4C8BB43}" = dir=out | name=@{microsoft.zunemusic_2.2.931.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{17DD9FB6-2AE2-471E-B4DE-BB0DEA030DA3}" = dir=in | name=mcafee® central for sony |
"{1A6B4D74-2A98-40D3-938B-78443AA3251A}" = dir=out | name=sony select |
"{1A73D7E3-209F-4D1E-9545-7E4D11323C68}" = protocol=6 | dir=out | app=system |
"{1FB698BF-4735-4CBE-97D8-4E4EB6AD0FDA}" = dir=out | name=microsoft minesweeper |
"{2084B1B9-C9A6-417F-981A-D787C0B7317F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{21BFDA3E-2A93-473F-B772-667B01076326}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{2351BED2-2143-49A4-B4C3-DCBADB8E91FB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{263B3EA9-9E48-4AD2-8EDA-310736EE78AC}" = dir=out | name=@{microsoft.bingsports_3.0.2.317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{263C5183-B2FF-45B8-BECF-2B335EAF1F29}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{26719D7A-D5A2-4702-AB87-C4CAF90E3605}" = dir=in | name=juniper networks junos pulse |
"{2E32F130-BCF1-48CD-AECB-955B43601A3C}" = dir=out | name=juniper networks junos pulse |
"{2F3E727D-CC71-4533-B584-803B1E0C529C}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{2F522F85-964D-4FF8-80C1-7E9429426005}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{2F6B21B3-CF42-47F6-85AE-C45095FBA812}" = dir=out | name=vaio care |
"{2F71F6D2-8B4A-4EF0-8648-C94D81EB80E2}" = dir=out | name=- games app - |
"{302DD789-2769-4D7E-8712-7A0E58B11304}" = dir=in | name=microsoft minesweeper |
"{313F0D2F-EC6F-4307-8C72-AC6B7C540249}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{32DD8247-27F1-43DD-A33B-3BFC3EB8E502}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3329E50E-D514-4A00-BE5C-6EFD44B75F77}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{34C71DC9-3CFB-4C30-897E-A7583222713E}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3A48B196-4B0B-4173-A984-65DFEAF9DACA}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{3F1B62FF-8F0B-4A0E-9C50-1D9AEA7B9BF3}" = dir=in | name=skype |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{43219BD5-F0C3-475C-94B2-C68B7247343C}" = dir=out | name=@{microsoft.zunevideo_1.5.338.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{438E36CC-1B94-41AE-ABC5-995653A8B9F1}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{48D4E687-B9F5-4AFE-892F-436F15B3996B}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{4A7C30CB-C022-43A2-A18A-0042C93A4C42}" = protocol=6 | dir=out | app=system |
"{4B4155A4-1EC0-4371-B5AB-4A1066774CC2}" = dir=in | name=mcafee® central for sony |
"{508A2261-AE87-4A3B-95B8-9AB6F5F1ECC2}" = dir=out | name=@{microsoft.bingtravel_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{55AC1D0D-797C-4B91-9F42-0214A591BABC}" = dir=in | name=microsoft solitaire collection |
"{55B1BF9D-EE69-4A5A-82D9-6A694741CC00}" = dir=in | name=microsoft minesweeper |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{5A6557A8-21E2-4D5F-8ECF-952E7B0666C3}" = dir=out | name=windows_ie_ac_001 |
"{5ABEA3F4-87D2-4151-B772-882064F87314}" = dir=out | name=check point vpn |
"{5B56F422-8C54-4727-88E1-461288305EF9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5C180B6B-167E-4C02-A378-B0F5BC88E08B}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{608400D0-4232-4911-83E4-BDFFF494F4DA}" = dir=out | name=taptiles |
"{623B3D06-7BEC-4583-A25F-3F45E6E6C449}" = dir=out | name=skype |
"{64FBCFD1-9BF5-44E0-93DE-6CF6FACBC84A}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{6693CC48-FD90-4B49-95EE-CBCDAD9B93BE}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{677D8E8B-AF81-4910-B6A9-A3E4385CAA94}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{685B3947-DDBC-48C2-985C-A81DC5EEADAB}" = dir=out | name=microsoft solitaire collection |
"{6CF61DE6-9F17-40BD-9670-67338B1C2A10}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{73BC64C0-6827-46BC-AC51-74B3C2B196CE}" = dir=in | app=c:\users\lidia\appdata\local\microsoft\skydrive\skydrive.exe |
"{74F762CD-615B-4D6E-8299-BCD640553F8C}" = dir=out | name=@{microsoft.bingweather_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{751944F4-D261-4D64-BA9E-FA82DE2F9048}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{78CE5D66-64B8-44C3-8F2F-9D28E336EAAD}" = dir=out | name=@{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{7BD0C972-641A-442F-ACD9-B312122F5921}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{822B057D-68BB-4593-996B-02C5FDEBB95B}" = dir=out | name=juniper networks junos pulse |
"{823FED70-BBA1-4705-8B37-7896CE34DCD9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8491F288-D7F9-4674-84C7-F3318C469372}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{856434AD-ADCA-4010-991F-62D9656039BD}" = protocol=6 | dir=out | app=system |
"{882A2F3D-5A0F-43E1-A53B-FE3DCEF867A8}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{88C7819F-C7CF-46B5-AE41-FED1A7FBD144}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{89B6F0BD-97A2-4C1A-953B-99B88725ACA1}" = dir=out | name=skype |
"{8C4DFB19-B22C-476A-ABAE-3DB39500DCB6}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{8D9777BA-1A90-4367-9191-574484072827}" = dir=out | name=wordament |
"{9238877F-603C-46ED-8F06-6F50FF39BC11}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{940E5550-504E-4037-9EE7-EC4CC2E0D1D9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9458264A-5F0C-44C1-81C3-479A589FB3E3}" = dir=out | name=f5 vpn |
"{96A32F70-AA90-47DD-9513-B7EFFAC25A65}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{97983CB2-9F05-4A90-9609-D03981F881CA}" = dir=out | name=@{microsoft.zunemusic_2.6.476.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{9820196B-CCF2-4B13-8362-7334EBEFACDE}" = dir=out | name=@{microsoft.bingnews_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{98B40748-33D7-45AB-9DB4-CAE11317C670}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{9A5BD996-2418-4372-AFE1-2D09C2648F34}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9E3B5818-96C3-430E-AF40-7D44969C65A4}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9F595940-23DC-48C5-B04D-EEFF37139C05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9F7E3951-E6AC-442E-A901-621741838FB2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9F8097D1-0C03-49CB-BF40-FB506509FC52}" = dir=out | name=windows_ie_ac_001 |
"{9FAC618A-BDEF-4D39-8BC4-98FAA73F54B9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A1E34056-B831-457A-8F2F-0A99315293CB}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{A317CFA9-E27F-494E-9601-E66D6FF76D27}" = dir=in | name=check point vpn |
"{A4AE9D4C-2657-4DE2-9A5E-90C35F65BCA5}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{A633D237-0CDA-42B1-A892-CE4248D109F5}" = dir=out | name=microsoft solitaire collection |
"{A7EAA7C9-A9FC-471E-89C6-F83C1BBB8B1F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A9EC2D1E-7E16-489A-AF3E-96BCCB03EF00}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{ACF7881E-0950-4BBE-99E4-320025746E05}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AF5FE555-86C7-4004-9037-062CAFC3233B}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{B4DB54BD-3FB9-462A-99D2-FE799A6D785D}" = dir=out | name=sony select |
"{B70810F0-B1ED-461F-A994-D6BE128B19AF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BC1BD523-BD0B-42B4-A3B3-EC6E24AE7F1E}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{BC9E5E3F-1D42-46B5-BC90-475E4D1364CD}" = dir=out | name=@{microsoft.bingmaps_2.1.2922.2139_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{BD018346-9CE3-4B57-9749-0BC8D368BB9B}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{BD9C016A-62EC-41F7-982C-DE3FD213C238}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0B0590D-8CB4-4B48-819F-9FE86F23F560}" = dir=out | name=vaio care |
"{C176AFC8-9DC3-410B-9D00-3B76F677A3E9}" = dir=out | name=check point vpn |
"{C2125D7A-F3EA-45B5-9ED5-76FBE4032813}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{C2466120-2EE4-47CD-BF95-688F79D435F8}" = dir=out | name=@{microsoft.zunevideo_2.6.215.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{C3F01482-0DB4-42CD-8A91-7172BE718019}" = dir=out | name=mcafee® central for sony |
"{C40839CB-E672-41BE-8179-77239F483D3B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C64B97B6-4AA6-4DD8-B4A5-1EBE1C68A53F}" = dir=out | name=windows_ie_ac_001 |
"{C6E9145A-0EE9-44DE-8A58-FF97231D8F5E}" = dir=out | name=f5 vpn |
"{C7389275-089D-4764-829D-FA319B338401}" = dir=out | name=sonicwall mobile connect |
"{C778CDD6-6BF6-4811-8375-B446ABBEDAC7}" = dir=in | name=vaio care |
"{CA45CB10-1ADB-4A15-929E-5497A2E623D9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CB354727-1CD4-4820-A6C8-6F6D2258101E}" = dir=in | name=check point vpn |
"{CCE7A28A-1B1C-4441-9697-ACD7A435C068}" = dir=in | name=sonicwall mobile connect |
"{CE7E2FBF-222A-40BB-97F8-28ABCFC857C1}" = dir=out | name=windows_ie_ac_001 |
"{D032395D-1786-4F9A-A512-8E07703A2B8D}" = dir=out | name=- games app - |
"{D14AF6D4-42A7-4DB7-AFDE-B34B169C7083}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{D23153B5-2163-49F8-9B26-77F501379547}" = dir=out | name=sonicwall mobile connect |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D70EAC0A-DAEE-4F16-A109-02929D410E67}" = dir=out | name=windows_ie_ac_001 |
"{D7880873-CC9D-4D1D-A52C-68FF92783C2D}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{D7D933AC-4D60-4F38-A828-64D4B46323C7}" = dir=out | name=microsoft minesweeper |
"{D8A0E1E8-82AA-48D2-8944-16525F39DE93}" = dir=in | name=skype |
"{DA3CF7A9-20F0-450E-A5A2-9651DD78FBC0}" = dir=in | name=juniper networks junos pulse |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DBFE4C41-4629-434B-B3F7-DFB0DEC44110}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DCB2A9F6-2AB1-4A41-B522-AF44BFD1D0BD}" = dir=in | name=vaio care |
"{DCCA78F9-2906-43B9-9B9C-76DBDC822912}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{DCD62A33-757D-4DF6-AD27-D3034BC8AB28}" = dir=in | name=f5 vpn |
"{DDB99518-2F6D-493A-A867-9A63600834F7}" = dir=in | name=sonicwall mobile connect |
"{E2ECA714-68DE-4E5B-9EEA-CCDDF1FFB846}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{E3E85A51-C589-4CB7-80C7-C553CEA3EC0B}" = dir=out | name=@{microsoft.zunevideo_2.6.408.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{E4705F09-9887-4F2B-8479-ADFC2DF1BBA3}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{E53611B4-545A-492D-A815-6B3F552E1646}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{E7211AB8-916E-4392-9278-045F599DFB54}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E76059C4-6926-4F96-8A2C-4FD2F0AEF1A8}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E8726D91-8391-485A-9E9B-4BCF023A311A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{ECBF3C57-D6CB-462F-BCB5-F5BBEE88E889}" = dir=out | name=mcafee® central for sony |
"{ECCDA18D-D39B-4815-9E46-AE9CA2E748B4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{EFD9D7E7-9D74-404A-B33A-9004227CE02D}" = dir=out | name=taptiles |
"{EFEA28EC-C9B1-4471-8630-DE38648359B4}" = dir=in | name=taptiles |
"{F1A5B808-1673-44B2-B0BC-0193CFFB8C33}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F230AAB7-996E-4D3B-B0EA-46CAEF46C59E}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{F9F0C374-492A-4350-B24C-D83A28B86960}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{FAF0E88C-088B-43DB-B464-41B743A98699}" = dir=out | name=wordament |
"{FBA7E63F-58E8-4C71-A003-A30F847720A5}" = dir=in | name=f5 vpn |
"TCP Query User{78B7C52D-B45B-4915-BD53-FCB6FC9D571B}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{E5F1B4C1-BBE5-457E-AE34-CDF31F9BDDEF}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{553A0E06-4AC5-46F5-B7DC-6D94EA0C3373}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{AA0903BB-5077-41E3-9785-1B6C21C88CD3}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{15B9204E-BA09-485E-8F2C-094AC0077664}" = VAIO Care Recovery
"{25ECAFCB-DCFB-4FCE-A5B2-772A57F59860}" = VCCx64
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{30EC1664-6916-5E36-FEA7-8E20B1C4DCD7}" = ccc-utility64
"{312395BC-7CC2-434C-A660-30250276A926}" = SSLx64
"{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}" = iTunes
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{46261E1C-5E0D-484E-8CCC-7F770375FBA2}" = VU5x64
"{4B432082-B58C-4035-91FB-F28D504D3148}" = VUx64
"{4F31AC31-0A28-4F5A-8416-513972DA1F79}" = VSSTx64
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{5388ABD8-6E23-4498-BE10-01079387590F}" = VGClientX64
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62A172B2-550E-499D-9A82-5190D18390AA}" = VAIO Media Server Settings
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}" = Apple Mobile Device Support
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{77619545-1710-CA11-4487-4CD836E76DB9}" = AMD Fuel
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007
"{92907606-B2FC-4193-B0CE-A21159DA3ABB}" = VAIO Care
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{AB447E3B-7A95-4CA6-8ECD-B25C96314B67}" = VCCx64
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{B81EACDF-16E0-A32C-F096-16EF2BD8405C}" = AMD Catalyst Install Manager
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{D55EAC07-7207-44BD-B524-0F063F327743}" = VIx64
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}" = VPMx64
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 5.10 (64-bitowy)
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"{10181264-340D-4BE7-B879-3A49604A6FD1}" = VUx86
"{10DD6128-A810-4A90-9523-475D573FBB37}" = PlayMemories Home
"{14AC95A2-7675-4988-A5BD-3F5B943AED08}" = VAIO Gate
"{1A207C93-12E4-5B88-777D-92F74DC29EDD}" = CCC Help Hungarian
"{1AE56779-2A31-8982-FF75-422457BA5123}" = CCC Help Danish
"{1B740CAA-D283-4662-0469-898A0850B622}" = CCC Help Chinese Traditional
"{1C7DDA73-0C05-E7DD-97A8-A8542B8EA404}" = CCC Help Norwegian
"{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}" = Obsługa programów Apple
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{26A3AC60-368D-D7FE-30C9-C85E4E1FD7EC}" = CCC Help Turkish
"{309DDAE9-A147-56A2-456D-F66BCEFA88E5}" = Catalyst Control Center Graphics Previews Common
"{3490653F-2789-46A1-B1BF-6BD4CF4131AB}" = FDUx86
"{3A26D9BD-0F73-432D-B522-2BA18138F7EF}" = VAIO Improvement
"{3B1AECFC-F652-9877-B6BE-5BFB5023B02F}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523ADF33-0165-88B2-E05E-22C934058B81}" = CCC Help German
"{54BDD1B2-1312-EF6F-ED92-1C300377D9DE}" = CCC Help Greek
"{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
"{60D1433B-175B-B907-DD89-D434997BEBEC}" = CCC Help Russian
"{63C43435-F428-42BA-8E7B-5848749D9262}" = SSLx86
"{641256B0-734F-2B3E-4AEA-4B2AB21F8916}" = Catalyst Control Center Profiles Mobile
"{661598FC-D512-F972-22D8-620D36CEA58B}" = CCC Help Italian
"{692955F2-DE9F-4078-8FAA-858D6F3A1776}" = VAIO Gesture Control
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{74B53C92-E8E8-1903-76FE-A113448EB504}" = CCC Help Japanese
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79954639-C427-4B14-B774-2F6EE649BE99}" = Catalyst Control Center - Branding
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{7AD4F11E-E27C-1455-3F32-076ABB2CE633}" = Catalyst Control Center InstallProxy
"{7B6D6F11-A5BC-4538-0017-21350BA54ED4}" = CCC Help Portuguese
"{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
"{7E5A5CA6-B7D0-406E-A75E-157CAB47EB94}" = VMLx86
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{82CFAFBA-3D52-F45B-67B1-3D1885C7F87D}" = CCC Help Thai
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{857087BB-A988-4462-A5C6-CF6739143B56}" = KUx86
"{88AEC113-3901-0902-A0B8-651A74D005BF}" = CCC Help Chinese Standard
"{8E797841-A110-41FD-B17A-3ABC0641187A}" = VAIO Control Center
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{913E2B02-1BA9-4B38-991B-31C717F9D00C}" = e-Deklaracje Desktop
"{94211EE0-14F9-58C8-676B-54462CB2A346}" = CCC Help Finnish
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
"{9D8112DB-3490-4BF1-AAFA-1D224FFB5D3C}" = VHD
"{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
"{A2F10E60-5D7D-E13B-E451-99A70EBB7C39}" = CCC Help Spanish
"{AA4B3623-6213-41EC-9BFB-F001D72C47A6}" = VAIO Gesture Control
"{AB57D823-F5BE-38AF-DD26-8E04E64308AA}" = CCC Help Polish
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.10) MUI
"{AFDC0CC0-39E8-42C0-9823-2C1C182676DC}" = VCCx86
"{AFE24FB0-8CC3-77A5-EBFA-132FD250FE66}" = CCC Help English
"{B24BB74E-8359-43AA-985A-8E80C9219C70}" = VSSTx86
"{B31938C7-7E97-49EE-8F88-951E156268A3}" = VCCx86
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B8991D99-88FD-41F2-8C32-DB70278D5C30}" = VWSTx86
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BCBBD089-FF54-3F73-2FB5-F3DD7ED7B439}" = Catalyst Control Center Localization All
"{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}" = VAIO CPU Fan Diagnostic
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C4001DF8-CE87-B7C5-5AC8-D8C321D070EA}" = CCC Help French
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
"{C820FBC5-0490-B6D7-0AF5-D8245E1BD903}" = CCC Help Swedish
"{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}" = VIx86
"{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
"{D91558BF-D1F3-411F-AEFE-8774CB406512}" = VAIO - Xperia Link
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ECCEB4D0-7080-4F8A-B498-E40A32A4FBED}" = Restore
"{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}" = XperiaLinkx86
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F458075C-E1AB-F9A6-3B97-D80BF7EC44A5}" = CCC Help Korean
"{F55687F5-D221-604B-61EA-49E80DB04D11}" = AMD VISION Engine Control Center
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FC9F3001-77BD-D664-5941-6E3F16203629}" = CCC Help Czech
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Avast" = Avast Free Antivirus
"e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1" = e-Deklaracje Desktop
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"Mozilla Firefox 33.1 (x86 pl)" = Mozilla Firefox 33.1 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NetSender_is1" = NetSender 3.0
"Picasa 3" = Picasa 3
"PIT Format 2013_is1" = PIT Format 2013
"PITy 2013/2014_is1" = PITy 2013/2014

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SkyDriveSetup.exe" = Microsoft SkyDrive

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2014-10-23 14:46:19 | Computer Name = Lila | Source = Microsoft-Windows-LocationProvider | ID = 2006
Description =

Error - 2014-10-23 16:08:53 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2014-10-23 16:08:53 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2110

Error - 2014-10-23 16:08:53 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2110

Error - 2014-10-23 21:28:22 | Computer Name = Lila | Source = Application Hang | ID = 1002
Description = Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować
z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej
informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum
akcji w Panelu sterowania.    Identyfikator procesu: 1010    Godzina rozpoczęcia: 01cfeef499eef0c0

Godzina
zakończenia: 4294967295    Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe    Identyfikator
raportu: 0617afd9-5b1d-11e4-bea5-083e8ebd58f0    Pełna nazwa pakietu powodującego błąd:
Microsoft.SkypeApp_3.1.0.1005_x86__kzf8qxf38zg5c    Identyfikator aplikacji względem
pakietu powodującego błąd: App 

Error - 2014-10-24 15:24:32 | Computer Name = Lila | Source = Application Hang | ID = 1002
Description = Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować
z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej
informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum
akcji w Panelu sterowania.    Identyfikator procesu: 1d44    Godzina rozpoczęcia: 01cfefbf128c9628

Godzina
zakończenia: 4294967295    Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe    Identyfikator
raportu: 5fd0f8db-5bb3-11e4-bea5-083e8ebd58f0    Pełna nazwa pakietu powodującego błąd:
Microsoft.SkypeApp_3.1.0.1005_x86__kzf8qxf38zg5c    Identyfikator aplikacji względem
pakietu powodującego błąd: App 

Error - 2014-10-31 15:27:11 | Computer Name = Lila | Source = .NET Runtime | ID = 1026
Description =

Error - 2014-10-31 15:27:11 | Computer Name = Lila | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: VCSystemTray.exe, wersja: 8.4.0.14200,
sygnatura czasowa: 0x53056230  Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja:
6.3.9600.17278, sygnatura czasowa: 0x53eebf2e  Kod wyjątku: 0xe0434352  Przesunięcie
błędu: 0x000000000000606c  Identyfikator procesu powodującego błąd: 0x13f8  Godzina
uruchomienia aplikacji powodującej błąd: 0x01cff53f41bf686e  Ścieżka aplikacji powodującej
błąd: C:\Program Files\Sony\VAIO Care\VCSystemTray.exe  Ścieżka modułu powodującego
błąd: C:\WINDOWS\system32\KERNELBASE.dll  Identyfikator raportu: e902485a-6133-11e4-bea6-083e8ebd58f0
Pełna
nazwa pakietu powodującego błąd:   Identyfikator aplikacji względem pakietu powodującego
błąd:

Error - 2014-11-01 17:58:15 | Computer Name = Lila | Source = SideBySide | ID = 16842830
Description = Nie można wygenerować kontekstu aktywacji dla „C:\Users\Lidia\Downloads\SoftonicDownloader_dla_anty-plagiat.exe”.
Błąd w pliku manifestu lub w pliku zasad „” w wierszu .  Wersja składnika wymagana
przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna.
Składniki
powodujące konflikt:  Składnik 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Składnik
2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error - 2014-11-01 18:03:41 | Computer Name = Lila | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Aktywacja aplikacji Microsoft.SkypeApp_kzf8qxf38zg5c!App nie powiodła
się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

[ ESRV_SVC Events ]
Error - 2014-04-26 11:37:10 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

[ System Events ]
Error - 2014-11-22 07:23:12 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-11-22 07:32:31 | Computer Name = Lila | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x8007045b: Aktualizacja systemu
Windows 8.1 dla komputerów z procesorami x64 (KB2976978).

Error - 2014-11-22 07:32:31 | Computer Name = Lila | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x8007045b: Aktualizacja systemu
Windows 8.1 dla komputerów z procesorami x64 (KB3003667).

Error - 2014-11-22 07:32:31 | Computer Name = Lila | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x8007045b: Aktualizacja systemu
Windows 8.1 dla komputerów z procesorami x64 (KB3008627).

Error - 2014-11-22 07:32:31 | Computer Name = Lila | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x8007045b: Aktualizacja systemu
Windows 8.1 dla komputerów z procesorami x64 (KB2976536).

Error - 2014-11-22 08:55:24 | Computer Name = Lila | Source = APXACC | ID = 16778219
Description = The NDIS6 LWF initialization has failed. (0xC0000001)

Error - 2014-11-22 08:55:24 | Computer Name = Lila | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AppEx Networks Accelerator LWF z powodu
następującego błędu:   %%31

Error - 2014-11-22 08:55:37 | Computer Name = Lila | Source = Service Control Manager | ID = 7003
Description = Usługa McAfee Content Filter zależy od następującej usługi: mfefire.
Ta usługa może nie być zainstalowana.

Error - 2014-11-22 17:29:01 | Computer Name = Lila | Source = DCOM | ID = 10016
Description =

Error - 2014-11-22 17:29:16 | Computer Name = Lila | Source = Service Control Manager | ID = 7023
Description = Usługa Wstępne ładowanie do pamięci zakończyła działanie; wystąpił
następujący błąd:   %%1062


< End of report >


Kod: Zaznacz wszystko
OTL logfile created on: 2014-11-30 17:24:55 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 53,07% Memory free
4,20 Gb Paging File | 2,40 Gb Available in Paging File | 57,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,63 Gb Free Space | 77,30% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014-11-30 16:25:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lidia\Downloads\OTL.exe
PRC - [2014-11-27 06:01:14 | 001,880,752 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
PRC - [2014-11-21 11:49:07 | 005,226,600 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-11-12 13:31:44 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2012-08-18 05:36:14 | 000,188,072 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
PRC - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
PRC - [2012-08-18 00:04:28 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2012-07-27 15:03:40 | 000,724,576 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2014-11-27 06:01:13 | 016,841,392 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
MOD - [2014-11-21 11:48:48 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-11-12 13:31:42 | 003,649,648 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014-07-03 12:20:20 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014-07-03 12:19:50 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - File not found [Auto | Stopped] -- C:\Program Files\McAfeeEx\MOCP\core\mfeicfcore.exe -- (mfeicfcoreocp)
SRV:[b]64bit:[/b] - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,368,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2014-08-16 01:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2014-08-16 01:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014-07-24 08:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2014-03-14 07:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2014-03-08 06:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2014-03-06 08:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2014-02-28 16:05:06 | 001,642,544 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Update\VUAgent.exe -- (VUAgent)
SRV:[b]64bit:[/b] - [2014-02-22 16:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014-02-22 10:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014-02-22 10:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014-02-22 10:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014-02-22 10:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2014-02-20 14:34:44 | 000,060,504 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\VCService.exe -- (VCService)
SRV:[b]64bit:[/b] - [2013-12-13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2013-12-10 08:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (USER_ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,266,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:[b]64bit:[/b] - [2013-08-22 12:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2013-08-22 12:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2013-08-22 12:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2013-08-22 12:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2013-08-22 12:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2013-08-22 11:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2013-08-22 10:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2013-08-22 10:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013-08-22 10:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2013-08-22 10:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2012-08-06 12:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:[b]64bit:[/b] - [2012-07-19 18:55:44 | 000,476,328 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:[b]64bit:[/b] - [2011-12-01 10:04:56 | 000,289,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,467,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,306,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:06 | 008,277,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2014-11-27 06:01:15 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-11-12 13:31:42 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-03-14 07:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013-10-23 07:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-08-22 04:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013-08-22 03:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe -- (VAIO Event Service)
SRV - [2012-08-13 17:24:56 | 000,211,584 | ---- | M] (Qualcomm Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt&Wlan Coex Agent)
SRV - [2012-08-08 10:56:22 | 000,972,000 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2012-08-08 10:56:18 | 000,460,512 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2012-08-08 10:23:30 | 000,123,616 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2012-08-08 10:23:30 | 000,078,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2012-07-20 09:35:03 | 002,445,968 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswmonflt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2014-09-22 03:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2014-08-15 17:21:14 | 000,061,112 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}w64.sys -- ({16d667ee-6782-4b21-81df-8ded8ebc3868}w64)
DRV:[b]64bit:[/b] - [2014-08-15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2014-07-24 12:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014-06-10 20:50:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2014-05-01 14:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014-04-28 05:33:30 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2014-03-20 04:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2014-03-13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014-03-08 21:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2014-02-22 17:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2014-02-22 16:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2014-02-22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2013-12-04 19:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2013-11-14 08:37:27 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2013-11-14 08:31:22 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013-11-14 08:16:43 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013-08-22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2013-08-22 13:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2013-08-22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2013-08-22 12:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2013-08-22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2013-08-13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013-08-10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013-07-30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013-07-25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013-06-18 15:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2013-06-18 15:45:02 | 003,680,256 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:[b]64bit:[/b] - [2012-08-21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012-08-21 07:08:26 | 000,447,800 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2012-08-21 07:07:09 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:04 | 000,135,832 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:02 | 000,076,952 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,178,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,114,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,088,728 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,033,944 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2012-08-13 17:04:58 | 000,344,216 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:[b]64bit:[/b] - [2012-08-10 09:54:22 | 000,098,472 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2012-07-20 09:35:03 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:[b]64bit:[/b] - [2012-07-20 09:30:55 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2012-07-11 13:33:28 | 000,014,336 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:[b]64bit:[/b] - [2012-06-23 06:23:38 | 000,199,008 | ---- | M] (AppEx Networks Corporation) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\appexDrv.sys -- (APXACC)
DRV:[b]64bit:[/b] - [2012-06-22 07:36:54 | 000,106,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:[b]64bit:[/b] - [2012-06-11 03:43:12 | 000,024,280 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sows.sys -- (SOWS)
DRV:[b]64bit:[/b] - [2012-04-20 16:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes,DefaultScope = {5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{24D97AEC-213C-4349-B7B8-0DE6F373CF11}: "URL" = http://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=http://shop.ebay.co.uk/?oemInLn=ieSrch-Q312&_nkw={searchTerms}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{50C2A73E-51DB-4318-8387-EB8607BB64FE}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASEJS
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "http://google.pl/"
FF - prefs.js..extensions.enabledAddons: %7B6d0f26ba-45b8-4871-9c07-43ab341d5b73%7D:0.1
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.0.2502.149
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1


FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files\mcafee\msc\npMcSnFFPl64.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-21 11:48:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013-12-27 22:29:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Extensions
[2014-11-23 17:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions
[2014-08-24 16:09:58 | 000,000,000 | ---D | M] ("Site Advisor") -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions\{6d0f26ba-45b8-4871-9c07-43ab341d5b73}
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions\staged
[2014-11-23 17:09:39 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\firefox\profiles\7ta50hxd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-11-12 13:31:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014-11-12 13:31:46 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-11-21 11:48:55 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

O1 HOSTS File: ([2013-08-22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AnyProtect Scanner] "C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe" File not found
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BlockAndSurf] C:\Program Files (x86)\ver8BlockAndSurf\BlockAndSurf.exe File not found
O4 - HKLM..\Run: [fst_pl_178]  File not found
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey File not found
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 File not found
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{222B836A-01B7-4D7A-86EB-80D9B1F34080}: DhcpNameServer = 192.168.1.254
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell - "" = AutoRun
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell\AutoRun\command - "" = "F:\LaunchU3.exe" -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = "E:\Autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2014-11-30 16:35:02 | 000,386,680 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:56:11 | 000,106,976 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-22 13:56:10 | 000,714,208 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-21 11:48:57 | 000,364,512 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:50 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-18 19:56:23 | 001,519,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2014-11-18 19:56:21 | 000,258,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2014-11-18 19:56:20 | 000,114,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2014-11-18 19:56:20 | 000,035,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2014-11-18 19:56:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2014-11-18 19:56:19 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2014-11-18 19:55:44 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-11-18 19:55:44 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-18 19:55:43 | 000,537,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-11-18 19:55:42 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-18 19:55:38 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-11-18 19:55:33 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-11-18 19:55:32 | 002,773,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-11-18 19:55:30 | 002,459,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-11-18 19:55:29 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-11-18 19:55:29 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-11-18 19:55:29 | 000,116,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-11-15 06:07:56 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2014-11-15 06:07:55 | 000,104,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2014-11-15 06:07:55 | 000,088,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2014-11-15 06:07:09 | 000,500,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-11-15 06:07:09 | 000,394,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,482,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-11-15 06:07:08 | 000,344,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,272,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-11-15 06:07:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2014-11-15 06:07:07 | 000,108,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-11-15 06:03:08 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-11-15 06:02:52 | 002,865,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-11-15 06:02:49 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-11-15 06:02:49 | 000,661,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-11-15 06:02:48 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-11-15 06:02:48 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-11-15 06:02:46 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-11-15 06:02:46 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-11-15 06:02:45 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-11-15 06:02:44 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-11-15 06:02:43 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-11-15 06:02:42 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-11-15 06:02:42 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-11-15 06:02:41 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-11-15 06:02:40 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-11-15 06:02:40 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-11-15 06:02:38 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-11-15 06:02:33 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-11-15 06:02:33 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-11-15 06:02:33 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-11-15 06:02:32 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-11-15 06:02:32 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-11-15 06:02:32 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-11-15 06:02:32 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-11-15 06:02:32 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-11-15 06:02:32 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-11-15 06:02:31 | 000,417,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-11-15 06:02:31 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-11-15 06:02:31 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-11-15 06:02:31 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-11-15 06:02:30 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-11-15 06:02:30 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-11-15 06:02:30 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:30 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-11-15 06:02:29 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-11-15 06:02:29 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-11-15 06:02:29 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-11-15 06:02:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-11-15 06:02:28 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-11-15 06:02:28 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-11-15 06:02:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-11-15 06:02:27 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:26 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-11-15 06:02:26 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-11-15 06:02:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-11-15 06:02:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-11-15 06:02:25 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-11-15 06:02:25 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-11-15 06:02:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-11-15 06:02:25 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-11-15 06:02:25 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-11-15 06:02:24 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-11-15 06:02:24 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-11-15 06:02:24 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-11-15 06:02:24 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-11-15 06:02:23 | 000,237,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-11-15 06:02:23 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-11-15 06:02:23 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-11-15 06:02:22 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-11-15 06:02:22 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-11-15 06:02:22 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-11-15 06:02:21 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-11-15 06:02:21 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-11-15 06:01:16 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-11-15 06:01:16 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-11-15 06:01:10 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-11-15 06:01:10 | 001,441,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-11-15 06:01:09 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-11-15 06:01:09 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-11-15 06:01:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-11-15 06:01:07 | 000,027,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-11-15 06:01:06 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-11-15 06:00:09 | 000,789,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-11-15 05:59:54 | 000,894,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-11-15 05:59:53 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-11-15 05:59:52 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-11-15 05:59:52 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-11-15 05:59:51 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-11-15 05:59:51 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-11-15 05:59:50 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-11-15 05:59:50 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-11-15 05:59:50 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-11-15 05:59:49 | 000,055,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-11-15 05:59:49 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-11-15 05:59:49 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-11-15 05:59:49 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-11-15 05:59:48 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-11-15 05:59:48 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-11-15 05:59:34 | 007,484,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2014-11-15 05:59:29 | 002,714,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2014-11-15 05:59:28 | 013,424,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2014-11-15 05:59:24 | 001,053,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014-11-15 05:59:24 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2014-11-15 05:59:23 | 000,836,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2014-11-15 05:59:21 | 011,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2014-11-15 05:59:19 | 000,822,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2014-11-15 05:59:19 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2014-11-15 05:59:19 | 000,670,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2014-11-15 05:59:18 | 000,474,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2014-11-15 05:59:16 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2014-11-15 05:59:16 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2014-11-15 05:59:09 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014-11-15 05:59:07 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
[2014-11-15 05:59:06 | 000,485,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
[2014-11-15 05:59:00 | 000,615,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSCOMEX.dll
[2014-11-15 05:58:56 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSAPI.dll
[2014-11-15 05:58:56 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FXSAPI.dll
[2014-11-12 13:31:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014-11-01 22:54:21 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-11-01 22:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014-11-01 22:53:21 | 001,050,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-01 22:53:21 | 000,436,624 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-01 22:53:21 | 000,116,728 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-01 22:53:21 | 000,093,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-01 22:53:21 | 000,083,280 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-01 22:51:28 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2014-11-30 17:20:07 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014-11-30 17:18:03 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014-11-30 17:17:59 | 3066,671,104 | -HS- | M] () -- C:\hiberfil.sys
[2014-11-30 17:01:03 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:55:15 | 000,484,360 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-21 11:49:15 | 000,001,980 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014-11-21 11:48:54 | 000,267,632 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-21 11:48:53 | 000,364,512 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-21 11:48:53 | 000,065,776 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-21 11:48:53 | 000,029,208 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-11-21 11:48:50 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-20 21:51:37 | 000,714,208 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-20 21:51:37 | 000,106,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-05 00:38:37 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-04 01:10:18 | 000,304,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-02 01:51:02 | 000,807,160 | ---- | M] () -- C:\WINDOWS\SysNative\perfh015.dat
[2014-11-02 01:51:02 | 000,722,476 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014-11-02 01:51:02 | 000,163,478 | ---- | M] () -- C:\WINDOWS\SysNative\perfc015.dat
[2014-11-02 01:51:02 | 000,135,592 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014-11-02 01:51:01 | 001,825,074 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2014-11-21 11:49:15 | 000,001,980 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014-11-15 05:58:55 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014-11-01 22:53:21 | 000,267,632 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-01 22:53:21 | 000,065,776 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-01 22:53:21 | 000,029,208 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-08-16 18:02:22 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014-08-16 15:24:01 | 000,000,000 | ---- | C] () -- C:\Users\Lidia\AppData\Roaming\aps.uninstall.scan.results
[2014-05-01 02:03:48 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014-03-22 06:09:22 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014-02-11 13:48:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013-12-13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013-12-13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013-12-13 10:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013-12-13 10:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013-12-13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013-08-22 16:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013-08-22 16:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013-08-22 15:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013-08-22 08:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013-08-22 04:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013-08-22 00:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013-08-22 00:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2014-03-04 10:22:49 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-08-31 01:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-08-30 23:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-08-22 10:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013-08-22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-08-22 10:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2014-03-03 19:03:07 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\1H1Q
[2014-08-18 18:09:14 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\ap_logs
[2014-03-03 19:06:47 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\OpenOffice
[2014-05-05 18:56:35 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\Systweak
[2014-08-16 15:23:53 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\ap_logs
[2014-11-01 22:54:21 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-02-24 12:20:15 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje
[2014-02-24 12:20:16 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1
[2014-04-30 10:36:16 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\iolo
[2014-04-30 11:05:15 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\rightbackup
[2014-08-24 16:07:28 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\SimilarAddon
[2014-08-16 17:52:35 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\systweak

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 220 bytes -> C:\Users\Lidia\SkyDrive:ms-properties

< End of report >



gmer
Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-11-30 17:16:29
Windows 6.3.9600  x64 \Device\Harddisk0\DR0 -> \Device\00000029 Hitachi_HTS547550A9E384 rev.JE3OA50B 465,76GB
Running: 5iikfnoq.exe; Driver: C:\Users\Lidia\AppData\Local\Temp\pxldapow.sys


---- Kernel code sections - GMER 2.1 ----

.text   C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 960                             fffff801695e1f00 84 bytes [40, 01, A8, FF, 02, C4, 66, ...]

---- User code sections - GMER 2.1 ----

.text   C:\WINDOWS\Explorer.EXE[1012] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 714    00007fffacf0154a 4 bytes [F0, AC, FF, 7F]
.text   C:\WINDOWS\Explorer.EXE[1012] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 722    00007fffacf01552 4 bytes [F0, AC, FF, 7F]
.text   C:\WINDOWS\Explorer.EXE[1012] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 98   00007fffacf0162a 4 bytes [F0, AC, FF, 7F]
.text   C:\WINDOWS\Explorer.EXE[1012] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 122  00007fffacf01642 4 bytes [F0, AC, FF, 7F]

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\system32\csrss.exe [432:440]                                             fffff96000823b90

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                               unknown MBR code

---- EOF - GMER 2.1 ----
Załączniki
blad.png
blad gmera
blad.png (6.68 KiB) Obejrzany 238912 razy
hugo91
~user
 
Posty: 319
Dołączenie: 19 Cze 2006, 16:33
Pochwały: 6



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez ordynat 30 Lis 2014, 20:45

1) Użyj Adw-Cleaner http://www.programosy.pl/program,adwcleaner.html
najpierw kliknij na SZUKAJ, a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ, to kliknij na niego.
Daj z tego raport C:\AdwCleaner\AdwCleaner[S].txt.

2) Zrób nowy log z OTL.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez hugo91 01 Gru 2014, 00:14

Kod: Zaznacz wszystko
# AdwCleaner v4.102 - Log utworzony 30/11/2014 o 22:11:36
# Aktualizacja 23/11/2014 przez Xplode
# Database : 2014-11-27.1 [Live]
# System operacyjny : Windows 8.1  (64 bits)
# Użytkownik : Lidia - LILA
# Ścieżka : C:\Users\Lidia\Downloads\AdwCleaner.exe
# Opcja : Usuń

***** [ Usługi ] *****

Usługa Usunięto : {16d667ee-6782-4b21-81df-8ded8ebc3868}w64

***** [ Pliki / Foldery ] *****

Folder Usunięto : C:\ProgramData\iolo
Folder Usunięto : C:\Program Files (x86)\predm
Folder Usunięto : C:\Program Files (x86)\SiteLookup
Folder Usunięto : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Systweak
Folder Usunięto : C:\Users\Dom\AppData\Roaming\1H1Q
Folder Usunięto : C:\Users\Dom\AppData\Roaming\ap_logs
Folder Usunięto : C:\Users\Dom\AppData\Roaming\Systweak
Folder Usunięto : C:\Users\Lidia\AppData\Local\Temp\Yawtix
Folder Usunięto : C:\Users\Lidia\AppData\Roaming\ap_logs
Folder Usunięto : C:\Users\Lidia\AppData\Roaming\rightbackup
Folder Usunięto : C:\Users\Lidia\AppData\Roaming\SimilarAddon
Folder Usunięto : C:\Users\Lidia\AppData\Roaming\Systweak
Folder Usunięto : C:\Users\Lidia\AppData\Roaming\iolo
Plik Usunięto : C:\WINDOWS\System32\roboot64.exe
Plik Usunięto : C:\WINDOWS\System32\\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}w64.sys
Plik Usunięto : C:\Users\Dom\AppData\Roaming\aps.scan.quick.results
Plik Usunięto : C:\Users\Dom\AppData\Roaming\aps.scan.results
Plik Usunięto : C:\Users\Dom\AppData\Roaming\aps.uninstall.scan.results
Plik Usunięto : C:\Users\Lidia\AppData\Roaming\aps.uninstall.scan.results
Plik Usunięto : C:\Users\Lidia\Desktop\Continue Live Installation.lnk
Plik Usunięto : C:\Users\Dom\AppData\Roaming\Mozilla\Firefox\Profiles\hytnlelh.default\user.js
Plik Usunięto : C:\Users\Lidia\AppData\Roaming\Mozilla\Firefox\Profiles\7ta50hxd.default\user.js

***** [ Zadania ] *****

Zadanie Usunięto : APSnotifierPP1
Zadanie Usunięto : APSnotifierPP3

***** [ Skróty ] *****


***** [ Rejestr ] *****

Wartość Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [AnyProtect Scanner]
Wartość Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BlockAndSurf]
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Klucz Usunięto : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Klucz Usunięto : HKCU\Software\AnyProtect
Klucz Usunięto : HKCU\Software\Softonic
Klucz Usunięto : HKCU\Software\systweak
Klucz Usunięto : HKCU\Software\TutoTag
Klucz Usunięto : HKLM\SOFTWARE\FreeSoftToday
Klucz Usunięto : HKLM\SOFTWARE\systweak
Klucz Usunięto : HKLM\SOFTWARE\Tutorials

***** [ Przeglądarki internetowe ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v33.1 (x86 pl)


*************************

AdwCleaner[R0].txt - [3886 octets] - [30/11/2014 22:05:12]
AdwCleaner[S0].txt - [3476 octets] - [30/11/2014 22:11:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3536 octets] ##########


Kod: Zaznacz wszystko
OTL logfile created on: 2014-11-30 22:18:44 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 2,01 Gb Available Physical Memory | 56,26% Memory free
4,20 Gb Paging File | 2,52 Gb Available in Paging File | 59,99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,61 Gb Free Space | 77,29% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014-11-30 22:17:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lidia\Downloads\OTL.exe
PRC - [2014-11-27 06:01:14 | 001,880,752 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
PRC - [2014-11-21 11:49:07 | 005,226,600 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-11-12 13:31:44 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2012-08-18 05:36:14 | 000,188,072 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
PRC - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
PRC - [2012-08-18 00:04:28 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2012-08-06 13:30:40 | 000,642,216 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
PRC - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2012-07-27 15:03:40 | 000,724,576 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2014-11-27 06:01:13 | 016,841,392 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
MOD - [2014-11-21 11:48:48 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-11-12 13:31:42 | 003,649,648 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014-07-03 12:20:20 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014-07-03 12:19:50 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - File not found [Auto | Stopped] -- C:\Program Files\McAfeeEx\MOCP\core\mfeicfcore.exe -- (mfeicfcoreocp)
SRV:[b]64bit:[/b] - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,368,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2014-08-16 01:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2014-08-16 01:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014-07-24 08:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2014-03-14 07:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2014-03-08 06:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2014-03-06 08:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2014-02-28 16:05:06 | 001,642,544 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Update\VUAgent.exe -- (VUAgent)
SRV:[b]64bit:[/b] - [2014-02-22 16:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014-02-22 10:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014-02-22 10:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014-02-22 10:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014-02-22 10:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2014-02-20 14:34:44 | 000,060,504 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\VCService.exe -- (VCService)
SRV:[b]64bit:[/b] - [2013-12-13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2013-12-10 08:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (USER_ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,266,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:[b]64bit:[/b] - [2013-08-22 12:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2013-08-22 12:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2013-08-22 12:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2013-08-22 12:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2013-08-22 12:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2013-08-22 11:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2013-08-22 10:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2013-08-22 10:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013-08-22 10:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2013-08-22 10:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2012-08-06 12:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:[b]64bit:[/b] - [2012-07-19 18:55:44 | 000,476,328 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:[b]64bit:[/b] - [2011-12-01 10:04:56 | 000,289,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,467,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,306,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:06 | 008,277,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2014-11-27 06:01:15 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-11-12 13:31:42 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-03-14 07:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013-10-23 07:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-08-22 04:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013-08-22 03:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe -- (VAIO Event Service)
SRV - [2012-08-13 17:24:56 | 000,211,584 | ---- | M] (Qualcomm Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt&Wlan Coex Agent)
SRV - [2012-08-08 10:56:22 | 000,972,000 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2012-08-08 10:56:18 | 000,460,512 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2012-08-08 10:23:30 | 000,123,616 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2012-08-08 10:23:30 | 000,078,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2012-07-20 09:35:03 | 002,445,968 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswmonflt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2014-09-22 03:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2014-08-15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2014-07-24 12:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014-06-10 20:50:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2014-05-01 14:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014-04-28 05:33:30 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2014-03-20 04:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2014-03-13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014-03-08 21:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2014-02-22 17:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2014-02-22 16:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2014-02-22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2013-12-04 19:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2013-11-14 08:37:27 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2013-11-14 08:31:22 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013-11-14 08:16:43 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013-08-22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2013-08-22 13:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2013-08-22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2013-08-22 12:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2013-08-22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2013-08-13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013-08-10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013-07-30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013-07-25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013-06-18 15:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2013-06-18 15:45:02 | 003,680,256 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:[b]64bit:[/b] - [2012-08-21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012-08-21 07:08:26 | 000,447,800 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2012-08-21 07:07:09 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:04 | 000,135,832 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:02 | 000,076,952 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,178,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,114,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,088,728 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,033,944 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2012-08-13 17:04:58 | 000,344,216 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:[b]64bit:[/b] - [2012-08-10 09:54:22 | 000,098,472 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2012-07-20 09:35:03 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:[b]64bit:[/b] - [2012-07-20 09:30:55 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2012-07-11 13:33:28 | 000,014,336 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:[b]64bit:[/b] - [2012-06-23 06:23:38 | 000,199,008 | ---- | M] (AppEx Networks Corporation) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\appexDrv.sys -- (APXACC)
DRV:[b]64bit:[/b] - [2012-06-22 07:36:54 | 000,106,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:[b]64bit:[/b] - [2012-06-11 03:43:12 | 000,024,280 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sows.sys -- (SOWS)
DRV:[b]64bit:[/b] - [2012-04-20 16:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes,DefaultScope = {5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{24D97AEC-213C-4349-B7B8-0DE6F373CF11}: "URL" = http://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=http://shop.ebay.co.uk/?oemInLn=ieSrch-Q312&_nkw={searchTerms}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{50C2A73E-51DB-4318-8387-EB8607BB64FE}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASEJS
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "http://google.pl/"
FF - prefs.js..extensions.enabledAddons: %7B6d0f26ba-45b8-4871-9c07-43ab341d5b73%7D:0.1
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.0.2502.149
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files\mcafee\msc\npMcSnFFPl64.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-21 11:48:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013-12-27 22:29:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Extensions
[2014-11-23 17:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions
[2014-08-24 16:09:58 | 000,000,000 | ---D | M] ("Site Advisor") -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions\{6d0f26ba-45b8-4871-9c07-43ab341d5b73}
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions\staged
[2014-11-23 17:09:39 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\firefox\profiles\7ta50hxd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-11-12 13:31:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014-11-12 13:31:46 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-11-21 11:48:55 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

