
Dokonałem 2 dni temu reinstalacji Windowsa 7 (po uprzednim zakupieniu dysku SSD. Głównie właśnie pod system). Wchodząc do menadżera procesów zaraz po stracie Windowsa jest ich prawie 70 (w tym kilka-kilkanaście svhost.exe). Na moim "starym" systemie po starcie miałem nie wiecej niż 15 procesów. Na pierwszy rzut oka nie widzę objawów infekcji, (2 razy zawiesiła mi się Mozilla) ale wolę się upewnić.
Oto logi:
GMER:
Spoiler:
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-17 20:24:39
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\00000069 Crucial_ rev.MU05 111,79GB
Running: bddg2gdy.exe; Driver: C:\Users\Odyn\AppData\Local\Temp\uwtcqpoc.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x928FCAA0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x928FD57E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x929095C8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x92909614]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x929097AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x92909536]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x8D1976D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x9290957E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x928FDAB4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x928FDCD0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x92909768]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x928FE36C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x928FCB06]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x92901B40]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x928FC6F2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8D1977B2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x928FCB6C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x92901F36]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x928FEE54]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x929095F2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x92909636]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x929097D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x9290955C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x9290143A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x929096E6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x929095A6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x92901822]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x9290978C]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8D197556]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x928FECC8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x928FE9D6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x928FCBD2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x928FCC38]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x8D1978AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x928FC78C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x928FC95E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x928FC8EC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x928FE536]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x928FE698]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x928FC9E6]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x8D197624]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x928FE1C6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x928FCC9E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x928FD5DA]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 83091A09 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830CB1F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 830D2220 4 Bytes [A0, CA, 8F, 92]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 830D22A8 4 Bytes [7E, D5, 8F, 92]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 830D22FC 8 Bytes [C8, 95, 90, 92, 14, 96, 90, ...] {ENTER 0x9095, 0x92; ADC AL, 0x96; NOP ; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 830D2308 4 Bytes [AE, 97, 90, 92] {SCASB ; XCHG EDI, EAX; NOP ; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 830D2324 4 Bytes [36, 95, 90, 92] {XCHG EBP, EAX; NOP ; XCHG EDX, EAX}
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 8328D4DF 4 Bytes CALL 928FF517 \SystemRoot\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 832A7333 4 Bytes CALL 928FF52D \SystemRoot\system32\drivers\aswSnx.sys
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9B203000, 0x16640A, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\AUDIODG.EXE[176] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\webget\updatewebget.exe[436] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[472] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[552] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[560] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text ...
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateFile + 6 778C55CE 4 Bytes [28, 78, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateFile + B 778C55D3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateKey + 6 778C560E 4 Bytes [68, 79, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateKey + B 778C5613 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateMutant + 6 778C564E 4 Bytes [68, 7A, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateMutant + B 778C5653 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateSection + 6 778C56EE 4 Bytes [A8, 7A, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateSection + B 778C56F3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtMapViewOfSection + B 778C5C33 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenFile + 6 778C5CDE 4 Bytes [68, 78, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenFile + B 778C5CE3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenKey + 6 778C5D0E 4 Bytes [A8, 79, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenKey + B 778C5D13 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenKeyEx + B 778C5D23 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenMutant + 6 778C5D5E 4 Bytes [28, 7A, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenMutant + B 778C5D63 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcess + 6 778C5D8E 4 Bytes [68, 7B, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcess + B 778C5D93 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessToken + 6 778C5D9E 4 Bytes [A8, 7B, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessToken + B 778C5DA3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessTokenEx + 6 778C5DAE 4 Bytes [68, 7C, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessTokenEx + B 778C5DB3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenSection + B 778C5DD3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThread + 6 778C5E0E 4 Bytes [28, 7B, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThread + B 778C5E13 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadToken + 6 778C5E1E 4 Bytes [28, 7C, 07, 00] {SUB [EDI+EAX+0x0], BH}
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadToken + B 778C5E23 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadTokenEx + 6 778C5E2E 4 Bytes [A8, 7C, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadTokenEx + B 778C5E33 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtQueryAttributesFile + 6 778C5F3E 4 Bytes [A8, 78, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtQueryAttributesFile + B 778C5F43 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtQueryFullAttributesFile + B 778C5FF3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtSetInformationFile + 6 778C663E 4 Bytes [28, 79, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtSetInformationFile + B 778C6643 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtSetInformationThread + B 778C66A3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtUnmapViewOfSection + 6 778C69BE 4 Bytes [28, 7D, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtUnmapViewOfSection + B 778C69C3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] kernel32.dll!CreateProcessW 7686204D 5 Bytes JMP 00080030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] kernel32.dll!CreateProcessA 76862082 5 Bytes JMP 00080070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!DeleteObject 766D5F14 5 Bytes JMP 