O1 HOSTS File: ([2013-08-22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [fst_pl_178]  File not found
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey File not found
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 File not found
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{222B836A-01B7-4D7A-86EB-80D9B1F34080}: DhcpNameServer = 192.168.1.254
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell - "" = AutoRun
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell\AutoRun\command - "" = "F:\LaunchU3.exe" -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = "E:\Autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2014-11-30 22:05:08 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-11-30 16:35:02 | 000,386,680 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:56:11 | 000,106,976 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-22 13:56:10 | 000,714,208 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-21 11:48:57 | 000,364,512 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:50 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-18 19:56:23 | 001,519,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2014-11-18 19:56:21 | 000,258,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2014-11-18 19:56:20 | 000,114,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2014-11-18 19:56:20 | 000,035,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2014-11-18 19:56:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2014-11-18 19:56:19 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2014-11-18 19:55:44 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-11-18 19:55:44 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-18 19:55:43 | 000,537,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-11-18 19:55:42 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-18 19:55:38 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-11-18 19:55:33 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-11-18 19:55:32 | 002,773,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-11-18 19:55:30 | 002,459,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-11-18 19:55:29 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-11-18 19:55:29 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-11-18 19:55:29 | 000,116,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-11-15 06:07:56 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2014-11-15 06:07:55 | 000,104,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2014-11-15 06:07:55 | 000,088,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2014-11-15 06:07:09 | 000,500,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-11-15 06:07:09 | 000,394,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,482,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-11-15 06:07:08 | 000,344,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,272,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-11-15 06:07:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2014-11-15 06:07:07 | 000,108,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-11-15 06:03:08 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-11-15 06:02:52 | 002,865,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-11-15 06:02:49 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-11-15 06:02:49 | 000,661,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-11-15 06:02:48 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-11-15 06:02:48 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-11-15 06:02:46 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-11-15 06:02:46 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-11-15 06:02:45 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-11-15 06:02:44 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-11-15 06:02:43 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-11-15 06:02:42 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-11-15 06:02:42 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-11-15 06:02:41 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-11-15 06:02:40 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-11-15 06:02:40 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-11-15 06:02:38 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-11-15 06:02:33 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-11-15 06:02:33 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-11-15 06:02:33 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-11-15 06:02:32 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-11-15 06:02:32 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-11-15 06:02:32 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-11-15 06:02:32 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-11-15 06:02:32 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-11-15 06:02:32 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-11-15 06:02:31 | 000,417,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-11-15 06:02:31 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-11-15 06:02:31 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-11-15 06:02:31 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-11-15 06:02:30 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-11-15 06:02:30 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-11-15 06:02:30 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:30 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-11-15 06:02:29 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-11-15 06:02:29 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-11-15 06:02:29 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-11-15 06:02:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-11-15 06:02:28 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-11-15 06:02:28 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-11-15 06:02:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-11-15 06:02:27 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:26 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-11-15 06:02:26 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-11-15 06:02:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-11-15 06:02:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-11-15 06:02:25 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-11-15 06:02:25 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-11-15 06:02:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-11-15 06:02:25 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-11-15 06:02:25 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-11-15 06:02:24 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-11-15 06:02:24 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-11-15 06:02:24 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-11-15 06:02:24 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-11-15 06:02:23 | 000,237,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-11-15 06:02:23 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-11-15 06:02:23 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-11-15 06:02:22 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-11-15 06:02:22 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-11-15 06:02:22 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-11-15 06:02:21 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-11-15 06:02:21 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-11-15 06:01:16 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-11-15 06:01:16 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-11-15 06:01:10 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-11-15 06:01:10 | 001,441,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-11-15 06:01:09 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-11-15 06:01:09 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-11-15 06:01:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-11-15 06:01:07 | 000,027,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-11-15 06:01:06 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-11-15 06:00:09 | 000,789,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-11-15 05:59:54 | 000,894,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-11-15 05:59:53 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-11-15 05:59:52 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-11-15 05:59:52 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-11-15 05:59:51 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-11-15 05:59:51 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-11-15 05:59:50 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-11-15 05:59:50 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-11-15 05:59:50 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-11-15 05:59:49 | 000,055,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-11-15 05:59:49 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-11-15 05:59:49 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-11-15 05:59:49 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-11-15 05:59:48 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-11-15 05:59:48 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-11-15 05:59:34 | 007,484,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2014-11-15 05:59:29 | 002,714,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2014-11-15 05:59:28 | 013,424,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2014-11-15 05:59:24 | 001,053,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014-11-15 05:59:24 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2014-11-15 05:59:23 | 000,836,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2014-11-15 05:59:21 | 011,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2014-11-15 05:59:19 | 000,822,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2014-11-15 05:59:19 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2014-11-15 05:59:19 | 000,670,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2014-11-15 05:59:18 | 000,474,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2014-11-15 05:59:16 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2014-11-15 05:59:16 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2014-11-15 05:59:09 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014-11-15 05:59:07 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
[2014-11-15 05:59:06 | 000,485,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
[2014-11-15 05:59:00 | 000,615,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSCOMEX.dll
[2014-11-15 05:58:56 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSAPI.dll
[2014-11-15 05:58:56 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FXSAPI.dll
[2014-11-12 13:31:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014-11-01 22:54:21 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-11-01 22:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014-11-01 22:53:21 | 001,050,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-01 22:53:21 | 000,436,624 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-01 22:53:21 | 000,116,728 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-01 22:53:21 | 000,093,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-01 22:53:21 | 000,083,280 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-01 22:51:28 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-10-22 17:54:16 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014-10-22 17:54:16 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2014-10-22 17:54:12 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2014-10-22 06:10:35 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2014-10-22 06:10:35 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2014-10-22 06:09:29 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2014-10-22 06:09:28 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2014-10-22 06:09:27 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2014-10-22 06:09:26 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2014-10-22 06:09:25 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2014-10-22 06:09:23 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2014-10-22 06:09:23 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2014-10-22 06:09:20 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll
[2014-10-22 06:09:19 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2014-10-22 06:09:18 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll
[2014-10-22 06:09:16 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll
[2014-10-22 06:09:08 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2014-10-22 06:09:07 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2014-10-22 06:09:06 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2014-10-22 06:09:06 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll
[2014-10-22 06:09:06 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll
[2014-10-22 06:09:05 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll
[2014-10-22 06:09:05 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll
[2014-10-22 06:09:04 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll
[2014-10-22 06:09:04 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll
[2014-10-22 06:09:04 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll
[2014-10-22 06:09:04 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll
[2014-10-22 06:09:03 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-10-22 06:09:02 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-10-21 04:25:21 | 016,874,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2014-10-21 04:25:14 | 012,730,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2014-10-21 04:25:05 | 002,389,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10warp.dll
[2014-10-21 04:24:59 | 002,141,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2014-10-21 04:24:56 | 002,145,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2014-10-21 04:24:53 | 001,600,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2014-10-21 04:24:51 | 001,231,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2014-10-21 04:24:48 | 000,889,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2014-10-21 04:24:47 | 002,574,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVDECOD.DLL
[2014-10-21 04:24:46 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SRH.dll
[2014-10-21 04:24:46 | 000,882,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2014-10-21 04:24:46 | 000,707,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2014-10-21 04:24:45 | 001,182,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\printui.dll
[2014-10-21 04:24:44 | 002,410,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMVDECOD.DLL
[2014-10-21 04:24:43 | 001,287,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mispace.dll
[2014-10-21 04:24:42 | 001,992,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsPrint.dll
[2014-10-21 04:24:40 | 000,770,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2014-10-21 04:24:40 | 000,486,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netcfgx.dll
[2014-10-21 04:24:39 | 001,057,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\printui.dll
[2014-10-21 04:24:39 | 001,029,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mispace.dll
[2014-10-21 04:24:39 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2014-10-21 04:24:39 | 000,391,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netcfgx.dll
[2014-10-21 04:24:38 | 001,741,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SRH.dll
[2014-10-21 04:24:38 | 001,018,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aclui.dll
[2014-10-21 04:24:38 | 000,412,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2014-10-21 04:24:37 | 000,371,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2014-10-21 04:24:37 | 000,360,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfreadwrite.dll
[2014-10-21 04:24:36 | 000,889,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aclui.dll
[2014-10-21 04:24:36 | 000,645,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SHCore.dll
[2014-10-21 04:24:36 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2014-10-21 04:24:36 | 000,355,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfreadwrite.dll
[2014-10-21 04:24:35 | 000,439,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2014-10-21 04:24:35 | 000,302,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanmsm.dll
[2014-10-21 04:24:34 | 000,180,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mftranscode.dll
[2014-10-21 04:24:33 | 002,397,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storagewmi.dll
[2014-10-21 04:24:33 | 000,477,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SHCore.dll
[2014-10-21 04:24:33 | 000,205,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mftranscode.dll
[2014-10-21 04:24:32 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2014-10-21 04:24:32 | 000,427,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clusapi.dll
[2014-10-21 04:24:32 | 000,287,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usbmon.dll
[2014-10-21 04:24:31 | 001,660,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2014-10-21 04:24:31 | 000,468,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2014-10-21 04:24:30 | 001,519,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2014-10-21 04:24:29 | 000,487,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winspool.drv
[2014-10-21 04:24:29 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wisp.dll
[2014-10-21 04:24:28 | 001,488,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2014-10-21 04:24:28 | 001,463,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wsecedit.dll
[2014-10-21 04:24:28 | 001,356,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2014-10-21 04:24:26 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clusapi.dll
[2014-10-21 04:24:26 | 000,160,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmmbase.dll
[2014-10-21 04:24:25 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WiFiDisplay.dll
[2014-10-21 04:24:23 | 001,817,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Display.dll
[2014-10-21 04:24:23 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdvidcrl.dll
[2014-10-21 04:24:23 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\conhost.exe
[2014-10-21 04:24:22 | 001,844,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Display.dll
[2014-10-21 04:24:22 | 001,404,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\storagewmi.dll
[2014-10-21 04:24:22 | 000,576,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSync.dll
[2014-10-21 04:24:22 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VAN.dll
[2014-10-21 04:24:22 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSip.dll
[2014-10-21 04:24:21 | 000,834,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\osk.exe
[2014-10-21 04:24:21 | 000,211,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVol.exe
[2014-10-21 04:24:21 | 000,127,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmmbase.dll
[2014-10-21 04:24:21 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersGPExt.dll
[2014-10-21 04:24:20 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DafPrintProvider.dll
[2014-10-21 04:24:20 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wisp.dll
[2014-10-21 04:24:19 | 000,387,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2014-10-21 04:24:19 | 000,233,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2014-10-21 04:24:19 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2014-10-21 04:24:18 | 000,335,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2014-10-21 04:24:18 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\NdisImPlatform.sys
[2014-10-21 04:24:17 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.dll
[2014-10-21 04:24:17 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.dll
[2014-10-21 04:24:17 | 000,125,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2014-10-21 04:24:17 | 000,123,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmm.dll
[2014-10-21 04:24:17 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxSip.dll
[2014-10-21 04:24:16 | 001,319,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wsecedit.dll
[2014-10-21 04:24:15 | 001,656,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2014-10-21 04:24:15 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\prnntfy.dll
[2014-10-21 04:24:14 | 001,089,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpedit.dll
[2014-10-21 04:24:14 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\prnntfy.dll
[2014-10-21 04:24:14 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersShell.dll
[2014-10-21 04:24:13 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsPrint.dll
[2014-10-21 04:24:13 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiapi.dll
[2014-10-21 04:24:13 | 000,162,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiapi.dll
[2014-10-21 04:24:11 | 000,448,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VAN.dll
[2014-10-21 04:24:11 | 000,180,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SndVol.exe
[2014-10-21 04:24:09 | 000,263,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlows.exe
[2014-10-21 04:24:08 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdvidcrl.dll
[2014-10-21 04:24:08 | 000,432,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanconn.dll
[2014-10-21 04:24:08 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2014-10-21 04:24:08 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2014-10-21 04:24:08 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dab.dll
[2014-10-21 04:24:08 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2014-10-21 04:24:06 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpedit.dll
[2014-10-21 04:24:06 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionCenter.dll
[2014-10-21 04:24:06 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2014-10-21 04:24:06 | 000,216,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rsaenh.dll
[2014-10-21 04:24:04 | 000,779,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\osk.exe
[2014-10-21 04:24:04 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.dll
[2014-10-21 04:24:03 | 000,557,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PrintDialogs.dll
[2014-10-21 04:24:03 | 000,459,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSync.dll
[2014-10-21 04:24:03 | 000,200,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DafPrintProvider.dll
[2014-10-21 04:24:02 | 000,659,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2014-10-21 04:24:01 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansvcpal.dll
[2014-10-21 04:23:58 | 000,832,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ActionCenter.dll
[2014-10-21 04:23:57 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powercfg.cpl
[2014-10-21 04:23:56 | 000,183,808 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysNative\Defrag.exe
[2014-10-21 04:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRUM.DLL
[2014-10-21 04:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRUM.DLL
[2014-10-21 04:23:55 | 001,351,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2014-10-21 04:23:54 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\powercfg.cpl
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDYAK.DLL
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU1.DLL
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDBASH.DLL
[2014-10-21 04:23:54 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU.DLL
[2014-10-21 04:23:53 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BluetoothApis.dll
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDYAK.DLL
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU1.DLL
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDBASH.DLL
[2014-10-21 04:23:52 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU.DLL
[2014-10-21 04:23:14 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintDialogs.dll
[2014-10-21 04:23:10 | 001,144,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanmm.dll
[2014-10-21 04:23:08 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTAT.DLL
[2014-10-21 04:23:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVolSSO.dll
[2014-10-21 04:23:07 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTAT.DLL
[2014-10-21 04:23:06 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\compstui.dll
[2014-10-21 04:23:06 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BluetoothApis.dll
[2014-10-21 04:23:05 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansec.dll
[2014-10-21 04:23:04 | 002,100,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlowUI.dll
[2014-10-21 04:23:02 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTT102.DLL
[2014-10-21 04:23:02 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTT102.DLL
[2014-10-21 04:14:49 | 002,084,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2014-10-21 04:14:49 | 000,796,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uDWM.dll
[2014-10-21 04:14:47 | 002,374,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2014-10-21 04:14:26 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UXInit.dll
[2014-10-21 04:14:26 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UXInit.dll
[2014-10-21 04:14:08 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSDMon.dll
[2014-10-21 04:14:08 | 000,205,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcpmon.dll
[2014-10-20 05:33:28 | 000,146,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpioclx.sys
[2014-10-17 12:02:12 | 000,875,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvcr120_clr0400.dll
[2014-10-17 12:02:12 | 000,869,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvcr120_clr0400.dll
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2014-11-30 22:15:03 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014-11-30 22:12:59 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014-11-30 22:12:56 | 3066,671,104 | -HS- | M] () -- C:\hiberfil.sys
[2014-11-30 18:01:02 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:55:15 | 000,484,360 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-21 11:49:15 | 000,001,980 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014-11-21 11:48:54 | 000,267,632 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-21 11:48:53 | 000,364,512 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-21 11:48:53 | 000,065,776 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-21 11:48:53 | 000,029,208 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-11-21 11:48:50 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-20 21:51:37 | 000,714,208 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-20 21:51:37 | 000,106,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-05 00:38:37 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-04 01:10:18 | 000,304,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-02 01:51:02 | 000,807,160 | ---- | M] () -- C:\WINDOWS\SysNative\perfh015.dat
[2014-11-02 01:51:02 | 000,722,476 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014-11-02 01:51:02 | 000,163,478 | ---- | M] () -- C:\WINDOWS\SysNative\perfc015.dat
[2014-11-02 01:51:02 | 000,135,592 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014-11-02 01:51:01 | 001,825,074 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014-10-31 06:12:41 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-10-31 06:12:05 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-10-31 06:10:13 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-10-31 06:09:37 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-10-31 06:08:00 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-10-31 06:06:45 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-10-31 06:06:21 | 000,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-10-31 06:06:09 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-10-31 06:06:00 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-10-31 06:05:50 | 000,417,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-10-31 06:04:28 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-10-31 05:56:53 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-10-31 05:54:13 | 000,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-10-31 05:53:32 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-10-31 05:53:06 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-10-31 05:52:22 | 000,108,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-10-31 05:51:37 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-10-31 05:51:31 | 000,812,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-10-31 05:50:44 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-10-31 05:50:11 | 006,040,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-10-31 05:49:39 | 000,537,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-10-31 05:40:07 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-10-31 05:38:28 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-10-31 05:30:28 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-10-31 05:29:50 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-10-31 05:29:17 | 000,087,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-10-31 05:28:58 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-10-31 05:25:24 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-10-31 05:24:48 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-10-31 05:24:25 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-10-31 05:23:46 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-10-31 05:21:30 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-10-31 05:19:49 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-10-31 05:05:52 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-10-31 05:05:35 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-10-31 05:03:02 | 002,124,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-10-31 04:44:32 | 002,865,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-10-31 04:42:04 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-10-31 04:28:47 | 000,137,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-10-31 04:27:26 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-10-31 04:26:45 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-10-31 04:25:24 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-10-31 04:24:23 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-10-31 04:24:00 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-10-31 04:23:37 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-10-31 04:23:21 | 000,340,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-10-31 04:22:08 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-10-31 04:20:27 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-10-31 04:15:59 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-10-31 04:14:25 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-10-31 04:13:35 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-10-31 04:12:17 | 000,661,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-10-31 04:12:17 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-10-31 04:11:30 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-10-31 04:03:33 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-10-31 03:57:20 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-10-31 03:56:44 | 000,090,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-10-31 03:56:18 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-10-31 03:56:08 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-10-31 03:53:21 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-10-31 03:52:23 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-10-31 03:51:02 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-10-31 03:48:50 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-10-31 03:39:28 | 002,051,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-10-31 03:11:30 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-10-23 06:48:37 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-10-23 06:05:08 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-10-18 10:55:17 | 000,055,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-10-18 09:09:52 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-10-18 09:09:44 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-10-18 08:25:54 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-10-18 07:50:21 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-10-18 07:27:15 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-10-18 07:26:48 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-10-18 07:23:51 | 000,407,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-10-18 07:23:11 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-10-18 07:21:47 | 000,894,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-10-18 07:20:43 | 001,714,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-10-18 07:14:54 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-10-18 07:14:32 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-10-18 07:12:10 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-10-18 07:11:35 | 000,723,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-10-18 06:20:02 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollectorres.dll
[2014-10-17 08:01:28 | 000,789,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-10-13 03:33:24 | 000,116,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-10-11 01:58:13 | 003,320,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-10-08 08:37:31 | 000,154,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-10-08 08:37:27 | 000,736,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-10-08 08:34:45 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-10-08 08:24:03 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-10-08 08:09:31 | 000,428,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-10-08 07:56:48 | 000,445,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-10-08 07:51:16 | 000,154,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-10-08 07:51:03 | 000,736,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-10-08 07:27:17 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-10-08 07:18:10 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-10-08 07:17:58 | 001,441,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-10-08 06:32:48 | 002,773,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-10-08 06:23:52 | 003,547,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-10-08 06:19:04 | 002,459,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-10-07 07:28:00 | 000,500,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-10-07 07:27:59 | 000,394,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-10-07 07:27:56 | 000,482,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-10-07 07:27:56 | 000,272,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-10-07 07:27:55 | 000,108,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-10-07 04:34:01 | 000,344,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2014-11-21 11:49:15 | 000,001,980 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014-11-15 05:58:55 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014-11-01 22:53:21 | 000,267,632 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-01 22:53:21 | 000,065,776 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-01 22:53:21 | 000,029,208 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-10-17 11:14:49 | 000,001,196 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xperia Link.lnk
[2014-10-03 02:45:20 | 000,000,998 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
[2014-08-16 18:02:22 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014-05-01 02:03:48 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014-03-22 06:09:22 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014-02-11 13:48:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013-12-13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013-12-13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013-12-13 10:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013-12-13 10:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013-12-13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013-08-22 16:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013-08-22 16:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013-08-22 15:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013-08-22 08:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013-08-22 04:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013-08-22 00:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013-08-22 00:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2014-03-04 10:22:49 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-08-31 01:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-08-30 23:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-08-22 10:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013-08-22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-08-22 10:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2014-03-03 19:06:47 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\OpenOffice
[2014-11-01 22:54:21 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-02-24 12:20:15 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje
[2014-02-24 12:20:16 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 220 bytes -> C:\Users\Lidia\SkyDrive:ms-properties

< End of report >


Kod: Zaznacz wszystko
OTL Extras logfile created on: 2014-11-30 22:18:44 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 2,01 Gb Available Physical Memory | 56,26% Memory free
4,20 Gb Paging File | 2,52 Gb Available in Paging File | 59,99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,61 Gb Free Space | 77,29% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{030F16B3-AC3F-4B85-AC18-6EF3E5F4F36C}" = rport=138 | protocol=17 | dir=out | app=system |
"{0E408148-2463-493C-974D-9831F0585CEE}" = lport=9996 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcsystemtray.exe |
"{199E3C84-2FDE-45F8-9913-CEF74D8D3499}" = lport=1900 | protocol=17 | dir=in | app=%programfiles%\zune\zune.exe |
"{19AFECAE-A699-4CCD-B7D2-172015BF52AA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BA398D1-E360-4F0D-9A98-5EAB8B6CB86B}" = rport=445 | protocol=6 | dir=out | app=system |
"{31113462-1629-4950-917E-0BF2DAA24DD8}" = lport=138 | protocol=17 | dir=in | app=system |
"{3B656BEE-00F6-450C-8B2A-B8B6EA1052A1}" = lport=445 | protocol=6 | dir=in | app=system |
"{3DE59B36-AF3E-4A20-8268-BF907CEF1972}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4CF0A1A0-996D-404B-BEB9-9ED8531E56BD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D06C62A-FF0C-4F4C-A019-9FCA8B50AAE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{538335E5-13F7-47F7-AE49-8A22B0E73D97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{550A699B-3CDF-49AB-A293-25E8A6ABAA81}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{55A8CA9F-00E5-4CAB-95E8-C51B169A51F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5FDD1F6D-898C-4865-8569-C10751DFED61}" = lport=2869 | protocol=6 | dir=in | app=system |
"{68243D58-392D-41F5-8FE7-E6151EDCF778}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6E23CD0C-702C-4253-A384-C9DB53797B8F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{747A8562-F3A7-4A9C-A2E8-DE0E0E2584A0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7A4A8B49-C91E-4D16-B17A-C7E940954444}" = lport=139 | protocol=6 | dir=in | app=system |
"{898FB1AB-3DFC-4CC1-81F1-084A319F3C00}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A921310-5D00-44ED-9AAF-40780C05A99E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9B997EBD-66BE-4CE7-BB01-81F7CFC56AB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{A04A87E8-DA87-47B1-A0F1-914AD3757D53}" = lport=9997 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vaioshell.exe |
"{AAB83954-A7FE-468B-8A89-95CF1163699A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B01E4F72-CD19-480B-A104-A4C349D3C314}" = lport=9999 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe |
"{B4688510-2513-4F34-8332-47DAB553E0A1}" = lport=9998 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcadmin.exe |
"{BA8646D0-E0D5-420F-92F4-D99D5B2B2C8B}" = lport=137 | protocol=17 | dir=in | app=system |
"{D95F677C-FE69-4D9C-A800-B512F493DBAC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FAE44678-023C-46B8-862D-59FEB9CF75C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FB6C0575-99EB-41D6-AD97-40511D65DC77}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FC9FD662-EA31-42C0-A9A0-AEADD0F29594}" = rport=137 | protocol=17 | dir=out | app=system |
"{FE0B0C3F-A187-41CA-90E8-A3AE57FBF8F9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001464FC-E3E9-4828-BC6F-628A59D79CE4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.315_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{02A0F843-9E76-4C52-A0EE-7C02CE119ADC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{02A6CE20-3CE5-4935-804F-AF1CFCC01946}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{06773AF9-A653-4505-9AF2-878617C09D4A}" = dir=in | name=taptiles |
"{08DD2950-9786-49FC-9B3B-45DE06576044}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{093A6F4D-638C-49E3-BB66-0F338B51A334}" = dir=in | name=microsoft solitaire collection |
"{0D9B20DA-20EC-43B7-AB43-6E400C3EB4A7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{124BE3DC-93D9-4D46-8FB3-94980959F22A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{153DDAFE-7284-48EB-BB8E-2780F4C8BB43}" = dir=out | name=@{microsoft.zunemusic_2.2.931.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{17DD9FB6-2AE2-471E-B4DE-BB0DEA030DA3}" = dir=in | name=mcafee® central for sony |
"{1A6B4D74-2A98-40D3-938B-78443AA3251A}" = dir=out | name=sony select |
"{1A73D7E3-209F-4D1E-9545-7E4D11323C68}" = protocol=6 | dir=out | app=system |
"{1FB698BF-4735-4CBE-97D8-4E4EB6AD0FDA}" = dir=out | name=microsoft minesweeper |
"{2084B1B9-C9A6-417F-981A-D787C0B7317F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{21BFDA3E-2A93-473F-B772-667B01076326}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{2351BED2-2143-49A4-B4C3-DCBADB8E91FB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{263B3EA9-9E48-4AD2-8EDA-310736EE78AC}" = dir=out | name=@{microsoft.bingsports_3.0.2.317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{263C5183-B2FF-45B8-BECF-2B335EAF1F29}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{26719D7A-D5A2-4702-AB87-C4CAF90E3605}" = dir=in | name=juniper networks junos pulse |
"{2E32F130-BCF1-48CD-AECB-955B43601A3C}" = dir=out | name=juniper networks junos pulse |
"{2F3E727D-CC71-4533-B584-803B1E0C529C}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{2F522F85-964D-4FF8-80C1-7E9429426005}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{2F6B21B3-CF42-47F6-85AE-C45095FBA812}" = dir=out | name=vaio care |
"{2F71F6D2-8B4A-4EF0-8648-C94D81EB80E2}" = dir=out | name=- games app - |
"{302DD789-2769-4D7E-8712-7A0E58B11304}" = dir=in | name=microsoft minesweeper |
"{313F0D2F-EC6F-4307-8C72-AC6B7C540249}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{32DD8247-27F1-43DD-A33B-3BFC3EB8E502}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3329E50E-D514-4A00-BE5C-6EFD44B75F77}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{34C71DC9-3CFB-4C30-897E-A7583222713E}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3A48B196-4B0B-4173-A984-65DFEAF9DACA}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{3F1B62FF-8F0B-4A0E-9C50-1D9AEA7B9BF3}" = dir=in | name=skype |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{43219BD5-F0C3-475C-94B2-C68B7247343C}" = dir=out | name=@{microsoft.zunevideo_1.5.338.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{438E36CC-1B94-41AE-ABC5-995653A8B9F1}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{48D4E687-B9F5-4AFE-892F-436F15B3996B}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{4A7C30CB-C022-43A2-A18A-0042C93A4C42}" = protocol=6 | dir=out | app=system |
"{4B4155A4-1EC0-4371-B5AB-4A1066774CC2}" = dir=in | name=mcafee® central for sony |
"{508A2261-AE87-4A3B-95B8-9AB6F5F1ECC2}" = dir=out | name=@{microsoft.bingtravel_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{55AC1D0D-797C-4B91-9F42-0214A591BABC}" = dir=in | name=microsoft solitaire collection |
"{55B1BF9D-EE69-4A5A-82D9-6A694741CC00}" = dir=in | name=microsoft minesweeper |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{5A6557A8-21E2-4D5F-8ECF-952E7B0666C3}" = dir=out | name=windows_ie_ac_001 |
"{5ABEA3F4-87D2-4151-B772-882064F87314}" = dir=out | name=check point vpn |
"{5B56F422-8C54-4727-88E1-461288305EF9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5C180B6B-167E-4C02-A378-B0F5BC88E08B}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{608400D0-4232-4911-83E4-BDFFF494F4DA}" = dir=out | name=taptiles |
"{623B3D06-7BEC-4583-A25F-3F45E6E6C449}" = dir=out | name=skype |
"{64FBCFD1-9BF5-44E0-93DE-6CF6FACBC84A}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{6693CC48-FD90-4B49-95EE-CBCDAD9B93BE}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{677D8E8B-AF81-4910-B6A9-A3E4385CAA94}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{685B3947-DDBC-48C2-985C-A81DC5EEADAB}" = dir=out | name=microsoft solitaire collection |
"{6CF61DE6-9F17-40BD-9670-67338B1C2A10}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{73BC64C0-6827-46BC-AC51-74B3C2B196CE}" = dir=in | app=c:\users\lidia\appdata\local\microsoft\skydrive\skydrive.exe |
"{74F762CD-615B-4D6E-8299-BCD640553F8C}" = dir=out | name=@{microsoft.bingweather_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{751944F4-D261-4D64-BA9E-FA82DE2F9048}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{78CE5D66-64B8-44C3-8F2F-9D28E336EAAD}" = dir=out | name=@{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{7BD0C972-641A-442F-ACD9-B312122F5921}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{822B057D-68BB-4593-996B-02C5FDEBB95B}" = dir=out | name=juniper networks junos pulse |
"{823FED70-BBA1-4705-8B37-7896CE34DCD9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8491F288-D7F9-4674-84C7-F3318C469372}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{856434AD-ADCA-4010-991F-62D9656039BD}" = protocol=6 | dir=out | app=system |
"{882A2F3D-5A0F-43E1-A53B-FE3DCEF867A8}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{88C7819F-C7CF-46B5-AE41-FED1A7FBD144}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{89B6F0BD-97A2-4C1A-953B-99B88725ACA1}" = dir=out | name=skype |
"{8C4DFB19-B22C-476A-ABAE-3DB39500DCB6}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{8D9777BA-1A90-4367-9191-574484072827}" = dir=out | name=wordament |
"{9238877F-603C-46ED-8F06-6F50FF39BC11}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{940E5550-504E-4037-9EE7-EC4CC2E0D1D9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9458264A-5F0C-44C1-81C3-479A589FB3E3}" = dir=out | name=f5 vpn |
"{96A32F70-AA90-47DD-9513-B7EFFAC25A65}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{97983CB2-9F05-4A90-9609-D03981F881CA}" = dir=out | name=@{microsoft.zunemusic_2.6.476.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{9820196B-CCF2-4B13-8362-7334EBEFACDE}" = dir=out | name=@{microsoft.bingnews_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{98B40748-33D7-45AB-9DB4-CAE11317C670}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{9A5BD996-2418-4372-AFE1-2D09C2648F34}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9E3B5818-96C3-430E-AF40-7D44969C65A4}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9F595940-23DC-48C5-B04D-EEFF37139C05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9F7E3951-E6AC-442E-A901-621741838FB2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9F8097D1-0C03-49CB-BF40-FB506509FC52}" = dir=out | name=windows_ie_ac_001 |
"{9FAC618A-BDEF-4D39-8BC4-98FAA73F54B9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A1E34056-B831-457A-8F2F-0A99315293CB}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{A317CFA9-E27F-494E-9601-E66D6FF76D27}" = dir=in | name=check point vpn |
"{A4AE9D4C-2657-4DE2-9A5E-90C35F65BCA5}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{A633D237-0CDA-42B1-A892-CE4248D109F5}" = dir=out | name=microsoft solitaire collection |
"{A7EAA7C9-A9FC-471E-89C6-F83C1BBB8B1F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A9EC2D1E-7E16-489A-AF3E-96BCCB03EF00}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{ACF7881E-0950-4BBE-99E4-320025746E05}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AF5FE555-86C7-4004-9037-062CAFC3233B}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{B4DB54BD-3FB9-462A-99D2-FE799A6D785D}" = dir=out | name=sony select |
"{B70810F0-B1ED-461F-A994-D6BE128B19AF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BC1BD523-BD0B-42B4-A3B3-EC6E24AE7F1E}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{BC9E5E3F-1D42-46B5-BC90-475E4D1364CD}" = dir=out | name=@{microsoft.bingmaps_2.1.2922.2139_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{BD018346-9CE3-4B57-9749-0BC8D368BB9B}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{BD9C016A-62EC-41F7-982C-DE3FD213C238}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0B0590D-8CB4-4B48-819F-9FE86F23F560}" = dir=out | name=vaio care |
"{C176AFC8-9DC3-410B-9D00-3B76F677A3E9}" = dir=out | name=check point vpn |
"{C2125D7A-F3EA-45B5-9ED5-76FBE4032813}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{C2466120-2EE4-47CD-BF95-688F79D435F8}" = dir=out | name=@{microsoft.zunevideo_2.6.215.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{C3F01482-0DB4-42CD-8A91-7172BE718019}" = dir=out | name=mcafee® central for sony |
"{C40839CB-E672-41BE-8179-77239F483D3B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C64B97B6-4AA6-4DD8-B4A5-1EBE1C68A53F}" = dir=out | name=windows_ie_ac_001 |
"{C6E9145A-0EE9-44DE-8A58-FF97231D8F5E}" = dir=out | name=f5 vpn |
"{C7389275-089D-4764-829D-FA319B338401}" = dir=out | name=sonicwall mobile connect |
"{C778CDD6-6BF6-4811-8375-B446ABBEDAC7}" = dir=in | name=vaio care |
"{CA45CB10-1ADB-4A15-929E-5497A2E623D9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CB354727-1CD4-4820-A6C8-6F6D2258101E}" = dir=in | name=check point vpn |
"{CCE7A28A-1B1C-4441-9697-ACD7A435C068}" = dir=in | name=sonicwall mobile connect |
"{CE7E2FBF-222A-40BB-97F8-28ABCFC857C1}" = dir=out | name=windows_ie_ac_001 |
"{D032395D-1786-4F9A-A512-8E07703A2B8D}" = dir=out | name=- games app - |
"{D14AF6D4-42A7-4DB7-AFDE-B34B169C7083}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{D23153B5-2163-49F8-9B26-77F501379547}" = dir=out | name=sonicwall mobile connect |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D70EAC0A-DAEE-4F16-A109-02929D410E67}" = dir=out | name=windows_ie_ac_001 |
"{D7880873-CC9D-4D1D-A52C-68FF92783C2D}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{D7D933AC-4D60-4F38-A828-64D4B46323C7}" = dir=out | name=microsoft minesweeper |
"{D8A0E1E8-82AA-48D2-8944-16525F39DE93}" = dir=in | name=skype |
"{DA3CF7A9-20F0-450E-A5A2-9651DD78FBC0}" = dir=in | name=juniper networks junos pulse |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DBFE4C41-4629-434B-B3F7-DFB0DEC44110}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DCB2A9F6-2AB1-4A41-B522-AF44BFD1D0BD}" = dir=in | name=vaio care |
"{DCCA78F9-2906-43B9-9B9C-76DBDC822912}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{DCD62A33-757D-4DF6-AD27-D3034BC8AB28}" = dir=in | name=f5 vpn |
"{DDB99518-2F6D-493A-A867-9A63600834F7}" = dir=in | name=sonicwall mobile connect |
"{E2ECA714-68DE-4E5B-9EEA-CCDDF1FFB846}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{E3E85A51-C589-4CB7-80C7-C553CEA3EC0B}" = dir=out | name=@{microsoft.zunevideo_2.6.408.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{E4705F09-9887-4F2B-8479-ADFC2DF1BBA3}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{E53611B4-545A-492D-A815-6B3F552E1646}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{E7211AB8-916E-4392-9278-045F599DFB54}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E76059C4-6926-4F96-8A2C-4FD2F0AEF1A8}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E8726D91-8391-485A-9E9B-4BCF023A311A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{ECBF3C57-D6CB-462F-BCB5-F5BBEE88E889}" = dir=out | name=mcafee® central for sony |
"{ECCDA18D-D39B-4815-9E46-AE9CA2E748B4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{EFD9D7E7-9D74-404A-B33A-9004227CE02D}" = dir=out | name=taptiles |
"{EFEA28EC-C9B1-4471-8630-DE38648359B4}" = dir=in | name=taptiles |
"{F1A5B808-1673-44B2-B0BC-0193CFFB8C33}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F230AAB7-996E-4D3B-B0EA-46CAEF46C59E}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{F9F0C374-492A-4350-B24C-D83A28B86960}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{FAF0E88C-088B-43DB-B464-41B743A98699}" = dir=out | name=wordament |
"{FBA7E63F-58E8-4C71-A003-A30F847720A5}" = dir=in | name=f5 vpn |
"TCP Query User{78B7C52D-B45B-4915-BD53-FCB6FC9D571B}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{E5F1B4C1-BBE5-457E-AE34-CDF31F9BDDEF}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{553A0E06-4AC5-46F5-B7DC-6D94EA0C3373}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{AA0903BB-5077-41E3-9785-1B6C21C88CD3}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{15B9204E-BA09-485E-8F2C-094AC0077664}" = VAIO Care Recovery
"{25ECAFCB-DCFB-4FCE-A5B2-772A57F59860}" = VCCx64
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{30EC1664-6916-5E36-FEA7-8E20B1C4DCD7}" = ccc-utility64
"{312395BC-7CC2-434C-A660-30250276A926}" = SSLx64
"{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}" = iTunes
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{46261E1C-5E0D-484E-8CCC-7F770375FBA2}" = VU5x64
"{4B432082-B58C-4035-91FB-F28D504D3148}" = VUx64
"{4F31AC31-0A28-4F5A-8416-513972DA1F79}" = VSSTx64
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{5388ABD8-6E23-4498-BE10-01079387590F}" = VGClientX64
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62A172B2-550E-499D-9A82-5190D18390AA}" = VAIO Media Server Settings
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}" = Apple Mobile Device Support
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{77619545-1710-CA11-4487-4CD836E76DB9}" = AMD Fuel
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007
"{92907606-B2FC-4193-B0CE-A21159DA3ABB}" = VAIO Care
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{AB447E3B-7A95-4CA6-8ECD-B25C96314B67}" = VCCx64
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{B81EACDF-16E0-A32C-F096-16EF2BD8405C}" = AMD Catalyst Install Manager
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{D55EAC07-7207-44BD-B524-0F063F327743}" = VIx64
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}" = VPMx64
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 5.10 (64-bitowy)
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"{10181264-340D-4BE7-B879-3A49604A6FD1}" = VUx86
"{10DD6128-A810-4A90-9523-475D573FBB37}" = PlayMemories Home
"{14AC95A2-7675-4988-A5BD-3F5B943AED08}" = VAIO Gate
"{1A207C93-12E4-5B88-777D-92F74DC29EDD}" = CCC Help Hungarian
"{1AE56779-2A31-8982-FF75-422457BA5123}" = CCC Help Danish
"{1B740CAA-D283-4662-0469-898A0850B622}" = CCC Help Chinese Traditional
"{1C7DDA73-0C05-E7DD-97A8-A8542B8EA404}" = CCC Help Norwegian
"{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}" = Obsługa programów Apple
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{26A3AC60-368D-D7FE-30C9-C85E4E1FD7EC}" = CCC Help Turkish
"{309DDAE9-A147-56A2-456D-F66BCEFA88E5}" = Catalyst Control Center Graphics Previews Common
"{3490653F-2789-46A1-B1BF-6BD4CF4131AB}" = FDUx86
"{3A26D9BD-0F73-432D-B522-2BA18138F7EF}" = VAIO Improvement
"{3B1AECFC-F652-9877-B6BE-5BFB5023B02F}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523ADF33-0165-88B2-E05E-22C934058B81}" = CCC Help German
"{54BDD1B2-1312-EF6F-ED92-1C300377D9DE}" = CCC Help Greek
"{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
"{60D1433B-175B-B907-DD89-D434997BEBEC}" = CCC Help Russian
"{63C43435-F428-42BA-8E7B-5848749D9262}" = SSLx86
"{641256B0-734F-2B3E-4AEA-4B2AB21F8916}" = Catalyst Control Center Profiles Mobile
"{661598FC-D512-F972-22D8-620D36CEA58B}" = CCC Help Italian
"{692955F2-DE9F-4078-8FAA-858D6F3A1776}" = VAIO Gesture Control
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{74B53C92-E8E8-1903-76FE-A113448EB504}" = CCC Help Japanese
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79954639-C427-4B14-B774-2F6EE649BE99}" = Catalyst Control Center - Branding
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{7AD4F11E-E27C-1455-3F32-076ABB2CE633}" = Catalyst Control Center InstallProxy
"{7B6D6F11-A5BC-4538-0017-21350BA54ED4}" = CCC Help Portuguese
"{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
"{7E5A5CA6-B7D0-406E-A75E-157CAB47EB94}" = VMLx86
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{82CFAFBA-3D52-F45B-67B1-3D1885C7F87D}" = CCC Help Thai
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{857087BB-A988-4462-A5C6-CF6739143B56}" = KUx86
"{88AEC113-3901-0902-A0B8-651A74D005BF}" = CCC Help Chinese Standard
"{8E797841-A110-41FD-B17A-3ABC0641187A}" = VAIO Control Center
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{913E2B02-1BA9-4B38-991B-31C717F9D00C}" = e-Deklaracje Desktop
"{94211EE0-14F9-58C8-676B-54462CB2A346}" = CCC Help Finnish
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
"{9D8112DB-3490-4BF1-AAFA-1D224FFB5D3C}" = VHD
"{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
"{A2F10E60-5D7D-E13B-E451-99A70EBB7C39}" = CCC Help Spanish
"{AA4B3623-6213-41EC-9BFB-F001D72C47A6}" = VAIO Gesture Control
"{AB57D823-F5BE-38AF-DD26-8E04E64308AA}" = CCC Help Polish
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.10) MUI
"{AFDC0CC0-39E8-42C0-9823-2C1C182676DC}" = VCCx86
"{AFE24FB0-8CC3-77A5-EBFA-132FD250FE66}" = CCC Help English
"{B24BB74E-8359-43AA-985A-8E80C9219C70}" = VSSTx86
"{B31938C7-7E97-49EE-8F88-951E156268A3}" = VCCx86
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B8991D99-88FD-41F2-8C32-DB70278D5C30}" = VWSTx86
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BCBBD089-FF54-3F73-2FB5-F3DD7ED7B439}" = Catalyst Control Center Localization All
"{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}" = VAIO CPU Fan Diagnostic
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C4001DF8-CE87-B7C5-5AC8-D8C321D070EA}" = CCC Help French
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
"{C820FBC5-0490-B6D7-0AF5-D8245E1BD903}" = CCC Help Swedish
"{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}" = VIx86
"{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
"{D91558BF-D1F3-411F-AEFE-8774CB406512}" = VAIO - Xperia Link
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ECCEB4D0-7080-4F8A-B498-E40A32A4FBED}" = Restore
"{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}" = XperiaLinkx86
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F458075C-E1AB-F9A6-3B97-D80BF7EC44A5}" = CCC Help Korean
"{F55687F5-D221-604B-61EA-49E80DB04D11}" = AMD VISION Engine Control Center
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FC9F3001-77BD-D664-5941-6E3F16203629}" = CCC Help Czech
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Avast" = Avast Free Antivirus
"e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1" = e-Deklaracje Desktop
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"Mozilla Firefox 33.1 (x86 pl)" = Mozilla Firefox 33.1 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NetSender_is1" = NetSender 3.0
"Picasa 3" = Picasa 3
"PIT Format 2013_is1" = PIT Format 2013
"PITy 2013/2014_is1" = PITy 2013/2014

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SkyDriveSetup.exe" = Microsoft SkyDrive

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2014-10-23 16:08:53 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2110

Error - 2014-10-23 21:28:22 | Computer Name = Lila | Source = Application Hang | ID = 1002
Description = Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować
z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej
informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum
akcji w Panelu sterowania.    Identyfikator procesu: 1010    Godzina rozpoczęcia: 01cfeef499eef0c0

Godzina
zakończenia: 4294967295    Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe    Identyfikator
raportu: 0617afd9-5b1d-11e4-bea5-083e8ebd58f0    Pełna nazwa pakietu powodującego błąd:
Microsoft.SkypeApp_3.1.0.1005_x86__kzf8qxf38zg5c    Identyfikator aplikacji względem
pakietu powodującego błąd: App 

Error - 2014-10-24 15:24:32 | Computer Name = Lila | Source = Application Hang | ID = 1002
Description = Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować
z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej
informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum
akcji w Panelu sterowania.    Identyfikator procesu: 1d44    Godzina rozpoczęcia: 01cfefbf128c9628

Godzina
zakończenia: 4294967295    Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe    Identyfikator
raportu: 5fd0f8db-5bb3-11e4-bea5-083e8ebd58f0    Pełna nazwa pakietu powodującego błąd:
Microsoft.SkypeApp_3.1.0.1005_x86__kzf8qxf38zg5c    Identyfikator aplikacji względem
pakietu powodującego błąd: App 

Error - 2014-10-31 15:27:11 | Computer Name = Lila | Source = .NET Runtime | ID = 1026
Description =

Error - 2014-10-31 15:27:11 | Computer Name = Lila | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: VCSystemTray.exe, wersja: 8.4.0.14200,
sygnatura czasowa: 0x53056230  Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja:
6.3.9600.17278, sygnatura czasowa: 0x53eebf2e  Kod wyjątku: 0xe0434352  Przesunięcie
błędu: 0x000000000000606c  Identyfikator procesu powodującego błąd: 0x13f8  Godzina
uruchomienia aplikacji powodującej błąd: 0x01cff53f41bf686e  Ścieżka aplikacji powodującej
błąd: C:\Program Files\Sony\VAIO Care\VCSystemTray.exe  Ścieżka modułu powodującego
błąd: C:\WINDOWS\system32\KERNELBASE.dll  Identyfikator raportu: e902485a-6133-11e4-bea6-083e8ebd58f0
Pełna
nazwa pakietu powodującego błąd:   Identyfikator aplikacji względem pakietu powodującego
błąd:

Error - 2014-11-01 17:58:15 | Computer Name = Lila | Source = SideBySide | ID = 16842830
Description = Nie można wygenerować kontekstu aktywacji dla „C:\Users\Lidia\Downloads\SoftonicDownloader_dla_anty-plagiat.exe”.
Błąd w pliku manifestu lub w pliku zasad „” w wierszu .  Wersja składnika wymagana
przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna.
Składniki
powodujące konflikt:  Składnik 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Składnik
2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error - 2014-11-01 18:03:41 | Computer Name = Lila | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Aktywacja aplikacji Microsoft.SkypeApp_kzf8qxf38zg5c!App nie powiodła
się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error - 2014-11-07 01:55:27 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2014-11-07 01:55:27 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 91476578

Error - 2014-11-07 01:55:27 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 91476578

[ ESRV_SVC Events ]
Error - 2014-04-26 11:37:10 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

[ System Events ]
Error - 2014-11-22 07:32:31 | Computer Name = Lila | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x8007045b: Aktualizacja systemu
Windows 8.1 dla komputerów z procesorami x64 (KB3008627).

Error - 2014-11-22 07:32:31 | Computer Name = Lila | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x8007045b: Aktualizacja systemu
Windows 8.1 dla komputerów z procesorami x64 (KB2976536).

Error - 2014-11-22 08:55:24 | Computer Name = Lila | Source = APXACC | ID = 16778219
Description = The NDIS6 LWF initialization has failed. (0xC0000001)

Error - 2014-11-22 08:55:24 | Computer Name = Lila | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AppEx Networks Accelerator LWF z powodu
następującego błędu:   %%31

Error - 2014-11-22 08:55:37 | Computer Name = Lila | Source = Service Control Manager | ID = 7003
Description = Usługa McAfee Content Filter zależy od następującej usługi: mfefire.
Ta usługa może nie być zainstalowana.

Error - 2014-11-22 17:29:01 | Computer Name = Lila | Source = DCOM | ID = 10016
Description =

Error - 2014-11-22 17:29:16 | Computer Name = Lila | Source = Service Control Manager | ID = 7023
Description = Usługa Wstępne ładowanie do pamięci zakończyła działanie; wystąpił
następujący błąd:   %%1062

Error - 2014-11-22 17:30:29 | Computer Name = Lila | Source = APXACC | ID = 16778219
Description = The NDIS6 LWF initialization has failed. (0xC0000001)

Error - 2014-11-22 17:30:29 | Computer Name = Lila | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AppEx Networks Accelerator LWF z powodu
następującego błędu:   %%31

Error - 2014-11-22 17:30:47 | Computer Name = Lila | Source = Service Control Manager | ID = 7003
Description = Usługa McAfee Content Filter zależy od następującej usługi: mfefire.
Ta usługa może nie być zainstalowana.


< End of report >
hugo91
~user
 
Posty: 319
Dołączenie: 19 Cze 2006, 16:33
Pochwały: 6



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez ordynat 01 Gru 2014, 00:22

Kosmetyka:
Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej to:
:OTL
[2014-11-15 05:58:55 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
O4 - HKLM..\Run: [fst_pl_178] File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\McAfeeEx\MOCP\core\mfeicfcore.exe -- (mfeicfcoreocp)

:Commands
[emptytemp]

Kliknij w Wykonaj Skrypt.

Raportu z tego już nie dawaj.

Kończymy:
W Adw-Cleaner kliknij na przycisk Odinstaluj (UNINSTALL).
W OTL kliknij na przycisk Sprzątanie - to go usunie razem z jego Kwarantanną.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez hugo91 01 Gru 2014, 23:10

gotowe, aczkolwiek jest moze minimalna roznica, jest nieco lepiej, co nie zmienia faktu ze dalej tnie go, najgorsze jest to ze otl nie chce odpalic, tzn dziala jako aplikacja w tle - ale okno nie chce sie ukazac, rozszezenie exe com src czy scr tak samo..


jedynie am log gmera ktory jest i tak okrojony bo bledy wyskakuja, moge powiedziec jeszcze ze na niektorych stronach mam tak ze jak sa jakies slowa to one sa podwojnie podkreslone i wykrywa mi jak by linki do tych slow. Jeszcze mam tak dziwnie w windzie ze nie moze mi zapisac ustawien ze pliki ukryte maja byc ukryte i ma ukrywac rozszerzenia plikow

Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-12-01 21:53:44
Windows 6.3.9600  x64 \Device\Harddisk0\DR0 -> \Device\00000029 Hitachi_HTS547550A9E384 rev.JE3OA50B 465,76GB
Running: uj1cm00z.exe; Driver: C:\Users\Lidia\AppData\Local\Temp\pxldapow.sys


---- Kernel code sections - GMER 2.1 ----

.text   C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 960                             fffff80247dd8f00 4 bytes [40, 01, A8, FF]
.text   C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 965                             fffff80247dd8f05 84 bytes [C4, 66, 03, C0, 88, B4, 04, ...]

---- User code sections - GMER 2.1 ----

.text   C:\WINDOWS\Explorer.EXE[1004] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 714    00007fffc060154a 4 bytes [60, C0, FF, 7F]
.text   C:\WINDOWS\Explorer.EXE[1004] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 722    00007fffc0601552 4 bytes [60, C0, FF, 7F]
.text   C:\WINDOWS\Explorer.EXE[1004] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 98   00007fffc060162a 4 bytes [60, C0, FF, 7F]
.text   C:\WINDOWS\Explorer.EXE[1004] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 122  00007fffc0601642 4 bytes [60, C0, FF, 7F]

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\system32\csrss.exe [440:448]                                             fffff96000929b90

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                               unknown MBR code

---- EOF - GMER 2.1 ----
hugo91
~user
 
Posty: 319
Dołączenie: 19 Cze 2006, 16:33
Pochwały: 6



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez ordynat 02 Gru 2014, 00:03

dalej tnie go

Nie zajmuję się złym działaniem komputera - to nie do tego działu Forum.

Czy problem reklam zniknął?

Możesz ewentualnie dać jeszcze logi z FRST http://forum.programosy.pl/frst-otl-zoek-vt139692.html
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez hugo91 02 Gru 2014, 20:49

reklamy niestety dalej wywala

Kod: Zaznacz wszystko
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2014
Ran by Lidia (administrator) on LILA on 02-12-2014 19:37:39
Running from C:\Users\Lidia\Desktop
Loaded Profile: Lidia (Available profiles: Lidia & Dom)
Platform: Windows 8.1 (X64) OS Language: Polski (Polska)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
() C:\Program Files\Sony\VAIO Care\listener.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-08-03] (Realtek Semiconductor)
HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-08-13] ()
HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-21] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [68776 2012-08-18] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [724576 2012-07-27] (Sony Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-21] (AVAST Software)
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\...\MountPoints2: E - "E:\Autorun.exe"
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\...\MountPoints2: {596cede7-8087-11e3-be8b-083e8ebd58f0} - "F:\LaunchU3.exe" -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Parental Controls.lnk
ShortcutTarget: McAfee Parental Controls.lnk -> C:\Program Files\McAfeeEx\MOCP\core\OcpTray.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://sony13.msn.com
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony13.msn.com
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://vaioportal.sony.eu
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://vaioportal.sony.eu
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKU\S-1-5-21-2017453163-4049187296-263026530-1002 -> {24D97AEC-213C-4349-B7B8-0DE6F373CF11} URL = http://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=http://shop.ebay.co.uk/?oemInLn=ieSrch-Q312&_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-2017453163-4049187296-263026530-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\Lidia\AppData\Roaming\Mozilla\Firefox\Profiles\7ta50hxd.default
FF Homepage: hxxp://google.pl/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\mcafee\msc\npMcSnFFPl64.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.0 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.0 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Site Advisor - C:\Users\Lidia\AppData\Roaming\Mozilla\Firefox\Profiles\7ta50hxd.default\Extensions\{6d0f26ba-45b8-4871-9c07-43ab341d5b73} [2014-08-24]
FF Extension: Adblock Plus - C:\Users\Lidia\AppData\Roaming\Mozilla\Firefox\Profiles\7ta50hxd.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-23]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-12]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-01]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: No Name - wrc@avast.com [Not Found]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-11-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-21]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-13] (Qualcomm Atheros Commnucations)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-21] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-19] (Intel Corporation)
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [474208 2012-07-27] (Sony Corporation)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [266168 2013-11-19] (Intel Corporation)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-19] (Intel Corporation)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [972000 2012-08-08] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-13] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-21] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-21] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-08-10] (Advanced Micro Devices)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-13] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106112 2012-06-22] (McAfee, Inc.)
R3 SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver_AMDASF.sys [41272 2012-08-21] (Synaptics Incorporated)
R3 SOWS; C:\Windows\System32\drivers\sows.sys [24280 2012-06-11] (Sony Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-11-30] (Duplex Secure Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-02 19:37 - 2014-12-02 19:38 - 00016709 _____ () C:\Users\Lidia\Desktop\FRST.txt
2014-12-02 19:36 - 2014-12-02 19:37 - 00000000 ____D () C:\FRST
2014-12-02 19:35 - 2014-12-02 19:35 - 02117120 _____ (Farbar) C:\Users\Lidia\Desktop\FRST64.exe
2014-12-01 22:02 - 2014-12-01 22:02 - 00602112 _____ (OldTimer Tools) C:\Users\Lidia\Downloads\OTL.scr
2014-12-01 22:01 - 2014-12-01 22:01 - 00602112 _____ (OldTimer Tools) C:\Users\Lidia\Downloads\OTL.com
2014-12-01 21:49 - 2014-12-01 21:49 - 00000000 ____D () C:\_OTL
2014-11-30 16:35 - 2014-11-30 16:35 - 00386680 _____ (Duplex Secure Ltd.) C:\WINDOWS\system32\Drivers\sptd.sys
2014-11-22 13:56 - 2014-11-20 21:51 - 00714208 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-11-22 13:56 - 2014-11-20 21:51 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-21 11:49 - 2014-11-21 11:49 - 00001980 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2014-11-21 11:48 - 2014-11-21 11:48 - 00364512 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-11-21 11:48 - 2014-11-21 11:48 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-11-21 06:11 - 2014-11-10 00:19 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2014-11-21 06:11 - 2014-11-10 00:19 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2014-11-21 06:11 - 2014-11-10 00:18 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2014-11-21 06:11 - 2014-11-10 00:18 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2014-11-18 19:56 - 2014-09-22 05:38 - 01519488 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2014-11-18 19:56 - 2014-09-22 04:06 - 00258368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-11-18 19:56 - 2014-09-22 04:06 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-11-18 19:56 - 2014-09-22 03:49 - 00035320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-11-18 19:56 - 2014-09-19 01:16 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2014-11-18 19:56 - 2014-09-02 23:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2014-11-18 19:56 - 2014-09-02 23:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2014-11-18 19:55 - 2014-11-05 00:38 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-11-18 19:55 - 2014-11-04 01:10 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2014-11-18 19:55 - 2014-10-31 05:53 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2014-11-18 19:55 - 2014-10-31 05:49 - 00537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-11-18 19:55 - 2014-10-31 05:24 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-11-18 19:55 - 2014-10-13 03:33 - 00116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-11-18 19:55 - 2014-10-11 01:58 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-11-18 19:55 - 2014-10-11 01:53 - 03607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-11-18 19:55 - 2014-10-08 08:30 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-11-18 19:55 - 2014-10-08 08:09 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-11-18 19:55 - 2014-10-08 07:27 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-11-18 19:55 - 2014-10-08 06:32 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-11-18 19:55 - 2014-10-08 06:19 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-11-15 06:07 - 2014-10-07 07:28 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-11-15 06:07 - 2014-10-07 07:27 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-11-15 06:07 - 2014-10-07 07:27 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-11-15 06:07 - 2014-10-07 07:27 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-11-15 06:07 - 2014-10-07 07:27 - 00108432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2014-11-15 06:07 - 2014-10-07 04:34 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-11-15 06:07 - 2014-10-07 04:34 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-11-15 06:07 - 2014-10-07 04:33 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-11-15 06:07 - 2014-10-07 02:54 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-11-15 06:07 - 2014-10-07 02:46 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-11-15 06:07 - 2014-09-27 08:13 - 00104336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2014-11-15 06:07 - 2014-09-27 06:24 - 00088800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2014-11-15 06:07 - 2014-09-27 04:38 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2014-11-15 06:07 - 2014-09-27 04:30 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2014-11-15 06:07 - 2014-09-27 04:17 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2014-11-15 06:07 - 2014-08-23 06:18 - 02149376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-11-15 06:07 - 2014-08-23 06:03 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-11-15 06:06 - 2014-10-31 06:28 - 25110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-11-15 06:06 - 2014-10-31 04:42 - 19781632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-11-15 06:03 - 2014-10-31 05:50 - 06040064 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-11-15 06:03 - 2014-10-31 04:59 - 14390272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-11-15 06:03 - 2014-10-31 03:46 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-11-15 06:03 - 2014-10-31 03:30 - 12819456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-11-15 06:02 - 2014-10-31 06:12 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wextract.exe
2014-11-15 06:02 - 2014-10-31 06:12 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshta.exe
2014-11-15 06:02 - 2014-10-31 06:10 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iexpress.exe
2014-11-15 06:02 - 2014-10-31 06:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll
2014-11-15 06:02 - 2014-10-31 06:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2014-11-15 06:02 - 2014-10-31 06:06 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-11-15 06:02 - 2014-10-31 06:06 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-11-15 06:02 - 2014-10-31 06:06 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-11-15 06:02 - 2014-10-31 06:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-11-15 06:02 - 2014-10-31 06:05 - 02884096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-11-15 06:02 - 2014-10-31 06:05 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-11-15 06:02 - 2014-10-31 06:04 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-11-15 06:02 - 2014-10-31 05:57 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-11-15 06:02 - 2014-10-31 05:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-11-15 06:02 - 2014-10-31 05:54 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\IEAdvpack.dll
2014-11-15 06:02 - 2014-10-31 05:53 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2014-11-15 06:02 - 2014-10-31 05:52 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2014-11-15 06:02 - 2014-10-31 05:51 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-11-15 06:02 - 2014-10-31 05:51 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-11-15 06:02 - 2014-10-31 05:51 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-11-15 06:02 - 2014-10-31 05:50 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-11-15 06:02 - 2014-10-31 05:40 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-11-15 06:02 - 2014-10-31 05:38 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-11-15 06:02 - 2014-10-31 05:30 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-11-15 06:02 - 2014-10-31 05:29 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-11-15 06:02 - 2014-10-31 05:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2014-11-15 06:02 - 2014-10-31 05:28 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2014-11-15 06:02 - 2014-10-31 05:25 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-11-15 06:02 - 2014-10-31 05:24 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-11-15 06:02 - 2014-10-31 05:24 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-11-15 06:02 - 2014-10-31 05:23 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-11-15 06:02 - 2014-10-31 05:21 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-11-15 06:02 - 2014-10-31 05:19 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-11-15 06:02 - 2014-10-31 05:15 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2014-11-15 06:02 - 2014-10-31 05:08 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2014-11-15 06:02 - 2014-10-31 05:06 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-11-15 06:02 - 2014-10-31 05:05 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-11-15 06:02 - 2014-10-31 05:05 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-11-15 06:02 - 2014-10-31 05:03 - 02124288 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-11-15 06:02 - 2014-10-31 04:45 - 02365440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-11-15 06:02 - 2014-10-31 04:44 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-11-15 06:02 - 2014-10-31 04:42 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\imgutil.dll
2014-11-15 06:02 - 2014-10-31 04:32 - 01550336 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-11-15 06:02 - 2014-10-31 04:28 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wextract.exe
2014-11-15 06:02 - 2014-10-31 04:28 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshta.exe
2014-11-15 06:02 - 2014-10-31 04:27 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iexpress.exe
2014-11-15 06:02 - 2014-10-31 04:26 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pngfilt.dll
2014-11-15 06:02 - 2014-10-31 04:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2014-11-15 06:02 - 2014-10-31 04:24 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-11-15 06:02 - 2014-10-31 04:24 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\url.dll
2014-11-15 06:02 - 2014-10-31 04:24 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-11-15 06:02 - 2014-10-31 04:23 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2014-11-15 06:02 - 2014-10-31 04:23 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-11-15 06:02 - 2014-10-31 04:22 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-11-15 06:02 - 2014-10-31 04:20 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-11-15 06:02 - 2014-10-31 04:18 - 02277376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-11-15 06:02 - 2014-10-31 04:16 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-11-15 06:02 - 2014-10-31 04:15 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-11-15 06:02 - 2014-10-31 04:14 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IEAdvpack.dll
2014-11-15 06:02 - 2014-10-31 04:13 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2014-11-15 06:02 - 2014-10-31 04:13 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2014-11-15 06:02 - 2014-10-31 04:12 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-11-15 06:02 - 2014-10-31 04:12 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-11-15 06:02 - 2014-10-31 04:11 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-11-15 06:02 - 2014-10-31 04:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licmgr10.dll
2014-11-15 06:02 - 2014-10-31 04:02 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-11-15 06:02 - 2014-10-31 03:57 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-15 06:02 - 2014-10-31 03:56 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inseng.dll
2014-11-15 06:02 - 2014-10-31 03:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-11-15 06:02 - 2014-10-31 03:56 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2014-11-15 06:02 - 2014-10-31 03:53 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-11-15 06:02 - 2014-10-31 03:53 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2014-11-15 06:02 - 2014-10-31 03:52 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-11-15 06:02 - 2014-10-31 03:51 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2014-11-15 06:02 - 2014-10-31 03:50 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-11-15 06:02 - 2014-10-31 03:48 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\occache.dll
2014-11-15 06:02 - 2014-10-31 03:46 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2014-11-15 06:02 - 2014-10-31 03:42 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2014-11-15 06:02 - 2014-10-31 03:40 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-11-15 06:02 - 2014-10-31 03:40 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-11-15 06:02 - 2014-10-31 03:39 - 02051072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-11-15 06:02 - 2014-10-31 03:26 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-11-15 06:02 - 2014-10-31 03:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imgutil.dll
2014-11-15 06:02 - 2014-10-31 03:17 - 01892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-11-15 06:02 - 2014-10-31 03:13 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-11-15 06:02 - 2014-10-31 03:11 - 00708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-11-15 06:01 - 2014-10-23 06:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-11-15 06:01 - 2014-10-23 06:05 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-11-15 06:01 - 2014-10-10 02:58 - 00177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-11-15 06:01 - 2014-10-10 02:58 - 00027456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2014-11-15 06:01 - 2014-10-10 02:44 - 00563976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-11-15 06:01 - 2014-10-08 08:37 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-11-15 06:01 - 2014-10-08 08:37 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2014-11-15 06:01 - 2014-10-08 08:34 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-11-15 06:01 - 2014-10-08 08:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2014-11-15 06:01 - 2014-10-08 07:56 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-11-15 06:01 - 2014-10-08 07:51 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-11-15 06:01 - 2014-10-08 07:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2014-11-15 06:01 - 2014-10-08 07:18 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-11-15 06:01 - 2014-10-08 07:17 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-11-15 06:01 - 2014-10-08 06:23 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-11-15 06:01 - 2014-10-07 04:30 - 04182016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-11-15 06:00 - 2014-10-17 08:01 - 00789184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-11-15 06:00 - 2014-10-17 07:58 - 00602768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-11-15 05:59 - 2014-10-18 10:55 - 00055776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-11-15 05:59 - 2014-10-18 09:09 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-11-15 05:59 - 2014-10-18 09:09 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2014-11-15 05:59 - 2014-10-18 08:25 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-11-15 05:59 - 2014-10-18 07:50 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2014-11-15 05:59 - 2014-10-18 07:38 - 03557376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-11-15 05:59 - 2014-10-18 07:27 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-11-15 05:59 - 2014-10-18 07:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-11-15 05:59 - 2014-10-18 07:23 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-11-15 05:59 - 2014-10-18 07:23 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-11-15 05:59 - 2014-10-18 07:21 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-11-15 05:59 - 2014-10-18 07:20 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-11-15 05:59 - 2014-10-18 07:14 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-11-15 05:59 - 2014-10-18 07:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-11-15 05:59 - 2014-10-18 07:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-11-15 05:59 - 2014-10-18 07:11 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-11-15 05:59 - 2014-09-10 07:25 - 00474432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2014-11-15 05:59 - 2014-09-08 04:07 - 02497344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-11-15 05:59 - 2014-09-08 04:07 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-11-15 05:59 - 2014-09-04 23:30 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-11-15 05:59 - 2014-09-04 23:21 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-11-15 05:59 - 2014-09-04 04:05 - 00836176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-11-15 05:59 - 2014-09-04 03:22 - 00670384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-11-15 05:59 - 2014-09-04 02:01 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2014-11-15 05:59 - 2014-09-04 01:32 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2014-11-15 05:59 - 2014-08-31 01:17 - 00148800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-11-15 05:59 - 2014-08-31 01:15 - 21197152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-11-15 05:59 - 2014-08-30 23:59 - 18723112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-11-15 05:59 - 2014-08-30 23:05 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2014-11-15 05:59 - 2014-08-30 22:04 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-11-15 05:59 - 2014-08-30 21:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-11-15 05:59 - 2014-08-28 03:55 - 07484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-11-15 05:59 - 2014-08-28 01:21 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-11-15 05:59 - 2014-08-28 01:06 - 02030592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2014-11-15 05:59 - 2014-08-23 06:14 - 13424128 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-11-15 05:59 - 2014-08-23 06:04 - 11820544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-11-15 05:59 - 2014-08-23 05:50 - 02714112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-11-15 05:59 - 2014-08-02 01:51 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2014-11-15 05:59 - 2014-08-02 01:35 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2014-11-15 05:58 - 2014-09-07 23:08 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-11-15 05:58 - 2014-08-30 22:58 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2014-11-15 05:58 - 2014-08-30 21:53 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2014-11-12 13:31 - 2014-11-12 13:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-02 19:35 - 2014-03-26 22:05 - 00003968 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BEAB951D-AFE0-42CA-A498-55488A38759E}
2014-12-02 19:32 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-12-01 23:01 - 2013-12-28 17:46 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-12-01 22:17 - 2014-02-11 14:16 - 01099571 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-01 22:16 - 2014-02-11 15:26 - 00000000 ___DO () C:\Users\Lidia\SkyDrive
2014-12-01 22:16 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-01 22:11 - 2013-11-13 23:22 - 00813280 _____ () C:\WINDOWS\PFRO.log
2014-12-01 21:22 - 2014-03-16 13:19 - 00000000 ___HD () C:\Users\Lidia\Desktop\.picasaoriginals
2014-12-01 21:22 - 2014-02-11 13:58 - 00000000 ____D () C:\Users\Lidia
2014-12-01 20:55 - 2013-12-20 20:18 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2017453163-4049187296-263026530-1002
2014-12-01 20:23 - 2014-02-19 09:53 - 00508416 ___SH () C:\Users\Lidia\Downloads\Thumbs.db
2014-12-01 20:14 - 2014-02-13 15:55 - 00377344 ___SH () C:\Users\Lidia\Desktop\Thumbs.db
2014-12-01 20:13 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2014-12-01 20:06 - 2014-11-01 22:53 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2014-11-30 16:25 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-11-27 13:09 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-11-27 06:01 - 2013-12-28 17:46 - 00003818 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-11-25 07:56 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-11-25 06:44 - 2014-07-11 12:48 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-11-25 06:44 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-25 06:44 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-25 06:44 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-11-25 06:44 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-11-23 20:59 - 2012-09-25 19:54 - 00000000 ____D () C:\Program Files (x86)\WildGames
2014-11-23 20:59 - 2012-09-25 19:52 - 00000000 ____D () C:\ProgramData\WildTangent
2014-11-23 20:55 - 2012-09-25 19:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-11-22 13:56 - 2013-12-28 15:38 - 00000000 ___RD () C:\Users\Lidia\Podcasts
2014-11-22 13:55 - 2013-08-22 15:44 - 00484360 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-11-22 13:54 - 2013-12-27 22:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-22 12:32 - 2013-12-23 01:18 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-11-22 12:32 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-11-22 12:32 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-11-22 12:24 - 2013-12-23 01:18 - 103374192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-21 23:49 - 2014-11-01 22:53 - 01050432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00436624 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00267632 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00116728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00093568 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00083280 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00065776 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-11-21 11:48 - 2014-11-01 22:53 - 00029208 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-11-20 06:45 - 2014-05-28 17:09 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-02 01:51 - 2013-11-14 08:33 - 01825074 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-02 01:51 - 2013-11-14 08:13 - 00807160 _____ () C:\WINDOWS\system32\perfh015.dat
2014-11-02 01:51 - 2013-11-14 08:13 - 00163478 _____ () C:\WINDOWS\system32\perfc015.dat

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-01 22:27

==================== End Of Log ============================



Kod: Zaznacz wszystko
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-12-2014
Ran by Lidia at 2014-12-02 19:39:50
Running from C:\Users\Lidia\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{04E205D6-88B1-4652-B162-42DF2C3B1228}) (Version:  - Microsoft)
Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{442ECBCF-94A7-48CC-8CD9-D31FFFD5FA86}) (Version:  - Microsoft)
Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{128A36ED-21BE-4547-9FFE-5B85AEC735DD}) (Version:  - Microsoft)
AMD Catalyst Install Manager (HKLM\...\{B81EACDF-16E0-A32C-F096-16EF2BD8405C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.3.26.0 - AppEx Networks)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
e-Deklaracje Desktop (HKLM-x32\...\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1) (Version: 6.0.1 - Ministerstwo Finansow)
e-Deklaracje Desktop (x32 Version: 6.0.1 - Ministerstwo Finansow) Hidden
FDUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.)
Java(TM) 7 Update 5 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417005FF}) (Version: 7.0.50 - Oracle)
Java(TM) 7 Update 5 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217005FF}) (Version: 7.0.50 - Oracle)
KUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-2017453163-4049187296-263026530-1002\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 33.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 pl)) (Version: 33.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
NetSender 3.0 (HKLM-x32\...\NetSender_is1) (Version:  - Foto Witalińska)
Obsługa programów Apple (HKLM-x32\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PIT Format 2013 (HKLM-x32\...\PIT Format 2013_is1) (Version:  - Biuro Informatyki Stosowanej FORMAT)
PITy 2013/2014 (HKLM-x32\...\PITy 2013/2014_is1) (Version: 2.0 - NEONET CONSULTING S.C.)
PlayMemories Home (HKLM-x32\...\{10DD6128-A810-4A90-9523-475D573FBB37}) (Version: 6.3.02.07270 - Sony Corporation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.206 - Qualcomm Atheros Communications)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6685 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.28121 - Realtek Semiconductor Corp.)
Restore (x32 Version: 1.0.0 - Sony Corporation) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden
SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.5 - Synaptics Incorporated)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.0.631 - Electronic Arts)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VAIO - Xperia Link (HKLM-x32\...\{D91558BF-D1F3-411F-AEFE-8774CB406512}) (Version: 1.3.2.07020 - Sony Corporation)
VAIO Care (HKLM\...\{92907606-B2FC-4193-B0CE-A21159DA3ABB}) (Version: 8.4.0.14286 - Sony Corporation)
VAIO Care Recovery (HKLM\...\{15B9204E-BA09-485E-8F2C-094AC0077664}) (Version: 1.1.2.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\...\{8E797841-A110-41FD-B17A-3ABC0641187A}) (Version: 6.0.0.08200 - Sony Corporation)
VAIO CPU Fan Diagnostic (HKLM-x32\...\{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}) (Version: 1.1.0.09200 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.10.0.07270 - Sony Corporation)
VAIO Easy Connect (x32 Version: 8.2.0.14170 - Sony Corporation) Hidden
VAIO Gate (HKLM-x32\...\{14AC95A2-7675-4988-A5BD-3F5B943AED08}) (Version: 3.0.0.08140 - Sony Corporation)
VAIO Gate Default (HKLM-x32\...\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 3.0.0.08060 - Sony Corporation)
VAIO Gesture Control (HKLM-x32\...\{692955F2-DE9F-4078-8FAA-858D6F3A1776}) (Version: 2.0.0.08240 - Sony Corporation)
VAIO Gesture Control (x32 Version: 2.0.0.08240 - Sony Corporation) Hidden
VAIO Image Optimizer (HKLM-x32\...\InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}) (Version: 3.0.00.08170 - Sony Corporation)
VAIO Image Optimizer (x32 Version: 3.0.00.08170 - Sony Corporation) Hidden
VAIO Improvement (HKLM-x32\...\{3A26D9BD-0F73-432D-B522-2BA18138F7EF}) (Version: 2.0.0.08090 - Sony Corporation)
VAIO Manual (HKLM-x32\...\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 3.0.0.08100 - Sony Corporation)
VAIO Media Server Settings (HKLM\...\{62A172B2-550E-499D-9A82-5190D18390AA}) (Version: 1.0.0.08240 - Sony Corporation)
VAIO Movie Creator Template Data (HKLM-x32\...\InstallShield_{00A663F1-6C03-48CA-8E85-55806AAE2615}) (Version: 4.0.00.08170 - Sony Corporation)
VAIO Movie Creator Template Data (x32 Version: 4.0.00.08170 - Sony Corporation) Hidden
VAIO Transfer Support (HKLM-x32\...\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.8.0.08212 - Sony Corporation)
VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.0.1.02280 - Sony Corporation)
VCCx64 (Version: 1.0.0 - Sony Corporation) Hidden
VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VGClientX64 (Version: 1.0.0 - Sony Corporation) Hidden
VHD (x32 Version: 1.0.0 - Sony Corporation) Hidden
VIx64 (Version: 1.0.0 - Sony Corporation) Hidden
VIx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VMLx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VoiceOver Kit (HKLM-x32\...\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.)
VPMx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VSSTx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VSSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VU5x64 (Version: 1.0.0 - Sony Corporation ) Hidden
VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
VUx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VUx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
VWSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
WinRAR 5.10 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
XperiaLinkx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2017453163-4049187296-263026530-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Lidia\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811_1\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

10-11-2014 04:41:22 Zaplanowany punkt kontrolny
18-11-2014 18:37:10 Windows Update
21-11-2014 10:46:39 avast! antivirus system restore point
27-11-2014 12:07:42 Windows Update
30-11-2014 15:32:37 SPTD setup V1.86

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {04F9B265-8B2B-4195-827D-F13966E495EA} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {0902DD4B-BC86-4367-966C-6A6724ADC7C5} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-11-22] (Microsoft Corporation)
Task: {1A585802-CC03-4AD6-9053-36C69CB4078A} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {2F2AAF6E-6142-4706-9182-805785D337E7} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2014-01-16] (Sony Corporation)
Task: {340A79D9-7B8D-45DA-BA04-7318D48956A6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-27] (Adobe Systems Incorporated)
Task: {36AFEBF3-2922-42D2-BFC9-D0ACE4B3FDAF} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2014-03-01] (Sony Corporation)
Task: {3B9FCAB4-F0BD-4F10-9E2A-DF5559F5D46D} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-21] (Synaptics Incorporated)
Task: {3F3B5943-7BD2-4907-BF21-731B50D5A9A9} - System32\Tasks\Sony Corporation\VAIO Control Center\NetworkSetting\NetworkSetting Logon Start => C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient
Task: {3F91AB3A-3FB8-4A01-AA5B-7181425771BF} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2012-08-09] (Sony Corporation)
Task: {4916F404-DAC3-42A6-BB3F-EF9F40E32C95} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {4D6A8C20-97A0-45E0-BD94-ED7A105D3164} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {51C1E150-79B2-4BFA-9BAF-0C2BD504ECCA} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {60027697-BD1E-4B75-BCA3-E24072C420FA} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Daily => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-08-18] (Sony Corporation)
Task: {7192E974-1384-4488-97E3-92D745DF3D65} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Month => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-08-18] (Sony Corporation)
Task: {78CCEB53-8AB7-4EA9-A008-89B05E16A021} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {94979990-3C63-4289-9F13-D2BCD5D8C677} - System32\Tasks\Sony Corporation\VAIO Gesture Control\VCGULogonTask => C:\Program Files (x86)\Sony\VAIO Camera Gesture Utility\VCGU.exe [2012-08-04] (Sony Corporation)
Task: {A261B3DA-5E58-42AA-BB54-037DBE5D24EC} - System32\Tasks\VHDInformationCheck => C:\Program Files (x86)\Sony\VAIO Recovery\plugins\InformationCheck.exe [2012-07-31] (Sony Corporation)
Task: {A8DD27C3-EE18-4562-8BB2-96858FBFCBC1} - System32\Tasks\Sony Corporation\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2012-08-14] (Sony Corporation)
Task: {A9ECEA41-C463-4128-8546-EB52BAEEFFCC} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {AE6B72B3-6BFD-417C-9C4E-A5F96EA38B4D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-21] (AVAST Software)
Task: {B8D681D1-C9AC-447A-8C39-12D687CDE2CB} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2014-02-27] (Sony Corporation)
Task: {BB31CB45-9FF6-46F7-B54C-22651868D88C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C895FEBB-8A51-4257-8FB7-390275C8539A} - System32\Tasks\Sony Corporation\VAIO Care\UpdateContacts => %ProgramData%\Sony Corporation\VAIO Care\UpdateContacts.exe
Task: {D4A371EC-C6CB-4A50-8FEE-D1A75CE63499} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {D509BF6D-0246-45F9-AD6F-8CA8CB3C3DC8} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementMonitorSystem => C:\Program Files\Sony\VAIO Improvement\vim.exe [2012-08-09] (Sony Corporation)
Task: {D6567711-E20F-4CD4-9A3F-187FAE0CC5CF} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {DB86125F-DACD-45FF-895A-A16594FED86D} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementMonitorUser => C:\Program Files\Sony\VAIO Improvement\vim.exe [2012-08-09] (Sony Corporation)
Task: {DE0FD9DC-4733-402C-8F62-98D7CD9BA052} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-02-20] (Sony Corporation)
Task: {F0854941-7EED-4980-9E33-C4A8D1FAA592} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2014-02-28] (Sony Corporation)
Task: {F5A7A782-DFF4-4875-889A-B3F2FF4CF2FF} - System32\Tasks\Sony Corporation\Xperia Link\Xperia Link Logon Start => C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe [2014-07-03] (Sony Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

==================== Loaded Modules (whitelisted) =============

2012-08-06 12:09 - 2012-08-06 12:09 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2012-08-13 17:25 - 2012-08-13 17:25 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
2012-08-13 17:20 - 2012-08-13 17:20 - 00020992 _____ () C:\Program Files (x86)\Bluetooth Suite\L10n\pl-PL\BtTray.pl-PL.dll
2012-08-06 12:08 - 2012-08-06 12:08 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-11-19 09:21 - 2013-11-19 09:21 - 00062464 _____ () C:\Program Files\Sony\VAIO Care\listener.exe
2014-12-01 20:06 - 2014-12-01 20:06 - 02904064 _____ () C:\Program Files\AVAST Software\Avast\defs\14120100\algo.dll
2014-12-02 19:38 - 2014-12-02 19:38 - 02904576 _____ () C:\Program Files\AVAST Software\Avast\defs\14120201\algo.dll
2014-07-03 12:20 - 2014-07-03 12:20 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-07-03 12:19 - 2014-07-03 12:19 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-11-21 11:48 - 2014-11-21 11:48 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-11-12 13:31 - 2014-11-12 13:31 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Lidia\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\StartupFolder: => "McAfee Parental Controls.lnk"

========================= Accounts: ==========================

Administrator (S-1-5-21-2017453163-4049187296-263026530-500 - Administrator - Disabled)
Dom (S-1-5-21-2017453163-4049187296-263026530-1005 - Administrator - Enabled) => C:\Users\Dom
Gość (S-1-5-21-2017453163-4049187296-263026530-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2017453163-4049187296-263026530-1004 - Limited - Enabled)
Lidia (S-1-5-21-2017453163-4049187296-263026530-1002 - Administrator - Enabled) => C:\Users\Lidia

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/02/2014 07:33:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji Microsoft.SkypeApp_kzf8qxf38zg5c!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 07:32:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nazwa aplikacji powodującej błąd: wwahost.exe, wersja: 6.3.9600.17031, sygnatura czasowa: 0x53085904
Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.3.9600.17278, sygnatura czasowa: 0x53eeb460
Kod wyjątku: 0x00000004
Przesunięcie błędu: 0x00012f71
Identyfikator procesu powodującego błąd: 0x10b8
Godzina uruchomienia aplikacji powodującej błąd: 0xwwahost.exe0
Ścieżka aplikacji powodującej błąd: wwahost.exe1
Ścieżka modułu powodującego błąd: wwahost.exe2
Identyfikator raportu: wwahost.exe3
Pełna nazwa pakietu powodującego błąd: wwahost.exe4
Identyfikator aplikacji względem pakietu powodującego błąd: wwahost.exe5

Error: (12/02/2014 06:51:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji Microsoft.SkypeApp_kzf8qxf38zg5c!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (12/02/2014 06:51:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LILA)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.


System errors:
=============
Error: (12/02/2014 07:32:56 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: App.AppX54xz6wnkhmw763c2y8tb018n7d71dtx7.wwa

Error: (12/02/2014 07:32:49 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca

Error: (12/02/2014 07:32:47 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca

Error: (12/02/2014 07:32:46 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca

Error: (12/02/2014 07:32:46 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Windows.Networking.BackgroundTransfer.Internal.NetworkChangeTask.ClassId.4

Error: (12/02/2014 07:32:45 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Windows.Networking.BackgroundTransfer.Internal.NetworkChangeTask.ClassId.4

Error: (12/02/2014 07:32:45 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Windows.Networking.BackgroundTransfer.Internal.NetworkChangeTask.ClassId.1

Error: (12/02/2014 06:51:08 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: App.AppX54xz6wnkhmw763c2y8tb018n7d71dtx7.wwa

Error: (12/02/2014 06:51:04 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Windows.Networking.BackgroundTransfer.Internal.NetworkChangeTask.ClassId.1

Error: (12/02/2014 06:50:52 PM) (Source: DCOM) (EventID: 10010) (User: LILA)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-08-17 03:32:13.050
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-07-13 07:02:29.732
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-06-29 05:29:59.555
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-06-23 05:19:18.795
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: AMD E2-1800 APU with Radeon(tm) HD Graphics
Percentage of memory in use: 46%
Total physical RAM: 3655.76 MB
Available physical RAM: 1973.7 MB
Total Pagefile: 4295.76 MB
Available Pagefile: 2117.29 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:225.91 GB) (Free:174.83 GB) NTFS
Drive d: (Dane) (Fixed) (Total:209.71 GB) (Free:128.59 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 47FCAF7E)

Partition: GPT Partition Type.

==================== End Of Log ============================
hugo91
~user
 
Posty: 319
Dołączenie: 19 Cze 2006, 16:33
Pochwały: 6



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez ordynat 02 Gru 2014, 22:08

Otwórz Notatnik i wklej w nim:
Task: C:\WINDOWS\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTIOn
C:\Program Files (x86)\AnyProtectEx
EmptyTemp:

Plik zapisz pod nazwą [color="#483D8B"]fixlist.txt[/color] i umieść obok FRST. Uruchom FRST i kliknij przycisk Fix.
Powstanie plik fixlog.txt.
Daj ten log.

Napisz, czy problem reklam znikł?
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez hugo91 04 Gru 2014, 20:43

niestety nie, aczkolwiek puscilo otl

Kod: Zaznacz wszystko
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014
Ran by Lidia at 2014-12-04 18:46:55 Run:1
Running from C:\Users\Lidia\Desktop
Loaded Profile: Lidia (Available profiles: Lidia & Dom)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Task: C:\WINDOWS\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTIOn
C:\Program Files (x86)\AnyProtectEx
EmptyTemp:
*****************

C:\WINDOWS\Tasks\APSnotifierPP2.job => Moved successfully.
"C:\Program Files (x86)\AnyProtectEx" => File/Directory not found.
EmptyTemp: => Removed 1.4 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====



Kod: Zaznacz wszystko
OTL logfile created on: 2014-12-04 18:59:03 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 2,40 Gb Available Physical Memory | 67,19% Memory free
4,20 Gb Paging File | 2,98 Gb Available in Paging File | 71,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,99 Gb Free Space | 77,46% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014-12-01 22:02:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lidia\Downloads\OTL.scr
PRC - [2014-11-21 11:49:07 | 005,226,600 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014-02-20 14:34:44 | 000,060,504 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Care\VCService.exe
PRC - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2012-08-18 05:36:14 | 000,188,072 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
PRC - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
PRC - [2012-08-18 00:04:28 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2012-08-06 13:30:40 | 000,642,216 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
PRC - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2012-07-27 15:03:40 | 000,724,576 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2014-11-21 11:48:48 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-07-03 12:20:20 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014-07-03 12:19:50 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,368,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2014-08-16 01:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2014-08-16 01:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014-07-24 08:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2014-03-14 07:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2014-03-08 06:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2014-03-06 08:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2014-02-28 16:05:06 | 001,642,544 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Update\VUAgent.exe -- (VUAgent)
SRV:[b]64bit:[/b] - [2014-02-22 16:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014-02-22 10:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014-02-22 10:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014-02-22 10:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014-02-22 10:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2014-02-20 14:34:44 | 000,060,504 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Care\VCService.exe -- (VCService)
SRV:[b]64bit:[/b] - [2013-12-13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2013-12-10 08:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (USER_ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,266,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:[b]64bit:[/b] - [2013-08-22 12:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2013-08-22 12:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2013-08-22 12:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2013-08-22 12:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2013-08-22 12:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2013-08-22 11:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2013-08-22 10:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2013-08-22 10:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013-08-22 10:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2013-08-22 10:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2012-08-06 12:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:[b]64bit:[/b] - [2012-07-19 18:55:44 | 000,476,328 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:[b]64bit:[/b] - [2011-12-01 10:04:56 | 000,289,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,467,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,306,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:06 | 008,277,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2014-11-27 06:01:15 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-11-12 13:31:42 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-03-14 07:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013-10-23 07:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-08-22 04:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013-08-22 03:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe -- (VAIO Event Service)
SRV - [2012-08-13 17:24:56 | 000,211,584 | ---- | M] (Qualcomm Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt&Wlan Coex Agent)
SRV - [2012-08-08 10:56:22 | 000,972,000 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2012-08-08 10:56:18 | 000,460,512 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2012-08-08 10:23:30 | 000,123,616 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2012-08-08 10:23:30 | 000,078,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2012-07-20 09:35:03 | 002,445,968 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswmonflt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2014-09-22 03:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2014-08-15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2014-07-24 12:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014-06-10 20:50:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2014-05-01 14:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014-04-28 05:33:30 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2014-03-20 04:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2014-03-13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014-03-08 21:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2014-02-22 17:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2014-02-22 16:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2014-02-22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2013-12-04 19:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2013-11-14 08:37:27 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2013-11-14 08:31:22 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013-11-14 08:16:43 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013-08-22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2013-08-22 13:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2013-08-22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2013-08-22 12:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2013-08-22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2013-08-13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013-08-10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013-07-30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013-07-25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013-06-18 15:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2013-06-18 15:45:02 | 003,680,256 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:[b]64bit:[/b] - [2012-08-21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012-08-21 07:08:26 | 000,447,800 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2012-08-21 07:07:09 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:04 | 000,135,832 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:02 | 000,076,952 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,178,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,114,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,088,728 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,033,944 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2012-08-13 17:04:58 | 000,344,216 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:[b]64bit:[/b] - [2012-08-10 09:54:22 | 000,098,472 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2012-07-20 09:35:03 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:[b]64bit:[/b] - [2012-07-20 09:30:55 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2012-07-11 13:33:28 | 000,014,336 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:[b]64bit:[/b] - [2012-06-23 06:23:38 | 000,199,008 | ---- | M] (AppEx Networks Corporation) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\appexDrv.sys -- (APXACC)
DRV:[b]64bit:[/b] - [2012-06-22 07:36:54 | 000,106,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:[b]64bit:[/b] - [2012-06-11 03:43:12 | 000,024,280 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sows.sys -- (SOWS)
DRV:[b]64bit:[/b] - [2012-04-20 16:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes,DefaultScope = {5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{24D97AEC-213C-4349-B7B8-0DE6F373CF11}: "URL" = http://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=http://shop.ebay.co.uk/?oemInLn=ieSrch-Q312&_nkw={searchTerms}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{50C2A73E-51DB-4318-8387-EB8607BB64FE}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASEJS
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "http://google.pl/"
FF - prefs.js..extensions.enabledAddons: %7B6d0f26ba-45b8-4871-9c07-43ab341d5b73%7D:0.1
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.0.2502.149
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files\mcafee\msc\npMcSnFFPl64.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-21 11:48:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013-12-27 22:29:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Extensions
[2014-11-23 17:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions
[2014-08-24 16:09:58 | 000,000,000 | ---D | M] ("Site Advisor") -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions\{6d0f26ba-45b8-4871-9c07-43ab341d5b73}
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions\staged
[2014-11-23 17:09:39 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\firefox\profiles\7ta50hxd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-11-12 13:31:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014-11-12 13:31:46 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-11-21 11:48:55 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

O1 HOSTS File: ([2013-08-22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey File not found
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 File not found
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{222B836A-01B7-4D7A-86EB-80D9B1F34080}: DhcpNameServer = 192.168.1.254
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell - "" = AutoRun
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell\AutoRun\command - "" = "F:\LaunchU3.exe" -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = "E:\Autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2014-12-02 19:36:38 | 000,000,000 | ---D | C] -- C:\FRST
[2014-12-02 19:35:06 | 002,117,632 | ---- | C] (Farbar) -- C:\Users\Lidia\Desktop\FRST64.exe
[2014-12-01 21:54:20 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\ElevatedDiagnostics
[2014-12-01 21:49:54 | 000,000,000 | ---D | C] -- C:\_OTL
[2014-11-30 16:35:02 | 000,386,680 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:56:11 | 000,106,976 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-22 13:56:10 | 000,714,208 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-21 11:48:57 | 000,364,512 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:50 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-18 19:56:23 | 001,519,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2014-11-18 19:56:21 | 000,258,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2014-11-18 19:56:20 | 000,114,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2014-11-18 19:56:20 | 000,035,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2014-11-18 19:56:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2014-11-18 19:56:19 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2014-11-18 19:55:44 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-11-18 19:55:44 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-18 19:55:43 | 000,537,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-11-18 19:55:42 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-18 19:55:38 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-11-18 19:55:33 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-11-18 19:55:32 | 002,773,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-11-18 19:55:30 | 002,459,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-11-18 19:55:29 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-11-18 19:55:29 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-11-18 19:55:29 | 000,116,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-11-15 06:07:56 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2014-11-15 06:07:55 | 000,104,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2014-11-15 06:07:55 | 000,088,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2014-11-15 06:07:09 | 000,500,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-11-15 06:07:09 | 000,394,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,482,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-11-15 06:07:08 | 000,344,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,272,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-11-15 06:07:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2014-11-15 06:07:07 | 000,108,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-11-15 06:03:08 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-11-15 06:02:52 | 002,865,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-11-15 06:02:49 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-11-15 06:02:49 | 000,661,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-11-15 06:02:48 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-11-15 06:02:48 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-11-15 06:02:46 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-11-15 06:02:46 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-11-15 06:02:45 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-11-15 06:02:44 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-11-15 06:02:43 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-11-15 06:02:42 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-11-15 06:02:42 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-11-15 06:02:41 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-11-15 06:02:40 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-11-15 06:02:40 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-11-15 06:02:38 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-11-15 06:02:33 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-11-15 06:02:33 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-11-15 06:02:33 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-11-15 06:02:32 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-11-15 06:02:32 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-11-15 06:02:32 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-11-15 06:02:32 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-11-15 06:02:32 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-11-15 06:02:32 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-11-15 06:02:31 | 000,417,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-11-15 06:02:31 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-11-15 06:02:31 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-11-15 06:02:31 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-11-15 06:02:30 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-11-15 06:02:30 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-11-15 06:02:30 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:30 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-11-15 06:02:29 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-11-15 06:02:29 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-11-15 06:02:29 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-11-15 06:02:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-11-15 06:02:28 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-11-15 06:02:28 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-11-15 06:02:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-11-15 06:02:27 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:26 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-11-15 06:02:26 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-11-15 06:02:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-11-15 06:02:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-11-15 06:02:25 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-11-15 06:02:25 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-11-15 06:02:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-11-15 06:02:25 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-11-15 06:02:25 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-11-15 06:02:24 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-11-15 06:02:24 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-11-15 06:02:24 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-11-15 06:02:24 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-11-15 06:02:23 | 000,237,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-11-15 06:02:23 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-11-15 06:02:23 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-11-15 06:02:22 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-11-15 06:02:22 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-11-15 06:02:22 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-11-15 06:02:21 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-11-15 06:02:21 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-11-15 06:01:16 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-11-15 06:01:16 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-11-15 06:01:10 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-11-15 06:01:10 | 001,441,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-11-15 06:01:09 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-11-15 06:01:09 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-11-15 06:01:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-11-15 06:01:07 | 000,027,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-11-15 06:01:06 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-11-15 06:00:09 | 000,789,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-11-15 05:59:54 | 000,894,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-11-15 05:59:53 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-11-15 05:59:52 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-11-15 05:59:52 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-11-15 05:59:51 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-11-15 05:59:51 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-11-15 05:59:50 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-11-15 05:59:50 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-11-15 05:59:50 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-11-15 05:59:49 | 000,055,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-11-15 05:59:49 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-11-15 05:59:49 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-11-15 05:59:49 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-11-15 05:59:48 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-11-15 05:59:48 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-11-15 05:59:34 | 007,484,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2014-11-15 05:59:29 | 002,714,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2014-11-15 05:59:28 | 013,424,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2014-11-15 05:59:24 | 001,053,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014-11-15 05:59:24 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2014-11-15 05:59:23 | 000,836,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2014-11-15 05:59:21 | 011,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2014-11-15 05:59:19 | 000,822,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2014-11-15 05:59:19 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2014-11-15 05:59:19 | 000,670,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2014-11-15 05:59:18 | 000,474,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2014-11-15 05:59:16 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2014-11-15 05:59:16 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2014-11-15 05:59:09 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014-11-15 05:59:07 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
[2014-11-15 05:59:06 | 000,485,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
[2014-11-15 05:59:00 | 000,615,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSCOMEX.dll
[2014-11-15 05:58:56 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSAPI.dll
[2014-11-15 05:58:56 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FXSAPI.dll
[2014-11-12 13:31:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014-11-01 22:54:21 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-11-01 22:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014-11-01 22:53:21 | 001,050,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-01 22:53:21 | 000,436,624 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-01 22:53:21 | 000,116,728 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-01 22:53:21 | 000,093,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-01 22:53:21 | 000,083,280 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-01 22:51:28 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-10-22 17:54:16 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014-10-22 17:54:16 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2014-10-22 17:54:12 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2014-10-22 06:10:35 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2014-10-22 06:10:35 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2014-10-22 06:09:29 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2014-10-22 06:09:28 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2014-10-22 06:09:27 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2014-10-22 06:09:26 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2014-10-22 06:09:25 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2014-10-22 06:09:23 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2014-10-22 06:09:23 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2014-10-22 06:09:20 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll
[2014-10-22 06:09:19 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2014-10-22 06:09:18 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll
[2014-10-22 06:09:16 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll
[2014-10-22 06:09:08 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2014-10-22 06:09:07 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2014-10-22 06:09:06 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2014-10-22 06:09:06 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll
[2014-10-22 06:09:06 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll
[2014-10-22 06:09:05 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll
[2014-10-22 06:09:05 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll
[2014-10-22 06:09:04 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll
[2014-10-22 06:09:04 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll
[2014-10-22 06:09:04 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll
[2014-10-22 06:09:04 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll
[2014-10-22 06:09:03 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-10-22 06:09:02 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-10-21 04:25:21 | 016,874,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2014-10-21 04:25:14 | 012,730,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2014-10-21 04:25:05 | 002,389,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10warp.dll
[2014-10-21 04:24:59 | 002,141,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2014-10-21 04:24:56 | 002,145,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2014-10-21 04:24:53 | 001,600,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2014-10-21 04:24:51 | 001,231,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2014-10-21 04:24:48 | 000,889,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2014-10-21 04:24:47 | 002,574,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVDECOD.DLL
[2014-10-21 04:24:46 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SRH.dll
[2014-10-21 04:24:46 | 000,882,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2014-10-21 04:24:46 | 000,707,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2014-10-21 04:24:45 | 001,182,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\printui.dll
[2014-10-21 04:24:44 | 002,410,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMVDECOD.DLL
[2014-10-21 04:24:43 | 001,287,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mispace.dll
[2014-10-21 04:24:42 | 001,992,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsPrint.dll
[2014-10-21 04:24:40 | 000,770,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2014-10-21 04:24:40 | 000,486,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netcfgx.dll
[2014-10-21 04:24:39 | 001,057,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\printui.dll
[2014-10-21 04:24:39 | 001,029,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mispace.dll
[2014-10-21 04:24:39 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2014-10-21 04:24:39 | 000,391,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netcfgx.dll
[2014-10-21 04:24:38 | 001,741,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SRH.dll
[2014-10-21 04:24:38 | 001,018,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aclui.dll
[2014-10-21 04:24:38 | 000,412,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2014-10-21 04:24:37 | 000,371,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2014-10-21 04:24:37 | 000,360,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfreadwrite.dll
[2014-10-21 04:24:36 | 000,889,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aclui.dll
[2014-10-21 04:24:36 | 000,645,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SHCore.dll
[2014-10-21 04:24:36 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2014-10-21 04:24:36 | 000,355,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfreadwrite.dll
[2014-10-21 04:24:35 | 000,439,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2014-10-21 04:24:35 | 000,302,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanmsm.dll
[2014-10-21 04:24:34 | 000,180,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mftranscode.dll
[2014-10-21 04:24:33 | 002,397,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storagewmi.dll
[2014-10-21 04:24:33 | 000,477,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SHCore.dll
[2014-10-21 04:24:33 | 000,205,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mftranscode.dll
[2014-10-21 04:24:32 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2014-10-21 04:24:32 | 000,427,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clusapi.dll
[2014-10-21 04:24:32 | 000,287,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usbmon.dll
[2014-10-21 04:24:31 | 001,660,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2014-10-21 04:24:31 | 000,468,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2014-10-21 04:24:30 | 001,519,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2014-10-21 04:24:29 | 000,487,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winspool.drv
[2014-10-21 04:24:29 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wisp.dll
[2014-10-21 04:24:28 | 001,488,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2014-10-21 04:24:28 | 001,463,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wsecedit.dll
[2014-10-21 04:24:28 | 001,356,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2014-10-21 04:24:26 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clusapi.dll
[2014-10-21 04:24:26 | 000,160,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmmbase.dll
[2014-10-21 04:24:25 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WiFiDisplay.dll
[2014-10-21 04:24:23 | 001,817,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Display.dll
[2014-10-21 04:24:23 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdvidcrl.dll
[2014-10-21 04:24:23 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\conhost.exe
[2014-10-21 04:24:22 | 001,844,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Display.dll
[2014-10-21 04:24:22 | 001,404,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\storagewmi.dll
[2014-10-21 04:24:22 | 000,576,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSync.dll
[2014-10-21 04:24:22 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VAN.dll
[2014-10-21 04:24:22 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSip.dll
[2014-10-21 04:24:21 | 000,834,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\osk.exe
[2014-10-21 04:24:21 | 000,211,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVol.exe
[2014-10-21 04:24:21 | 000,127,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmmbase.dll
[2014-10-21 04:24:21 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersGPExt.dll
[2014-10-21 04:24:20 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DafPrintProvider.dll
[2014-10-21 04:24:20 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wisp.dll
[2014-10-21 04:24:19 | 000,387,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2014-10-21 04:24:19 | 000,233,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2014-10-21 04:24:19 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2014-10-21 04:24:18 | 000,335,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2014-10-21 04:24:18 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\NdisImPlatform.sys
[2014-10-21 04:24:17 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.dll
[2014-10-21 04:24:17 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.dll
[2014-10-21 04:24:17 | 000,125,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2014-10-21 04:24:17 | 000,123,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmm.dll
[2014-10-21 04:24:17 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxSip.dll
[2014-10-21 04:24:16 | 001,319,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wsecedit.dll
[2014-10-21 04:24:15 | 001,656,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2014-10-21 04:24:15 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\prnntfy.dll
[2014-10-21 04:24:14 | 001,089,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpedit.dll
[2014-10-21 04:24:14 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\prnntfy.dll
[2014-10-21 04:24:14 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersShell.dll
[2014-10-21 04:24:13 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsPrint.dll
[2014-10-21 04:24:13 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiapi.dll
[2014-10-21 04:24:13 | 000,162,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiapi.dll
[2014-10-21 04:24:11 | 000,448,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VAN.dll
[2014-10-21 04:24:11 | 000,180,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SndVol.exe
[2014-10-21 04:24:09 | 000,263,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlows.exe
[2014-10-21 04:24:08 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdvidcrl.dll
[2014-10-21 04:24:08 | 000,432,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanconn.dll
[2014-10-21 04:24:08 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2014-10-21 04:24:08 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2014-10-21 04:24:08 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dab.dll
[2014-10-21 04:24:08 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2014-10-21 04:24:06 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpedit.dll
[2014-10-21 04:24:06 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionCenter.dll
[2014-10-21 04:24:06 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2014-10-21 04:24:06 | 000,216,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rsaenh.dll
[2014-10-21 04:24:04 | 000,779,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\osk.exe
[2014-10-21 04:24:04 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.dll
[2014-10-21 04:24:03 | 000,557,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PrintDialogs.dll
[2014-10-21 04:24:03 | 000,459,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSync.dll
[2014-10-21 04:24:03 | 000,200,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DafPrintProvider.dll
[2014-10-21 04:24:02 | 000,659,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2014-10-21 04:24:01 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansvcpal.dll
[2014-10-21 04:23:58 | 000,832,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ActionCenter.dll
[2014-10-21 04:23:57 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powercfg.cpl
[2014-10-21 04:23:56 | 000,183,808 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysNative\Defrag.exe
[2014-10-21 04:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRUM.DLL
[2014-10-21 04:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRUM.DLL
[2014-10-21 04:23:55 | 001,351,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2014-10-21 04:23:54 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\powercfg.cpl
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDYAK.DLL
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU1.DLL
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDBASH.DLL
[2014-10-21 04:23:54 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU.DLL
[2014-10-21 04:23:53 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BluetoothApis.dll
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDYAK.DLL
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU1.DLL
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDBASH.DLL
[2014-10-21 04:23:52 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU.DLL
[2014-10-21 04:23:14 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintDialogs.dll
[2014-10-21 04:23:10 | 001,144,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanmm.dll
[2014-10-21 04:23:08 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTAT.DLL
[2014-10-21 04:23:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVolSSO.dll
[2014-10-21 04:23:07 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTAT.DLL
[2014-10-21 04:23:06 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\compstui.dll
[2014-10-21 04:23:06 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BluetoothApis.dll
[2014-10-21 04:23:05 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansec.dll
[2014-10-21 04:23:04 | 002,100,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlowUI.dll
[2014-10-21 04:23:02 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTT102.DLL
[2014-10-21 04:23:02 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTT102.DLL
[2014-10-21 04:14:49 | 002,084,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2014-10-21 04:14:49 | 000,796,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uDWM.dll
[2014-10-21 04:14:47 | 002,374,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2014-10-21 04:14:26 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UXInit.dll
[2014-10-21 04:14:26 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UXInit.dll
[2014-10-21 04:14:08 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSDMon.dll
[2014-10-21 04:14:08 | 000,205,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcpmon.dll
[2014-10-20 05:33:28 | 000,146,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpioclx.sys
[2014-10-17 12:02:12 | 000,875,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvcr120_clr0400.dll
[2014-10-17 12:02:12 | 000,869,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvcr120_clr0400.dll
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2014-12-04 19:01:01 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014-12-04 18:54:44 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014-12-04 18:52:40 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014-12-04 18:52:37 | 3066,671,104 | -HS- | M] () -- C:\hiberfil.sys
[2014-12-04 18:44:27 | 002,117,632 | ---- | M] (Farbar) -- C:\Users\Lidia\Desktop\FRST64.exe
[2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:55:15 | 000,484,360 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-21 11:49:15 | 000,001,980 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014-11-21 11:48:54 | 000,267,632 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-21 11:48:53 | 000,364,512 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-21 11:48:53 | 000,065,776 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-21 11:48:53 | 000,029,208 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-11-21 11:48:50 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-20 21:51:37 | 000,714,208 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-20 21:51:37 | 000,106,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-05 00:38:37 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-04 01:10:18 | 000,304,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-02 01:51:02 | 000,807,160 | ---- | M] () -- C:\WINDOWS\SysNative\perfh015.dat
[2014-11-02 01:51:02 | 000,722,476 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014-11-02 01:51:02 | 000,163,478 | ---- | M] () -- C:\WINDOWS\SysNative\perfc015.dat
[2014-11-02 01:51:02 | 000,135,592 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014-11-02 01:51:01 | 001,825,074 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014-10-31 06:12:41 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-10-31 06:12:05 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-10-31 06:10:13 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-10-31 06:09:37 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-10-31 06:08:00 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-10-31 06:06:45 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-10-31 06:06:21 | 000,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-10-31 06:06:09 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-10-31 06:06:00 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-10-31 06:05:50 | 000,417,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-10-31 06:04:28 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-10-31 05:56:53 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-10-31 05:54:13 | 000,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-10-31 05:53:32 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-10-31 05:53:06 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-10-31 05:52:22 | 000,108,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-10-31 05:51:37 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-10-31 05:51:31 | 000,812,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-10-31 05:50:44 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-10-31 05:50:11 | 006,040,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-10-31 05:49:39 | 000,537,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-10-31 05:40:07 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-10-31 05:38:28 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-10-31 05:30:28 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-10-31 05:29:50 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-10-31 05:29:17 | 000,087,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-10-31 05:28:58 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-10-31 05:25:24 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-10-31 05:24:48 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-10-31 05:24:25 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-10-31 05:23:46 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-10-31 05:21:30 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-10-31 05:19:49 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-10-31 05:05:52 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-10-31 05:05:35 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-10-31 05:03:02 | 002,124,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-10-31 04:44:32 | 002,865,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-10-31 04:42:04 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-10-31 04:28:47 | 000,137,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-10-31 04:27:26 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-10-31 04:26:45 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-10-31 04:25:24 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-10-31 04:24:23 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-10-31 04:24:00 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-10-31 04:23:37 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-10-31 04:23:21 | 000,340,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-10-31 04:22:08 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-10-31 04:20:27 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-10-31 04:15:59 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-10-31 04:14:25 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-10-31 04:13:35 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-10-31 04:12:17 | 000,661,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-10-31 04:12:17 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-10-31 04:11:30 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-10-31 04:03:33 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-10-31 03:57:20 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-10-31 03:56:44 | 000,090,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-10-31 03:56:18 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-10-31 03:56:08 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-10-31 03:53:21 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-10-31 03:52:23 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-10-31 03:51:02 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-10-31 03:48:50 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-10-31 03:39:28 | 002,051,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-10-31 03:11:30 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-10-23 06:48:37 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-10-23 06:05:08 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-10-18 10:55:17 | 000,055,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-10-18 09:09:52 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-10-18 09:09:44 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-10-18 08:25:54 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-10-18 07:50:21 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-10-18 07:27:15 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-10-18 07:26:48 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-10-18 07:23:51 | 000,407,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-10-18 07:23:11 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-10-18 07:21:47 | 000,894,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-10-18 07:20:43 | 001,714,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-10-18 07:14:54 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-10-18 07:14:32 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-10-18 07:12:10 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-10-18 07:11:35 | 000,723,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-10-18 06:20:02 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollectorres.dll
[2014-10-17 08:01:28 | 000,789,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-10-13 03:33:24 | 000,116,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-10-11 01:58:13 | 003,320,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-10-08 08:37:31 | 000,154,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-10-08 08:37:27 | 000,736,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-10-08 08:34:45 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-10-08 08:24:03 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-10-08 08:09:31 | 000,428,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-10-08 07:56:48 | 000,445,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-10-08 07:51:16 | 000,154,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-10-08 07:51:03 | 000,736,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-10-08 07:27:17 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-10-08 07:18:10 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-10-08 07:17:58 | 001,441,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-10-08 06:32:48 | 002,773,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-10-08 06:23:52 | 003,547,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-10-08 06:19:04 | 002,459,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-10-07 07:28:00 | 000,500,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-10-07 07:27:59 | 000,394,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-10-07 07:27:56 | 000,482,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-10-07 07:27:56 | 000,272,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-10-07 07:27:55 | 000,108,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-10-07 04:34:01 | 000,344,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2014-11-21 11:49:15 | 000,001,980 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014-11-15 05:58:55 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014-11-01 22:53:21 | 000,267,632 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-01 22:53:21 | 000,065,776 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-01 22:53:21 | 000,029,208 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-10-17 11:14:49 | 000,001,196 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xperia Link.lnk
[2014-08-16 18:02:22 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014-05-01 02:03:48 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014-03-22 06:09:22 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014-02-11 13:48:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013-12-13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013-12-13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013-12-13 10:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013-12-13 10:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013-12-13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013-08-22 16:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013-08-22 16:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013-08-22 15:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013-08-22 08:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013-08-22 04:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013-08-22 00:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013-08-22 00:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2014-03-04 10:22:49 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-08-31 01:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-08-30 23:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-08-22 10:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013-08-22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-08-22 10:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2014-03-03 19:06:47 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\OpenOffice
[2014-11-01 22:54:21 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-02-24 12:20:15 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje
[2014-02-24 12:20:16 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 220 bytes -> C:\Users\Lidia\SkyDrive:ms-properties

< End of report >


Kod: Zaznacz wszystko
OTL Extras logfile created on: 2014-12-04 18:59:03 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 2,40 Gb Available Physical Memory | 67,19% Memory free
4,20 Gb Paging File | 2,98 Gb Available in Paging File | 71,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,99 Gb Free Space | 77,46% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{030F16B3-AC3F-4B85-AC18-6EF3E5F4F36C}" = rport=138 | protocol=17 | dir=out | app=system |
"{0E408148-2463-493C-974D-9831F0585CEE}" = lport=9996 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcsystemtray.exe |
"{199E3C84-2FDE-45F8-9913-CEF74D8D3499}" = lport=1900 | protocol=17 | dir=in | app=%programfiles%\zune\zune.exe |
"{19AFECAE-A699-4CCD-B7D2-172015BF52AA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BA398D1-E360-4F0D-9A98-5EAB8B6CB86B}" = rport=445 | protocol=6 | dir=out | app=system |
"{31113462-1629-4950-917E-0BF2DAA24DD8}" = lport=138 | protocol=17 | dir=in | app=system |
"{3B656BEE-00F6-450C-8B2A-B8B6EA1052A1}" = lport=445 | protocol=6 | dir=in | app=system |
"{3DE59B36-AF3E-4A20-8268-BF907CEF1972}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4CF0A1A0-996D-404B-BEB9-9ED8531E56BD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D06C62A-FF0C-4F4C-A019-9FCA8B50AAE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{538335E5-13F7-47F7-AE49-8A22B0E73D97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{550A699B-3CDF-49AB-A293-25E8A6ABAA81}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{55A8CA9F-00E5-4CAB-95E8-C51B169A51F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5FDD1F6D-898C-4865-8569-C10751DFED61}" = lport=2869 | protocol=6 | dir=in | app=system |
"{68243D58-392D-41F5-8FE7-E6151EDCF778}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6E23CD0C-702C-4253-A384-C9DB53797B8F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{747A8562-F3A7-4A9C-A2E8-DE0E0E2584A0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7A4A8B49-C91E-4D16-B17A-C7E940954444}" = lport=139 | protocol=6 | dir=in | app=system |
"{898FB1AB-3DFC-4CC1-81F1-084A319F3C00}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A921310-5D00-44ED-9AAF-40780C05A99E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9B997EBD-66BE-4CE7-BB01-81F7CFC56AB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{A04A87E8-DA87-47B1-A0F1-914AD3757D53}" = lport=9997 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vaioshell.exe |
"{AAB83954-A7FE-468B-8A89-95CF1163699A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B01E4F72-CD19-480B-A104-A4C349D3C314}" = lport=9999 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe |
"{B4688510-2513-4F34-8332-47DAB553E0A1}" = lport=9998 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcadmin.exe |
"{BA8646D0-E0D5-420F-92F4-D99D5B2B2C8B}" = lport=137 | protocol=17 | dir=in | app=system |
"{D95F677C-FE69-4D9C-A800-B512F493DBAC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FAE44678-023C-46B8-862D-59FEB9CF75C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FB6C0575-99EB-41D6-AD97-40511D65DC77}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FC9FD662-EA31-42C0-A9A0-AEADD0F29594}" = rport=137 | protocol=17 | dir=out | app=system |
"{FE0B0C3F-A187-41CA-90E8-A3AE57FBF8F9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001464FC-E3E9-4828-BC6F-628A59D79CE4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.315_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{02A0F843-9E76-4C52-A0EE-7C02CE119ADC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{02A6CE20-3CE5-4935-804F-AF1CFCC01946}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{06773AF9-A653-4505-9AF2-878617C09D4A}" = dir=in | name=taptiles |
"{08DD2950-9786-49FC-9B3B-45DE06576044}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{093A6F4D-638C-49E3-BB66-0F338B51A334}" = dir=in | name=microsoft solitaire collection |
"{0D9B20DA-20EC-43B7-AB43-6E400C3EB4A7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{124BE3DC-93D9-4D46-8FB3-94980959F22A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{153DDAFE-7284-48EB-BB8E-2780F4C8BB43}" = dir=out | name=@{microsoft.zunemusic_2.2.931.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{17DD9FB6-2AE2-471E-B4DE-BB0DEA030DA3}" = dir=in | name=mcafee® central for sony |
"{1A6B4D74-2A98-40D3-938B-78443AA3251A}" = dir=out | name=sony select |
"{1A73D7E3-209F-4D1E-9545-7E4D11323C68}" = protocol=6 | dir=out | app=system |
"{1FB698BF-4735-4CBE-97D8-4E4EB6AD0FDA}" = dir=out | name=microsoft minesweeper |
"{2084B1B9-C9A6-417F-981A-D787C0B7317F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{21BFDA3E-2A93-473F-B772-667B01076326}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{2351BED2-2143-49A4-B4C3-DCBADB8E91FB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{263B3EA9-9E48-4AD2-8EDA-310736EE78AC}" = dir=out | name=@{microsoft.bingsports_3.0.2.317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{263C5183-B2FF-45B8-BECF-2B335EAF1F29}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{26719D7A-D5A2-4702-AB87-C4CAF90E3605}" = dir=in | name=juniper networks junos pulse |
"{2E32F130-BCF1-48CD-AECB-955B43601A3C}" = dir=out | name=juniper networks junos pulse |
"{2F3E727D-CC71-4533-B584-803B1E0C529C}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{2F522F85-964D-4FF8-80C1-7E9429426005}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{2F6B21B3-CF42-47F6-85AE-C45095FBA812}" = dir=out | name=vaio care |
"{2F71F6D2-8B4A-4EF0-8648-C94D81EB80E2}" = dir=out | name=- games app - |
"{302DD789-2769-4D7E-8712-7A0E58B11304}" = dir=in | name=microsoft minesweeper |
"{313F0D2F-EC6F-4307-8C72-AC6B7C540249}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{32DD8247-27F1-43DD-A33B-3BFC3EB8E502}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3329E50E-D514-4A00-BE5C-6EFD44B75F77}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{34C71DC9-3CFB-4C30-897E-A7583222713E}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3A48B196-4B0B-4173-A984-65DFEAF9DACA}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{3F1B62FF-8F0B-4A0E-9C50-1D9AEA7B9BF3}" = dir=in | name=skype |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{43219BD5-F0C3-475C-94B2-C68B7247343C}" = dir=out | name=@{microsoft.zunevideo_1.5.338.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{438E36CC-1B94-41AE-ABC5-995653A8B9F1}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{48D4E687-B9F5-4AFE-892F-436F15B3996B}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{4A7C30CB-C022-43A2-A18A-0042C93A4C42}" = protocol=6 | dir=out | app=system |
"{4B4155A4-1EC0-4371-B5AB-4A1066774CC2}" = dir=in | name=mcafee® central for sony |
"{508A2261-AE87-4A3B-95B8-9AB6F5F1ECC2}" = dir=out | name=@{microsoft.bingtravel_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{55AC1D0D-797C-4B91-9F42-0214A591BABC}" = dir=in | name=microsoft solitaire collection |
"{55B1BF9D-EE69-4A5A-82D9-6A694741CC00}" = dir=in | name=microsoft minesweeper |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{5A6557A8-21E2-4D5F-8ECF-952E7B0666C3}" = dir=out | name=windows_ie_ac_001 |
"{5ABEA3F4-87D2-4151-B772-882064F87314}" = dir=out | name=check point vpn |
"{5B56F422-8C54-4727-88E1-461288305EF9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5C180B6B-167E-4C02-A378-B0F5BC88E08B}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{608400D0-4232-4911-83E4-BDFFF494F4DA}" = dir=out | name=taptiles |
"{623B3D06-7BEC-4583-A25F-3F45E6E6C449}" = dir=out | name=skype |
"{64FBCFD1-9BF5-44E0-93DE-6CF6FACBC84A}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{6693CC48-FD90-4B49-95EE-CBCDAD9B93BE}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{677D8E8B-AF81-4910-B6A9-A3E4385CAA94}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{685B3947-DDBC-48C2-985C-A81DC5EEADAB}" = dir=out | name=microsoft solitaire collection |
"{6CF61DE6-9F17-40BD-9670-67338B1C2A10}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{73BC64C0-6827-46BC-AC51-74B3C2B196CE}" = dir=in | app=c:\users\lidia\appdata\local\microsoft\skydrive\skydrive.exe |
"{74F762CD-615B-4D6E-8299-BCD640553F8C}" = dir=out | name=@{microsoft.bingweather_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{751944F4-D261-4D64-BA9E-FA82DE2F9048}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{78CE5D66-64B8-44C3-8F2F-9D28E336EAAD}" = dir=out | name=@{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{7BD0C972-641A-442F-ACD9-B312122F5921}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{822B057D-68BB-4593-996B-02C5FDEBB95B}" = dir=out | name=juniper networks junos pulse |
"{823FED70-BBA1-4705-8B37-7896CE34DCD9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8491F288-D7F9-4674-84C7-F3318C469372}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{856434AD-ADCA-4010-991F-62D9656039BD}" = protocol=6 | dir=out | app=system |
"{882A2F3D-5A0F-43E1-A53B-FE3DCEF867A8}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{88C7819F-C7CF-46B5-AE41-FED1A7FBD144}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{89B6F0BD-97A2-4C1A-953B-99B88725ACA1}" = dir=out | name=skype |
"{8C4DFB19-B22C-476A-ABAE-3DB39500DCB6}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{8D9777BA-1A90-4367-9191-574484072827}" = dir=out | name=wordament |
"{9238877F-603C-46ED-8F06-6F50FF39BC11}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{940E5550-504E-4037-9EE7-EC4CC2E0D1D9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9458264A-5F0C-44C1-81C3-479A589FB3E3}" = dir=out | name=f5 vpn |
"{96A32F70-AA90-47DD-9513-B7EFFAC25A65}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{97983CB2-9F05-4A90-9609-D03981F881CA}" = dir=out | name=@{microsoft.zunemusic_2.6.476.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{9820196B-CCF2-4B13-8362-7334EBEFACDE}" = dir=out | name=@{microsoft.bingnews_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{98B40748-33D7-45AB-9DB4-CAE11317C670}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{9A5BD996-2418-4372-AFE1-2D09C2648F34}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9E3B5818-96C3-430E-AF40-7D44969C65A4}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9F595940-23DC-48C5-B04D-EEFF37139C05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9F7E3951-E6AC-442E-A901-621741838FB2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9F8097D1-0C03-49CB-BF40-FB506509FC52}" = dir=out | name=windows_ie_ac_001 |
"{9FAC618A-BDEF-4D39-8BC4-98FAA73F54B9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A1E34056-B831-457A-8F2F-0A99315293CB}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{A317CFA9-E27F-494E-9601-E66D6FF76D27}" = dir=in | name=check point vpn |
"{A4AE9D4C-2657-4DE2-9A5E-90C35F65BCA5}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{A633D237-0CDA-42B1-A892-CE4248D109F5}" = dir=out | name=microsoft solitaire collection |
"{A7EAA7C9-A9FC-471E-89C6-F83C1BBB8B1F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A9EC2D1E-7E16-489A-AF3E-96BCCB03EF00}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{ACF7881E-0950-4BBE-99E4-320025746E05}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AF5FE555-86C7-4004-9037-062CAFC3233B}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{B4DB54BD-3FB9-462A-99D2-FE799A6D785D}" = dir=out | name=sony select |
"{B70810F0-B1ED-461F-A994-D6BE128B19AF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BC1BD523-BD0B-42B4-A3B3-EC6E24AE7F1E}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{BC9E5E3F-1D42-46B5-BC90-475E4D1364CD}" = dir=out | name=@{microsoft.bingmaps_2.1.2922.2139_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{BD018346-9CE3-4B57-9749-0BC8D368BB9B}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{BD9C016A-62EC-41F7-982C-DE3FD213C238}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0B0590D-8CB4-4B48-819F-9FE86F23F560}" = dir=out | name=vaio care |
"{C176AFC8-9DC3-410B-9D00-3B76F677A3E9}" = dir=out | name=check point vpn |
"{C2125D7A-F3EA-45B5-9ED5-76FBE4032813}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{C2466120-2EE4-47CD-BF95-688F79D435F8}" = dir=out | name=@{microsoft.zunevideo_2.6.215.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{C3F01482-0DB4-42CD-8A91-7172BE718019}" = dir=out | name=mcafee® central for sony |
"{C40839CB-E672-41BE-8179-77239F483D3B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C64B97B6-4AA6-4DD8-B4A5-1EBE1C68A53F}" = dir=out | name=windows_ie_ac_001 |
"{C6E9145A-0EE9-44DE-8A58-FF97231D8F5E}" = dir=out | name=f5 vpn |
"{C7389275-089D-4764-829D-FA319B338401}" = dir=out | name=sonicwall mobile connect |
"{C778CDD6-6BF6-4811-8375-B446ABBEDAC7}" = dir=in | name=vaio care |
"{CA45CB10-1ADB-4A15-929E-5497A2E623D9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CB354727-1CD4-4820-A6C8-6F6D2258101E}" = dir=in | name=check point vpn |
"{CCE7A28A-1B1C-4441-9697-ACD7A435C068}" = dir=in | name=sonicwall mobile connect |
"{CE7E2FBF-222A-40BB-97F8-28ABCFC857C1}" = dir=out | name=windows_ie_ac_001 |
"{D032395D-1786-4F9A-A512-8E07703A2B8D}" = dir=out | name=- games app - |
"{D14AF6D4-42A7-4DB7-AFDE-B34B169C7083}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{D23153B5-2163-49F8-9B26-77F501379547}" = dir=out | name=sonicwall mobile connect |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D70EAC0A-DAEE-4F16-A109-02929D410E67}" = dir=out | name=windows_ie_ac_001 |
"{D7880873-CC9D-4D1D-A52C-68FF92783C2D}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{D7D933AC-4D60-4F38-A828-64D4B46323C7}" = dir=out | name=microsoft minesweeper |
"{D8A0E1E8-82AA-48D2-8944-16525F39DE93}" = dir=in | name=skype |
"{DA3CF7A9-20F0-450E-A5A2-9651DD78FBC0}" = dir=in | name=juniper networks junos pulse |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DBFE4C41-4629-434B-B3F7-DFB0DEC44110}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DCB2A9F6-2AB1-4A41-B522-AF44BFD1D0BD}" = dir=in | name=vaio care |
"{DCCA78F9-2906-43B9-9B9C-76DBDC822912}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{DCD62A33-757D-4DF6-AD27-D3034BC8AB28}" = dir=in | name=f5 vpn |
"{DDB99518-2F6D-493A-A867-9A63600834F7}" = dir=in | name=sonicwall mobile connect |
"{E2ECA714-68DE-4E5B-9EEA-CCDDF1FFB846}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{E3E85A51-C589-4CB7-80C7-C553CEA3EC0B}" = dir=out | name=@{microsoft.zunevideo_2.6.408.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{E4705F09-9887-4F2B-8479-ADFC2DF1BBA3}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{E53611B4-545A-492D-A815-6B3F552E1646}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{E7211AB8-916E-4392-9278-045F599DFB54}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E76059C4-6926-4F96-8A2C-4FD2F0AEF1A8}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E8726D91-8391-485A-9E9B-4BCF023A311A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{ECBF3C57-D6CB-462F-BCB5-F5BBEE88E889}" = dir=out | name=mcafee® central for sony |
"{ECCDA18D-D39B-4815-9E46-AE9CA2E748B4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{EFD9D7E7-9D74-404A-B33A-9004227CE02D}" = dir=out | name=taptiles |
"{EFEA28EC-C9B1-4471-8630-DE38648359B4}" = dir=in | name=taptiles |
"{F1A5B808-1673-44B2-B0BC-0193CFFB8C33}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F230AAB7-996E-4D3B-B0EA-46CAEF46C59E}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{F9F0C374-492A-4350-B24C-D83A28B86960}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{FAF0E88C-088B-43DB-B464-41B743A98699}" = dir=out | name=wordament |
"{FBA7E63F-58E8-4C71-A003-A30F847720A5}" = dir=in | name=f5 vpn |
"TCP Query User{78B7C52D-B45B-4915-BD53-FCB6FC9D571B}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{E5F1B4C1-BBE5-457E-AE34-CDF31F9BDDEF}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{553A0E06-4AC5-46F5-B7DC-6D94EA0C3373}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{AA0903BB-5077-41E3-9785-1B6C21C88CD3}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{15B9204E-BA09-485E-8F2C-094AC0077664}" = VAIO Care Recovery
"{25ECAFCB-DCFB-4FCE-A5B2-772A57F59860}" = VCCx64
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{30EC1664-6916-5E36-FEA7-8E20B1C4DCD7}" = ccc-utility64
"{312395BC-7CC2-434C-A660-30250276A926}" = SSLx64
"{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}" = iTunes
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{46261E1C-5E0D-484E-8CCC-7F770375FBA2}" = VU5x64
"{4B432082-B58C-4035-91FB-F28D504D3148}" = VUx64
"{4F31AC31-0A28-4F5A-8416-513972DA1F79}" = VSSTx64
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{5388ABD8-6E23-4498-BE10-01079387590F}" = VGClientX64
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62A172B2-550E-499D-9A82-5190D18390AA}" = VAIO Media Server Settings
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}" = Apple Mobile Device Support
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{77619545-1710-CA11-4487-4CD836E76DB9}" = AMD Fuel
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007
"{92907606-B2FC-4193-B0CE-A21159DA3ABB}" = VAIO Care
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{AB447E3B-7A95-4CA6-8ECD-B25C96314B67}" = VCCx64
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{B81EACDF-16E0-A32C-F096-16EF2BD8405C}" = AMD Catalyst Install Manager
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{D55EAC07-7207-44BD-B524-0F063F327743}" = VIx64
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}" = VPMx64
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 5.10 (64-bitowy)
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"{10181264-340D-4BE7-B879-3A49604A6FD1}" = VUx86
"{10DD6128-A810-4A90-9523-475D573FBB37}" = PlayMemories Home
"{14AC95A2-7675-4988-A5BD-3F5B943AED08}" = VAIO Gate
"{1A207C93-12E4-5B88-777D-92F74DC29EDD}" = CCC Help Hungarian
"{1AE56779-2A31-8982-FF75-422457BA5123}" = CCC Help Danish
"{1B740CAA-D283-4662-0469-898A0850B622}" = CCC Help Chinese Traditional
"{1C7DDA73-0C05-E7DD-97A8-A8542B8EA404}" = CCC Help Norwegian
"{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}" = Obsługa programów Apple
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{26A3AC60-368D-D7FE-30C9-C85E4E1FD7EC}" = CCC Help Turkish
"{309DDAE9-A147-56A2-456D-F66BCEFA88E5}" = Catalyst Control Center Graphics Previews Common
"{3490653F-2789-46A1-B1BF-6BD4CF4131AB}" = FDUx86
"{3A26D9BD-0F73-432D-B522-2BA18138F7EF}" = VAIO Improvement
"{3B1AECFC-F652-9877-B6BE-5BFB5023B02F}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523ADF33-0165-88B2-E05E-22C934058B81}" = CCC Help German
"{54BDD1B2-1312-EF6F-ED92-1C300377D9DE}" = CCC Help Greek
"{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
"{60D1433B-175B-B907-DD89-D434997BEBEC}" = CCC Help Russian
"{63C43435-F428-42BA-8E7B-5848749D9262}" = SSLx86
"{641256B0-734F-2B3E-4AEA-4B2AB21F8916}" = Catalyst Control Center Profiles Mobile
"{661598FC-D512-F972-22D8-620D36CEA58B}" = CCC Help Italian
"{692955F2-DE9F-4078-8FAA-858D6F3A1776}" = VAIO Gesture Control
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{74B53C92-E8E8-1903-76FE-A113448EB504}" = CCC Help Japanese
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79954639-C427-4B14-B774-2F6EE649BE99}" = Catalyst Control Center - Branding
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{7AD4F11E-E27C-1455-3F32-076ABB2CE633}" = Catalyst Control Center InstallProxy
"{7B6D6F11-A5BC-4538-0017-21350BA54ED4}" = CCC Help Portuguese
"{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
"{7E5A5CA6-B7D0-406E-A75E-157CAB47EB94}" = VMLx86
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{82CFAFBA-3D52-F45B-67B1-3D1885C7F87D}" = CCC Help Thai
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{857087BB-A988-4462-A5C6-CF6739143B56}" = KUx86
"{88AEC113-3901-0902-A0B8-651A74D005BF}" = CCC Help Chinese Standard
"{8E797841-A110-41FD-B17A-3ABC0641187A}" = VAIO Control Center
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{913E2B02-1BA9-4B38-991B-31C717F9D00C}" = e-Deklaracje Desktop
"{94211EE0-14F9-58C8-676B-54462CB2A346}" = CCC Help Finnish
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
"{9D8112DB-3490-4BF1-AAFA-1D224FFB5D3C}" = VHD
"{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
"{A2F10E60-5D7D-E13B-E451-99A70EBB7C39}" = CCC Help Spanish
"{AA4B3623-6213-41EC-9BFB-F001D72C47A6}" = VAIO Gesture Control
"{AB57D823-F5BE-38AF-DD26-8E04E64308AA}" = CCC Help Polish
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.11) MUI
"{AFDC0CC0-39E8-42C0-9823-2C1C182676DC}" = VCCx86
"{AFE24FB0-8CC3-77A5-EBFA-132FD250FE66}" = CCC Help English
"{B24BB74E-8359-43AA-985A-8E80C9219C70}" = VSSTx86
"{B31938C7-7E97-49EE-8F88-951E156268A3}" = VCCx86
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B8991D99-88FD-41F2-8C32-DB70278D5C30}" = VWSTx86
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BCBBD089-FF54-3F73-2FB5-F3DD7ED7B439}" = Catalyst Control Center Localization All
"{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}" = VAIO CPU Fan Diagnostic
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C4001DF8-CE87-B7C5-5AC8-D8C321D070EA}" = CCC Help French
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
"{C820FBC5-0490-B6D7-0AF5-D8245E1BD903}" = CCC Help Swedish
"{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}" = VIx86
"{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
"{D91558BF-D1F3-411F-AEFE-8774CB406512}" = VAIO - Xperia Link
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ECCEB4D0-7080-4F8A-B498-E40A32A4FBED}" = Restore
"{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}" = XperiaLinkx86
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F458075C-E1AB-F9A6-3B97-D80BF7EC44A5}" = CCC Help Korean
"{F55687F5-D221-604B-61EA-49E80DB04D11}" = AMD VISION Engine Control Center
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FC9F3001-77BD-D664-5941-6E3F16203629}" = CCC Help Czech
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Avast" = Avast Free Antivirus
"e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1" = e-Deklaracje Desktop
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"Mozilla Firefox 33.1 (x86 pl)" = Mozilla Firefox 33.1 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NetSender_is1" = NetSender 3.0
"Picasa 3" = Picasa 3
"PIT Format 2013_is1" = PIT Format 2013
"PITy 2013/2014_is1" = PITy 2013/2014

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SkyDriveSetup.exe" = Microsoft SkyDrive

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2014-11-30 10:03:20 | Computer Name = Lila | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja: 33.1.0.5423,
sygnatura czasowa: 0x545c0a59  Nazwa modułu powodującego błąd: mozalloc.dll, wersja:
33.1.0.5423, sygnatura czasowa: 0x545be5ee  Kod wyjątku: 0x80000003  Przesunięcie błędu:
0x00001425  Identyfikator procesu powodującego błąd: 0x174c  Godzina uruchomienia aplikacji
powodującej błąd: 0x01d00ca6113e2ce6  Ścieżka aplikacji powodującej błąd: C:\Program
Files (x86)\Mozilla Firefox\plugin-container.exe  Ścieżka modułu powodującego błąd:
C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll  Identyfikator raportu: a3895669-7899-11e4-beab-083e8ebd58f0
Pełna
nazwa pakietu powodującego błąd:   Identyfikator aplikacji względem pakietu powodującego
błąd:

Error - 2014-11-30 10:18:04 | Computer Name = Lila | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 2014-11-30 10:52:49 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2014-11-30 10:52:49 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1750

Error - 2014-11-30 10:52:49 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1750

Error - 2014-11-30 10:52:51 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2014-11-30 10:52:51 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5234

Error - 2014-11-30 10:52:51 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5234

Error - 2014-11-30 11:13:52 | Computer Name = Lila | Source = Microsoft-Windows-LocationProvider | ID = 2006
Description =

Error - 2014-11-30 11:32:36 | Computer Name = Lila | Source = VSS | ID = 8194
Description =

[ ESRV_SVC Events ]
Error - 2014-04-26 11:37:10 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

[ System Events ]
Error - 2014-12-01 15:15:07 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:15:07 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:15:07 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:20:37 | Computer Name = Lila | Source = APXACC | ID = 16778219
Description = The NDIS6 LWF initialization has failed. (0xC0000001)

Error - 2014-12-01 15:20:37 | Computer Name = Lila | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi AppEx Networks Accelerator LWF z powodu
następującego błędu:   %%31

Error - 2014-12-01 15:21:36 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:21:37 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:21:37 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:31:40 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:31:41 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =


< End of report >


Dodano 04.12.2014 19:56:11:
mam również część loga z GMER-a puszca go puszcza ale staje gdyż pojawia się błąd z pierwszego postu. Może się przyda:

Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-12-04 19:54:58
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\0000002a Hitachi_HTS547550A9E384 rev.JE3OA50B 465,76GB
Running: evbhsk4y.exe; Driver: C:\Users\Lidia\AppData\Local\Temp\pxldapow.sys


---- User code sections - GMER 2.1 ----

.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                  00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                           00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                           00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                      00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                           00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                    00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                       00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                             00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                           00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                         00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                          00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                       00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                          00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                               00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                           00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                              00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                       00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                    00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                          00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                       00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                        00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                           00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                    00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                       00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                            00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                       00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                       00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                              00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                         00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                      00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                                  00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                            00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                         00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                            00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                             00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                      00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                     00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                                 00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                        00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                    00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                      00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                  00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                   00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                        00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                        00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                         00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                    00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                            00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\System32\smss.exe[328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                        00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                 00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                          00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                          00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                               00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                     00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                          00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                   00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                      00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                            00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                          00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                        00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                         00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                      00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                         00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                              00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                          00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                             00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                      00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                   00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                         00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                      00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                       00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                          00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                   00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                      00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                           00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                      00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                      00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                             00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                        00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                     00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                                 00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                           00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                        00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                           00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                            00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                     00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                    00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                                00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                       00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                   00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                     00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                 00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                  00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                       00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                       00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                        00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                   00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                           00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\csrss.exe[580] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                       00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                               00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                        00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                        00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                             00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                        00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                 00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                    00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                          00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                        00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                      00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                       00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                    00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                       00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                            00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                        00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                           00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                    00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                 00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                       00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                    00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                     00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                        00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                 00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                    00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                         00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                    00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                    00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                           00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                      00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                   00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                               00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                         00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                      00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                         00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                          00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                   00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                  00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                              00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                     00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                 00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                   00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                               00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                     00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                     00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                      00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                 00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                         00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\wininit.exe[716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                     00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                 00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                          00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                          00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                               00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                     00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                          00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                   00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                      00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                            00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                          00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                        00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                         00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                      00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                         00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                              00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                          00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                             00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                      00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                   00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                         00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                      00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                       00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                          00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                   00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                      00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                           00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                      00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                      00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                             00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                        00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                     00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                                 00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                           00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                        00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                           00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                            00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                     00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                    00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                                00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                       00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                   00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                     00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                 00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                  00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                       00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                       00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                        00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                   00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                           00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\csrss.exe[724] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                       00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\winlogon.exe[768] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\services.exe[804] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                 00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                          00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                          00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                               00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                     00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                          00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                   00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                      00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                            00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                          00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                        00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                         00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                      00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                         00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                              00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                          00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                             00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                      00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                   00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                         00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                      00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                       00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                          00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                   00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                      00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                           00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                      00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                      00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                             00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                        00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                     00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                                 00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                           00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                        00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                           00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                            00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                     00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                    00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                                00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                       00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                   00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                     00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                 00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                  00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                       00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                       00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                        00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                   00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                           00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\lsass.exe[812] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                       00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                               00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                        00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                        00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                             00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                        00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                 00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                    00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                          00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                        00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                      00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                       00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                    00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                       00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                            00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                        00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                           00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                    00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                 00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                       00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                    00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                     00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                        00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                 00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                    00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                         00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                    00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                    00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                           00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                      00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                   00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                               00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                         00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                      00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                         00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                          00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                   00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                  00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                              00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                     00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                 00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                   00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                               00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                     00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                     00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                      00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                 00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                         00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                     00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                               00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                        00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                        00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                             00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                        00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                 00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                    00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                          00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                        00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                      00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                       00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                    00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                       00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                            00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                        00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                           00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                    00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                 00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                       00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                    00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                     00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                        00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                 00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                    00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                         00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                    00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                    00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                           00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                      00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                   00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                               00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                         00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                      00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                         00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                          00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                   00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                  00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                              00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                     00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                 00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                   00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                               00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                     00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                     00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                      00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                 00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                         00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                     00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                  00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                           00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                           00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                      00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                           00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                    00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                       00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                             00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                           00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                         00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                          00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                       00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                          00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                               00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                           00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                              00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                       00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                    00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                          00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                       00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                        00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                           00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                    00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                       00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                            00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                       00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                       00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                              00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                         00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                      00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                                  00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                            00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                         00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                            00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                             00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                      00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                     00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                                 00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                        00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                    00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                      00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                  00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                   00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                        00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                        00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                         00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                    00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                            00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\dwm.exe[1020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                        00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                            00007ff9efc4169a 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                            00007ff9efc416a2 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                               00007ff9efc4181a 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[392] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                               00007ff9efc41832 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                               00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                        00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                        00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                             00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                        00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                 00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                    00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                          00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                        00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                      00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                       00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                    00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                       00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                            00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                        00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                           00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                    00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                 00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                       00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                    00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                     00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                        00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                 00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                    00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                         00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                    00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                    00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                           00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                      00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                   00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                               00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                         00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                      00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                         00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                          00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                   00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                  00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                              00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                     00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                 00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                   00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                               00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                     00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                     00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                      00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                 00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                         00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\System32\svchost.exe[380] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                     00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                               00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                        00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                        00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                             00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                        00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                 00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                    00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                          00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                        00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                      00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                       00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                    00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                       00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                            00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                        00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                           00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                    00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                 00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                       00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                    00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                     00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                        00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                 00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                    00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                         00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                    00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                    00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                           00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                      00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                   00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                               00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                         00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                      00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                         00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                          00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                   00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                  00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                              00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                     00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                 00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                   00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                               00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                     00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                     00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                      00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                 00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                         00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[908] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                     00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[1032] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\System32\svchost.exe[1084] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                             00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                      00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                      00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                           00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                 00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                      00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                               00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                  00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                        00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                      00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                    00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                     00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                  00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                     00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                          00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                      00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                         00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                  00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                               00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                     00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                  00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                   00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                      00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                               00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                  00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                       00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                  00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                  00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                         00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                    00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                 00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                             00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                       00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                    00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                       00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                        00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                 00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                            00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                   00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                               00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                 00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                             00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                              00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                   00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                   00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                    00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                               00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                       00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                   00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                           00007ff9efc4169a 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                           00007ff9efc416a2 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                              00007ff9efc4181a 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1120] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                              00007ff9efc41832 4 bytes [C4, EF, F9, 7F]
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[1276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\System32\spoolsv.exe[1468] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[1524] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                      00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                               00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                               00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                    00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                          00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                               00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                        00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                           00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                 00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                               00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                             00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                              00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                           00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                              00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                   00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2               00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                  00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                           00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                        00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                              00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                           00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                            00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                               00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                        00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                           00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                           00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                           00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                  00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                             00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                          00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                      00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                             00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                 00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                          00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                         00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                     00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                            00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                        00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                          00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                      00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                       00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                            00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                            00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                             00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                        00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1264] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                            00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                   00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                            00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                            00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                 00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                       00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                            00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                     00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                        00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                              00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                            00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                          00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                           00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                        00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                           00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                            00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                               00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                        00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                     00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                           00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                        00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                         00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                            00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                     00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                        00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                             00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                        00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                        00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                               00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                          00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                       00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                   00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                             00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                          00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                             00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                              00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                       00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                      00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                  00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                         00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                     00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                       00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                   00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                    00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                         00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                         00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                          00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                     00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                             00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Bonjour\mDNSResponder.exe[1560] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                         00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\dashost.exe[2216] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                        00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                 00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                 00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                      00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                            00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                 00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                          00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                             00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                   00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                 00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                               00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                             00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                     00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                 00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                    00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                             00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                          00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                             00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                              00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                 00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                          00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                             00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                  00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                             00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                             00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                    00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                               00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                            00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                        00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                  00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                               00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                  00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                   00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                            00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                           00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                       00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                              00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                          00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                            00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                        00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                         00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                              00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                              00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                               00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                          00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                  00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\wbem\wmiprvse.exe[2612] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                              00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\svchost.exe[2080] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                           00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                    00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                    00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                         00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                               00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                    00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                             00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                      00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                    00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                  00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                   00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                   00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                        00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                    00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                       00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                             00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                   00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                 00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                    00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                             00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                     00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                       00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                  00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                               00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                           00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                     00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                  00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                     00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                      00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                               00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                              00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                          00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                 00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                             00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                               00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                           00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                            00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                 00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                 00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                  00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                             00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                     00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\taskhostex.exe[3180] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                 00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                      00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                               00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                               00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                    00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                          00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                               00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                        00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                           00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                                 00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                               00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                             00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                              00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                           00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                              00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                   00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                               00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                  00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                           00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                        00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                              00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                           00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                            00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                               00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                        00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                           00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                                00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                           00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                           00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                  00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                             00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                          00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                                      00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                                00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                             00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                                00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                                 00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                          00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                         00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                                     00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                            00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                        00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                          00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                      00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                       00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                            00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                            00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                             00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                        00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                                00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\Explorer.EXE[3296] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                            00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\DllHost.exe[3704] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                        00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                 00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                 00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                      00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                            00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                 00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                          00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                             00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                   00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                 00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                               00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                             00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                     00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                 00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                    00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                             00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                          00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                             00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                              00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                 00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                          00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                             00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                  00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                             00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                             00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                    00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                               00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                            00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                        00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                  00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                               00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                  00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                   00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                            00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                           00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                       00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                              00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                          00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                            00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                        00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                         00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                              00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                              00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                               00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                          00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                  00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\SearchIndexer.exe[3884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                              00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                             00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                      00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                      00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                           00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                 00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                      00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                               00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                  00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                        00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                      00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                    00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                     00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                  00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                     00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                          00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                      00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                         00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                  00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                               00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                     00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                  00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                   00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                      00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                               00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                  00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                       00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                  00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                  00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                         00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                    00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                 00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                             00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                       00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                    00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                       00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                        00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                 00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                            00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                   00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                               00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                 00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                             00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                              00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                   00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                   00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                    00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                               00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                       00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Windows\System32\skydrive.exe[3368] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                   00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                               00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                        00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                        00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                             00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                   00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                        00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                 00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                    00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                          00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                        00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                      00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                       00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                    00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                       00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                            00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                        00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                           00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                    00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                 00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                       00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                    00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                     00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                        00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                 00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                    00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                         00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                    00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                    00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                           00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                      00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                   00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                               00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                         00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                      00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                         00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                          00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                   00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                  00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                              00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                     00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                 00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                   00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                               00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                     00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                     00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                      00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                 00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                         00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                     00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                       00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                     00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                           00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                         00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                            00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                  00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                              00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                               00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                            00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                               00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                    00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                   00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                            00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                         00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                               00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                            00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                             00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                         00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                            00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                 00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                            00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                            00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                   00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                              00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                           00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                       00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                 00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                              00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                 00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                  00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                           00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                          00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                      00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                             00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                         00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                           00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                       00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                        00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                             00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                             00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                              00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                         00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                 00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Zune\ZuneLauncher.exe[4248] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                             00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\System32\svchost.exe[4316] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                         00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                         00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                              00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                    00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                         00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                  00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                     00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                           00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                         00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                       00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                        00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                     00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                        00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                             00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                         00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                            00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                     00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                  00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                        00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                     00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                      00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                         00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                  00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                     00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                          00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                     00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                     00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                            00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                       00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                    00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                          00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                       00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                          00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                           00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                    00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                   00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                               00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                      00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                  00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                    00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                 00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                      00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                      00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                       00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                  00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                          00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                      00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                              00007ff9efc4169a 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                              00007ff9efc416a2 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                 00007ff9efc4181a 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4324] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                 00007ff9efc41832 4 bytes [C4, EF, F9, 7F]
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                             00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                      00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                      00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                           00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                 00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                      00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                               00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                  00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                        00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                      00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                    00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                     00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                  00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                     00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                          00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                      00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                         00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                  00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                               00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                     00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                  00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                   00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                      00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                               00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                  00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                       00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                  00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                  00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                         00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                    00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                 00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                             00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                       00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                    00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                       00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                        00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                 00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                            00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                   00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                               00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                 00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                             00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                              00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                   00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                   00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                    00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                               00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                       00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                   00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                           00007ff9efc4169a 4 bytes [C4, EF, F9, 7F]
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                           00007ff9efc416a2 4 bytes [C4, EF, F9, 7F]
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                              00007ff9efc4181a 4 bytes [C4, EF, F9, 7F]
.text   C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4800] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                              00007ff9efc41832 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                    00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                             00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                             00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                  00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                        00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                             00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                      00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                         00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                               00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                             00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                           00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                            00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                         00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                            00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                 00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                             00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                         00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                      00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                            00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                         00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                          00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                             00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                      00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                         00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                              00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                         00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                         00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                           00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                        00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                    00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                              00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                           00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                              00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                               00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                        00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                       00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                   00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                          00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                      00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                        00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                    00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                     00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                          00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                          00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                           00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                      00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                              00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\iPod\bin\iPodService.exe[1732] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                          00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                        00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                 00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                 00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                      00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                            00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                 00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                          00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                             00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                   00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                 00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                               00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                             00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                     00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                 00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                    00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                             00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                          00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                             00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                              00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                 00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                          00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                             00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                  00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                             00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                             00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                    00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                               00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                            00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                        00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                  00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                               00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                  00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                   00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                            00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                           00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                       00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                              00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                          00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                            00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                        00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                         00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                              00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                              00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                               00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                          00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                  00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\wbem\unsecapp.exe[3936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                              00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\DllHost.exe[5228] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                            00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                     00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                     00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                          00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                     00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                              00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                 00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                       00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                     00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                   00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                    00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                 00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                    00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                         00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                     00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                        00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                 00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                              00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                    00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                 00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                  00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                     00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                              00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                 00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                      00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                 00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                 00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                        00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                   00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                            00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                      00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                   00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                      00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                       00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                               00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                           00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                  00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                              00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                            00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                             00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                  00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                  00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                   00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                              00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                      00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files (x86)\Bluetooth Suite\BtTray.exe[5676] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                  00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                          00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                   00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                   00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                        00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                              00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                   00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                            00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                               00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                     00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                   00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                 00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                  00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                               00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                  00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                       00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                   00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                      00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                               00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                            00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                  00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                               00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                   00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                            00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                               00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                    00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                               00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                               00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                      00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                 00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                              00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                          00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                    00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                 00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                    00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                     00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                              00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                             00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                         00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                            00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                              00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                          00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                           00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                 00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                            00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                    00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194                              00007ff9d8c51f6a 4 bytes [C5, D8, F9, 7F]
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[5688] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218                              00007ff9d8c51f82 4 bytes [C5, D8, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                         00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                         00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                              00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                    00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                         00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                  00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                     00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                           00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                         00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                       00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                        00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                     00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                        00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                             00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                         00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                            00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                     00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                  00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                        00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                     00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                      00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                         00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                  00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                     00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                          00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                     00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                     00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                            00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                       00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                    00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                          00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                       00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                          00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                           00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                    00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                   00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                               00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                      00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                  00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                    00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                 00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                      00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                      00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                       00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                  00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                          00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                      00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                              00007ff9efc4169a 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                              00007ff9efc416a2 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                 00007ff9efc4181a 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe[2668] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                 00007ff9efc41832 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                            00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                     00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                     00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                          00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                     00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                              00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                 00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                       00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                     00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                   00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                    00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                 00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                    00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                         00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                     00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                        00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                 00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                              00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                    00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                 00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                  00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                     00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                              00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                 00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                      00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                 00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                 00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                        00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                   00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                            00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                      00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                   00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                      00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                       00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                               00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                           00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                  00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                              00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                            00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                             00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                  00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                  00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                   00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                              00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                      00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe[5556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                  00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort         00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                  00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                  00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx       00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess             00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                  00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory           00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject              00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                    00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                  00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                 00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread              00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                 00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort      00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2  00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject     00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair              00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion           00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                 00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore              00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx               00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                  00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess           00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry              00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                   00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry              00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey              00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys     00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion             00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2         00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                   00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                   00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                    00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx             00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder            00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2        00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions               00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2           00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread             00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation         00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState          00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem               00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess               00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl           00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                   00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[5672] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3               00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                            00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                     00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                     00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                          00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                     00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                              00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                 00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                       00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                     00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                   00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                    00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                 00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                    00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                         00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                     00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                        00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                 00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                              00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                    00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                 00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                  00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                     00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                              00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                 00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                      00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                 00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                 00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                        00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                   00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                            00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                      00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                   00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                      00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                       00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                               00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                           00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                  00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                              00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                            00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                             00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                  00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                  00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                   00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                              00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                      00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                  00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                          00007ff9efc4169a 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                          00007ff9efc416a2 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                             00007ff9efc4181a 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Care\VCPerfService.exe[1048] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                             00007ff9efc41832 4 bytes [C4, EF, F9, 7F]
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                         00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                         00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                              00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                    00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                         00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                  00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                     00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                           00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                         00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                       00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                        00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                     00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                        00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                             00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                         00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                            00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                     00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                  00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                        00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                     00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                      00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                         00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                  00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                     00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                          00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                     00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                     00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                            00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                       00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                    00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                          00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                       00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                          00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                           00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                    00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                   00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                               00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                      00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                  00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                    00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                 00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                      00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                      00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                       00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                  00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                          00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Sony\VAIO Update\vuagent.exe[5584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                      00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                  00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                           00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                           00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                      00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                           00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                    00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                       00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                             00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                           00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                         00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                          00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                       00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                          00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                               00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                           00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                              00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                       00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                    00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                          00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                       00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                        00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                           00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                    00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                       00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                            00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                       00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                       00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                              00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                         00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                      00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                  00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                            00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                         00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                            00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                             00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                      00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                     00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                 00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                        00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                    00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                      00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                  00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                   00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                        00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                        00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                         00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                    00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                            00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\Program Files\Sony\VAIO Care\VCAgent.exe[3528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                        00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                             00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                      00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                      00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                           00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                 00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                      00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                               00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                  00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                        00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                      00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                    00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                     00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                  00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                     00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                          00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                      00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                         00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                  00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                               00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                     00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                  00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                   00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                      00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                               00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                  00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                       00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                  00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                  00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                         00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                    00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                 00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                             00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                       00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                    00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                       00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                        00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                 00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                            00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                   00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                               00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                 00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                             00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                              00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                   00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                   00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                    00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                               00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                       00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\taskhost.exe[5268] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                   00007ff9f0ad3123 2 bytes [12, 80]
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                              00007ff9f0ad1720 5 bytes JMP 00007ffa70c00460
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject                                                       00007ff9f0ad1770 5 bytes JMP 00007ffa70c00450
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess                                                       00007ff9f0ad18d0 5 bytes JMP 00007ffa70c00370
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                            00007ff9f0ad1920 5 bytes JMP 00007ffa70c00470
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00007ff9f0ad1930 5 bytes JMP 00007ffa70c003e0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection                                                       00007ff9f0ad19e0 5 bytes JMP 00007ffa70c00320
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                00007ff9f0ad1a10 5 bytes JMP 00007ffa70c003b0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject                                                   00007ff9f0ad1a30 5 bytes JMP 00007ffa70c00390
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent                                                         00007ff9f0ad1a70 5 bytes JMP 00007ffa70c002e0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent                                                       00007ff9f0ad1af0 5 bytes JMP 00007ffa70c002d0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection                                                     00007ff9f0ad1b10 5 bytes JMP 00007ffa70c00310
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread                                                      00007ff9f0ad1b50 5 bytes JMP 00007ffa70c003c0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread                                                   00007ff9f0ad1ba0 5 bytes JMP 00007ffa70c003f0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry                                                      00007ff9f0ad1d00 5 bytes JMP 00007ffa70c00230
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                           00007ff9f0ad1ef0 1 byte JMP 00007ffa70c00480
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort + 2                                       00007ff9f0ad1ef2 3 bytes {JMP 0xffffffff8012e590}
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                          00007ff9f0ad1f20 5 bytes JMP 00007ffa70c003a0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair                                                   00007ff9f0ad2040 5 bytes JMP 00007ffa70c002f0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                00007ff9f0ad2060 5 bytes JMP 00007ffa70c00350
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant                                                      00007ff9f0ad20d0 5 bytes JMP 00007ffa70c00290
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                   00007ff9f0ad2160 5 bytes JMP 00007ffa70c002b0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                    00007ff9f0ad2180 5 bytes JMP 00007ffa70c003d0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer                                                       00007ff9f0ad2190 5 bytes JMP 00007ffa70c00330
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                00007ff9f0ad2240 5 bytes JMP 00007ffa70c00410
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                   00007ff9f0ad2270 5 bytes JMP 00007ffa70c00240
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver                                                        00007ff9f0ad2590 5 bytes JMP 00007ffa70c001e0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                   00007ff9f0ad2650 5 bytes JMP 00007ffa70c00250
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                   00007ff9f0ad2680 5 bytes JMP 00007ffa70c00490
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                          00007ff9f0ad2690 5 bytes JMP 00007ffa70c004a0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair                                                     00007ff9f0ad26c0 5 bytes JMP 00007ffa70c00300
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                  00007ff9f0ad26d0 1 byte JMP 00007ffa70c00360
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion + 2                                              00007ff9f0ad26d2 3 bytes {JMP 0xffffffff8012dc90}
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant                                                        00007ff9f0ad2730 5 bytes JMP 00007ffa70c002a0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                     00007ff9f0ad2780 5 bytes JMP 00007ffa70c002c0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread                                                        00007ff9f0ad27b0 5 bytes JMP 00007ffa70c00380
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer                                                         00007ff9f0ad27c0 5 bytes JMP 00007ffa70c00340
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                  00007ff9f0ad2ad0 5 bytes JMP 00007ffa70c00440
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                 00007ff9f0ad2cd0 1 byte JMP 00007ffa70c00260
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder + 2                                             00007ff9f0ad2cd2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions                                                    00007ff9f0ad2ce0 1 byte JMP 00007ffa70c00270
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions + 2                                                00007ff9f0ad2ce2 3 bytes {JMP 0xffffffff8012d590}
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread                                                  00007ff9f0ad2d00 5 bytes JMP 00007ffa70c00400
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation                                              00007ff9f0ad2ee0 5 bytes JMP 00007ffa70c001f0
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                               00007ff9f0ad2ef0 5 bytes JMP 00007ffa70c00210
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem                                                    00007ff9f0ad2f80 5 bytes JMP 00007ffa70c00200
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess                                                    00007ff9f0ad2ff0 5 bytes JMP 00007ffa70c00420
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread                                                     00007ff9f0ad3000 5 bytes JMP 00007ffa70c00430
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                00007ff9f0ad3010 5 bytes JMP 00007ffa70c00220
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl                                                        00007ff9f0ad3120 2 bytes JMP 00007ffa70c00280
.text   C:\WINDOWS\system32\AUDIODG.EXE[2904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl + 3                                                    00007ff9f0ad3123 2 bytes [12, 80]

---- Devices - GMER 2.1 ----

Device  \Driver\amdsata \Device\RaidPort0                                                                                                       ffffe001cf2532c0
Device  \Driver\amdsata \Device\ScsiPort0                                                                                                       ffffe001cf2532c0
Device  \Driver\amdsata \Device\0000002a                                                                                                        ffffe001cf2532c0

---- Trace I/O - GMER 2.1 ----

Trace   ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xffffe001cf2552c0]<< sptd.sys amdxata.sys ACPI.sys storport.sys hal.dll amdsata.sys      ffffe001cf2552c0
Trace   1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001d01b5770]                                                                         ffffe001d01b5770
Trace   3 CLASSPNP.SYS[fffff8011bf9727b] -> nt!IofCallDriver -> [0xffffe001cfbf8940]                                                            ffffe001cfbf8940
Trace   \Driver\amdxata[0xffffe001cfbe4700] -> IRP_MJ_CREATE -> 0xffffe001cf2552c0                                                              ffffe001cf2552c0
Trace   5 amdxata.sys[fffff8011ba846b4] -> nt!IofCallDriver -> [0xffffe001cfbf8e50]                                                             ffffe001cfbf8e50
Trace   7 ACPI.sys[fffff8011b55b7aa] -> nt!IofCallDriver -> \Device\0000002a[0xffffe001cfbf57f0]                                                ffffe001cfbf57f0
Trace   \Driver\amdsata[0xffffe001cfbe5e60] -> IRP_MJ_CREATE -> 0xffffe001cf2532c0                                                              ffffe001cf2532c0

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\system32\csrss.exe [724:748]                                                                                                 fffff96000936b90
Thread  C:\WINDOWS\system32\svchost.exe [908:6956]                                                                                              00007ff9dda710e0
Thread  C:\WINDOWS\system32\svchost.exe [908:7100]                                                                                              00007ff9dd9438e0
Thread  C:\WINDOWS\system32\svchost.exe [1524:2356]                                                                                             00007ff9e4a94608
Thread  C:\WINDOWS\system32\svchost.exe [1524:1588]                                                                                             00007ff9e4841584
Thread  C:\WINDOWS\system32\svchost.exe [1524:2676]                                                                                             00007ff9e47d1b40
Thread  C:\WINDOWS\system32\svchost.exe [1524:2896]                                                                                             00007ff9e4a91040
hugo91
~user
 
Posty: 319
Dołączenie: 19 Cze 2006, 16:33
Pochwały: 6



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez ordynat 04 Gru 2014, 21:29

W nowych logach nie ma niczego podejrzanego.

Nie masz żadnej infekcji, nie masz żadnych "reklamiarzy".

Przeinstaluj przeglądarki, - może to pomoże?
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez hugo91 05 Gru 2014, 21:56

po przeinstalowaniu instalowaniu nic sie nie zmienilo

Image

a mogł bym prosić jeszcze to sprawdzić

Kod: Zaznacz wszystko
OTL logfile created on: 2014-12-04 21:16:47 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 2,51 Gb Available Physical Memory | 70,17% Memory free
4,20 Gb Paging File | 2,63 Gb Available in Paging File | 62,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,92 Gb Free Space | 77,43% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014-12-01 22:02:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lidia\Downloads\OTL.scr
PRC - [2014-11-21 11:49:07 | 005,226,600 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014-02-20 14:34:44 | 000,060,504 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Care\VCService.exe
PRC - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2012-08-18 05:36:14 | 000,188,072 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
PRC - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
PRC - [2012-08-18 00:04:28 | 000,068,776 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2012-07-27 15:03:40 | 000,724,576 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2014-11-21 11:48:48 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-07-03 12:20:20 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014-07-03 12:19:50 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013-11-19 09:21:08 | 000,062,464 | ---- | M] () -- C:\Program Files\Sony\VAIO Care\listener.exe


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2014-11-21 11:48:45 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,368,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2014-09-22 04:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2014-08-16 01:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2014-08-16 01:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014-07-24 08:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2014-03-14 07:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2014-03-08 06:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2014-03-06 08:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2014-02-28 16:05:06 | 001,642,544 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Update\VUAgent.exe -- (VUAgent)
SRV:[b]64bit:[/b] - [2014-02-22 16:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014-02-22 10:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014-02-22 10:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014-02-22 10:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014-02-22 10:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2014-02-20 14:34:44 | 000,060,504 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Care\VCService.exe -- (VCService)
SRV:[b]64bit:[/b] - [2013-12-13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2013-12-10 08:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (USER_ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,377,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe -- (ESRV_SVC)
SRV:[b]64bit:[/b] - [2013-11-19 09:21:08 | 000,266,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:[b]64bit:[/b] - [2013-08-22 12:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2013-08-22 12:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2013-08-22 12:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2013-08-22 12:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2013-08-22 12:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2013-08-22 11:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2013-08-22 10:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2013-08-22 10:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2013-08-22 10:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013-08-22 10:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2013-08-22 10:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2013-08-22 10:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2012-08-06 12:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:[b]64bit:[/b] - [2012-07-19 18:55:44 | 000,476,328 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:[b]64bit:[/b] - [2011-12-01 10:04:56 | 000,289,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,467,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:12 | 000,306,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:[b]64bit:[/b] - [2011-08-05 12:53:06 | 008,277,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2014-11-27 06:01:15 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-11-26 17:40:36 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014-07-14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014-07-14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014-05-08 03:20:58 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-03-14 07:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013-10-23 07:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-08-22 04:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013-08-22 03:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2012-08-18 05:36:14 | 000,068,776 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe -- (VAIO Event Service)
SRV - [2012-08-13 17:24:56 | 000,211,584 | ---- | M] (Qualcomm Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012-08-13 16:27:08 | 000,323,584 | R--- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt&Wlan Coex Agent)
SRV - [2012-08-08 10:56:22 | 000,972,000 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2012-08-08 10:56:18 | 000,460,512 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2012-08-08 10:23:30 | 000,123,616 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2012-08-08 10:23:30 | 000,078,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2012-07-27 15:08:52 | 000,474,208 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2012-07-20 09:35:03 | 002,445,968 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswmonflt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2014-11-21 11:48:53 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2014-09-22 04:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2014-09-22 03:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2014-08-15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2014-07-24 12:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014-06-10 20:50:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2014-05-01 14:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014-04-28 05:33:30 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2014-03-20 04:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2014-03-13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014-03-08 21:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2014-02-22 17:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2014-02-22 16:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2014-02-22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2014-02-11 13:41:10 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2013-12-13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2013-12-04 19:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2013-11-14 08:37:27 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2013-11-14 08:31:22 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013-11-14 08:16:43 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013-08-22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013-08-22 13:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013-08-22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2013-08-22 13:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2013-08-22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013-08-22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013-08-22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013-08-22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013-08-22 12:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2013-08-22 12:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2013-08-22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2013-08-13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013-08-10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013-07-30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013-07-25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013-06-18 15:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2013-06-18 15:45:02 | 003,680,256 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:[b]64bit:[/b] - [2012-09-11 05:42:04 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:[b]64bit:[/b] - [2012-08-21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012-08-21 07:08:26 | 000,447,800 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2012-08-21 07:07:09 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:04 | 000,135,832 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:02 | 000,076,952 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,178,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,114,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,088,728 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:[b]64bit:[/b] - [2012-08-13 17:05:00 | 000,033,944 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2012-08-13 17:04:58 | 000,344,216 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:[b]64bit:[/b] - [2012-08-10 09:54:22 | 000,098,472 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2012-07-20 09:35:03 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:[b]64bit:[/b] - [2012-07-20 09:30:55 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2012-07-11 13:33:28 | 000,014,336 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:[b]64bit:[/b] - [2012-06-23 06:23:38 | 000,199,008 | ---- | M] (AppEx Networks Corporation) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\appexDrv.sys -- (APXACC)
DRV:[b]64bit:[/b] - [2012-06-22 07:36:54 | 000,106,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:[b]64bit:[/b] - [2012-06-11 03:43:12 | 000,024,280 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sows.sys -- (SOWS)
DRV:[b]64bit:[/b] - [2012-04-20 16:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://vaioportal.sony.eu [binary data]
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sony13.msn.com
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes,DefaultScope = {5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{24D97AEC-213C-4349-B7B8-0DE6F373CF11}: "URL" = http://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=http://shop.ebay.co.uk/?oemInLn=ieSrch-Q312&_nkw={searchTerms}
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{50C2A73E-51DB-4318-8387-EB8607BB64FE}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASEJS
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{5C4AA0EE-800D-4C75-9FF0-E2FE4A101C1F}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-2017453163-4049187296-263026530-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "http://google.pl/"
FF - prefs.js..extensions.enabledAddons: %7B6d0f26ba-45b8-4871-9c07-43ab341d5b73%7D:0.1
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.0.2502.149
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:34.0.5
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: C:\Program Files\mcafee\msc\npMcSnFFPl64.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-21 11:48:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK

[2013-12-27 22:29:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Extensions
[2014-11-23 17:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions
[2014-08-24 16:09:58 | 000,000,000 | ---D | M] ("Site Advisor") -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles\7ta50hxd.default\extensions\{6d0f26ba-45b8-4871-9c07-43ab341d5b73}
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions
[2014-08-24 16:07:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\Firefox\Profiles7ta50hxd.default\extensions\staged
[2014-11-23 17:09:39 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Lidia\AppData\Roaming\mozilla\firefox\profiles\7ta50hxd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-12-04 21:14:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014-12-04 21:14:03 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-11-21 11:48:55 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

O1 HOSTS File: ([2013-08-22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey File not found
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 File not found
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{222B836A-01B7-4D7A-86EB-80D9B1F34080}: DhcpNameServer = 192.168.1.254
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell - "" = AutoRun
O33 - MountPoints2\{596cede7-8087-11e3-be8b-083e8ebd58f0}\Shell\AutoRun\command - "" = "F:\LaunchU3.exe" -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = "E:\Autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 360 Days ==========[/color]

[2014-12-04 21:14:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2014-12-04 21:12:26 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\AppData\Local\EmieBrowserModeList
[2014-12-02 19:36:38 | 000,000,000 | ---D | C] -- C:\FRST
[2014-12-02 19:35:06 | 002,117,632 | ---- | C] (Farbar) -- C:\Users\Lidia\Desktop\FRST64.exe
[2014-12-01 21:54:20 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\ElevatedDiagnostics
[2014-12-01 21:49:54 | 000,000,000 | ---D | C] -- C:\_OTL
[2014-11-30 16:35:02 | 000,386,680 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:56:11 | 000,106,976 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-22 13:56:10 | 000,714,208 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-21 11:48:57 | 000,364,512 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:50 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-18 19:56:23 | 001,519,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2014-11-18 19:56:21 | 000,258,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2014-11-18 19:56:20 | 000,114,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2014-11-18 19:56:20 | 000,035,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2014-11-18 19:56:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2014-11-18 19:56:19 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2014-11-18 19:55:44 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-11-18 19:55:44 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-18 19:55:43 | 000,537,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-11-18 19:55:42 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-18 19:55:38 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-11-18 19:55:33 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-11-18 19:55:32 | 002,773,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-11-18 19:55:30 | 002,459,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-11-18 19:55:29 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-11-18 19:55:29 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-11-18 19:55:29 | 000,116,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-11-15 06:07:56 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2014-11-15 06:07:55 | 000,104,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2014-11-15 06:07:55 | 000,088,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2014-11-15 06:07:09 | 000,500,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-11-15 06:07:09 | 000,394,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,482,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-11-15 06:07:08 | 000,344,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-11-15 06:07:08 | 000,272,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-11-15 06:07:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2014-11-15 06:07:07 | 000,108,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-11-15 06:03:08 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-11-15 06:02:52 | 002,865,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-11-15 06:02:49 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-11-15 06:02:49 | 000,661,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-11-15 06:02:48 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-11-15 06:02:48 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-11-15 06:02:46 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-11-15 06:02:46 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-11-15 06:02:45 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-11-15 06:02:44 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-11-15 06:02:43 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-11-15 06:02:42 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-11-15 06:02:42 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-11-15 06:02:41 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-11-15 06:02:40 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-11-15 06:02:40 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-11-15 06:02:38 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-11-15 06:02:33 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-11-15 06:02:33 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-11-15 06:02:33 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-11-15 06:02:32 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-11-15 06:02:32 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-11-15 06:02:32 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-11-15 06:02:32 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-11-15 06:02:32 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-11-15 06:02:32 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-11-15 06:02:31 | 000,417,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-11-15 06:02:31 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-11-15 06:02:31 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-11-15 06:02:31 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-11-15 06:02:30 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-11-15 06:02:30 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-11-15 06:02:30 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:30 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-11-15 06:02:29 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-11-15 06:02:29 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-11-15 06:02:29 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-11-15 06:02:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-11-15 06:02:28 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-11-15 06:02:28 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-11-15 06:02:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-11-15 06:02:27 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-11-15 06:02:26 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-11-15 06:02:26 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-11-15 06:02:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-11-15 06:02:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-11-15 06:02:25 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-11-15 06:02:25 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-11-15 06:02:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-11-15 06:02:25 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-11-15 06:02:25 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-11-15 06:02:24 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-11-15 06:02:24 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-11-15 06:02:24 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-11-15 06:02:24 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-11-15 06:02:23 | 000,237,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-11-15 06:02:23 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-11-15 06:02:23 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-11-15 06:02:22 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-11-15 06:02:22 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-11-15 06:02:22 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-11-15 06:02:21 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-11-15 06:02:21 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-11-15 06:01:16 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-11-15 06:01:16 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-11-15 06:01:10 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-11-15 06:01:10 | 001,441,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-11-15 06:01:09 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-11-15 06:01:09 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-11-15 06:01:08 | 000,736,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-11-15 06:01:07 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-11-15 06:01:07 | 000,027,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-11-15 06:01:06 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-11-15 06:01:06 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-11-15 06:00:09 | 000,789,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-11-15 05:59:54 | 000,894,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-11-15 05:59:53 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-11-15 05:59:52 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-11-15 05:59:52 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-11-15 05:59:51 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-11-15 05:59:51 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-11-15 05:59:50 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-11-15 05:59:50 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-11-15 05:59:50 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-11-15 05:59:49 | 000,055,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-11-15 05:59:49 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-11-15 05:59:49 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-11-15 05:59:49 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-11-15 05:59:48 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-11-15 05:59:48 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-11-15 05:59:34 | 007,484,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2014-11-15 05:59:29 | 002,714,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2014-11-15 05:59:28 | 013,424,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2014-11-15 05:59:24 | 001,053,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014-11-15 05:59:24 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2014-11-15 05:59:23 | 000,836,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2014-11-15 05:59:21 | 011,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2014-11-15 05:59:19 | 000,822,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2014-11-15 05:59:19 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2014-11-15 05:59:19 | 000,670,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2014-11-15 05:59:18 | 000,474,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2014-11-15 05:59:16 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2014-11-15 05:59:16 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2014-11-15 05:59:09 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014-11-15 05:59:07 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
[2014-11-15 05:59:06 | 000,485,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
[2014-11-15 05:59:00 | 000,615,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSCOMEX.dll
[2014-11-15 05:58:56 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSAPI.dll
[2014-11-15 05:58:56 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FXSAPI.dll
[2014-11-12 13:31:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014-11-01 22:54:21 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-11-01 22:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014-11-01 22:53:21 | 001,050,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-01 22:53:21 | 000,436,624 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-01 22:53:21 | 000,116,728 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-01 22:53:21 | 000,093,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-01 22:53:21 | 000,083,280 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-01 22:51:28 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-10-22 17:54:16 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014-10-22 17:54:16 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2014-10-22 17:54:12 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2014-10-22 06:10:35 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2014-10-22 06:10:35 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2014-10-22 06:09:29 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2014-10-22 06:09:28 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2014-10-22 06:09:27 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2014-10-22 06:09:26 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2014-10-22 06:09:25 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2014-10-22 06:09:23 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2014-10-22 06:09:23 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2014-10-22 06:09:20 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll
[2014-10-22 06:09:19 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2014-10-22 06:09:18 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll
[2014-10-22 06:09:16 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll
[2014-10-22 06:09:08 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2014-10-22 06:09:07 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2014-10-22 06:09:06 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2014-10-22 06:09:06 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll
[2014-10-22 06:09:06 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll
[2014-10-22 06:09:05 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll
[2014-10-22 06:09:05 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll
[2014-10-22 06:09:04 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll
[2014-10-22 06:09:04 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll
[2014-10-22 06:09:04 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll
[2014-10-22 06:09:04 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll
[2014-10-22 06:09:03 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-10-22 06:09:02 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-10-21 04:25:21 | 016,874,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2014-10-21 04:25:14 | 012,730,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2014-10-21 04:25:05 | 002,389,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10warp.dll
[2014-10-21 04:24:59 | 002,141,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2014-10-21 04:24:56 | 002,145,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2014-10-21 04:24:53 | 001,600,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2014-10-21 04:24:51 | 001,231,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2014-10-21 04:24:48 | 000,889,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2014-10-21 04:24:47 | 002,574,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVDECOD.DLL
[2014-10-21 04:24:46 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SRH.dll
[2014-10-21 04:24:46 | 000,882,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2014-10-21 04:24:46 | 000,707,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2014-10-21 04:24:45 | 001,182,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\printui.dll
[2014-10-21 04:24:44 | 002,410,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMVDECOD.DLL
[2014-10-21 04:24:43 | 001,287,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mispace.dll
[2014-10-21 04:24:42 | 001,992,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsPrint.dll
[2014-10-21 04:24:40 | 000,770,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2014-10-21 04:24:40 | 000,486,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netcfgx.dll
[2014-10-21 04:24:39 | 001,057,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\printui.dll
[2014-10-21 04:24:39 | 001,029,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mispace.dll
[2014-10-21 04:24:39 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2014-10-21 04:24:39 | 000,391,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netcfgx.dll
[2014-10-21 04:24:38 | 001,741,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SRH.dll
[2014-10-21 04:24:38 | 001,018,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aclui.dll
[2014-10-21 04:24:38 | 000,412,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2014-10-21 04:24:37 | 000,371,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2014-10-21 04:24:37 | 000,360,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfreadwrite.dll
[2014-10-21 04:24:36 | 000,889,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aclui.dll
[2014-10-21 04:24:36 | 000,645,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SHCore.dll
[2014-10-21 04:24:36 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2014-10-21 04:24:36 | 000,355,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfreadwrite.dll
[2014-10-21 04:24:35 | 000,439,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2014-10-21 04:24:35 | 000,302,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanmsm.dll
[2014-10-21 04:24:34 | 000,180,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mftranscode.dll
[2014-10-21 04:24:33 | 002,397,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storagewmi.dll
[2014-10-21 04:24:33 | 000,477,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SHCore.dll
[2014-10-21 04:24:33 | 000,205,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mftranscode.dll
[2014-10-21 04:24:32 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2014-10-21 04:24:32 | 000,427,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clusapi.dll
[2014-10-21 04:24:32 | 000,287,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usbmon.dll
[2014-10-21 04:24:31 | 001,660,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2014-10-21 04:24:31 | 000,468,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2014-10-21 04:24:30 | 001,519,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2014-10-21 04:24:29 | 000,487,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winspool.drv
[2014-10-21 04:24:29 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wisp.dll
[2014-10-21 04:24:28 | 001,488,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2014-10-21 04:24:28 | 001,463,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wsecedit.dll
[2014-10-21 04:24:28 | 001,356,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2014-10-21 04:24:26 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clusapi.dll
[2014-10-21 04:24:26 | 000,160,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmmbase.dll
[2014-10-21 04:24:25 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WiFiDisplay.dll
[2014-10-21 04:24:23 | 001,817,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Display.dll
[2014-10-21 04:24:23 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdvidcrl.dll
[2014-10-21 04:24:23 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\conhost.exe
[2014-10-21 04:24:22 | 001,844,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Display.dll
[2014-10-21 04:24:22 | 001,404,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\storagewmi.dll
[2014-10-21 04:24:22 | 000,576,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSync.dll
[2014-10-21 04:24:22 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VAN.dll
[2014-10-21 04:24:22 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSip.dll
[2014-10-21 04:24:21 | 000,834,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\osk.exe
[2014-10-21 04:24:21 | 000,211,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVol.exe
[2014-10-21 04:24:21 | 000,127,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmmbase.dll
[2014-10-21 04:24:21 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersGPExt.dll
[2014-10-21 04:24:20 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DafPrintProvider.dll
[2014-10-21 04:24:20 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wisp.dll
[2014-10-21 04:24:19 | 000,387,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2014-10-21 04:24:19 | 000,233,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2014-10-21 04:24:19 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2014-10-21 04:24:18 | 000,335,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2014-10-21 04:24:18 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\NdisImPlatform.sys
[2014-10-21 04:24:17 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.dll
[2014-10-21 04:24:17 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.dll
[2014-10-21 04:24:17 | 000,125,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2014-10-21 04:24:17 | 000,123,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmm.dll
[2014-10-21 04:24:17 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxSip.dll
[2014-10-21 04:24:16 | 001,319,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wsecedit.dll
[2014-10-21 04:24:15 | 001,656,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2014-10-21 04:24:15 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\prnntfy.dll
[2014-10-21 04:24:14 | 001,089,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpedit.dll
[2014-10-21 04:24:14 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\prnntfy.dll
[2014-10-21 04:24:14 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersShell.dll
[2014-10-21 04:24:13 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsPrint.dll
[2014-10-21 04:24:13 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiapi.dll
[2014-10-21 04:24:13 | 000,162,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiapi.dll
[2014-10-21 04:24:11 | 000,448,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VAN.dll
[2014-10-21 04:24:11 | 000,180,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SndVol.exe
[2014-10-21 04:24:09 | 000,263,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlows.exe
[2014-10-21 04:24:08 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdvidcrl.dll
[2014-10-21 04:24:08 | 000,432,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanconn.dll
[2014-10-21 04:24:08 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2014-10-21 04:24:08 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2014-10-21 04:24:08 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dab.dll
[2014-10-21 04:24:08 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2014-10-21 04:24:06 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpedit.dll
[2014-10-21 04:24:06 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionCenter.dll
[2014-10-21 04:24:06 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2014-10-21 04:24:06 | 000,216,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rsaenh.dll
[2014-10-21 04:24:04 | 000,779,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\osk.exe
[2014-10-21 04:24:04 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.dll
[2014-10-21 04:24:03 | 000,557,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PrintDialogs.dll
[2014-10-21 04:24:03 | 000,459,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSync.dll
[2014-10-21 04:24:03 | 000,200,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DafPrintProvider.dll
[2014-10-21 04:24:02 | 000,659,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2014-10-21 04:24:01 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansvcpal.dll
[2014-10-21 04:23:58 | 000,832,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ActionCenter.dll
[2014-10-21 04:23:57 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powercfg.cpl
[2014-10-21 04:23:56 | 000,183,808 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysNative\Defrag.exe
[2014-10-21 04:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRUM.DLL
[2014-10-21 04:23:56 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRUM.DLL
[2014-10-21 04:23:55 | 001,351,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2014-10-21 04:23:54 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\powercfg.cpl
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDYAK.DLL
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU1.DLL
[2014-10-21 04:23:54 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDBASH.DLL
[2014-10-21 04:23:54 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU.DLL
[2014-10-21 04:23:53 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BluetoothApis.dll
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDYAK.DLL
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU1.DLL
[2014-10-21 04:23:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDBASH.DLL
[2014-10-21 04:23:52 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU.DLL
[2014-10-21 04:23:14 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintDialogs.dll
[2014-10-21 04:23:10 | 001,144,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanmm.dll
[2014-10-21 04:23:08 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTAT.DLL
[2014-10-21 04:23:07 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVolSSO.dll
[2014-10-21 04:23:07 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTAT.DLL
[2014-10-21 04:23:06 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\compstui.dll
[2014-10-21 04:23:06 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BluetoothApis.dll
[2014-10-21 04:23:05 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansec.dll
[2014-10-21 04:23:04 | 002,100,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlowUI.dll
[2014-10-21 04:23:02 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTT102.DLL
[2014-10-21 04:23:02 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTT102.DLL
[2014-10-21 04:14:49 | 002,084,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2014-10-21 04:14:49 | 000,796,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uDWM.dll
[2014-10-21 04:14:47 | 002,374,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2014-10-21 04:14:26 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UXInit.dll
[2014-10-21 04:14:26 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UXInit.dll
[2014-10-21 04:14:08 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSDMon.dll
[2014-10-21 04:14:08 | 000,205,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcpmon.dll
[2014-10-20 05:33:28 | 000,146,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpioclx.sys
[2014-10-17 12:02:12 | 000,875,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvcr120_clr0400.dll
[2014-10-17 12:02:12 | 000,869,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvcr120_clr0400.dll
[2014-09-11 19:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014-09-11 19:27:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2014-09-11 19:27:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2014-08-24 21:28:00 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014-08-24 15:14:29 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\chorzowski park
[2014-08-18 18:09:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014-08-16 18:01:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\fst_pl_178
[2014-08-16 17:56:23 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\ustr
[2014-08-16 17:54:51 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\WinRAR
[2014-08-16 17:54:05 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014-08-16 17:54:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014-08-16 17:53:36 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2014-08-16 14:07:37 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\DM
[2014-08-14 11:10:45 | 001,273,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2014-08-14 11:10:37 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2014-08-14 11:10:37 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2014-08-14 11:00:32 | 000,517,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2014-08-14 11:00:31 | 002,133,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2014-08-14 11:00:29 | 003,118,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wpc.dll
[2014-08-14 11:00:27 | 003,048,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcMon.exe
[2014-08-14 11:00:27 | 002,861,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcWebSync.dll
[2014-08-14 11:00:26 | 002,344,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Wpc.dll
[2014-08-14 10:57:42 | 002,125,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2014-08-14 10:57:31 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll
[2014-08-14 10:57:31 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vpnike.dll
[2014-08-14 10:57:29 | 000,301,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\framedynos.dll
[2014-08-14 10:57:27 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcore6.dll
[2014-08-14 10:57:27 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\framedynos.dll
[2014-08-14 10:57:26 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dhcpcore6.dll
[2014-08-14 10:57:25 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncobjapi.dll
[2014-08-14 10:57:21 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\framedyn.dll
[2014-08-14 10:57:19 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncobjapi.dll
[2014-08-14 10:57:15 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Robocopy.exe
[2014-08-14 10:57:10 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Robocopy.exe
[2014-08-14 10:57:10 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcsvc6.dll
[2014-08-14 10:57:09 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\framedyn.dll
[2014-08-14 10:57:09 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BulkOperationHost.exe
[2014-08-14 10:57:07 | 000,997,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2014-08-14 10:55:52 | 000,440,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbport.sys
[2014-08-14 10:55:42 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUDFHost.exe
[2014-08-14 10:55:42 | 000,209,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUDFPlatform.dll
[2014-08-14 10:55:41 | 000,423,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2014-08-14 10:55:41 | 000,323,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DaOtpCredentialProvider.dll
[2014-08-14 10:55:41 | 000,027,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbd.sys
[2014-08-14 10:55:34 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DaOtpCredentialProvider.dll
[2014-08-14 10:55:07 | 000,623,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2014-08-14 10:54:55 | 001,336,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2014-08-13 00:00:10 | 004,575,232 | ---- | C] (Google Inc.) -- C:\WINDOWS\SysWow64\GPhotos.scr
[2014-07-13 16:01:05 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\Nowy folder
[2014-07-12 15:40:29 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Apple Computer
[2014-07-12 15:40:29 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Apple Computer
[2014-07-12 15:40:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014-07-12 15:40:18 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\WINDOWS\SysNative\drivers\GEARAspiWDM.sys
[2014-07-12 15:38:06 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014-07-12 15:38:01 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014-07-12 15:38:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2014-07-12 15:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2014-07-12 15:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2014-07-12 15:30:00 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Apple
[2014-07-12 15:29:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2014-07-12 15:29:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2014-07-12 15:29:04 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2014-07-12 15:29:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2014-07-12 15:28:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2014-07-12 15:28:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2014-07-11 12:49:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Atheros
[2014-07-11 12:48:03 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\CompatTel
[2014-07-09 18:26:10 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\qedit.dll
[2014-07-09 18:26:10 | 000,488,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\qedit.dll
[2014-07-09 18:25:43 | 001,054,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2014-07-09 18:25:43 | 000,828,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2014-07-09 18:25:43 | 000,555,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.appcore.dll
[2014-07-09 12:46:15 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSReset.exe
[2014-06-21 15:36:15 | 007,173,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Data.Pdf.dll
[2014-06-21 15:36:12 | 005,104,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
[2014-06-21 15:36:03 | 000,765,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll
[2014-06-21 15:36:02 | 000,669,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
[2014-06-21 15:36:02 | 000,491,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2014-06-21 15:36:01 | 001,403,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2014-06-21 15:36:01 | 001,379,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2014-06-21 15:36:01 | 000,407,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\services.exe
[2014-06-21 15:36:01 | 000,387,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2014-06-21 15:36:00 | 001,222,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.dll
[2014-06-21 15:36:00 | 000,491,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GeofenceMonitorService.dll
[2014-06-21 15:36:00 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsGdiConverter.dll
[2014-06-21 15:35:59 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GeofenceMonitorService.dll
[2014-06-21 15:35:59 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsGdiConverter.dll
[2014-06-21 15:35:59 | 000,335,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDEServer.exe
[2014-06-21 15:35:58 | 001,209,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2014-06-21 15:35:58 | 000,982,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Streaming.dll
[2014-06-21 15:35:58 | 000,250,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpencom.dll
[2014-06-21 15:35:57 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpencom.dll
[2014-06-21 15:35:57 | 000,032,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ploptin.dll
[2014-06-21 15:35:56 | 000,337,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\Classpnp.sys
[2014-06-21 15:35:56 | 000,324,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFCaptureEngine.dll
[2014-06-21 15:35:56 | 000,281,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\resutils.dll
[2014-06-21 15:35:55 | 000,285,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFCaptureEngine.dll
[2014-06-21 15:35:55 | 000,201,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2014-06-21 15:35:55 | 000,130,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpapi.dll
[2014-06-21 15:35:54 | 000,372,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2014-06-21 15:35:54 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpchttp.dll
[2014-06-21 15:35:54 | 000,178,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSVideoDSP.dll
[2014-06-21 15:35:54 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rpchttp.dll
[2014-06-21 15:35:53 | 000,609,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mf.dll
[2014-06-21 15:35:53 | 000,518,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mf.dll
[2014-06-21 15:35:52 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\energyprov.dll
[2014-06-21 15:35:50 | 000,307,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2014-06-21 15:35:50 | 000,028,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfpmp.exe
[2014-06-21 15:35:49 | 000,467,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srcore.dll
[2014-06-21 15:35:49 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\resutils.dll
[2014-06-21 15:35:49 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tlscsp.dll
[2014-06-21 15:35:48 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tlscsp.dll
[2014-06-21 15:35:47 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BootMenuUX.dll
[2014-06-21 15:35:31 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rstrui.exe
[2014-06-21 15:35:31 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srclient.dll
[2014-06-21 15:35:31 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tsgqec.dll
[2014-06-21 15:35:30 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanhlp.dll
[2014-06-21 15:35:30 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanhlp.dll
[2014-06-21 15:33:42 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drvinst.exe
[2014-06-21 15:33:42 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\drvinst.exe
[2014-06-21 15:33:41 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drvcfg.exe
[2014-06-21 15:33:33 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2014-06-21 15:33:27 | 002,834,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2014-06-21 15:33:27 | 000,055,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wpcfltr.sys
[2014-06-21 15:30:47 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tsgqec.dll
[2014-06-21 15:29:00 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollectorres.dll
[2014-06-10 20:50:24 | 006,112,864 | ---- | C] (Apple, Inc.) -- C:\WINDOWS\SysNative\usbaaplrc.dll
[2014-06-10 20:50:24 | 000,054,784 | ---- | C] (Apple, Inc.) -- C:\WINDOWS\SysNative\drivers\usbaapl64.sys
[2014-06-04 14:27:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2014-05-28 17:15:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2014-05-28 17:14:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2014-05-28 17:13:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2014-05-28 17:12:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHEALTH
[2014-05-28 17:10:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2014-05-28 17:10:00 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Microsoft Help
[2014-05-28 17:09:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2014-05-28 17:09:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2014-05-28 17:09:38 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2014-05-15 02:06:49 | 000,308,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wusa.exe
[2014-05-15 02:06:49 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wusa.exe
[2014-05-15 02:05:36 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2014-05-15 02:05:33 | 000,201,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ubpm.dll
[2014-05-15 02:05:32 | 000,419,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.appcore.dll
[2014-05-15 02:04:49 | 000,086,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mrt_map.dll
[2014-05-15 02:04:49 | 000,080,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mrt_map.dll
[2014-05-15 02:04:49 | 000,028,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mrt100.dll
[2014-05-15 02:04:49 | 000,026,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mrt100.dll
[2014-05-03 15:29:50 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\AppData\Local\EmieUserList
[2014-05-03 15:29:50 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\AppData\Local\EmieSiteList
[2014-05-01 02:26:59 | 001,291,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kernel32.dll
[2014-05-01 02:26:58 | 000,376,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\clfs.sys
[2014-05-01 02:26:52 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Shell.Search.UriHandler.dll
[2014-05-01 02:26:42 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Shell.Search.UriHandler.dll
[2014-05-01 02:26:38 | 002,900,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2014-05-01 02:26:36 | 002,270,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2014-05-01 02:26:33 | 001,306,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2014-05-01 02:26:32 | 002,141,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2014-05-01 02:26:31 | 001,542,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2014-05-01 02:26:30 | 001,764,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2014-05-01 02:26:29 | 001,779,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2014-05-01 02:26:26 | 000,950,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll
[2014-05-01 02:26:26 | 000,655,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2014-05-01 02:26:25 | 000,512,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidprov.dll
[2014-05-01 02:26:24 | 000,800,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll
[2014-05-01 02:26:22 | 000,356,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dcomp.dll
[2014-05-01 02:26:21 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidprov.dll
[2014-05-01 02:26:20 | 000,834,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netlogon.dll
[2014-05-01 02:26:20 | 000,669,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasapi32.dll
[2014-05-01 02:26:20 | 000,379,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2014-05-01 02:26:19 | 000,157,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wof.sys
[2014-05-01 02:26:16 | 000,291,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2014-05-01 02:26:16 | 000,222,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dcomp.dll
[2014-05-01 02:26:15 | 000,924,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2014-05-01 02:26:13 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2014-05-01 02:26:12 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsApi.dll
[2014-05-01 02:26:12 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2014-05-01 02:26:11 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2014-05-01 02:26:10 | 000,171,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsApi.dll
[2014-05-01 02:26:07 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWfdProvider.dll
[2014-05-01 02:26:07 | 000,113,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\userenv.dll
[2014-05-01 02:26:06 | 000,299,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pdh.dll
[2014-05-01 02:26:06 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\davclnt.dll
[2014-05-01 02:26:05 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cdd.dll
[2014-05-01 02:26:05 | 000,201,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReInfo.dll
[2014-05-01 02:26:05 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2014-05-01 02:26:05 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2014-05-01 02:26:04 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlangpui.dll
[2014-05-01 02:26:03 | 000,412,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FWPUCLNT.DLL
[2014-05-01 02:26:02 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Graphics.Printing.dll
[2014-05-01 02:26:02 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spp.dll
[2014-05-01 02:26:01 | 000,254,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pdh.dll
[2014-05-01 02:26:01 | 000,136,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wfplwfs.sys
[2014-05-01 02:26:00 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\w32tm.exe
[2014-05-01 02:25:59 | 000,386,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlangpui.dll
[2014-05-01 02:25:59 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FWPUCLNT.DLL
[2014-05-01 02:25:59 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredentialMigrationHandler.dll
[2014-05-01 02:25:58 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapibase.dll
[2014-05-01 02:25:58 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\hidclass.sys
[2014-05-01 02:25:58 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\w32tm.exe
[2014-05-01 02:25:58 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredentialMigrationHandler.dll
[2014-05-01 02:25:57 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationApi.dll
[2014-05-01 02:25:57 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Scanners.dll
[2014-05-01 02:25:57 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RMapi.dll
[2014-05-01 02:25:56 | 000,402,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Graphics.Printing.dll
[2014-05-01 02:25:56 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReInfo.dll
[2014-05-01 02:25:56 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BitLockerDeviceEncryption.exe
[2014-05-01 02:25:55 | 000,794,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fvewiz.dll
[2014-05-01 02:25:55 | 000,717,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2014-05-01 02:25:55 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Scanners.dll
[2014-05-01 02:25:55 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevPropMgr.dll
[2014-05-01 02:25:54 | 000,567,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
[2014-05-01 02:25:54 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LocationApi.dll
[2014-05-01 02:25:54 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sxproxy.dll
[2014-05-01 02:25:54 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SetNetworkLocation.dll
[2014-05-01 02:25:54 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sxproxy.dll
[2014-05-01 02:25:51 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WsmWmiPl.dll
[2014-05-01 02:25:51 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BdeHdCfgLib.dll
[2014-05-01 02:25:51 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\l2gpstore.dll
[2014-05-01 02:25:51 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\l2gpstore.dll
[2014-05-01 02:08:57 | 011,742,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\glcndFilter.dll
[2014-05-01 02:08:55 | 003,394,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSService.dll
[2014-05-01 02:08:55 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OobeFldr.dll
[2014-05-01 02:08:54 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OobeFldr.dll
[2014-05-01 02:08:45 | 008,946,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\glcndFilter.dll
[2014-05-01 02:08:35 | 001,927,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2014-05-01 02:08:29 | 013,933,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2014-05-01 02:08:26 | 001,435,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2014-05-01 02:08:25 | 001,374,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2014-05-01 02:08:24 | 003,494,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2014-05-01 02:08:22 | 011,776,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2014-05-01 02:08:16 | 002,368,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2014-05-01 02:08:15 | 001,576,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2014-05-01 02:08:12 | 002,643,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2014-05-01 02:08:09 | 001,728,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dui70.dll
[2014-05-01 02:08:08 | 001,716,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2014-05-01 02:08:03 | 001,445,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webservices.dll
[2014-05-01 02:08:01 | 001,132,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Globalization.dll
[2014-05-01 02:07:58 | 001,290,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctf.dll
[2014-05-01 02:07:57 | 001,640,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2014-05-01 02:07:57 | 001,341,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dui70.dll
[2014-05-01 02:07:56 | 000,628,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msTextPrediction.dll
[2014-05-01 02:07:54 | 000,647,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2014-05-01 02:07:53 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Security.Authentication.OnlineId.dll
[2014-05-01 02:07:51 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Globalization.dll
[2014-05-01 02:07:49 | 000,777,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2014-05-01 02:07:48 | 001,215,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetsrc.dll
[2014-05-01 02:07:48 | 000,800,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetcore.dll
[2014-05-01 02:07:47 | 001,496,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2014-05-01 02:07:47 | 001,000,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinTypes.dll
[2014-05-01 02:07:46 | 000,461,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WerFault.exe
[2014-05-01 02:07:46 | 000,407,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Faultrep.dll
[2014-05-01 02:07:46 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWWIN.EXE
[2014-05-01 02:07:45 | 001,077,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webservices.dll
[2014-05-01 02:07:45 | 000,410,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WerFault.exe
[2014-05-01 02:07:45 | 000,369,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Faultrep.dll
[2014-05-01 02:07:45 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DWWIN.EXE
[2014-05-01 02:07:44 | 000,825,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\samsrv.dll
[2014-05-01 02:07:43 | 002,825,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2014-05-01 02:07:40 | 000,526,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2014-05-01 02:07:39 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StructuredQuery.dll
[2014-05-01 02:07:39 | 000,390,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DfpCommon.dll
[2014-05-01 02:07:39 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WofTasks.dll
[2014-05-01 02:07:38 | 001,929,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setupapi.dll
[2014-05-01 02:07:34 | 001,621,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RacEngn.dll
[2014-05-01 02:07:33 | 000,635,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe
[2014-05-01 02:07:33 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2014-05-01 02:07:33 | 000,517,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2014-05-01 02:07:31 | 001,011,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfnetsrc.dll
[2014-05-01 02:07:30 | 000,422,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2014-05-01 02:07:29 | 001,653,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsCodecs.dll
[2014-05-01 02:07:29 | 000,569,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2014-05-01 02:07:28 | 000,650,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfnetcore.dll
[2014-05-01 02:07:28 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe
[2014-05-01 02:07:27 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2014-05-01 02:07:25 | 000,556,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.dll
[2014-05-01 02:07:24 | 001,392,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPDMC.exe
[2014-05-01 02:07:23 | 002,428,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2014-05-01 02:07:22 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll
[2014-05-01 02:07:15 | 000,366,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmsvc.dll
[2014-05-01 02:07:13 | 001,757,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPDMC.exe
[2014-05-01 02:07:11 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WofUtil.dll
[2014-05-01 02:07:10 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimgapi.dll
[2014-05-01 02:07:08 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\scrrun.dll
[2014-05-01 02:07:07 | 000,391,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MMDevAPI.dll
[2014-05-01 02:07:07 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scrrun.dll
[2014-05-01 02:07:06 | 000,530,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppReadiness.dll
[2014-05-01 02:07:05 | 001,206,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Taskmgr.exe
[2014-05-01 02:07:05 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\apphelp.dll
[2014-05-01 02:07:02 | 001,258,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RacEngn.dll
[2014-05-01 02:07:02 | 001,063,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Taskmgr.exe
[2014-05-01 02:07:02 | 000,551,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wimgapi.dll
[2014-05-01 02:07:01 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dfp.exe
[2014-05-01 02:07:00 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\recimg.exe
[2014-05-01 02:06:59 | 001,107,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perftrack.dll
[2014-05-01 02:06:58 | 001,227,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usercpl.dll
[2014-05-01 02:06:57 | 001,162,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\usercpl.dll
[2014-05-01 02:06:57 | 000,669,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\advapi32.dll
[2014-05-01 02:06:56 | 001,428,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RecoveryDrive.exe
[2014-05-01 02:06:56 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsm.dll
[2014-05-01 02:06:55 | 000,467,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\energy.dll
[2014-05-01 02:06:54 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssvp.dll
[2014-05-01 02:06:53 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdh.dll
[2014-05-01 02:06:50 | 000,653,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DismApi.dll
[2014-05-01 02:06:49 | 000,562,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2014-05-01 02:06:49 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssph.dll
[2014-05-01 02:06:47 | 000,441,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssph.dll
[2014-05-01 02:06:47 | 000,372,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvproc.dll
[2014-05-01 02:06:46 | 001,224,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\werconcpl.dll
[2014-05-01 02:06:46 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\portcls.sys
[2014-05-01 02:06:45 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\thumbcache.dll
[2014-05-01 02:06:42 | 001,791,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMALFXGFXDSP.dll
[2014-05-01 02:06:42 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctfuimanager.dll
[2014-05-01 02:06:42 | 000,320,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2014-05-01 02:06:41 | 000,531,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2014-05-01 02:06:38 | 000,716,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2014-05-01 02:06:38 | 000,244,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2014-05-01 02:06:37 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdh.dll
[2014-05-01 02:06:37 | 000,709,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msctfuimanager.dll
[2014-05-01 02:06:36 | 000,761,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iuilp.dll
[2014-05-01 02:06:36 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSClient.dll
[2014-05-01 02:06:36 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2014-05-01 02:06:35 | 000,747,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidcli.dll
[2014-05-01 02:06:35 | 000,317,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvproc.dll
[2014-05-01 02:06:34 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSClient.dll
[2014-05-01 02:06:33 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmIndexer.dll
[2014-05-01 02:06:33 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vmrdvcore.dll
[2014-05-01 02:06:32 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Dism.exe
[2014-05-01 02:06:32 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Vpn.dll
[2014-05-01 02:06:32 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slc.dll
[2014-05-01 02:06:31 | 000,912,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nettrace.dll
[2014-05-01 02:06:31 | 000,675,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssvp.dll
[2014-05-01 02:06:29 | 000,609,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pnidui.dll
[2014-05-01 02:06:28 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmredir.dll
[2014-05-01 02:06:25 | 001,008,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WlanMM.dll
[2014-05-01 02:06:24 | 000,388,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ninput.dll
[2014-05-01 02:06:24 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputSwitch.dll
[2014-05-01 02:06:22 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authz.dll
[2014-05-01 02:06:20 | 002,288,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncCenter.dll
[2014-05-01 02:06:19 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rascustom.dll
[2014-05-01 02:06:18 | 000,469,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskeng.exe
[2014-05-01 02:06:16 | 002,862,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\themeui.dll
[2014-05-01 02:06:16 | 000,286,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidcredprov.dll
[2014-05-01 02:06:15 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdbui.dll
[2014-05-01 02:06:14 | 003,596,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2014-05-01 02:06:14 | 000,459,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DismApi.dll
[2014-05-01 02:06:14 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mdmregistration.dll
[2014-05-01 02:06:14 | 000,289,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sqmapi.dll
[2014-05-01 02:06:12 | 002,811,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\themeui.dll
[2014-05-01 02:06:11 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmIndexer.dll
[2014-05-01 02:06:10 | 000,559,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll
[2014-05-01 02:06:09 | 000,211,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Dism.exe
[2014-05-01 02:06:07 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputSwitch.dll
[2014-05-01 02:06:07 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppc.dll
[2014-05-01 02:06:06 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2014-05-01 02:05:59 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.HumanInterfaceDevice.dll
[2014-05-01 02:05:59 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clrhost.dll
[2014-05-01 02:05:58 | 000,512,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimserv.exe
[2014-05-01 02:05:58 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WLanConn.dll
[2014-05-01 02:05:58 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PkgMgr.exe
[2014-05-01 02:05:58 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sppc.dll
[2014-05-01 02:05:57 | 000,236,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdbus.sys
[2014-05-01 02:05:57 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscinterop.dll
[2014-05-01 02:05:56 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-system-events.dll
[2014-05-01 02:05:55 | 000,797,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PurchaseWindowsLicense.dll
[2014-05-01 02:05:54 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gameux.dll
[2014-05-01 02:05:54 | 002,165,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SyncCenter.dll
[2014-05-01 02:05:53 | 000,722,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgradeui.exe
[2014-05-01 02:05:53 | 000,693,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcfg.dll
[2014-05-01 02:05:52 | 000,943,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WlanMM.dll
[2014-05-01 02:05:52 | 000,325,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2014-05-01 02:05:52 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwm.exe
[2014-05-01 02:05:51 | 000,506,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WinTypes.dll
[2014-05-01 02:05:51 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winsrv.dll
[2014-05-01 02:05:51 | 000,083,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhost.exe
[2014-05-01 02:05:50 | 000,935,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasgcw.dll
[2014-05-01 02:05:49 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmdskmgr.dll
[2014-05-01 02:05:48 | 000,170,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscapi.dll
[2014-05-01 02:05:47 | 000,350,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srchadmin.dll
[2014-05-01 02:05:47 | 000,139,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2014-05-01 02:05:46 | 003,085,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2014-05-01 02:05:45 | 000,242,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mdmregistration.dll
[2014-05-01 02:05:45 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.HumanInterfaceDevice.dll
[2014-05-01 02:05:45 | 000,151,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpsd.sys
[2014-05-01 02:05:45 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clrhost.dll
[2014-05-01 02:05:44 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ninput.dll
[2014-05-01 02:05:40 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wsqmcons.exe
[2014-05-01 02:05:40 | 000,142,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\smss.exe
[2014-05-01 02:05:39 | 000,316,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BioCredProv.dll
[2014-05-01 02:05:39 | 000,209,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imm32.dll
[2014-05-01 02:05:39 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AltTab.dll
[2014-05-01 02:05:38 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RASMM.dll
[2014-05-01 02:05:38 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcpl.dll
[2014-05-01 02:05:38 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsbas.dll
[2014-05-01 02:05:38 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToManager.dll
[2014-05-01 02:05:38 | 000,188,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\systemreset.exe
[2014-05-01 02:05:37 | 000,232,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sqmapi.dll
[2014-05-01 02:05:36 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\timedate.cpl
[2014-05-01 02:05:36 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netid.dll
[2014-05-01 02:05:36 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fsutil.exe
[2014-05-01 02:05:33 | 000,080,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhostex.exe
[2014-05-01 02:05:32 | 000,397,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sharemediacpl.dll
[2014-05-01 02:05:31 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\das.dll
[2014-05-01 02:05:30 | 000,043,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CloudNotifications.exe
[2014-05-01 02:05:29 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFilterHost.exe
[2014-05-01 02:05:27 | 000,897,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sdclt.exe
[2014-05-01 02:05:25 | 000,619,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserLanguagesCpl.dll
[2014-05-01 02:05:24 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fsutil.exe
[2014-05-01 02:05:23 | 000,041,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CloudNotifications.exe
[2014-05-01 02:05:22 | 000,924,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refs.sys
[2014-05-01 02:05:22 | 000,140,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscapi.dll
[2014-05-01 02:05:21 | 000,331,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\newdev.dll
[2014-05-01 02:05:21 | 000,275,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powrprof.dll
[2014-05-01 02:05:21 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2014-05-01 02:05:21 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BasicRender.sys
[2014-05-01 02:05:20 | 000,432,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\zipfldr.dll
[2014-05-01 02:05:20 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll
[2014-05-01 02:05:19 | 002,537,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gameux.dll
[2014-05-01 02:05:19 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BthLEEnum.sys
[2014-05-01 02:05:19 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SndVolSSO.dll
[2014-05-01 02:05:19 | 000,079,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdstor.sys
[2014-05-01 02:05:18 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmvdsitf.dll
[2014-05-01 02:05:18 | 000,101,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RestoreOptIn.exe
[2014-05-01 02:05:17 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\timedate.cpl
[2014-05-01 02:05:16 | 000,444,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spwizeng.dll
[2014-05-01 02:05:16 | 000,137,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2014-05-01 02:05:15 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wow64win.dll
[2014-05-01 02:05:15 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-kernel-power-events.dll
[2014-05-01 02:05:15 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContent.dll
[2014-05-01 02:05:15 | 000,032,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserAccountBroker.exe
[2014-05-01 02:05:14 | 000,336,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApiPublic.dll
[2014-05-01 02:05:13 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WLanConn.dll
[2014-05-01 02:05:13 | 000,155,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MicrosoftAccountTokenProvider.dll
[2014-05-01 02:05:13 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2014-05-01 02:05:12 | 000,835,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasgcw.dll
[2014-05-01 02:05:11 | 000,094,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcd.dll
[2014-05-01 02:05:11 | 000,089,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RestoreOptIn.exe
[2014-05-01 02:05:10 | 000,141,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dot3mm.dll
[2014-05-01 02:05:09 | 000,308,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srchadmin.dll
[2014-05-01 02:05:09 | 000,029,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserAccountBroker.exe
[2014-05-01 02:05:08 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\newdev.dll
[2014-05-01 02:05:07 | 000,131,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\easinvoker.exe
[2014-05-01 02:05:07 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscinterop.dll
[2014-05-01 02:05:06 | 003,312,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bootux.dll
[2014-05-01 02:05:06 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DAMM.dll
[2014-05-01 02:05:05 | 000,079,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcd.dll
[2014-05-01 02:05:05 | 000,071,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2014-05-01 02:04:57 | 000,213,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cleanmgr.exe
[2014-05-01 02:04:55 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cleanmgr.exe
[2014-05-01 02:04:55 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\samlib.dll
[2014-05-01 02:04:46 | 000,162,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AuthHost.exe
[2014-05-01 02:04:44 | 000,189,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UCX01000.SYS
[2014-05-01 02:04:43 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\easwrt.dll
[2014-05-01 02:04:42 | 000,203,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netiohlp.dll
[2014-05-01 02:04:41 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\deviceaccess.dll
[2014-05-01 02:04:39 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\korwbrkr.dll
[2014-05-01 02:04:38 | 000,036,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WerFaultSecure.exe
[2014-05-01 02:04:37 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netid.dll
[2014-05-01 02:04:36 | 000,033,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WerFaultSecure.exe
[2014-05-01 02:04:35 | 000,260,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BioCredProv.dll
[2014-05-01 02:04:34 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmvdsitf.dll
[2014-05-01 02:04:31 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netiohlp.dll
[2014-05-01 02:04:29 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acppage.dll
[2014-05-01 02:04:28 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netplwiz.dll
[2014-05-01 02:04:28 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CloudStorageWizard.exe
[2014-05-01 02:04:25 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmdskmgr.dll
[2014-05-01 02:04:24 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scrobj.dll
[2014-05-01 02:04:22 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AuthBroker.dll
[2014-05-01 02:04:21 | 000,038,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContentServer.exe
[2014-05-01 02:04:20 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbrand.dll
[2014-05-01 02:04:18 | 001,152,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscui.cpl
[2014-05-01 02:04:18 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slpts.dll
[2014-05-01 02:04:17 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MicrosoftAccountTokenProvider.dll
[2014-05-01 02:04:16 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApiPublic.dll
[2014-05-01 02:04:16 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\deviceaccess.dll
[2014-05-01 02:04:15 | 000,349,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2014-05-01 02:04:14 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\acppage.dll
[2014-05-01 02:04:13 | 000,283,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wbadmin.exe
[2014-05-01 02:04:13 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnprv.dll
[2014-05-01 02:04:13 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netplwiz.dll
[2014-05-01 02:04:12 | 000,902,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autoconv.exe
[2014-05-01 02:04:12 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Sockets.PushEnabledApplication.dll
[2014-05-01 02:04:11 | 000,874,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autofmt.exe
[2014-05-01 02:04:10 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sud.dll
[2014-05-01 02:04:10 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Renewal.dll
[2014-05-01 02:04:09 | 000,027,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SysResetErr.exe
[2014-05-01 02:04:06 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidcredprov.dll
[2014-05-01 02:04:06 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\scrobj.dll
[2014-05-01 02:04:06 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppnp.dll
[2014-05-01 02:04:05 | 000,890,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autochk.exe
[2014-05-01 02:04:05 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdboot.exe
[2014-05-01 02:04:03 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll
[2014-05-01 02:04:02 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spbcd.dll
[2014-05-01 02:04:02 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\slpts.dll
[2014-05-01 02:04:01 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\migisol.dll
[2014-05-01 02:04:00 | 000,780,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autofmt.exe
[2014-05-01 02:04:00 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PkgMgr.exe
[2014-05-01 02:03:59 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autochk.exe
[2014-05-01 02:03:59 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winbrand.dll
[2014-05-01 02:03:58 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DAConn.dll
[2014-05-01 02:03:55 | 000,800,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autoconv.exe
[2014-05-01 02:03:55 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgradeResults.exe
[2014-05-01 02:03:55 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhevents.dll
[2014-05-01 02:03:54 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafBth.dll
[2014-05-01 02:03:53 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IdCtrls.dll
[2014-05-01 02:03:52 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AuthBroker.dll
[2014-05-01 02:03:52 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spcompat.dll
[2014-05-01 02:03:51 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsutil.dll
[2014-05-01 02:03:51 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Sockets.PushEnabledApplication.dll
[2014-05-01 02:03:51 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\StorageContextHandler.dll
[2014-05-01 02:03:51 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\watchdog.sys
[2014-05-01 02:03:50 | 000,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgrade.exe
[2014-05-01 02:03:50 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cscript.exe
[2014-05-01 02:03:49 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spwizeng.dll
[2014-05-01 02:03:49 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\energytask.dll
[2014-05-01 02:03:48 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diskpart.exe
[2014-05-01 02:03:48 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spbcd.dll
[2014-05-01 02:03:45 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\werui.dll
[2014-05-01 02:03:42 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powercfg.exe
[2014-05-01 02:03:38 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sud.dll
[2014-05-01 02:03:38 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RelPost.exe
[2014-05-01 02:03:37 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pnpclean.dll
[2014-05-01 02:03:37 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\deviceassociation.dll
[2014-05-01 02:03:36 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingMonitor.dll
[2014-05-01 02:03:35 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidcli.dll
[2014-05-01 02:03:35 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dasHost.exe
[2014-05-01 02:03:34 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToDevice.dll
[2014-05-01 02:03:34 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingMonitor.dll
[2014-05-01 02:03:33 | 001,136,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscui.cpl
[2014-05-01 02:03:32 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srrstr.dll
[2014-05-01 02:03:31 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2014-05-01 02:03:31 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2014-05-01 02:03:31 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgentc.exe
[2014-05-01 02:03:30 | 000,299,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll
[2014-05-01 02:03:30 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winsku.dll
[2014-05-01 02:03:30 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionQueue.dll
[2014-05-01 02:03:30 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CloudStorageWizard.exe
[2014-05-01 02:03:29 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dfrgui.exe
[2014-05-01 02:03:29 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SSShim.dll
[2014-05-01 02:03:29 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IdCtrls.dll
[2014-05-01 02:03:28 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToDevice.dll
[2014-05-01 02:03:28 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\deviceassociation.dll
[2014-05-01 02:03:28 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msshooks.dll
[2014-05-01 02:03:27 | 000,559,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserLanguagesCpl.dll
[2014-05-01 02:03:27 | 000,468,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettings.Handlers.dll
[2014-05-01 02:03:27 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mf3216.dll
[2014-05-01 02:03:26 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werui.dll
[2014-05-01 02:03:26 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\powercfg.exe
[2014-05-01 02:03:26 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\f3ahvoas.dll
[2014-05-01 02:03:25 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\migisol.dll
[2014-05-01 02:03:24 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SrTasks.exe
[2014-05-01 02:03:23 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wshom.ocx
[2014-05-01 02:03:23 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgentc.exe
[2014-05-01 02:03:22 | 000,589,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsdyn.dll
[2014-05-01 02:03:22 | 000,561,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dfrgui.exe
[2014-05-01 02:03:22 | 000,316,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winsku.dll
[2014-05-01 02:03:21 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\easwrt.dll
[2014-05-01 02:03:21 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContentHost.dll
[2014-05-01 02:03:20 | 002,566,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\themecpl.dll
[2014-05-01 02:03:20 | 000,504,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevicePairing.dll
[2014-05-01 02:03:20 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AepRoam.dll
[2014-05-01 02:03:18 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\diskpart.exe
[2014-05-01 02:03:17 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cscript.exe
[2014-05-01 02:03:17 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sxshared.dll
[2014-05-01 02:03:16 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msshooks.dll
[2014-05-01 02:03:15 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
[2014-05-01 02:03:15 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConfigureExpandedStorage.dll
[2014-05-01 02:03:15 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ConfigureExpandedStorage.dll
[2014-05-01 02:03:14 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scavengeui.dll
[2014-05-01 02:03:09 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wincorlib.dll
[2014-05-01 02:03:08 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-session-winsta-l1-1-0.dll
[2014-05-01 02:03:06 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\setupugc.exe
[2014-05-01 02:03:05 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wincorlib.dll
[2014-05-01 02:02:58 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\syncui.dll
[2014-05-01 02:02:58 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncPolicy.dll
[2014-05-01 02:02:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\finger.exe
[2014-05-01 02:02:55 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpdxm.dll
[2014-05-01 02:02:54 | 002,544,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\themecpl.dll
[2014-05-01 02:02:54 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncPolicy.dll
[2014-05-01 02:02:53 | 000,323,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GlobCollationHost.dll
[2014-05-01 02:02:53 | 000,162,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ocsetapi.dll
[2014-05-01 02:02:52 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StorageContextHandler.dll
[2014-05-01 02:02:51 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GlobCollationHost.dll
[2014-05-01 02:02:51 | 000,163,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ocsetapi.dll
[2014-05-01 02:02:51 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-session-winsta-l1-1-0.dll
[2014-05-01 02:02:50 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitagent.exe
[2014-05-01 02:02:50 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dataclen.dll
[2014-05-01 02:02:49 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\korwbrkr.dll
[2014-05-01 02:02:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-kernel32-package-l1-1-1.dll
[2014-05-01 02:02:48 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shsetup.dll
[2014-05-01 02:02:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-kernel32-package-l1-1-1.dll
[2014-05-01 02:02:46 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bthprops.cpl
[2014-05-01 02:02:45 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dataclen.dll
[2014-05-01 02:02:45 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhsvcctl.dll
[2014-05-01 02:02:44 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lpksetupproxyserv.dll
[2014-05-01 02:02:44 | 000,008,192 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-ntuser-private-l1-1-1.dll
[2014-05-01 02:02:44 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shimeng.dll
[2014-05-01 02:02:43 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxmasf.dll
[2014-05-01 02:02:43 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-ntuser-private-l1-1-0.dll
[2014-05-01 02:02:42 | 000,008,192 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-ntuser-private-l1-1-1.dll
[2014-05-01 02:02:42 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msdxm.ocx
[2014-05-01 02:02:41 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveskybackup.dll
[2014-05-01 02:02:41 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-ntuser-private-l1-1-0.dll
[2014-05-01 02:02:40 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\finger.exe
[2014-05-01 02:02:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-networking-wcmapi-l1-1-0.dll
[2014-05-01 02:02:39 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\f3ahvoas.dll
[2014-04-28 17:22:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014-04-28 17:22:05 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2014-04-28 17:22:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2014-04-28 05:33:30 | 000,599,240 | ---- | C] (Qualcomm Atheros) -- C:\WINDOWS\SysNative\drivers\btfilter.sys
[2014-04-28 05:33:30 | 000,182,784 | ---- | C] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll
[2014-04-28 05:33:30 | 000,181,760 | ---- | C] (Qualcomm Atheros Communications Inc.) -- C:\WINDOWS\SysNative\btcoinst.dll
[2014-04-28 05:33:30 | 000,011,264 | ---- | C] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll.muien-US
[2014-04-26 16:36:42 | 000,000,000 | RH-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
[2014-04-01 17:19:11 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\poqexec.exe
[2014-04-01 17:19:10 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\poqexec.exe
[2014-03-31 21:46:48 | 001,070,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSCOMCTL.OCX
[2014-03-31 21:46:48 | 000,130,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSSTDFMT.DLL
[2014-03-22 06:09:16 | 000,842,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MsSpellCheckingFacility.dll
[2014-03-22 06:09:09 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MsSpellCheckingFacility.dll
[2014-03-22 06:09:03 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sti.dll
[2014-03-20 11:49:33 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Documents\Niestandardowe szablony pakietu Office
[2014-03-20 09:36:48 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Documents\NetSender
[2014-03-20 09:35:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetSender
[2014-03-20 09:34:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NetSender
[2014-03-16 14:06:04 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\Zdjęcia
[2014-03-16 13:19:38 | 000,000,000 | -H-D | C] -- C:\Users\Lidia\Desktop\.picasaoriginals
[2014-03-16 13:14:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2014-03-16 13:14:40 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Google
[2014-03-16 13:14:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2014-03-11 18:39:37 | 004,175,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbgeng.dll
[2014-03-11 18:39:37 | 001,486,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbghelp.dll
[2014-03-11 18:39:34 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbgeng.dll
[2014-03-11 18:39:32 | 001,238,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbghelp.dll
[2014-03-11 18:39:28 | 000,447,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcomapi.dll
[2014-03-05 21:54:06 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Documents\Electronic Arts
[2014-03-05 21:53:06 | 000,447,752 | R--- | C] (On2.com) -- C:\WINDOWS\SysWow64\vp6vfw.dll
[2014-03-05 21:53:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft WSE
[2014-03-05 21:52:02 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_31.dll
[2014-03-05 21:52:02 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_31.dll
[2014-03-05 21:37:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
[2014-03-03 18:56:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014-02-24 12:20:16 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1
[2014-02-24 12:20:15 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje
[2014-02-24 12:20:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\e-Deklaracje
[2014-02-24 12:20:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2014-02-24 11:55:05 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\PITy
[2014-02-24 11:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\PITy
[2014-02-24 11:55:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Program PITy
[2014-02-24 11:54:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProgramPITy
[2014-02-24 11:43:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PIT Format 2013
[2014-02-24 11:42:40 | 000,000,000 | ---D | C] -- C:\PIT Format 2013
[2014-02-24 11:42:29 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Programs
[2014-02-19 10:37:23 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\Studia
[2014-02-19 10:08:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive
[2014-02-18 15:13:10 | 003,210,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msmpeg2vdec.dll
[2014-02-18 15:13:09 | 002,804,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msmpeg2vdec.dll
[2014-02-18 15:12:40 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfds.dll
[2014-02-18 15:12:39 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Graphics.dll
[2014-02-18 15:12:35 | 000,433,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfds.dll
[2014-02-18 15:12:26 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Graphics.dll
[2014-02-18 15:12:24 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msieftp.dll
[2014-02-18 15:12:23 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bi.dll
[2014-02-18 15:12:22 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msieftp.dll
[2014-02-18 15:12:22 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BtaMPM.sys
[2014-02-18 15:12:20 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\deviceregistration.dll
[2014-02-14 08:56:30 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcaui.exe
[2014-02-14 08:56:30 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pcaui.exe
[2014-02-14 08:56:25 | 000,570,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msdrm.dll
[2014-02-14 08:50:15 | 000,000,000 | R--D | C] -- C:\WINDOWS\BrowserChoice
[2014-02-14 04:32:16 | 004,604,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d2d1.dll
[2014-02-11 15:26:24 | 000,000,000 | ---D | C] -- C:\Users\Lidia\SkyDrive
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2014-02-11 14:17:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji
[2014-02-11 13:58:41 | 000,000,000 | --SD | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft
[2014-02-11 13:58:41 | 000,000,000 | R--D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2014-02-11 13:58:41 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Favorites
[2014-02-11 13:58:41 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Documents
[2014-02-11 13:58:41 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Desktop
[2014-02-11 13:58:41 | 000,000,000 | R--D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014-02-11 13:58:41 | 000,000,000 | R--D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Ustawienia lokalne
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\AppData\Local\Temporary Internet Files
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Szablony
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\SendTo
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Recent
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\PrintHood
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\NetHood
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Documents\Moje wideo
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Documents\Moje obrazy
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Moje dokumenty
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Documents\Moja muzyka
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Menu Start
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\AppData\Local\Historia
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Dane aplikacji
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\AppData\Local\Dane aplikacji
[2014-02-11 13:58:41 | 000,000,000 | -HSD | C] -- C:\Users\Lidia\Cookies
[2014-02-11 13:58:41 | 000,000,000 | -H-D | C] -- C:\Users\Lidia\AppData
[2014-02-11 13:58:41 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Temp
[2014-02-11 13:58:41 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Microsoft
[2014-02-11 13:58:41 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014-02-11 13:49:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2014-02-11 13:49:06 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2014-02-11 13:49:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2014-02-11 13:49:04 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2014-02-11 13:49:03 | 000,000,000 | ---D | C] -- C:\AMD
[2014-02-11 13:48:42 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2014-02-11 13:48:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2014-02-11 13:45:50 | 000,000,000 | -HSD | C] -- C:\Recovery
[2014-02-11 13:45:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2014-02-11 13:44:14 | 000,075,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imagehlp.dll
[2014-02-11 13:43:52 | 000,393,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPhoto.dll
[2014-02-11 13:43:52 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPhoto.dll
[2014-02-11 13:43:42 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSCollect.exe
[2014-02-11 13:41:10 | 000,146,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\SerCx2.sys
[2014-02-11 13:41:10 | 000,086,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pdc.sys
[2014-02-11 13:41:10 | 000,039,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\intelpep.sys
[2014-02-11 13:36:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2014-02-11 13:36:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2014-02-11 13:36:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2014-02-11 13:36:03 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2014-02-11 13:36:03 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2014-02-11 13:34:53 | 000,778,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
[2014-02-11 13:34:53 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2014-02-11 13:34:51 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2014-02-11 13:34:50 | 001,166,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationNative_v0300.dll
[2014-02-07 15:13:17 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Documents\Sony PMB
[2014-01-24 20:16:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2014-01-22 07:52:10 | 000,206,080 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\WINDOWS\SysNative\drivers\ssudmdm.sys
[2014-01-22 07:52:10 | 000,108,800 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\WINDOWS\SysNative\drivers\ssudbus.sys
[2014-01-01 15:08:19 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\sylwester
[2013-12-30 18:57:07 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Desktop\MP3
[2013-12-28 17:46:43 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Macromedia
[2013-12-28 17:45:20 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Adobe
[2013-12-28 15:38:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ms-MY
[2013-12-28 15:38:03 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2013-12-28 15:38:02 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Podcasts
[2013-12-28 14:06:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zune
[2013-12-28 14:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\Zune
[2013-12-27 22:28:48 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Mozilla
[2013-12-27 22:28:48 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Mozilla
[2013-12-27 22:28:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013-12-23 16:57:21 | 000,000,000 | ---D | C] -- C:\Update
[2013-12-23 01:18:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MRT
[2013-12-22 23:16:30 | 000,014,848 | ---- | C] (Microsoft) -- C:\WINDOWS\SysWow64\rars.rs
[2013-12-22 23:16:30 | 000,014,848 | ---- | C] (Microsoft) -- C:\WINDOWS\SysNative\rars.rs
[2013-12-20 21:18:02 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\CrashDumps
[2013-12-20 20:42:41 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Macromedia
[2013-12-20 20:18:13 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\AMD
[2013-12-20 20:15:00 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\ATI
[2013-12-20 20:14:59 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\ATI
[2013-12-20 20:11:19 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\BMExplorer
[2013-12-20 20:11:18 | 000,000,000 | ---D | C] -- C:\Users\Lidia\Documents\Bluetooth Folder
[2013-12-20 20:10:57 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Atheros
[2013-12-20 20:08:52 | 000,000,000 | R--D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013-12-20 20:08:52 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Searches
[2013-12-20 20:08:52 | 000,000,000 | R--D | C] -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013-12-20 20:08:51 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Contacts
[2013-12-20 20:08:44 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Identities
[2013-12-20 20:08:39 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Sony Corporation
[2013-12-20 20:07:27 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Adobe
[2013-12-20 20:05:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\VAIO Startup Setting Tool
[2013-12-20 20:05:27 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Roaming\Sony Corporation
[2013-12-20 20:05:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2013-12-20 20:04:03 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\VirtualStore
[2013-12-20 20:03:35 | 000,000,000 | ---D | C] -- C:\Users\Lidia\AppData\Local\Packages
[2013-12-20 20:00:28 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Videos
[2013-12-20 20:00:28 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Saved Games
[2013-12-20 20:00:28 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Pictures
[2013-12-20 20:00:28 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Music
[2013-12-20 20:00:28 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Links
[2013-12-20 20:00:28 | 000,000,000 | R--D | C] -- C:\Users\Lidia\Downloads
[2013-12-13 10:24:06 | 000,129,536 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\coinst_13.251.dll
[2013-12-13 10:24:06 | 000,099,840 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OpenVideo64.dll
[2013-12-13 10:24:06 | 000,086,528 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OVDecode64.dll
[2013-12-13 10:24:06 | 000,083,968 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OpenVideo.dll
[2013-12-13 10:24:06 | 000,073,728 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OVDecode.dll
[2013-12-13 10:23:54 | 008,287,008 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiumdva.dll
[2013-12-13 10:23:54 | 000,143,304 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiuxp64.dll
[2013-12-13 10:23:54 | 000,126,336 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiuxpag.dll
[2013-12-13 10:23:50 | 008,927,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiumd6a.dll
[2013-12-13 10:23:50 | 006,630,232 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiumdag.dll
[2013-12-13 10:23:48 | 007,751,920 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiumd64.dll
[2013-12-13 10:23:46 | 022,157,824 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atioglxx.dll
[2013-12-13 10:23:46 | 000,190,976 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atitmm64.dll
[2013-12-13 10:23:46 | 000,115,512 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiu9p64.dll
[2013-12-13 10:23:46 | 000,098,496 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiu9pag.dll
[2013-12-13 10:23:42 | 000,332,800 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\ATIODE.exe
[2013-12-13 10:23:42 | 000,051,200 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\ATIODCLI.exe
[2013-12-13 10:23:40 | 026,352,128 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atio6axx.dll
[2013-12-13 10:23:36 | 013,207,552 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmdag.sys
[2013-12-13 10:23:36 | 000,626,176 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmpag.sys
[2013-12-13 10:23:36 | 000,078,432 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atimpc64.dll
[2013-12-13 10:23:36 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atimpc32.dll
[2013-12-13 10:23:36 | 000,031,232 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atimuixx.dll
[2013-12-13 10:23:34 | 000,100,352 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6txx.dll
[2013-12-13 10:23:34 | 000,096,768 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atigktxx.dll
[2013-12-13 10:23:34 | 000,074,752 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6pxx.dll
[2013-12-13 10:23:34 | 000,069,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiglpxx.dll
[2013-12-13 10:23:34 | 000,069,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiglpxx.dll
[2013-12-13 10:23:32 | 009,753,752 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atidxx64.dll
[2013-12-13 10:23:32 | 008,406,024 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atidxx32.dll
[2013-12-13 10:23:32 | 000,588,288 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atieclxx.exe
[2013-12-13 10:23:32 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atidemgy.dll
[2013-12-13 10:23:32 | 000,239,616 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atiesrxx.exe
[2013-12-13 10:23:30 | 015,716,352 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticaldd64.dll
[2013-12-13 10:23:30 | 001,318,552 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\aticfx64.dll
[2013-12-13 10:23:30 | 001,100,216 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\aticfx32.dll
[2013-12-13 10:23:30 | 000,062,464 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalrt64.dll
[2013-12-13 10:23:30 | 000,052,224 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalrt.dll
[2013-12-13 10:23:28 | 014,302,208 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticaldd.dll
[2013-12-13 10:23:28 | 000,368,640 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiapfxx.exe
[2013-12-13 10:23:28 | 000,118,784 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atibtmon.exe
[2013-12-13 10:23:28 | 000,055,808 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalcl64.dll
[2013-12-13 10:23:28 | 000,049,152 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalcl.dll
[2013-12-13 10:23:26 | 001,144,320 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiadlxx.dll
[2013-12-13 10:23:26 | 000,825,344 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atiadlxy.dll
[2013-12-13 10:23:26 | 000,078,432 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdpcom64.dll
[2013-12-13 10:23:26 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdpcom32.dll
[2013-12-13 10:23:26 | 000,063,488 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2013-12-13 10:23:26 | 000,057,344 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.dll
[2013-12-13 10:23:26 | 000,043,520 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\ati2erec.dll
[2013-12-13 10:23:24 | 029,382,144 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\amdocl64.dll
[2013-12-13 10:23:20 | 024,860,160 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\amdocl.dll
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 360 Days ==========[/color]

[2014-12-04 21:14:09 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014-12-04 21:05:57 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014-12-04 19:01:01 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014-12-04 18:52:40 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014-12-04 18:52:37 | 3066,671,104 | -HS- | M] () -- C:\hiberfil.sys
[2014-12-04 18:44:27 | 002,117,632 | ---- | M] (Farbar) -- C:\Users\Lidia\Desktop\FRST64.exe
[2014-11-30 16:35:02 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\SysNative\drivers\sptd.sys
[2014-11-22 13:55:15 | 000,484,360 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014-11-21 23:49:10 | 001,050,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014-11-21 11:48:54 | 000,267,632 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-21 11:48:54 | 000,116,728 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswStm.sys
[2014-11-21 11:48:53 | 000,436,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSP.sys
[2014-11-21 11:48:53 | 000,364,512 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014-11-21 11:48:53 | 000,093,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014-11-21 11:48:53 | 000,083,280 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswmonflt.sys
[2014-11-21 11:48:53 | 000,065,776 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-21 11:48:53 | 000,029,208 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-11-21 11:48:50 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2014-11-20 21:51:37 | 000,714,208 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-11-20 21:51:37 | 000,106,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-05 00:38:37 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-11-04 01:10:18 | 000,304,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014-11-02 01:51:02 | 000,807,160 | ---- | M] () -- C:\WINDOWS\SysNative\perfh015.dat
[2014-11-02 01:51:02 | 000,722,476 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014-11-02 01:51:02 | 000,163,478 | ---- | M] () -- C:\WINDOWS\SysNative\perfc015.dat
[2014-11-02 01:51:02 | 000,135,592 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014-11-02 01:51:01 | 001,825,074 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014-10-31 06:12:41 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wextract.exe
[2014-10-31 06:12:05 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshta.exe
[2014-10-31 06:10:13 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iexpress.exe
[2014-10-31 06:09:37 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pngfilt.dll
[2014-10-31 06:08:00 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeedssync.exe
[2014-10-31 06:06:45 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-10-31 06:06:21 | 000,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\url.dll
[2014-10-31 06:06:09 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-10-31 06:06:00 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-10-31 06:05:50 | 000,417,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2014-10-31 06:04:28 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-10-31 05:56:53 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-10-31 05:54:13 | 000,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IEAdvpack.dll
[2014-10-31 05:53:32 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2014-10-31 05:53:06 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2014-10-31 05:52:22 | 000,108,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2014-10-31 05:51:37 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-10-31 05:51:31 | 000,812,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2014-10-31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-10-31 05:50:44 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-10-31 05:50:11 | 006,040,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-10-31 05:49:39 | 000,537,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-10-31 05:40:07 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\licmgr10.dll
[2014-10-31 05:38:28 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-10-31 05:30:28 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-10-31 05:29:50 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesysprep.dll
[2014-10-31 05:29:17 | 000,087,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2014-10-31 05:28:58 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2014-10-31 05:25:24 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-10-31 05:24:48 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2014-10-31 05:24:25 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-10-31 05:23:46 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2014-10-31 05:21:30 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-10-31 05:19:49 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\occache.dll
[2014-10-31 05:05:52 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-10-31 05:05:35 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-10-31 05:03:02 | 002,124,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-10-31 04:44:32 | 002,865,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-10-31 04:42:04 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imgutil.dll
[2014-10-31 04:28:47 | 000,137,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wextract.exe
[2014-10-31 04:27:26 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iexpress.exe
[2014-10-31 04:26:45 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pngfilt.dll
[2014-10-31 04:25:24 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msfeedssync.exe
[2014-10-31 04:24:23 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-10-31 04:24:00 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\url.dll
[2014-10-31 04:23:37 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-10-31 04:23:21 | 000,340,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2014-10-31 04:22:08 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-10-31 04:20:27 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-10-31 04:15:59 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-10-31 04:14:25 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IEAdvpack.dll
[2014-10-31 04:13:35 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2014-10-31 04:12:17 | 000,661,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2014-10-31 04:12:17 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-10-31 04:11:30 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-10-31 04:03:33 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\licmgr10.dll
[2014-10-31 03:57:20 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-10-31 03:56:44 | 000,090,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesysprep.dll
[2014-10-31 03:56:18 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2014-10-31 03:56:08 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inseng.dll
[2014-10-31 03:53:21 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-10-31 03:52:23 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-10-31 03:51:02 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2014-10-31 03:48:50 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\occache.dll
[2014-10-31 03:39:28 | 002,051,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-10-31 03:11:30 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-10-23 06:48:37 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014-10-23 06:05:08 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014-10-18 10:55:17 | 000,055,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014-10-18 09:09:52 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014-10-18 09:09:44 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014-10-18 08:25:54 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2014-10-18 07:50:21 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2014-10-18 07:27:15 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014-10-18 07:26:48 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014-10-18 07:23:51 | 000,407,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014-10-18 07:23:11 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014-10-18 07:21:47 | 000,894,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014-10-18 07:20:43 | 001,714,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014-10-18 07:14:54 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014-10-18 07:14:32 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014-10-18 07:12:10 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014-10-18 07:11:35 | 000,723,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014-10-18 06:20:02 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollectorres.dll
[2014-10-17 08:01:28 | 000,789,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2014-10-13 03:33:24 | 000,116,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-10-11 01:58:13 | 003,320,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-10-10 02:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys
[2014-10-08 08:37:31 | 000,154,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msaudite.dll
[2014-10-08 08:37:27 | 000,736,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adtschema.dll
[2014-10-08 08:34:45 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2014-10-08 08:24:03 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rfxvmt.dll
[2014-10-08 08:09:31 | 000,428,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-10-08 07:56:48 | 000,445,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2014-10-08 07:51:16 | 000,154,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msaudite.dll
[2014-10-08 07:51:03 | 000,736,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adtschema.dll
[2014-10-08 07:27:17 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-10-08 07:18:10 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2014-10-08 07:17:58 | 001,441,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2014-10-08 06:32:48 | 002,773,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-10-08 06:23:52 | 003,547,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2014-10-08 06:19:04 | 002,459,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-10-07 07:28:00 | 000,500,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2014-10-07 07:27:59 | 000,394,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AUDIOKSE.dll
[2014-10-07 07:27:56 | 000,482,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2014-10-07 07:27:56 | 000,272,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\audiodg.exe
[2014-10-07 07:27:55 | 000,108,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EncDump.dll
[2014-10-07 04:34:01 | 000,344,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AUDIOKSE.dll
[2014-10-07 02:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2014-09-27 08:13:42 | 000,104,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2014-09-27 06:24:47 | 000,088,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2014-09-27 04:30:42 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2014-09-22 05:38:24 | 001,519,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2014-09-22 04:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2014-09-22 04:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2014-09-22 03:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2014-09-10 07:25:19 | 000,474,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2014-09-08 04:07:37 | 000,428,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014-09-07 23:08:25 | 000,389,176 | ---- | M] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014-09-04 23:30:06 | 000,822,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2014-09-04 23:21:08 | 001,053,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014-09-04 04:05:22 | 000,836,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2014-09-04 03:22:45 | 000,670,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2014-09-04 02:01:40 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2014-09-04 01:32:55 | 000,334,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2014-09-04 01:12:01 | 000,590,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2014-09-04 01:10:52 | 000,118,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2014-09-04 01:01:29 | 000,514,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2014-09-04 00:57:48 | 000,921,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014-09-04 00:49:39 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2014-09-02 23:08:11 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2014-09-02 23:08:02 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2014-08-30 23:05:35 | 000,615,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSCOMEX.dll
[2014-08-30 22:58:26 | 000,275,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FXSAPI.dll
[2014-08-30 22:04:22 | 000,941,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2014-08-30 21:53:00 | 000,239,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FXSAPI.dll
[2014-08-30 21:17:42 | 000,799,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2014-08-28 03:55:25 | 007,484,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2014-08-24 21:35:07 | 000,000,266 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2014-08-24 15:28:01 | 000,068,466 | ---- | M] () -- C:\Users\Lidia\Desktop\sciaga-102561.rtf
[2014-08-23 08:48:28 | 002,374,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2014-08-23 08:13:24 | 002,084,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2014-08-23 07:10:58 | 000,068,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UXInit.dll
[2014-08-23 06:32:39 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UXInit.dll
[2014-08-23 06:14:12 | 013,424,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2014-08-23 06:04:31 | 011,820,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2014-08-23 05:50:26 | 002,714,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2014-08-23 05:33:24 | 000,796,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uDWM.dll
[2014-08-16 18:02:24 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_webinstr_01009.Wdf
[2014-08-16 05:08:38 | 001,507,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll
[2014-08-16 05:01:48 | 001,710,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2014-08-16 04:58:45 | 001,112,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2014-08-16 03:55:32 | 002,407,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2014-08-16 02:04:21 | 000,359,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll
[2014-08-16 01:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll
[2014-08-16 01:53:32 | 000,118,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll
[2014-08-16 01:46:38 | 000,290,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll
[2014-08-16 01:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll
[2014-08-16 01:43:38 | 000,075,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll
[2014-08-16 01:31:57 | 000,286,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll
[2014-08-16 01:29:54 | 000,249,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-08-16 01:23:10 | 001,106,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2014-08-16 01:22:56 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll
[2014-08-16 01:22:06 | 000,286,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll
[2014-08-16 01:19:42 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2014-08-16 01:18:36 | 004,758,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2014-08-16 01:17:51 | 008,757,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2014-08-16 01:14:34 | 000,265,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll
[2014-08-16 01:13:50 | 006,649,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2014-08-16 01:13:17 | 005,902,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2014-08-16 01:11:08 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2014-08-16 01:10:35 | 001,120,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2014-08-16 01:08:48 | 005,777,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2014-08-16 01:07:01 | 000,756,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2014-08-15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpioclx.sys
[2014-08-13 00:00:10 | 004,575,232 | ---- | M] (Google Inc.) -- C:\WINDOWS\SysWow64\GPhotos.scr
[2014-08-07 03:12:27 | 001,336,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2014-08-02 01:51:14 | 000,545,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\untfs.dll
[2014-08-02 01:35:12 | 000,485,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\untfs.dll
[2014-07-30 02:56:08 | 000,299,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSDMon.dll
[2014-07-29 06:22:47 | 000,205,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcpmon.dll
[2014-07-25 00:37:35 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pl-PL\usbhub.sys.mui
[2014-07-25 00:37:21 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pl-PL\spaceport.sys.mui
[2014-07-24 16:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2014-07-24 16:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2014-07-24 16:23:21 | 000,125,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2014-07-24 16:20:37 | 000,645,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SHCore.dll
[2014-07-24 16:20:37 | 000,263,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlows.exe
[2014-07-24 16:16:25 | 002,574,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMVDECOD.DLL
[2014-07-24 16:16:24 | 000,211,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVol.exe
[2014-07-24 16:05:56 | 001,660,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2014-07-24 16:05:56 | 001,519,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2014-07-24 16:05:56 | 001,488,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2014-07-24 16:05:56 | 001,356,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2014-07-24 16:03:56 | 000,882,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2014-07-24 16:03:55 | 000,233,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2014-07-24 16:03:54 | 002,141,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2014-07-24 16:03:53 | 000,360,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfreadwrite.dll
[2014-07-24 16:03:53 | 000,205,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mftranscode.dll
[2014-07-24 14:48:15 | 002,410,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMVDECOD.DLL
[2014-07-24 14:48:15 | 000,180,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SndVol.exe
[2014-07-24 14:46:50 | 000,477,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SHCore.dll
[2014-07-24 14:36:22 | 000,707,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2014-07-24 14:36:20 | 002,145,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2014-07-24 14:36:20 | 000,355,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfreadwrite.dll
[2014-07-24 14:36:20 | 000,180,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mftranscode.dll
[2014-07-24 12:51:25 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTAT.DLL
[2014-07-24 12:51:24 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDYAK.DLL
[2014-07-24 12:51:22 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDTT102.DLL
[2014-07-24 12:51:18 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRUM.DLL
[2014-07-24 12:51:18 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU1.DLL
[2014-07-24 12:51:18 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDRU.DLL
[2014-07-24 12:51:05 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KBDBASH.DLL
[2014-07-24 12:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\NdisImPlatform.sys
[2014-07-24 12:22:12 | 000,308,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\compstui.dll
[2014-07-24 12:05:37 | 000,287,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usbmon.dll
[2014-07-24 11:52:10 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDYAK.DLL
[2014-07-24 11:52:02 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTT102.DLL
[2014-07-24 11:52:02 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDTAT.DLL
[2014-07-24 11:51:55 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRUM.DLL
[2014-07-24 11:51:55 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU1.DLL
[2014-07-24 11:51:54 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDRU.DLL
[2014-07-24 11:51:26 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\KBDBASH.DLL
[2014-07-24 11:49:29 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersGPExt.dll
[2014-07-24 11:32:51 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powercfg.cpl
[2014-07-24 11:20:33 | 002,050,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SRH.dll
[2014-07-24 11:18:22 | 001,089,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpedit.dll
[2014-07-24 11:12:23 | 000,878,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionCenter.dll
[2014-07-24 11:10:56 | 001,844,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Display.dll
[2014-07-24 11:10:55 | 000,834,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\osk.exe
[2014-07-24 11:09:22 | 001,057,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdvidcrl.dll
[2014-07-24 11:05:33 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersShell.dll
[2014-07-24 10:53:13 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\prnntfy.dll
[2014-07-24 10:52:16 | 000,621,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2014-07-24 10:44:15 | 016,874,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2014-07-24 10:42:22 | 000,206,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\powercfg.cpl
[2014-07-24 10:40:10 | 000,557,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PrintDialogs.dll
[2014-07-24 10:39:33 | 000,770,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2014-07-24 10:33:43 | 001,741,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SRH.dll
[2014-07-24 10:32:13 | 001,048,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpedit.dll
[2014-07-24 10:27:30 | 000,779,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\osk.exe
[2014-07-24 10:27:20 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdvidcrl.dll
[2014-07-24 10:25:41 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ActionCenter.dll
[2014-07-24 10:24:06 | 001,817,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Display.dll
[2014-07-24 10:18:17 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansvcpal.dll
[2014-07-24 10:16:37 | 012,730,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2014-07-24 10:14:59 | 000,443,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlansec.dll
[2014-07-24 10:13:48 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\prnntfy.dll
[2014-07-24 10:12:48 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WiFiDisplay.dll
[2014-07-24 10:11:56 | 000,356,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\conhost.exe
[2014-07-24 10:04:44 | 000,492,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintDialogs.dll
[2014-07-24 10:04:32 | 000,183,808 | ---- | M] (Microsoft Corp.) -- C:\WINDOWS\SysNative\Defrag.exe
[2014-07-24 09:58:54 | 000,105,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BluetoothApis.dll
[2014-07-24 09:49:34 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2014-07-24 09:49:09 | 001,287,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mispace.dll
[2014-07-24 09:48:58 | 000,659,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2014-07-24 09:47:04 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2014-07-24 09:39:28 | 002,397,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storagewmi.dll
[2014-07-24 09:38:23 | 000,371,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2014-07-24 09:36:14 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BluetoothApis.dll
[2014-07-24 09:30:04 | 000,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2014-07-24 09:29:06 | 000,439,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2014-07-24 09:28:28 | 000,595,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.dll
[2014-07-24 09:23:15 | 001,404,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\storagewmi.dll
[2014-07-24 09:22:20 | 000,487,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winspool.drv
[2014-07-24 09:21:55 | 001,231,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2014-07-24 09:21:08 | 000,302,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanmsm.dll
[2014-07-24 09:20:51 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiapi.dll
[2014-07-24 09:18:34 | 001,144,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanmm.dll
[2014-07-24 09:16:57 | 000,505,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VAN.dll
[2014-07-24 09:15:36 | 000,432,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.dll
[2014-07-24 09:15:27 | 000,721,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.dll
[2014-07-24 09:13:19 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SndVolSSO.dll
[2014-07-24 09:10:57 | 000,889,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2014-07-24 09:08:51 | 000,162,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiapi.dll
[2014-07-24 09:08:14 | 000,321,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2014-07-24 09:05:59 | 000,448,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VAN.dll
[2014-07-24 09:01:07 | 001,992,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsPrint.dll
[2014-07-24 09:00:53 | 002,100,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettingsAdminFlowUI.dll
[2014-07-24 08:58:46 | 000,432,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanconn.dll
[2014-07-24 08:54:35 | 001,290,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsPrint.dll
[2014-07-24 08:50:41 | 001,182,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\printui.dll
[2014-07-24 08:49:41 | 000,263,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DafPrintProvider.dll
[2014-07-24 08:47:52 | 000,576,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSync.dll
[2014-07-24 08:44:12 | 001,057,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\printui.dll
[2014-07-24 08:43:13 | 000,200,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DafPrintProvider.dll
[2014-07-24 08:41:12 | 000,459,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSync.dll
[2014-07-24 08:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2014-07-24 04:20:33 | 000,875,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvcr120_clr0400.dll
[2014-07-24 04:20:23 | 000,869,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvcr120_clr0400.dll
[2014-07-21 19:39:20 | 000,277,712 | ---- | M] () -- C:\Users\Lidia\Desktop\Europass-CV-20140110-Kowalczyk-PL.pdf
[2014-07-15 19:16:27 | 003,048,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcMon.exe
[2014-07-15 09:29:16 | 003,118,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wpc.dll
[2014-07-15 09:22:59 | 002,861,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcWebSync.dll
[2014-07-15 09:03:50 | 002,344,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Wpc.dll
[2014-07-12 15:40:22 | 000,001,795 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014-07-12 06:55:33 | 000,268,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wisp.dll
[2014-07-12 05:58:45 | 000,210,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wisp.dll
[2014-07-12 05:17:55 | 000,623,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2014-07-09 12:46:15 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSReset.exe
[2014-07-04 11:29:21 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSip.dll
[2014-07-04 11:20:07 | 001,656,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2014-07-04 11:06:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxSip.dll
[2014-07-04 11:00:32 | 001,351,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2014-07-04 10:30:46 | 000,544,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2014-07-04 10:27:05 | 000,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2014-06-26 01:32:51 | 001,029,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mispace.dll
[2014-06-26 01:29:49 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dab.dll
[2014-06-21 15:30:47 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tsgqec.dll
[2014-06-20 02:48:19 | 001,273,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2014-06-14 07:03:57 | 002,389,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10warp.dll
[2014-06-13 02:15:21 | 000,517,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2014-06-10 20:50:24 | 006,112,864 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\SysNative\usbaaplrc.dll
[2014-06-10 20:50:24 | 000,054,784 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\SysNative\drivers\usbaapl64.sys
[2014-06-09 23:13:27 | 000,035,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2014-06-09 23:13:22 | 000,035,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2014-06-07 13:46:36 | 000,216,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rsaenh.dll
[2014-06-06 14:04:45 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\qedit.dll
[2014-06-06 13:18:07 | 000,488,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\qedit.dll
[2014-06-06 12:34:04 | 002,133,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2014-06-05 11:18:38 | 001,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aclui.dll
[2014-06-05 10:42:34 | 000,889,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aclui.dll
[2014-06-02 03:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2014-05-31 11:07:07 | 000,440,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbport.sys
[2014-05-31 11:07:07 | 000,027,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbd.sys
[2014-05-31 11:06:57 | 000,555,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.appcore.dll
[2014-05-31 06:00:42 | 001,463,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wsecedit.dll
[2014-05-31 05:18:56 | 001,319,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wsecedit.dll
[2014-05-31 05:01:13 | 000,209,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUDFPlatform.dll
[2014-05-31 05:01:09 | 000,284,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUDFHost.exe
[2014-05-31 03:37:54 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2014-05-31 03:35:41 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2014-05-30 11:05:27 | 000,202,149 | ---- | M] () -- C:\Users\Lidia\Desktop\D20050267Lj.pdf
[2014-05-30 11:03:40 | 001,137,133 | ---- | M] () -- C:\Users\Lidia\Desktop\D20131440.pdf
[2014-05-30 11:01:11 | 000,987,322 | ---- | M] () -- C:\Users\Lidia\Desktop\D20131442.pdf
[2014-05-29 07:23:49 | 000,427,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clusapi.dll
[2014-05-29 06:25:51 | 000,313,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clusapi.dll
[2014-05-27 10:56:49 | 000,323,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DaOtpCredentialProvider.dll
[2014-05-27 10:53:25 | 000,270,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DaOtpCredentialProvider.dll
[2014-05-26 08:26:05 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2014-05-23 11:27:01 | 000,259,202 | ---- | M] () -- C:\Users\Lidia\Desktop\02kurowski.pdf
[2014-05-23 11:26:28 | 000,215,828 | ---- | M] () -- C:\Users\Lidia\Desktop\009.pdf
[2014-05-19 07:31:41 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drvcfg.exe
[2014-05-19 07:21:30 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drvinst.exe
[2014-05-19 06:23:45 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\drvinst.exe
[2014-05-13 08:01:42 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BulkOperationHost.exe
[2014-05-10 11:12:53 | 000,387,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2014-05-10 09:46:45 | 000,335,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2014-05-06 05:41:19 | 000,486,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netcfgx.dll
[2014-05-06 01:55:29 | 000,391,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netcfgx.dll
[2014-05-03 06:36:12 | 000,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2014-05-03 06:19:27 | 000,071,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncobjapi.dll
[2014-05-03 06:08:33 | 000,301,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\framedynos.dll
[2014-05-03 06:07:13 | 000,262,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\framedyn.dll
[2014-05-03 05:46:18 | 000,052,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncobjapi.dll
[2014-05-03 05:37:39 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\framedynos.dll
[2014-05-03 05:37:01 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\framedyn.dll
[2014-05-03 00:26:26 | 000,050,745 | ---- | M] () -- C:\WINDOWS\SysNative\srms.dat
[2014-05-01 14:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wpcfltr.sys
[2014-05-01 06:24:11 | 002,834,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2014-04-30 11:23:26 | 000,005,602 | ---- | M] () -- C:\Users\Lidia\Desktop\UPO_b2287a35176f0fe33e10790af9cc3930.sig
[2014-04-30 06:45:04 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Robocopy.exe
[2014-04-30 05:48:16 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Robocopy.exe
[2014-04-30 05:43:27 | 001,975,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2014-04-30 05:24:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcsvc6.dll
[2014-04-30 05:23:43 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcore6.dll
[2014-04-30 04:46:07 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dhcpcore6.dll
[2014-04-30 04:42:16 | 000,403,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vpnike.dll
[2014-04-28 23:40:27 | 000,721,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll
[2014-04-28 17:22:08 | 000,002,715 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2014-04-28 05:33:30 | 000,599,240 | ---- | M] (Qualcomm Atheros) -- C:\WINDOWS\SysNative\drivers\btfilter.sys
[2014-04-28 05:33:30 | 000,246,804 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AtherosBT.bin
[2014-04-28 05:33:30 | 000,182,784 | ---- | M] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll
[2014-04-28 05:33:30 | 000,181,760 | ---- | M] (Qualcomm Atheros Communications Inc.) -- C:\WINDOWS\SysNative\btcoinst.dll
[2014-04-28 05:33:30 | 000,048,092 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020200.dfu
[2014-04-28 05:33:30 | 000,046,212 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020000.dfu
[2014-04-28 05:33:30 | 000,023,532 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020201.dfu
[2014-04-28 05:33:30 | 000,011,264 | ---- | M] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll.muien-US
[2014-04-28 05:33:30 | 000,001,796 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020000_40.dfu
[2014-04-28 05:33:30 | 000,001,242 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2014-04-28 05:33:30 | 000,001,228 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2014-04-28 05:33:30 | 000,001,214 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2014-04-28 05:33:30 | 000,001,204 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2014-04-28 05:33:30 | 000,001,204 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40.dfu
[2014-04-28 05:33:30 | 000,001,198 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26.dfu
[2014-04-28 05:33:30 | 000,001,192 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2014-04-28 05:33:30 | 000,000,296 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x01.dfu
[2014-04-28 05:33:30 | 000,000,278 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x04.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x03.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x02.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26_0x01.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26.dfu
[2014-04-26 16:34:02 | 000,013,792 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\semav6thermal64ro.sys
[2014-04-18 15:57:16 | 000,032,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ploptin.dll
[2014-04-18 10:44:23 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\energyprov.dll
[2014-04-14 10:37:33 | 002,125,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2014-04-14 10:20:34 | 000,324,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFCaptureEngine.dll
[2014-04-14 09:01:02 | 000,285,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFCaptureEngine.dll
[2014-04-11 09:25:54 | 000,419,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.appcore.dll
[2014-04-11 05:51:25 | 000,250,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpencom.dll
[2014-04-11 05:23:52 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpencom.dll
[2014-04-11 04:54:45 | 000,201,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ubpm.dll
[2014-04-11 03:57:31 | 000,190,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2014-04-10 16:53:53 | 000,005,569 | ---- | M] () -- C:\Users\Lidia\Desktop\UPO_4c56b4c61726460e3e10790a28aade2b.sig
[2014-04-09 12:53:58 | 000,337,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\Classpnp.sys
[2014-04-09 07:39:36 | 000,191,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpchttp.dll
[2014-04-09 06:44:22 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rpchttp.dll
[2014-04-08 23:46:35 | 000,086,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mrt_map.dll
[2014-04-08 23:46:35 | 000,028,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mrt100.dll
[2014-04-08 19:54:55 | 000,080,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mrt_map.dll
[2014-04-08 19:54:55 | 000,026,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mrt100.dll
[2014-04-06 17:34:15 | 000,372,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2014-04-06 17:30:04 | 000,201,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2014-04-06 17:20:55 | 001,379,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2014-04-06 17:20:53 | 000,028,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfpmp.exe
[2014-04-06 17:20:52 | 000,491,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2014-04-06 17:20:51 | 001,403,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2014-04-06 17:20:51 | 000,765,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll
[2014-04-06 17:20:51 | 000,609,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mf.dll
[2014-04-06 16:22:41 | 000,178,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSVideoDSP.dll
[2014-04-06 16:16:37 | 000,387,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2014-04-06 16:16:35 | 001,209,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2014-04-06 16:16:35 | 000,669,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
[2014-04-06 16:16:35 | 000,518,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mf.dll
[2014-04-06 13:58:24 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srclient.dll
[2014-04-06 13:51:42 | 000,467,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srcore.dll
[2014-04-06 13:33:38 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDEServer.exe
[2014-04-06 13:24:55 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rstrui.exe
[2014-04-06 12:26:55 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BootMenuUX.dll
[2014-04-06 11:05:04 | 001,222,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.dll
[2014-04-06 10:59:53 | 000,982,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Streaming.dll
[2014-04-03 09:12:01 | 000,307,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2014-04-03 09:12:01 | 000,130,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpapi.dll
[2014-04-03 03:23:11 | 000,046,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tlscsp.dll
[2014-04-03 03:22:10 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tlscsp.dll
[2014-03-31 21:46:48 | 001,070,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSCOMCTL.OCX
[2014-03-31 21:46:48 | 000,130,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSSTDFMT.DLL
[2014-03-28 16:58:34 | 000,407,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\services.exe
[2014-03-27 06:36:40 | 000,281,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\resutils.dll
[2014-03-27 05:48:26 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\resutils.dll
[2014-03-25 03:27:40 | 000,160,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmmbase.dll
[2014-03-25 03:27:40 | 000,123,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmm.dll
[2014-03-25 02:20:46 | 000,127,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmmbase.dll
[2014-03-22 06:09:22 | 000,103,936 | ---- | M] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014-03-22 06:09:16 | 000,842,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MsSpellCheckingFacility.dll
[2014-03-22 06:09:14 | 000,138,240 | ---- | M] () -- C:\WINDOWS\SysNative\OEMLicense.dll
[2014-03-22 06:09:11 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UMDF\LocationProvider.dll
[2014-03-22 06:09:09 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MsSpellCheckingFacility.dll
[2014-03-22 06:09:03 | 000,303,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sti.dll
[2014-03-21 23:42:13 | 000,023,603 | ---- | M] () -- C:\Users\Lidia\Desktop\Never-Let-Me-Go-poster.jpg
[2014-03-20 11:48:05 | 000,000,162 | -H-- | M] () -- C:\Users\Lidia\Desktop\~$CV.pl_Lidia_Czubek.pdf
[2014-03-20 09:35:00 | 000,001,031 | ---- | M] () -- C:\Users\Lidia\Desktop\NetSender.lnk
[2014-03-20 05:19:59 | 001,291,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kernel32.dll
[2014-03-20 04:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\clfs.sys
[2014-03-20 01:53:21 | 000,950,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll
[2014-03-20 01:48:30 | 000,201,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReInfo.dll
[2014-03-20 00:39:38 | 000,800,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll
[2014-03-20 00:36:36 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReInfo.dll
[2014-03-19 09:15:44 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanhlp.dll
[2014-03-19 08:24:49 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tsgqec.dll
[2014-03-19 08:17:27 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanhlp.dll
[2014-03-19 06:50:30 | 000,079,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\w32tm.exe
[2014-03-19 06:20:42 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\w32tm.exe
[2014-03-18 06:00:32 | 007,173,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Data.Pdf.dll
[2014-03-18 05:52:01 | 005,104,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
[2014-03-17 06:09:03 | 000,462,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XpsGdiConverter.dll
[2014-03-17 05:11:55 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XpsGdiConverter.dll
[2014-03-16 13:15:05 | 000,001,122 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2014-03-14 07:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GeofenceMonitorService.dll
[2014-03-14 07:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GeofenceMonitorService.dll
[2014-03-13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wof.sys
[2014-03-13 08:42:24 | 000,308,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wusa.exe
[2014-03-13 07:51:36 | 000,305,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wusa.exe
[2014-03-11 16:45:44 | 000,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BdeHdCfgLib.dll
[2014-03-11 16:02:25 | 000,794,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fvewiz.dll
[2014-03-11 15:25:32 | 000,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BitLockerDeviceEncryption.exe
[2014-03-11 15:05:16 | 000,210,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapibase.dll
[2014-03-08 21:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wfplwfs.sys
[2014-03-08 21:38:31 | 001,542,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2014-03-08 16:29:39 | 000,356,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dcomp.dll
[2014-03-08 10:02:24 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sxproxy.dll
[2014-03-08 09:33:33 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spp.dll
[2014-03-08 09:25:39 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SetNetworkLocation.dll
[2014-03-08 09:12:05 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sxproxy.dll
[2014-03-08 08:04:41 | 000,160,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2014-03-08 07:48:17 | 000,252,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2014-03-08 07:41:34 | 000,412,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FWPUCLNT.DLL
[2014-03-08 07:40:06 | 000,139,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2014-03-08 07:31:32 | 000,222,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dcomp.dll
[2014-03-08 07:30:07 | 000,197,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2014-03-08 07:25:42 | 000,264,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FWPUCLNT.DLL
[2014-03-08 07:04:54 | 000,717,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2014-03-08 06:58:24 | 000,567,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
[2014-03-08 06:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2014-03-08 06:11:16 | 000,924,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2014-03-06 15:34:58 | 000,113,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\userenv.dll
[2014-03-06 13:53:14 | 002,141,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2014-03-06 13:51:51 | 000,379,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2014-03-06 13:39:53 | 000,212,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cdd.dll
[2014-03-06 12:13:13 | 001,779,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2014-03-06 10:24:41 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\hidclass.sys
[2014-03-06 10:19:23 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Shell.Search.UriHandler.dll
[2014-03-06 10:08:39 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\l2gpstore.dll
[2014-03-06 09:48:57 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UMDF\HidBthLE.dll
[2014-03-06 09:41:09 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevPropMgr.dll
[2014-03-06 09:38:49 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\davclnt.dll
[2014-03-06 09:20:22 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Shell.Search.UriHandler.dll
[2014-03-06 09:10:28 | 000,058,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\l2gpstore.dll
[2014-03-06 09:00:27 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsApi.dll
[2014-03-06 08:16:28 | 000,171,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsApi.dll
[2014-03-06 08:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netlogon.dll
[2014-03-06 07:51:21 | 002,900,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2014-03-06 07:27:24 | 000,274,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WsmWmiPl.dll
[2014-03-06 07:24:02 | 000,462,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlangpui.dll
[2014-03-06 07:23:50 | 000,186,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWfdProvider.dll
[2014-03-06 07:23:34 | 002,270,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2014-03-06 07:21:36 | 000,291,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2014-03-06 07:09:50 | 001,764,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2014-03-06 07:06:39 | 000,386,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlangpui.dll
[2014-03-06 07:04:58 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2014-03-06 07:01:55 | 000,192,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Scanners.dll
[2014-03-06 06:51:16 | 000,151,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Scanners.dll
[2014-03-05 21:51:39 | 000,002,110 | ---- | M] () -- C:\Users\Public\Desktop\The Sims™ 3.lnk
[2014-03-04 08:16:09 | 000,655,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2014-03-04 08:08:35 | 000,299,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pdh.dll
[2014-03-04 08:00:12 | 000,512,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidprov.dll
[2014-03-04 07:56:31 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RMapi.dll
[2014-03-04 07:39:13 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pdh.dll
[2014-03-04 07:32:51 | 000,356,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidprov.dll
[2014-03-04 07:15:50 | 000,542,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Graphics.Printing.dll
[2014-03-04 07:05:32 | 000,402,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Graphics.Printing.dll
[2014-03-04 07:03:08 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredentialMigrationHandler.dll
[2014-03-04 07:03:01 | 000,669,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasapi32.dll
[2014-03-04 06:54:01 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredentialMigrationHandler.dll
[2014-02-24 19:44:09 | 000,005,569 | ---- | M] () -- C:\Users\Lidia\Desktop\UPO_6534a21d4767a5733e10790a4d8cbcc1.sig
[2014-02-24 12:20:12 | 000,000,923 | ---- | M] () -- C:\Users\Public\Desktop\e-Deklaracje.lnk
[2014-02-22 23:56:14 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pl-PL\fvevol.sys.mui
[2014-02-22 22:07:37 | 000,093,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pl-PL\ntfs.sys.mui
[2014-02-22 17:59:25 | 001,290,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctf.dll
[2014-02-22 17:59:25 | 000,526,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2014-02-22 17:59:25 | 000,461,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WerFault.exe
[2014-02-22 17:59:25 | 000,407,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Faultrep.dll
[2014-02-22 17:59:25 | 000,289,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sqmapi.dll
[2014-02-22 17:59:25 | 000,209,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imm32.dll
[2014-02-22 17:59:25 | 000,139,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2014-02-22 17:58:24 | 000,036,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WerFaultSecure.exe
[2014-02-22 17:15:19 | 001,929,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setupapi.dll
[2014-02-22 17:15:19 | 000,275,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powrprof.dll
[2014-02-22 17:15:19 | 000,188,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\systemreset.exe
[2014-02-22 17:15:19 | 000,071,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2014-02-22 17:15:15 | 001,206,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Taskmgr.exe
[2014-02-22 17:15:15 | 000,531,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2014-02-22 17:02:34 | 000,170,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscapi.dll
[2014-02-22 17:02:34 | 000,083,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhost.exe
[2014-02-22 17:02:34 | 000,080,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskhostex.exe
[2014-02-22 17:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdbus.sys
[2014-02-22 17:00:20 | 000,151,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpsd.sys
[2014-02-22 16:59:47 | 000,027,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SysResetErr.exe
[2014-02-22 16:55:42 | 000,162,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AuthHost.exe
[2014-02-22 16:55:41 | 001,435,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2014-02-22 16:55:41 | 000,244,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2014-02-22 16:55:41 | 000,131,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\easinvoker.exe
[2014-02-22 16:55:40 | 000,152,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2014-02-22 16:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSService.dll
[2014-02-22 16:50:32 | 000,761,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iuilp.dll
[2014-02-22 16:50:32 | 000,101,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RestoreOptIn.exe
[2014-02-22 16:50:31 | 000,032,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserAccountBroker.exe
[2014-02-22 16:50:30 | 000,043,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CloudNotifications.exe
[2014-02-22 16:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2014-02-22 16:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UCX01000.SYS
[2014-02-22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdstor.sys
[2014-02-22 16:48:56 | 001,791,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMALFXGFXDSP.dll
[2014-02-22 16:46:42 | 001,927,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2014-02-22 16:46:42 | 001,445,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webservices.dll
[2014-02-22 16:46:42 | 001,000,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinTypes.dll
[2014-02-22 16:46:39 | 000,669,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\advapi32.dll
[2014-02-22 16:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refs.sys
[2014-02-22 16:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\smss.exe
[2014-02-22 16:43:01 | 000,094,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcd.dll
[2014-02-22 16:41:17 | 000,372,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvproc.dll
[2014-02-22 16:41:15 | 001,215,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetsrc.dll
[2014-02-22 16:41:15 | 000,800,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfnetcore.dll
[2014-02-22 16:41:15 | 000,391,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MMDevAPI.dll
[2014-02-22 15:51:59 | 001,063,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Taskmgr.exe
[2014-02-22 15:51:02 | 000,140,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscapi.dll
[2014-02-22 15:49:21 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\en-US\ks.sys.mui
[2014-02-22 15:42:12 | 000,422,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2014-02-22 15:42:12 | 000,410,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WerFault.exe
[2014-02-22 15:42:12 | 000,369,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Faultrep.dll
[2014-02-22 15:42:12 | 000,137,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2014-02-22 15:42:11 | 000,232,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sqmapi.dll
[2014-02-22 15:41:31 | 000,033,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WerFaultSecure.exe
[2014-02-22 15:38:06 | 001,374,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2014-02-22 15:38:06 | 001,077,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webservices.dll
[2014-02-22 15:38:06 | 000,506,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WinTypes.dll
[2014-02-22 15:18:25 | 000,041,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CloudNotifications.exe
[2014-02-22 15:18:25 | 000,029,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserAccountBroker.exe
[2014-02-22 15:18:24 | 000,089,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RestoreOptIn.exe
[2014-02-22 15:08:52 | 000,079,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcd.dll
[2014-02-22 15:04:50 | 000,317,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvproc.dll
[2014-02-22 15:04:48 | 000,650,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfnetcore.dll
[2014-02-22 15:04:47 | 001,011,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfnetsrc.dll
[2014-02-22 13:24:42 | 002,825,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2014-02-22 13:22:26 | 001,163,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll
[2014-02-22 13:20:09 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-system-events.dll
[2014-02-22 13:20:09 | 000,128,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-kernel-power-events.dll
[2014-02-22 13:17:59 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\f3ahvoas.dll
[2014-02-22 13:17:44 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-ntuser-private-l1-1-0.dll
[2014-02-22 13:17:39 | 000,008,192 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-ntuser-private-l1-1-1.dll
[2014-02-22 13:17:11 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-kernel32-package-l1-1-1.dll
[2014-02-22 13:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autochk.exe
[2014-02-22 13:17:06 | 000,874,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autofmt.exe
[2014-02-22 13:17:05 | 000,902,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\autoconv.exe
[2014-02-22 13:17:04 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ext-ms-win-session-winsta-l1-1-0.dll
[2014-02-22 13:16:06 | 000,139,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\poqexec.exe
[2014-02-22 13:14:40 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\watchdog.sys
[2014-02-22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\BasicRender.sys
[2014-02-22 13:11:27 | 000,272,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\portcls.sys
[2014-02-22 13:08:40 | 000,173,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\syncui.dll
[2014-02-22 13:08:16 | 000,630,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OobeFldr.dll
[2014-02-22 13:08:14 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msdxm.ocx
[2014-02-22 13:08:14 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxmasf.dll
[2014-02-22 13:08:11 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mf3216.dll
[2014-02-22 13:08:03 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shimeng.dll
[2014-02-22 13:07:46 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WofUtil.dll
[2014-02-22 13:07:44 | 000,068,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll
[2014-02-22 13:07:41 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clrhost.dll
[2014-02-22 13:07:26 | 000,545,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\apphelp.dll
[2014-02-22 13:04:42 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2014-02-22 13:03:16 | 000,349,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2014-02-22 13:03:00 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spbcd.dll
[2014-02-22 13:01:47 | 000,094,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spcompat.dll
[2014-02-22 13:00:15 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lpksetupproxyserv.dll
[2014-02-22 13:00:08 | 000,025,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgentc.exe
[2014-02-22 12:59:53 | 000,188,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgrade.exe
[2014-02-22 12:57:46 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slc.dll
[2014-02-22 12:54:10 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppc.dll
[2014-02-22 12:50:36 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fsutil.exe
[2014-02-22 12:50:22 | 000,224,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionQueue.dll
[2014-02-22 12:48:33 | 000,162,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ocsetapi.dll
[2014-02-22 12:47:43 | 000,589,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsdyn.dll
[2014-02-22 12:47:36 | 000,165,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdboot.exe
[2014-02-22 12:47:35 | 000,236,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsbas.dll
[2014-02-22 12:46:41 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scrrun.dll
[2014-02-22 12:45:56 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhevents.dll
[2014-02-22 12:45:46 | 000,214,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scrobj.dll
[2014-02-22 12:42:14 | 000,038,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContentServer.exe
[2014-02-22 12:41:15 | 000,196,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PkgMgr.exe
[2014-02-22 12:39:20 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhsvcctl.dll
[2014-02-22 12:37:37 | 000,146,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diskpart.exe
[2014-02-22 12:34:35 | 000,273,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmdskmgr.dll
[2014-02-22 12:32:56 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsutil.dll
[2014-02-22 12:29:29 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RelPost.exe
[2014-02-22 12:28:51 | 002,428,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2014-02-22 12:27:17 | 000,141,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dot3mm.dll
[2014-02-22 12:25:43 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\f3ahvoas.dll
[2014-02-22 12:25:39 | 000,584,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\recimg.exe
[2014-02-22 12:25:36 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWWIN.EXE
[2014-02-22 12:25:31 | 000,008,192 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-ntuser-private-l1-1-1.dll
[2014-02-22 12:25:25 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-ntuser-private-l1-1-0.dll
[2014-02-22 12:25:05 | 000,148,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppnp.dll
[2014-02-22 12:24:51 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-kernel32-package-l1-1-1.dll
[2014-02-22 12:24:48 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-session-winsta-l1-1-0.dll
[2014-02-22 12:24:36 | 000,800,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autoconv.exe
[2014-02-22 12:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autochk.exe
[2014-02-22 12:24:35 | 000,780,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\autofmt.exe
[2014-02-22 12:24:24 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ext-ms-win-networking-wcmapi-l1-1-0.dll
[2014-02-22 12:24:09 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SSShim.dll
[2014-02-22 12:24:08 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\poqexec.exe
[2014-02-22 12:22:17 | 000,177,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\easwrt.dll
[2014-02-22 12:17:26 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DAMM.dll
[2014-02-22 12:17:14 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OobeFldr.dll
[2014-02-22 12:16:53 | 000,432,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\zipfldr.dll
[2014-02-22 12:16:32 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clrhost.dll
[2014-02-22 12:16:26 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wshom.ocx
[2014-02-22 12:16:21 | 000,148,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cscript.exe
[2014-02-22 12:14:48 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cleanmgr.exe
[2014-02-22 12:13:22 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2014-02-22 12:11:50 | 000,068,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spbcd.dll
[2014-02-22 12:09:26 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgentc.exe
[2014-02-22 12:08:30 | 000,113,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shsetup.dll
[2014-02-22 12:07:28 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StorageContextHandler.dll
[2014-02-22 12:07:10 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\scavengeui.dll
[2014-02-22 12:05:58 | 000,463,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RASMM.dll
[2014-02-22 12:05:51 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pnpclean.dll
[2014-02-22 12:05:49 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContentHost.dll
[2014-02-22 12:05:19 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sppc.dll
[2014-02-22 12:04:20 | 000,575,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dfrgui.exe
[2014-02-22 12:02:49 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acppage.dll
[2014-02-22 12:02:48 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContent.dll
[2014-02-22 12:01:37 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fsutil.exe
[2014-02-22 11:59:30 | 000,163,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ocsetapi.dll
[2014-02-22 11:59:12 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\werui.dll
[2014-02-22 11:58:49 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DAConn.dll
[2014-02-22 11:58:35 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sud.dll
[2014-02-22 11:57:32 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\scrrun.dll
[2014-02-22 11:57:05 | 000,165,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\scrobj.dll
[2014-02-22 11:56:40 | 002,862,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\themeui.dll
[2014-02-22 11:56:27 | 000,350,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srchadmin.dll
[2014-02-22 11:56:14 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmvdsitf.dll
[2014-02-22 11:55:56 | 000,248,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srrstr.dll
[2014-02-22 11:55:51 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SrTasks.exe
[2014-02-22 11:53:25 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PkgMgr.exe
[2014-02-22 11:52:51 | 002,288,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncCenter.dll
[2014-02-22 11:52:32 | 000,331,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\newdev.dll
[2014-02-22 11:51:34 | 000,444,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spwizeng.dll
[2014-02-22 11:50:16 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\diskpart.exe
[2014-02-22 11:47:46 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\setupugc.exe
[2014-02-22 11:47:40 | 000,207,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmdskmgr.dll
[2014-02-22 11:47:38 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dfp.exe
[2014-02-22 11:47:32 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\migisol.dll
[2014-02-22 11:46:35 | 000,283,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wbadmin.exe
[2014-02-22 11:41:52 | 002,566,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\themecpl.dll
[2014-02-22 11:41:27 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netid.dll
[2014-02-22 11:41:12 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2014-02-22 11:40:32 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DWWIN.EXE
[2014-02-22 11:38:39 | 000,390,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DfpCommon.dll
[2014-02-22 11:38:04 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\easwrt.dll
[2014-02-22 11:37:49 | 000,912,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nettrace.dll
[2014-02-22 11:36:51 | 000,441,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssph.dll
[2014-02-22 11:35:40 | 000,504,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevicePairing.dll
[2014-02-22 11:35:30 | 000,156,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitagent.exe
[2014-02-22 11:34:44 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgradeResults.exe
[2014-02-22 11:34:12 | 011,742,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\glcndFilter.dll
[2014-02-22 11:32:19 | 000,118,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cscript.exe
[2014-02-22 11:30:57 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cleanmgr.exe
[2014-02-22 11:27:17 | 000,397,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sharemediacpl.dll
[2014-02-22 11:25:16 | 001,428,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RecoveryDrive.exe
[2014-02-22 11:25:12 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\StorageContextHandler.dll
[2014-02-22 11:21:53 | 000,561,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dfrgui.exe
[2014-02-22 11:21:14 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\acppage.dll
[2014-02-22 11:20:54 | 001,152,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscui.cpl
[2014-02-22 11:18:25 | 000,752,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssvp.dll
[2014-02-22 11:18:11 | 000,722,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgradeui.exe
[2014-02-22 11:17:32 | 000,693,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcfg.dll
[2014-02-22 11:17:21 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werui.dll
[2014-02-22 11:16:42 | 000,592,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sud.dll
[2014-02-22 11:16:32 | 000,308,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srchadmin.dll
[2014-02-22 11:16:17 | 000,151,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmvdsitf.dll
[2014-02-22 11:14:49 | 002,165,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SyncCenter.dll
[2014-02-22 11:14:38 | 000,376,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wsqmcons.exe
[2014-02-22 11:14:37 | 002,811,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\themeui.dll
[2014-02-22 11:13:57 | 000,897,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sdclt.exe
[2014-02-22 11:13:28 | 000,307,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\newdev.dll
[2014-02-22 11:12:55 | 000,352,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spwizeng.dll
[2014-02-22 11:12:14 | 000,797,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PurchaseWindowsLicense.dll
[2014-02-22 11:09:56 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\migisol.dll
[2014-02-22 11:09:50 | 001,224,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\werconcpl.dll
[2014-02-22 11:09:27 | 002,706,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gameux.dll
[2014-02-22 11:05:42 | 001,757,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPDMC.exe
[2014-02-22 11:04:46 | 000,483,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WLanConn.dll
[2014-02-22 11:04:41 | 000,935,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasgcw.dll
[2014-02-22 11:04:33 | 000,098,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netid.dll
[2014-02-22 11:03:19 | 002,544,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\themecpl.dll
[2014-02-22 11:02:33 | 008,946,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\glcndFilter.dll
[2014-02-22 11:01:21 | 001,227,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usercpl.dll
[2014-02-22 11:01:19 | 000,367,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssph.dll
[2014-02-22 10:59:38 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpdxm.dll
[2014-02-22 10:59:24 | 000,290,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mdmregistration.dll
[2014-02-22 10:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsm.dll
[2014-02-22 10:56:07 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\samlib.dll
[2014-02-22 10:54:54 | 000,275,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authz.dll
[2014-02-22 10:54:17 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\deviceassociation.dll
[2014-02-22 10:54:01 | 000,323,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GlobCollationHost.dll
[2014-02-22 10:53:48 | 000,825,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\samsrv.dll
[2014-02-22 10:52:49 | 001,132,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Globalization.dll
[2014-02-22 10:52:19 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\powercfg.exe
[2014-02-22 10:51:26 | 000,054,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveskybackup.dll
[2014-02-22 10:50:41 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbrand.dll
[2014-02-22 10:49:04 | 000,155,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MicrosoftAccountTokenProvider.dll
[2014-02-22 10:48:45 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2014-02-22 10:48:09 | 000,355,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wincorlib.dll
[2014-02-22 10:48:07 | 001,136,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscui.cpl
[2014-02-22 10:46:47 | 000,316,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winsku.dll
[2014-02-22 10:45:48 | 000,562,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2014-02-22 10:45:36 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winsrv.dll
[2014-02-22 10:45:13 | 000,512,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimserv.exe
[2014-02-22 10:44:46 | 000,675,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssvp.dll
[2014-02-22 10:44:29 | 000,182,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\korwbrkr.dll
[2014-02-22 10:43:30 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Sockets.PushEnabledApplication.dll
[2014-02-22 10:40:35 | 002,537,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gameux.dll
[2014-02-22 10:39:47 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dasHost.exe
[2014-02-22 10:36:58 | 000,391,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WLanConn.dll
[2014-02-22 10:36:35 | 000,275,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Dism.exe
[2014-02-22 10:36:13 | 000,835,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasgcw.dll
[2014-02-22 10:36:04 | 001,392,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPDMC.exe
[2014-02-22 10:35:37 | 000,968,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdh.dll
[2014-02-22 10:35:04 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WofTasks.dll
[2014-02-22 10:34:40 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmredir.dll
[2014-02-22 10:34:25 | 000,467,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\energy.dll
[2014-02-22 10:33:34 | 000,653,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DismApi.dll
[2014-02-22 10:32:52 | 001,162,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\usercpl.dll
[2014-02-22 10:31:29 | 000,242,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mdmregistration.dll
[2014-02-22 10:28:02 | 002,643,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2014-02-22 10:28:02 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\deviceassociation.dll
[2014-02-22 10:27:54 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GlobCollationHost.dll
[2014-02-22 10:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmsvc.dll
[2014-02-22 10:26:58 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\powercfg.exe
[2014-02-22 10:26:55 | 000,299,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll
[2014-02-22 10:26:33 | 000,792,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Globalization.dll
[2014-02-22 10:25:45 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.HumanInterfaceDevice.dll
[2014-02-22 10:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\das.dll
[2014-02-22 10:25:36 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winbrand.dll
[2014-02-22 10:25:08 | 000,164,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscinterop.dll
[2014-02-22 10:24:22 | 000,666,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimgapi.dll
[2014-02-22 10:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2014-02-22 10:23:51 | 000,628,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msTextPrediction.dll
[2014-02-22 10:23:36 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MicrosoftAccountTokenProvider.dll
[2014-02-22 10:23:21 | 000,256,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wincorlib.dll
[2014-02-22 10:23:11 | 003,494,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2014-02-22 10:22:24 | 000,336,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApiPublic.dll
[2014-02-22 10:22:03 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winsku.dll
[2014-02-22 10:19:50 | 000,146,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\korwbrkr.dll
[2014-02-22 10:19:06 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Sockets.PushEnabledApplication.dll
[2014-02-22 10:18:08 | 000,619,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserLanguagesCpl.dll
[2014-02-22 10:16:16 | 000,017,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sxshared.dll
[2014-02-22 10:16:07 | 011,776,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2014-02-22 10:15:23 | 000,211,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Dism.exe
[2014-02-22 10:14:31 | 000,752,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdh.dll
[2014-02-22 10:14:00 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StructuredQuery.dll
[2014-02-22 10:13:14 | 001,728,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dui70.dll
[2014-02-22 10:12:42 | 000,459,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DismApi.dll
[2014-02-22 10:11:10 | 000,704,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Security.Authentication.OnlineId.dll
[2014-02-22 10:10:45 | 000,747,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidcli.dll
[2014-02-22 10:10:33 | 000,569,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2014-02-22 10:09:49 | 000,109,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwm.exe
[2014-02-22 10:09:30 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
[2014-02-22 10:08:39 | 000,155,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.HumanInterfaceDevice.dll
[2014-02-22 10:07:53 | 000,109,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscinterop.dll
[2014-02-22 10:07:13 | 000,551,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wimgapi.dll
[2014-02-22 10:06:11 | 000,251,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApiPublic.dll
[2014-02-22 10:04:34 | 001,107,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\perftrack.dll
[2014-02-22 10:04:26 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slpts.dll
[2014-02-22 10:02:38 | 000,208,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToManager.dll
[2014-02-22 10:02:31 | 000,559,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserLanguagesCpl.dll
[2014-02-22 10:01:11 | 013,933,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2014-02-22 10:00:32 | 001,341,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dui70.dll
[2014-02-22 09:59:14 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2014-02-22 09:59:07 | 001,621,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RacEngn.dll
[2014-02-22 09:58:04 | 000,544,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidcli.dll
[2014-02-22 09:55:49 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\slpts.dll
[2014-02-22 09:55:41 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\energytask.dll
[2014-02-22 09:55:29 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dataclen.dll
[2014-02-22 09:55:28 | 000,059,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConfigureExpandedStorage.dll
[2014-02-22 09:55:24 | 000,132,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2014-02-22 09:55:03 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msshooks.dll
[2014-02-22 09:54:51 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidcredprov.dll
[2014-02-22 09:54:45 | 000,615,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdbui.dll
[2014-02-22 09:54:32 | 000,647,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2014-02-22 09:54:28 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AepRoam.dll
[2014-02-22 09:54:24 | 000,194,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFilterHost.exe
[2014-02-22 09:54:11 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2014-02-22 09:52:10 | 000,196,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSClient.dll
[2014-02-22 09:51:45 | 000,716,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2014-02-22 09:51:29 | 001,258,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RacEngn.dll
[2014-02-22 09:51:14 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netplwiz.dll
[2014-02-22 09:51:02 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\thumbcache.dll
[2014-02-22 09:49:25 | 000,755,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctfuimanager.dll
[2014-02-22 09:49:20 | 000,468,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemSettings.Handlers.dll
[2014-02-22 09:48:41 | 000,316,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BioCredProv.dll
[2014-02-22 09:48:33 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ConfigureExpandedStorage.dll
[2014-02-22 09:48:33 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dataclen.dll
[2014-02-22 09:48:04 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msshooks.dll
[2014-02-22 09:47:55 | 000,517,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2014-02-22 09:47:47 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlidcredprov.dll
[2014-02-22 09:47:15 | 000,108,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AltTab.dll
[2014-02-22 09:47:03 | 001,008,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WlanMM.dll
[2014-02-22 09:46:35 | 003,312,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bootux.dll
[2014-02-22 09:45:31 | 000,269,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToDevice.dll
[2014-02-22 09:45:29 | 000,169,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSClient.dll
[2014-02-22 09:44:55 | 000,154,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netplwiz.dll
[2014-02-22 09:44:19 | 000,510,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\timedate.cpl
[2014-02-22 09:43:47 | 000,469,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskeng.exe
[2014-02-22 09:43:33 | 000,260,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BioCredProv.dll
[2014-02-22 09:43:03 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Renewal.dll
[2014-02-22 09:42:24 | 000,943,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WlanMM.dll
[2014-02-22 09:42:07 | 000,709,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msctfuimanager.dll
[2014-02-22 09:40:30 | 002,368,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2014-02-22 09:40:08 | 000,203,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToDevice.dll
[2014-02-22 09:40:07 | 000,322,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcpl.dll
[2014-02-22 09:39:33 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bthprops.cpl
[2014-02-22 09:39:28 | 000,556,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.dll
[2014-02-22 09:38:33 | 000,470,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\timedate.cpl
[2014-02-22 09:37:12 | 001,716,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2014-02-22 09:36:21 | 000,232,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputSwitch.dll
[2014-02-22 09:35:39 | 000,155,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingMonitor.dll
[2014-02-22 09:33:13 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingMonitor.dll
[2014-02-22 09:33:08 | 000,609,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pnidui.dll
[2014-02-22 09:31:49 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IdCtrls.dll
[2014-02-22 09:30:51 | 000,198,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnprv.dll
[2014-02-22 09:29:08 | 000,191,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputSwitch.dll
[2014-02-22 09:24:53 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\IdCtrls.dll
[2014-02-22 09:24:43 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmIndexer.dll
[2014-02-22 09:22:47 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncPolicy.dll
[2014-02-22 09:22:42 | 000,777,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2014-02-22 09:21:53 | 000,518,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmIndexer.dll
[2014-02-22 09:21:09 | 000,600,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2014-02-22 09:20:52 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncPolicy.dll
[2014-02-22 09:20:46 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AuthBroker.dll
[2014-02-22 09:19:00 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AuthBroker.dll
[2014-02-22 09:17:51 | 000,128,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CloudStorageWizard.exe
[2014-02-22 09:17:22 | 000,109,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CloudStorageWizard.exe
[2014-02-22 09:06:24 | 001,640,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2014-02-22 09:03:13 | 001,496,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2014-02-22 09:01:02 | 000,635,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe
[2014-02-22 09:00:27 | 000,514,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe
[2014-02-22 08:54:40 | 000,214,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SndVolSSO.dll
[2014-02-22 05:33:20 | 000,262,335 | ---- | M] () -- C:\WINDOWS\SysNative\dfpinc.dat
[2014-02-11 14:16:34 | 000,020,958 | ---- | M] () -- C:\WINDOWS\diagwrn.xml
[2014-02-11 14:16:34 | 000,020,958 | ---- | M] () -- C:\WINDOWS\diagerr.xml
[2014-02-11 14:15:55 | 000,023,044 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2014-02-11 13:49:56 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
[2014-02-11 13:49:55 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2014-02-11 13:49:04 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_AMDASF_01009.Wdf
[2014-02-11 13:48:58 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2014-02-11 13:44:14 | 000,075,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\imagehlp.dll
[2014-02-11 13:43:52 | 000,393,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPhoto.dll
[2014-02-11 13:43:52 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPhoto.dll
[2014-02-11 13:43:42 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSCollect.exe
[2014-02-11 13:41:10 | 000,146,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\SerCx2.sys
[2014-02-11 13:41:10 | 000,086,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\pdc.sys
[2014-02-11 13:41:10 | 000,039,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\intelpep.sys
[2014-02-08 02:08:40 | 000,139,600 | ---- | M] () -- C:\WINDOWS\SysNative\systemsf.ebd
[2014-02-08 02:08:40 | 000,100,197 | ---- | M] () -- C:\WINDOWS\SysNative\RacRules.xml
[2014-02-08 02:08:28 | 000,100,197 | ---- | M] () -- C:\WINDOWS\SysWow64\RacRules.xml
[2014-02-03 23:17:17 | 018,542,920 | ---- | M] () -- C:\Users\Lidia\Desktop\dri15_xvid.avi
[2014-02-01 07:00:38 | 000,002,255 | ---- | M] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014-02-01 07:00:36 | 000,011,109 | ---- | M] () -- C:\WINDOWS\SysWow64\connectedsearch-results.searchconnector-ms
[2014-02-01 07:00:36 | 000,007,762 | ---- | M] () -- C:\WINDOWS\SysWow64\connectedsearch-suggestions.searchconnector-ms
[2014-02-01 07:00:36 | 000,007,130 | ---- | M] () -- C:\WINDOWS\SysWow64\connectedsearch-zeroinput.searchconnector-ms
[2014-02-01 07:00:31 | 000,011,109 | ---- | M] () -- C:\WINDOWS\SysNative\connectedsearch-results.searchconnector-ms
[2014-02-01 07:00:31 | 000,007,762 | ---- | M] () -- C:\WINDOWS\SysNative\connectedsearch-suggestions.searchconnector-ms
[2014-02-01 07:00:31 | 000,007,130 | ---- | M] () -- C:\WINDOWS\SysNative\connectedsearch-zeroinput.searchconnector-ms
[2014-02-01 07:00:27 | 000,002,255 | ---- | M] () -- C:\WINDOWS\SysNative\WimBootCompress.ini
[2014-01-31 10:55:17 | 003,596,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2014-01-31 10:35:29 | 003,085,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2014-01-31 10:19:56 | 000,092,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafBth.dll
[2014-01-31 10:10:58 | 000,559,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll
[2014-01-31 10:04:30 | 000,409,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll
[2014-01-29 09:53:43 | 001,653,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsCodecs.dll
[2014-01-29 01:36:35 | 000,249,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rascustom.dll
[2014-01-29 01:17:43 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Vpn.dll
[2014-01-27 20:53:11 | 000,413,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wow64win.dll
[2014-01-27 20:07:57 | 004,175,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbgeng.dll
[2014-01-27 19:23:33 | 002,873,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbgeng.dll
[2014-01-27 18:18:53 | 001,486,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbghelp.dll
[2014-01-27 18:00:35 | 001,238,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbghelp.dll
[2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\WINDOWS\SysNative\drivers\ssudmdm.sys
[2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\WINDOWS\SysNative\drivers\ssudbus.sys
[2014-01-22 07:21:05 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\deviceaccess.dll
[2014-01-22 06:50:16 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\deviceaccess.dll
[2014-01-17 18:24:15 | 000,388,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ninput.dll
[2014-01-17 18:04:11 | 000,292,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ninput.dll
[2014-01-16 20:30:58 | 000,641,410 | ---- | M] () -- C:\Users\Lidia\Desktop\ListMotywacyjny_List_motywacyjny.pdf
[2014-01-07 08:03:30 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcaui.exe
[2014-01-07 06:59:03 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pcaui.exe
[2014-01-01 14:49:53 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2013-12-29 17:30:25 | 000,000,363 | ---- | M] () -- C:\Users\Lidia\Desktop\Komputer.lnk
[2013-12-29 12:24:51 | 000,116,866 | -H-- | M] () -- C:\Users\Lidia\Desktop\Folder.jpg
[2013-12-28 15:39:13 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
[2013-12-28 15:38:42 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_winusb_01009.Wdf
[2013-12-28 14:06:40 | 000,000,927 | ---- | M] () -- C:\Users\Public\Desktop\Zune.lnk
[2013-12-24 00:28:43 | 000,262,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LocationApi.dll
[2013-12-24 00:26:01 | 000,325,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationApi.dll
[2013-12-21 18:15:01 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2013-12-21 09:54:07 | 000,447,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcomapi.dll
[2013-12-20 20:09:15 | 000,001,887 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Parental Controls.lnk
[2013-12-13 10:24:06 | 000,230,912 | ---- | M] () -- C:\WINDOWS\SysNative\clinfo.exe
[2013-12-13 10:24:06 | 000,129,536 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\coinst_13.251.dll
[2013-12-13 10:24:06 | 000,099,840 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OpenVideo64.dll
[2013-12-13 10:24:06 | 000,086,528 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OVDecode64.dll
[2013-12-13 10:24:06 | 000,083,968 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OpenVideo.dll
[2013-12-13 10:24:06 | 000,073,728 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OVDecode.dll
[2013-12-13 10:23:56 | 000,204,952 | ---- | M] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013-12-13 10:23:56 | 000,204,952 | ---- | M] () -- C:\WINDOWS\SysNative\ativvsvl.dat
[2013-12-13 10:23:54 | 008,287,008 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiumdva.dll
[2013-12-13 10:23:54 | 000,234,036 | ---- | M] () -- C:\WINDOWS\SysNative\ativvaxy_cik.dat
[2013-12-13 10:23:54 | 000,233,776 | ---- | M] () -- C:\WINDOWS\SysNative\ativvaxy_cik_nd.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | M] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | M] () -- C:\WINDOWS\SysNative\ativvsva.dat
[2013-12-13 10:23:54 | 000,143,304 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiuxp64.dll
[2013-12-13 10:23:54 | 000,126,336 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiuxpag.dll
[2013-12-13 10:23:54 | 000,083,552 | ---- | M] () -- C:\WINDOWS\SysNative\ativce02.dat
[2013-12-13 10:23:52 | 003,461,040 | ---- | M] () -- C:\WINDOWS\SysWow64\atiumdva.cap
[2013-12-13 10:23:50 | 008,927,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiumd6a.dll
[2013-12-13 10:23:50 | 006,630,232 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiumdag.dll
[2013-12-13 10:23:48 | 007,751,920 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiumd64.dll
[2013-12-13 10:23:48 | 003,426,688 | ---- | M] () -- C:\WINDOWS\SysNative\atiumd6a.cap
[2013-12-13 10:23:46 | 022,157,824 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atioglxx.dll
[2013-12-13 10:23:46 | 000,190,976 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atitmm64.dll
[2013-12-13 10:23:46 | 000,115,512 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiu9p64.dll
[2013-12-13 10:23:46 | 000,098,496 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiu9pag.dll
[2013-12-13 10:23:46 | 000,003,917 | ---- | M] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013-12-13 10:23:46 | 000,003,917 | ---- | M] () -- C:\WINDOWS\SysNative\atipblag.dat
[2013-12-13 10:23:42 | 000,332,800 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\ATIODE.exe
[2013-12-13 10:23:42 | 000,051,200 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\ATIODCLI.exe
[2013-12-13 10:23:42 | 000,047,887 | ---- | M] () -- C:\WINDOWS\atiogl.xml
[2013-12-13 10:23:40 | 026,352,128 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atio6axx.dll
[2013-12-13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmdag.sys
[2013-12-13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmpag.sys
[2013-12-13 10:23:36 | 000,078,432 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atimpc64.dll
[2013-12-13 10:23:36 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atimpc32.dll
[2013-12-13 10:23:36 | 000,031,232 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atimuixx.dll
[2013-12-13 10:23:34 | 000,721,296 | ---- | M] () -- C:\WINDOWS\SysNative\atiicdxx.dat
[2013-12-13 10:23:34 | 000,100,352 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6txx.dll
[2013-12-13 10:23:34 | 000,096,768 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atigktxx.dll
[2013-12-13 10:23:34 | 000,074,752 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6pxx.dll
[2013-12-13 10:23:34 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiglpxx.dll
[2013-12-13 10:23:34 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiglpxx.dll
[2013-12-13 10:23:32 | 009,753,752 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atidxx64.dll
[2013-12-13 10:23:32 | 008,406,024 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atidxx32.dll
[2013-12-13 10:23:32 | 000,588,288 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atieclxx.exe
[2013-12-13 10:23:32 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atidemgy.dll
[2013-12-13 10:23:32 | 000,239,616 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atiesrxx.exe
[2013-12-13 10:23:30 | 015,716,352 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticaldd64.dll
[2013-12-13 10:23:30 | 001,318,552 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\aticfx64.dll
[2013-12-13 10:23:30 | 001,100,216 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\aticfx32.dll
[2013-12-13 10:23:30 | 000,062,464 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalrt64.dll
[2013-12-13 10:23:30 | 000,052,224 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalrt.dll
[2013-12-13 10:23:28 | 014,302,208 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticaldd.dll
[2013-12-13 10:23:28 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiapfxx.exe
[2013-12-13 10:23:28 | 000,118,784 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atibtmon.exe
[2013-12-13 10:23:28 | 000,055,808 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalcl64.dll
[2013-12-13 10:23:28 | 000,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalcl.dll
[2013-12-13 10:23:26 | 001,144,320 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiadlxx.dll
[2013-12-13 10:23:26 | 000,825,344 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atiadlxy.dll
[2013-12-13 10:23:26 | 000,550,456 | ---- | M] () -- C:\WINDOWS\SysWow64\atiapfxx.blb
[2013-12-13 10:23:26 | 000,550,456 | ---- | M] () -- C:\WINDOWS\SysNative\atiapfxx.blb
[2013-12-13 10:23:26 | 000,078,432 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdpcom64.dll
[2013-12-13 10:23:26 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdpcom32.dll
[2013-12-13 10:23:26 | 000,063,488 | ---- | M] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2013-12-13 10:23:26 | 000,057,344 | ---- | M] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.dll
[2013-12-13 10:23:26 | 000,043,520 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\ati2erec.dll
[2013-12-13 10:23:24 | 029,382,144 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\amdocl64.dll
[2013-12-13 10:23:24 | 001,187,342 | ---- | M] () -- C:\WINDOWS\SysNative\amdocl_as64.exe
[2013-12-13 10:23:24 | 001,061,902 | ---- | M] () -- C:\WINDOWS\SysNative\amdocl_ld64.exe
[2013-12-13 10:23:24 | 000,995,342 | ---- | M] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013-12-13 10:23:24 | 000,798,734 | ---- | M] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013-12-13 10:23:20 | 024,860,160 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\amdocl.dll
[2013-12-13 10:23:16 | 000,412,672 | ---- | M] () -- C:\WINDOWS\SysNative\amdmiracast.dll
[2013-12-13 10:23:16 | 000,134,656 | ---- | M] () -- C:\WINDOWS\SysNative\amdhdl64.dll
[2013-12-13 10:23:14 | 000,123,392 | ---- | M] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013-12-11 13:47:28 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2013-12-10 08:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppReadiness.dll
[2 C:\Users\Lidia\AppData\Local\*.tmp files -> C:\Users\Lidia\AppData\Local\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2014-12-04 21:14:09 | 000,001,131 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2014-12-04 21:14:09 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014-11-15 05:58:55 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014-11-01 22:53:21 | 000,267,632 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014-11-01 22:53:21 | 000,065,776 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014-11-01 22:53:21 | 000,029,208 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014-10-17 11:14:49 | 000,001,196 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xperia Link.lnk
[2014-10-03 02:45:20 | 000,000,998 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
[2014-08-24 15:25:43 | 000,068,466 | ---- | C] () -- C:\Users\Lidia\Desktop\sciaga-102561.rtf
[2014-08-16 18:02:24 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_webinstr_01009.Wdf
[2014-08-16 18:02:22 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014-08-14 10:57:07 | 000,050,745 | ---- | C] () -- C:\WINDOWS\SysNative\srms.dat
[2014-07-21 19:39:16 | 000,277,712 | ---- | C] () -- C:\Users\Lidia\Desktop\Europass-CV-20140110-Kowalczyk-PL.pdf
[2014-07-12 15:40:22 | 000,001,795 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014-07-12 15:29:58 | 000,002,535 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2014-05-30 11:05:24 | 000,202,149 | ---- | C] () -- C:\Users\Lidia\Desktop\D20050267Lj.pdf
[2014-05-30 11:03:38 | 001,137,133 | ---- | C] () -- C:\Users\Lidia\Desktop\D20131440.pdf
[2014-05-30 11:01:09 | 000,987,322 | ---- | C] () -- C:\Users\Lidia\Desktop\D20131442.pdf
[2014-05-23 11:26:59 | 000,259,202 | ---- | C] () -- C:\Users\Lidia\Desktop\02kurowski.pdf
[2014-05-23 11:26:24 | 000,215,828 | ---- | C] () -- C:\Users\Lidia\Desktop\009.pdf
[2014-05-01 02:09:16 | 000,139,600 | ---- | C] () -- C:\WINDOWS\SysNative\systemsf.ebd
[2014-05-01 02:06:57 | 000,262,335 | ---- | C] () -- C:\WINDOWS\SysNative\dfpinc.dat
[2014-05-01 02:03:48 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014-05-01 02:03:48 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysNative\WimBootCompress.ini
[2014-05-01 02:02:54 | 000,100,197 | ---- | C] () -- C:\WINDOWS\SysWow64\RacRules.xml
[2014-05-01 02:02:53 | 000,100,197 | ---- | C] () -- C:\WINDOWS\SysNative\RacRules.xml
[2014-05-01 02:02:52 | 000,007,762 | ---- | C] () -- C:\WINDOWS\SysWow64\connectedsearch-suggestions.searchconnector-ms
[2014-05-01 02:02:52 | 000,007,762 | ---- | C] () -- C:\WINDOWS\SysNative\connectedsearch-suggestions.searchconnector-ms
[2014-05-01 02:02:52 | 000,007,130 | ---- | C] () -- C:\WINDOWS\SysWow64\connectedsearch-zeroinput.searchconnector-ms
[2014-05-01 02:02:52 | 000,007,130 | ---- | C] () -- C:\WINDOWS\SysNative\connectedsearch-zeroinput.searchconnector-ms
[2014-05-01 02:02:39 | 000,011,109 | ---- | C] () -- C:\WINDOWS\SysWow64\connectedsearch-results.searchconnector-ms
[2014-05-01 02:02:38 | 000,011,109 | ---- | C] () -- C:\WINDOWS\SysNative\connectedsearch-results.searchconnector-ms
[2014-05-01 02:02:26 | 000,002,440 | R-S- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileManager.lnk
[2014-04-30 11:23:26 | 000,005,602 | ---- | C] () -- C:\Users\Lidia\Desktop\UPO_b2287a35176f0fe33e10790af9cc3930.sig
[2014-04-28 17:22:08 | 000,002,715 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2014-04-28 05:33:30 | 000,246,804 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AtherosBT.bin
[2014-04-28 05:33:30 | 000,048,092 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020200.dfu
[2014-04-28 05:33:30 | 000,046,212 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020000.dfu
[2014-04-28 05:33:30 | 000,023,532 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020201.dfu
[2014-04-28 05:33:30 | 000,001,796 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020000_40.dfu
[2014-04-28 05:33:30 | 000,001,242 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2014-04-28 05:33:30 | 000,001,228 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2014-04-28 05:33:30 | 000,001,214 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2014-04-28 05:33:30 | 000,001,204 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2014-04-28 05:33:30 | 000,001,204 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40.dfu
[2014-04-28 05:33:30 | 000,001,198 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26.dfu
[2014-04-28 05:33:30 | 000,001,192 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2014-04-28 05:33:30 | 000,000,296 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x01.dfu
[2014-04-28 05:33:30 | 000,000,278 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x04.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x03.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x02.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26_0x01.dfu
[2014-04-28 05:33:30 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26.dfu
[2014-04-26 16:37:02 | 000,013,792 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\semav6thermal64ro.sys
[2014-04-26 16:36:42 | 000,002,060 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care (Desktop).lnk
[2014-04-10 16:53:53 | 000,005,569 | ---- | C] () -- C:\Users\Lidia\Desktop\UPO_4c56b4c61726460e3e10790a28aade2b.sig
[2014-03-22 06:09:22 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014-03-22 06:09:14 | 000,138,240 | ---- | C] () -- C:\WINDOWS\SysNative\OEMLicense.dll
[2014-03-21 23:42:13 | 000,023,603 | ---- | C] () -- C:\Users\Lidia\Desktop\Never-Let-Me-Go-poster.jpg
[2014-03-20 11:48:05 | 000,000,162 | -H-- | C] () -- C:\Users\Lidia\Desktop\~$CV.pl_Lidia_Czubek.pdf
[2014-03-20 09:35:00 | 000,001,031 | ---- | C] () -- C:\Users\Lidia\Desktop\NetSender.lnk
[2014-03-16 13:15:05 | 000,001,122 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2014-03-05 21:51:39 | 000,002,110 | ---- | C] () -- C:\Users\Public\Desktop\The Sims™ 3.lnk
[2014-02-25 15:30:46 | 000,001,572 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Control Center.lnk
[2014-02-24 19:44:09 | 000,005,569 | ---- | C] () -- C:\Users\Lidia\Desktop\UPO_6534a21d4767a5733e10790a4d8cbcc1.sig
[2014-02-24 12:20:12 | 000,000,935 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk
[2014-02-24 12:20:12 | 000,000,923 | ---- | C] () -- C:\Users\Public\Desktop\e-Deklaracje.lnk
[2014-02-11 15:23:46 | 000,001,450 | ---- | C] () -- C:\Users\Lidia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-02-11 14:15:55 | 000,023,044 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2014-02-11 14:04:28 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2014-02-11 13:58:23 | 000,020,958 | ---- | C] () -- C:\WINDOWS\diagwrn.xml
[2014-02-11 13:58:23 | 000,020,958 | ---- | C] () -- C:\WINDOWS\diagerr.xml
[2014-02-11 13:49:56 | 000,000,264 | ---- | C] () -- C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
[2014-02-11 13:49:55 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2014-02-11 13:49:04 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_AMDASF_01009.Wdf
[2014-02-11 13:48:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2014-02-03 23:16:59 | 018,542,920 | ---- | C] () -- C:\Users\Lidia\Desktop\dri15_xvid.avi
[2014-01-16 20:30:58 | 000,641,410 | ---- | C] () -- C:\Users\Lidia\Desktop\ListMotywacyjny_List_motywacyjny.pdf
[2014-01-01 14:49:53 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2013-12-29 17:30:25 | 000,000,363 | ---- | C] () -- C:\Users\Lidia\Desktop\Komputer.lnk
[2013-12-29 12:25:05 | 000,116,866 | -H-- | C] () -- C:\Users\Lidia\Desktop\Folder.jpg
[2013-12-28 17:46:21 | 000,000,930 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013-12-28 15:39:13 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
[2013-12-28 15:38:42 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_winusb_01009.Wdf
[2013-12-28 14:06:40 | 000,000,927 | ---- | C] () -- C:\Users\Public\Desktop\Zune.lnk
[2013-12-21 18:15:01 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2013-12-13 10:24:06 | 000,230,912 | ---- | C] () -- C:\WINDOWS\SysNative\clinfo.exe
[2013-12-13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013-12-13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysNative\ativvsvl.dat
[2013-12-13 10:23:54 | 000,234,036 | ---- | C] () -- C:\WINDOWS\SysNative\ativvaxy_cik.dat
[2013-12-13 10:23:54 | 000,233,776 | ---- | C] () -- C:\WINDOWS\SysNative\ativvaxy_cik_nd.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013-12-13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysNative\ativvsva.dat
[2013-12-13 10:23:54 | 000,083,552 | ---- | C] () -- C:\WINDOWS\SysNative\ativce02.dat
[2013-12-13 10:23:52 | 003,461,040 | ---- | C] () -- C:\WINDOWS\SysWow64\atiumdva.cap
[2013-12-13 10:23:48 | 003,426,688 | ---- | C] () -- C:\WINDOWS\SysNative\atiumd6a.cap
[2013-12-13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013-12-13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysNative\atipblag.dat
[2013-12-13 10:23:42 | 000,047,887 | ---- | C] () -- C:\WINDOWS\atiogl.xml
[2013-12-13 10:23:34 | 000,721,296 | ---- | C] () -- C:\WINDOWS\SysNative\atiicdxx.dat
[2013-12-13 10:23:26 | 000,550,456 | ---- | C] () -- C:\WINDOWS\SysWow64\atiapfxx.blb
[2013-12-13 10:23:26 | 000,550,456 | ---- | C] () -- C:\WINDOWS\SysNative\atiapfxx.blb
[2013-12-13 10:23:24 | 001,187,342 | ---- | C] () -- C:\WINDOWS\SysNative\amdocl_as64.exe
[2013-12-13 10:23:24 | 001,061,902 | ---- | C] () -- C:\WINDOWS\SysNative\amdocl_ld64.exe
[2013-12-13 10:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013-12-13 10:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013-12-13 10:23:16 | 000,412,672 | ---- | C] () -- C:\WINDOWS\SysNative\amdmiracast.dll
[2013-12-13 10:23:16 | 000,134,656 | ---- | C] () -- C:\WINDOWS\SysNative\amdhdl64.dll
[2013-12-13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013-12-11 13:47:28 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2013-08-22 16:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013-08-22 16:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013-08-22 15:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013-08-22 08:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013-08-22 04:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013-08-22 00:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013-08-22 00:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2014-03-04 10:22:49 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-08-31 01:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-08-30 23:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-08-22 10:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013-08-22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-08-22 10:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2014-03-03 19:06:47 | 000,000,000 | ---D | M] -- C:\Users\Dom\AppData\Roaming\OpenOffice
[2014-11-01 22:54:21 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\AVAST Software
[2014-02-24 12:20:15 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje
[2014-02-24 12:20:16 | 000,000,000 | ---D | M] -- C:\Users\Lidia\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 220 bytes -> C:\Users\Lidia\SkyDrive:ms-properties

< End of report >



Kod: Zaznacz wszystko
OTL Extras logfile created on: 2014-12-04 21:16:47 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Lidia\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,57 Gb Total Physical Memory | 2,51 Gb Available Physical Memory | 70,17% Memory free
4,20 Gb Paging File | 2,63 Gb Available in Paging File | 62,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225,91 Gb Total Space | 174,92 Gb Free Space | 77,43% Space Free | Partition Type: NTFS
Drive D: | 209,71 Gb Total Space | 128,59 Gb Free Space | 61,32% Space Free | Partition Type: NTFS

Computer Name: LILA | User Name: Lidia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{030F16B3-AC3F-4B85-AC18-6EF3E5F4F36C}" = rport=138 | protocol=17 | dir=out | app=system |
"{0E408148-2463-493C-974D-9831F0585CEE}" = lport=9996 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcsystemtray.exe |
"{199E3C84-2FDE-45F8-9913-CEF74D8D3499}" = lport=1900 | protocol=17 | dir=in | app=%programfiles%\zune\zune.exe |
"{19AFECAE-A699-4CCD-B7D2-172015BF52AA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BA398D1-E360-4F0D-9A98-5EAB8B6CB86B}" = rport=445 | protocol=6 | dir=out | app=system |
"{31113462-1629-4950-917E-0BF2DAA24DD8}" = lport=138 | protocol=17 | dir=in | app=system |
"{3B656BEE-00F6-450C-8B2A-B8B6EA1052A1}" = lport=445 | protocol=6 | dir=in | app=system |
"{3DE59B36-AF3E-4A20-8268-BF907CEF1972}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4CF0A1A0-996D-404B-BEB9-9ED8531E56BD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D06C62A-FF0C-4F4C-A019-9FCA8B50AAE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{538335E5-13F7-47F7-AE49-8A22B0E73D97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{550A699B-3CDF-49AB-A293-25E8A6ABAA81}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{55A8CA9F-00E5-4CAB-95E8-C51B169A51F7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5FDD1F6D-898C-4865-8569-C10751DFED61}" = lport=2869 | protocol=6 | dir=in | app=system |
"{68243D58-392D-41F5-8FE7-E6151EDCF778}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6E23CD0C-702C-4253-A384-C9DB53797B8F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{747A8562-F3A7-4A9C-A2E8-DE0E0E2584A0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7A4A8B49-C91E-4D16-B17A-C7E940954444}" = lport=139 | protocol=6 | dir=in | app=system |
"{898FB1AB-3DFC-4CC1-81F1-084A319F3C00}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A921310-5D00-44ED-9AAF-40780C05A99E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9B997EBD-66BE-4CE7-BB01-81F7CFC56AB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{A04A87E8-DA87-47B1-A0F1-914AD3757D53}" = lport=9997 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vaioshell.exe |
"{AAB83954-A7FE-468B-8A89-95CF1163699A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B01E4F72-CD19-480B-A104-A4C349D3C314}" = lport=9999 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe |
"{B4688510-2513-4F34-8332-47DAB553E0A1}" = lport=9998 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcadmin.exe |
"{BA8646D0-E0D5-420F-92F4-D99D5B2B2C8B}" = lport=137 | protocol=17 | dir=in | app=system |
"{D95F677C-FE69-4D9C-A800-B512F493DBAC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FAE44678-023C-46B8-862D-59FEB9CF75C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FB6C0575-99EB-41D6-AD97-40511D65DC77}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FC9FD662-EA31-42C0-A9A0-AEADD0F29594}" = rport=137 | protocol=17 | dir=out | app=system |
"{FE0B0C3F-A187-41CA-90E8-A3AE57FBF8F9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001464FC-E3E9-4828-BC6F-628A59D79CE4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.315_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{02A0F843-9E76-4C52-A0EE-7C02CE119ADC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{02A6CE20-3CE5-4935-804F-AF1CFCC01946}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{06773AF9-A653-4505-9AF2-878617C09D4A}" = dir=in | name=taptiles |
"{08DD2950-9786-49FC-9B3B-45DE06576044}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{093A6F4D-638C-49E3-BB66-0F338B51A334}" = dir=in | name=microsoft solitaire collection |
"{0D9B20DA-20EC-43B7-AB43-6E400C3EB4A7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{124BE3DC-93D9-4D46-8FB3-94980959F22A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{153DDAFE-7284-48EB-BB8E-2780F4C8BB43}" = dir=out | name=@{microsoft.zunemusic_2.2.931.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{17DD9FB6-2AE2-471E-B4DE-BB0DEA030DA3}" = dir=in | name=mcafee® central for sony |
"{1A6B4D74-2A98-40D3-938B-78443AA3251A}" = dir=out | name=sony select |
"{1A73D7E3-209F-4D1E-9545-7E4D11323C68}" = protocol=6 | dir=out | app=system |
"{1FB698BF-4735-4CBE-97D8-4E4EB6AD0FDA}" = dir=out | name=microsoft minesweeper |
"{2084B1B9-C9A6-417F-981A-D787C0B7317F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{21BFDA3E-2A93-473F-B772-667B01076326}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{2351BED2-2143-49A4-B4C3-DCBADB8E91FB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{263B3EA9-9E48-4AD2-8EDA-310736EE78AC}" = dir=out | name=@{microsoft.bingsports_3.0.2.317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{263C5183-B2FF-45B8-BECF-2B335EAF1F29}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{26719D7A-D5A2-4702-AB87-C4CAF90E3605}" = dir=in | name=juniper networks junos pulse |
"{2E32F130-BCF1-48CD-AECB-955B43601A3C}" = dir=out | name=juniper networks junos pulse |
"{2F3E727D-CC71-4533-B584-803B1E0C529C}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{2F522F85-964D-4FF8-80C1-7E9429426005}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{2F6B21B3-CF42-47F6-85AE-C45095FBA812}" = dir=out | name=vaio care |
"{2F71F6D2-8B4A-4EF0-8648-C94D81EB80E2}" = dir=out | name=- games app - |
"{302DD789-2769-4D7E-8712-7A0E58B11304}" = dir=in | name=microsoft minesweeper |
"{313F0D2F-EC6F-4307-8C72-AC6B7C540249}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{32DD8247-27F1-43DD-A33B-3BFC3EB8E502}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3329E50E-D514-4A00-BE5C-6EFD44B75F77}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{34C71DC9-3CFB-4C30-897E-A7583222713E}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{3A48B196-4B0B-4173-A984-65DFEAF9DACA}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{3F1B62FF-8F0B-4A0E-9C50-1D9AEA7B9BF3}" = dir=in | name=skype |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{43219BD5-F0C3-475C-94B2-C68B7247343C}" = dir=out | name=@{microsoft.zunevideo_1.5.338.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{438E36CC-1B94-41AE-ABC5-995653A8B9F1}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{48D4E687-B9F5-4AFE-892F-436F15B3996B}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{4A7C30CB-C022-43A2-A18A-0042C93A4C42}" = protocol=6 | dir=out | app=system |
"{4B4155A4-1EC0-4371-B5AB-4A1066774CC2}" = dir=in | name=mcafee® central for sony |
"{508A2261-AE87-4A3B-95B8-9AB6F5F1ECC2}" = dir=out | name=@{microsoft.bingtravel_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{55AC1D0D-797C-4B91-9F42-0214A591BABC}" = dir=in | name=microsoft solitaire collection |
"{55B1BF9D-EE69-4A5A-82D9-6A694741CC00}" = dir=in | name=microsoft minesweeper |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{5A6557A8-21E2-4D5F-8ECF-952E7B0666C3}" = dir=out | name=windows_ie_ac_001 |
"{5ABEA3F4-87D2-4151-B772-882064F87314}" = dir=out | name=check point vpn |
"{5B56F422-8C54-4727-88E1-461288305EF9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5C180B6B-167E-4C02-A378-B0F5BC88E08B}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{608400D0-4232-4911-83E4-BDFFF494F4DA}" = dir=out | name=taptiles |
"{623B3D06-7BEC-4583-A25F-3F45E6E6C449}" = dir=out | name=skype |
"{64FBCFD1-9BF5-44E0-93DE-6CF6FACBC84A}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{6693CC48-FD90-4B49-95EE-CBCDAD9B93BE}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{677D8E8B-AF81-4910-B6A9-A3E4385CAA94}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{685B3947-DDBC-48C2-985C-A81DC5EEADAB}" = dir=out | name=microsoft solitaire collection |
"{6CF61DE6-9F17-40BD-9670-67338B1C2A10}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{73BC64C0-6827-46BC-AC51-74B3C2B196CE}" = dir=in | app=c:\users\lidia\appdata\local\microsoft\skydrive\skydrive.exe |
"{74F762CD-615B-4D6E-8299-BCD640553F8C}" = dir=out | name=@{microsoft.bingweather_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{751944F4-D261-4D64-BA9E-FA82DE2F9048}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{78CE5D66-64B8-44C3-8F2F-9D28E336EAAD}" = dir=out | name=@{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{7BD0C972-641A-442F-ACD9-B312122F5921}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{822B057D-68BB-4593-996B-02C5FDEBB95B}" = dir=out | name=juniper networks junos pulse |
"{823FED70-BBA1-4705-8B37-7896CE34DCD9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8491F288-D7F9-4674-84C7-F3318C469372}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{856434AD-ADCA-4010-991F-62D9656039BD}" = protocol=6 | dir=out | app=system |
"{882A2F3D-5A0F-43E1-A53B-FE3DCEF867A8}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{88C7819F-C7CF-46B5-AE41-FED1A7FBD144}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{89B6F0BD-97A2-4C1A-953B-99B88725ACA1}" = dir=out | name=skype |
"{8C4DFB19-B22C-476A-ABAE-3DB39500DCB6}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{8D9777BA-1A90-4367-9191-574484072827}" = dir=out | name=wordament |
"{9238877F-603C-46ED-8F06-6F50FF39BC11}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{940E5550-504E-4037-9EE7-EC4CC2E0D1D9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9458264A-5F0C-44C1-81C3-479A589FB3E3}" = dir=out | name=f5 vpn |
"{96A32F70-AA90-47DD-9513-B7EFFAC25A65}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{97983CB2-9F05-4A90-9609-D03981F881CA}" = dir=out | name=@{microsoft.zunemusic_2.6.476.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{9820196B-CCF2-4B13-8362-7334EBEFACDE}" = dir=out | name=@{microsoft.bingnews_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{98B40748-33D7-45AB-9DB4-CAE11317C670}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{9A5BD996-2418-4372-AFE1-2D09C2648F34}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9E3B5818-96C3-430E-AF40-7D44969C65A4}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9F595940-23DC-48C5-B04D-EEFF37139C05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9F7E3951-E6AC-442E-A901-621741838FB2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9F8097D1-0C03-49CB-BF40-FB506509FC52}" = dir=out | name=windows_ie_ac_001 |
"{9FAC618A-BDEF-4D39-8BC4-98FAA73F54B9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A1E34056-B831-457A-8F2F-0A99315293CB}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{A317CFA9-E27F-494E-9601-E66D6FF76D27}" = dir=in | name=check point vpn |
"{A4AE9D4C-2657-4DE2-9A5E-90C35F65BCA5}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{A633D237-0CDA-42B1-A892-CE4248D109F5}" = dir=out | name=microsoft solitaire collection |
"{A7EAA7C9-A9FC-471E-89C6-F83C1BBB8B1F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A9EC2D1E-7E16-489A-AF3E-96BCCB03EF00}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{ACF7881E-0950-4BBE-99E4-320025746E05}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AF5FE555-86C7-4004-9037-062CAFC3233B}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{B4DB54BD-3FB9-462A-99D2-FE799A6D785D}" = dir=out | name=sony select |
"{B70810F0-B1ED-461F-A994-D6BE128B19AF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BC1BD523-BD0B-42B4-A3B3-EC6E24AE7F1E}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{BC9E5E3F-1D42-46B5-BC90-475E4D1364CD}" = dir=out | name=@{microsoft.bingmaps_2.1.2922.2139_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{BD018346-9CE3-4B57-9749-0BC8D368BB9B}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{BD9C016A-62EC-41F7-982C-DE3FD213C238}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0B0590D-8CB4-4B48-819F-9FE86F23F560}" = dir=out | name=vaio care |
"{C176AFC8-9DC3-410B-9D00-3B76F677A3E9}" = dir=out | name=check point vpn |
"{C2125D7A-F3EA-45B5-9ED5-76FBE4032813}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{C2466120-2EE4-47CD-BF95-688F79D435F8}" = dir=out | name=@{microsoft.zunevideo_2.6.215.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{C3F01482-0DB4-42CD-8A91-7172BE718019}" = dir=out | name=mcafee® central for sony |
"{C40839CB-E672-41BE-8179-77239F483D3B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C64B97B6-4AA6-4DD8-B4A5-1EBE1C68A53F}" = dir=out | name=windows_ie_ac_001 |
"{C6E9145A-0EE9-44DE-8A58-FF97231D8F5E}" = dir=out | name=f5 vpn |
"{C7389275-089D-4764-829D-FA319B338401}" = dir=out | name=sonicwall mobile connect |
"{C778CDD6-6BF6-4811-8375-B446ABBEDAC7}" = dir=in | name=vaio care |
"{CA45CB10-1ADB-4A15-929E-5497A2E623D9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CB354727-1CD4-4820-A6C8-6F6D2258101E}" = dir=in | name=check point vpn |
"{CCE7A28A-1B1C-4441-9697-ACD7A435C068}" = dir=in | name=sonicwall mobile connect |
"{CE7E2FBF-222A-40BB-97F8-28ABCFC857C1}" = dir=out | name=windows_ie_ac_001 |
"{D032395D-1786-4F9A-A512-8E07703A2B8D}" = dir=out | name=- games app - |
"{D14AF6D4-42A7-4DB7-AFDE-B34B169C7083}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{D23153B5-2163-49F8-9B26-77F501379547}" = dir=out | name=sonicwall mobile connect |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D70EAC0A-DAEE-4F16-A109-02929D410E67}" = dir=out | name=windows_ie_ac_001 |
"{D7880873-CC9D-4D1D-A52C-68FF92783C2D}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{D7D933AC-4D60-4F38-A828-64D4B46323C7}" = dir=out | name=microsoft minesweeper |
"{D8A0E1E8-82AA-48D2-8944-16525F39DE93}" = dir=in | name=skype |
"{DA3CF7A9-20F0-450E-A5A2-9651DD78FBC0}" = dir=in | name=juniper networks junos pulse |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DBFE4C41-4629-434B-B3F7-DFB0DEC44110}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DCB2A9F6-2AB1-4A41-B522-AF44BFD1D0BD}" = dir=in | name=vaio care |
"{DCCA78F9-2906-43B9-9B9C-76DBDC822912}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{DCD62A33-757D-4DF6-AD27-D3034BC8AB28}" = dir=in | name=f5 vpn |
"{DDB99518-2F6D-493A-A867-9A63600834F7}" = dir=in | name=sonicwall mobile connect |
"{E2ECA714-68DE-4E5B-9EEA-CCDDF1FFB846}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{E3E85A51-C589-4CB7-80C7-C553CEA3EC0B}" = dir=out | name=@{microsoft.zunevideo_2.6.408.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{E4705F09-9887-4F2B-8479-ADFC2DF1BBA3}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{E53611B4-545A-492D-A815-6B3F552E1646}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{E7211AB8-916E-4392-9278-045F599DFB54}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E76059C4-6926-4F96-8A2C-4FD2F0AEF1A8}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E8726D91-8391-485A-9E9B-4BCF023A311A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{ECBF3C57-D6CB-462F-BCB5-F5BBEE88E889}" = dir=out | name=mcafee® central for sony |
"{ECCDA18D-D39B-4815-9E46-AE9CA2E748B4}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{EFD9D7E7-9D74-404A-B33A-9004227CE02D}" = dir=out | name=taptiles |
"{EFEA28EC-C9B1-4471-8630-DE38648359B4}" = dir=in | name=taptiles |
"{F1A5B808-1673-44B2-B0BC-0193CFFB8C33}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F230AAB7-996E-4D3B-B0EA-46CAEF46C59E}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{F9F0C374-492A-4350-B24C-D83A28B86960}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{FAF0E88C-088B-43DB-B464-41B743A98699}" = dir=out | name=wordament |
"{FBA7E63F-58E8-4C71-A003-A30F847720A5}" = dir=in | name=f5 vpn |
"TCP Query User{78B7C52D-B45B-4915-BD53-FCB6FC9D571B}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{E5F1B4C1-BBE5-457E-AE34-CDF31F9BDDEF}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{553A0E06-4AC5-46F5-B7DC-6D94EA0C3373}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{AA0903BB-5077-41E3-9785-1B6C21C88CD3}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{15B9204E-BA09-485E-8F2C-094AC0077664}" = VAIO Care Recovery
"{25ECAFCB-DCFB-4FCE-A5B2-772A57F59860}" = VCCx64
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{30EC1664-6916-5E36-FEA7-8E20B1C4DCD7}" = ccc-utility64
"{312395BC-7CC2-434C-A660-30250276A926}" = SSLx64
"{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}" = iTunes
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{46261E1C-5E0D-484E-8CCC-7F770375FBA2}" = VU5x64
"{4B432082-B58C-4035-91FB-F28D504D3148}" = VUx64
"{4F31AC31-0A28-4F5A-8416-513972DA1F79}" = VSSTx64
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{5388ABD8-6E23-4498-BE10-01079387590F}" = VGClientX64
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62A172B2-550E-499D-9A82-5190D18390AA}" = VAIO Media Server Settings
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}" = Apple Mobile Device Support
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{77619545-1710-CA11-4487-4CD836E76DB9}" = AMD Fuel
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007
"{92907606-B2FC-4193-B0CE-A21159DA3ABB}" = VAIO Care
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{AB447E3B-7A95-4CA6-8ECD-B25C96314B67}" = VCCx64
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{B81EACDF-16E0-A32C-F096-16EF2BD8405C}" = AMD Catalyst Install Manager
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{D55EAC07-7207-44BD-B524-0F063F327743}" = VIx64
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}" = VPMx64
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 5.10 (64-bitowy)
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"{10181264-340D-4BE7-B879-3A49604A6FD1}" = VUx86
"{10DD6128-A810-4A90-9523-475D573FBB37}" = PlayMemories Home
"{14AC95A2-7675-4988-A5BD-3F5B943AED08}" = VAIO Gate
"{1A207C93-12E4-5B88-777D-92F74DC29EDD}" = CCC Help Hungarian
"{1AE56779-2A31-8982-FF75-422457BA5123}" = CCC Help Danish
"{1B740CAA-D283-4662-0469-898A0850B622}" = CCC Help Chinese Traditional
"{1C7DDA73-0C05-E7DD-97A8-A8542B8EA404}" = CCC Help Norwegian
"{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}" = Obsługa programów Apple
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{26A3AC60-368D-D7FE-30C9-C85E4E1FD7EC}" = CCC Help Turkish
"{309DDAE9-A147-56A2-456D-F66BCEFA88E5}" = Catalyst Control Center Graphics Previews Common
"{3490653F-2789-46A1-B1BF-6BD4CF4131AB}" = FDUx86
"{3A26D9BD-0F73-432D-B522-2BA18138F7EF}" = VAIO Improvement
"{3B1AECFC-F652-9877-B6BE-5BFB5023B02F}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523ADF33-0165-88B2-E05E-22C934058B81}" = CCC Help German
"{54BDD1B2-1312-EF6F-ED92-1C300377D9DE}" = CCC Help Greek
"{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
"{60D1433B-175B-B907-DD89-D434997BEBEC}" = CCC Help Russian
"{63C43435-F428-42BA-8E7B-5848749D9262}" = SSLx86
"{641256B0-734F-2B3E-4AEA-4B2AB21F8916}" = Catalyst Control Center Profiles Mobile
"{661598FC-D512-F972-22D8-620D36CEA58B}" = CCC Help Italian
"{692955F2-DE9F-4078-8FAA-858D6F3A1776}" = VAIO Gesture Control
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{74B53C92-E8E8-1903-76FE-A113448EB504}" = CCC Help Japanese
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79954639-C427-4B14-B774-2F6EE649BE99}" = Catalyst Control Center - Branding
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{7AD4F11E-E27C-1455-3F32-076ABB2CE633}" = Catalyst Control Center InstallProxy
"{7B6D6F11-A5BC-4538-0017-21350BA54ED4}" = CCC Help Portuguese
"{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
"{7E5A5CA6-B7D0-406E-A75E-157CAB47EB94}" = VMLx86
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{82CFAFBA-3D52-F45B-67B1-3D1885C7F87D}" = CCC Help Thai
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{857087BB-A988-4462-A5C6-CF6739143B56}" = KUx86
"{88AEC113-3901-0902-A0B8-651A74D005BF}" = CCC Help Chinese Standard
"{8E797841-A110-41FD-B17A-3ABC0641187A}" = VAIO Control Center
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{913E2B02-1BA9-4B38-991B-31C717F9D00C}" = e-Deklaracje Desktop
"{94211EE0-14F9-58C8-676B-54462CB2A346}" = CCC Help Finnish
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
"{9D8112DB-3490-4BF1-AAFA-1D224FFB5D3C}" = VHD
"{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
"{A2F10E60-5D7D-E13B-E451-99A70EBB7C39}" = CCC Help Spanish
"{AA4B3623-6213-41EC-9BFB-F001D72C47A6}" = VAIO Gesture Control
"{AB57D823-F5BE-38AF-DD26-8E04E64308AA}" = CCC Help Polish
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.11) MUI
"{AFDC0CC0-39E8-42C0-9823-2C1C182676DC}" = VCCx86
"{AFE24FB0-8CC3-77A5-EBFA-132FD250FE66}" = CCC Help English
"{B24BB74E-8359-43AA-985A-8E80C9219C70}" = VSSTx86
"{B31938C7-7E97-49EE-8F88-951E156268A3}" = VCCx86
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B8991D99-88FD-41F2-8C32-DB70278D5C30}" = VWSTx86
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BCBBD089-FF54-3F73-2FB5-F3DD7ED7B439}" = Catalyst Control Center Localization All
"{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}" = VAIO CPU Fan Diagnostic
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C4001DF8-CE87-B7C5-5AC8-D8C321D070EA}" = CCC Help French
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
"{C820FBC5-0490-B6D7-0AF5-D8245E1BD903}" = CCC Help Swedish
"{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}" = VIx86
"{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
"{D91558BF-D1F3-411F-AEFE-8774CB406512}" = VAIO - Xperia Link
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ECCEB4D0-7080-4F8A-B498-E40A32A4FBED}" = Restore
"{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}" = XperiaLinkx86
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F458075C-E1AB-F9A6-3B97-D80BF7EC44A5}" = CCC Help Korean
"{F55687F5-D221-604B-61EA-49E80DB04D11}" = AMD VISION Engine Control Center
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FC9F3001-77BD-D664-5941-6E3F16203629}" = CCC Help Czech
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Avast" = Avast Free Antivirus
"e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1" = e-Deklaracje Desktop
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{00A663F1-6C03-48CA-8E85-55806AAE2615}" = VAIO Movie Creator Template Data
"InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}" = VAIO Image Optimizer
"Mozilla Firefox 34.0.5 (x86 pl)" = Mozilla Firefox 34.0.5 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NetSender_is1" = NetSender 3.0
"Picasa 3" = Picasa 3
"PIT Format 2013_is1" = PIT Format 2013
"PITy 2013/2014_is1" = PITy 2013/2014

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-2017453163-4049187296-263026530-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SkyDriveSetup.exe" = Microsoft SkyDrive

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2014-11-30 10:52:49 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2014-11-30 10:52:49 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1750

Error - 2014-11-30 10:52:49 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1750

Error - 2014-11-30 10:52:51 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2014-11-30 10:52:51 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5234

Error - 2014-11-30 10:52:51 | Computer Name = Lila | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5234

Error - 2014-11-30 11:13:52 | Computer Name = Lila | Source = Microsoft-Windows-LocationProvider | ID = 2006
Description =

Error - 2014-11-30 11:32:36 | Computer Name = Lila | Source = VSS | ID = 8194
Description =

Error - 2014-11-30 11:47:04 | Computer Name = Lila | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: 5iikfnoq.exe, wersja: 2.1.19357.0,
sygnatura czasowa: 0x52e7ea83  Nazwa modułu powodującego błąd: 5iikfnoq.exe, wersja:
2.1.19357.0, sygnatura czasowa: 0x52e7ea83  Kod wyjątku: 0xc0000005  Przesunięcie błędu:
0x000011aa  Identyfikator procesu powodującego błąd: 0x13d0  Godzina uruchomienia aplikacji
powodującej błąd: 0x01d00cb4d75c5842  Ścieżka aplikacji powodującej błąd: C:\Users\Lidia\Downloads\5iikfnoq.exe
Ścieżka
modułu powodującego błąd: C:\Users\Lidia\Downloads\5iikfnoq.exe  Identyfikator raportu:
212cdf0e-78a8-11e4-bead-083e8ebd58f0  Pełna nazwa pakietu powodującego błąd:   Identyfikator
aplikacji względem pakietu powodującego błąd:

Error - 2014-11-30 11:47:49 | Computer Name = Lila | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: 5iikfnoq.exe, wersja: 2.1.19357.0,
sygnatura czasowa: 0x52e7ea83  Nazwa modułu powodującego błąd: 5iikfnoq.exe, wersja:
2.1.19357.0, sygnatura czasowa: 0x52e7ea83  Kod wyjątku: 0xc0000005  Przesunięcie błędu:
0x000011aa  Identyfikator procesu powodującego błąd: 0xee8  Godzina uruchomienia aplikacji
powodującej błąd: 0x01d00cb4f345ce39  Ścieżka aplikacji powodującej błąd: C:\Users\Lidia\Downloads\5iikfnoq.exe
Ścieżka
modułu powodującego błąd: C:\Users\Lidia\Downloads\5iikfnoq.exe  Identyfikator raportu:
3bbf6c63-78a8-11e4-bead-083e8ebd58f0  Pełna nazwa pakietu powodującego błąd:   Identyfikator
aplikacji względem pakietu powodującego błąd:

[ ESRV_SVC Events ]
Error - 2014-04-26 11:37:10 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

Error - 2014-10-17 06:00:47 | Computer Name = Lila | Source = ESRV_SVC | ID = 2
Description =

[ System Events ]
Error - 2014-12-01 15:21:37 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:31:40 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:31:41 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:31:47 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:35:38 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:50:38 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:50:43 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 15:56:00 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 16:05:28 | Computer Name = Lila | Source = DCOM | ID = 10010
Description =

Error - 2014-12-01 16:17:12 | Computer Name = Lila | Source = APXACC | ID = 16778219
Description = The NDIS6 LWF initialization has failed. (0xC0000001)


< End of report >
hugo91
~user
 
Posty: 319
Dołączenie: 19 Cze 2006, 16:33
Pochwały: 6



Bardzo powolny komputer, prosze o sprawdzenie loga

Postprzez ordynat 05 Gru 2014, 22:49

Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej to:
:OTL
O4 - HKLM..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey File not found

:Files
C:\Program Files (x86)\fst_pl_178

:Commands
[emptytemp]

Kliknij w Wykonaj Skrypt.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 7 gości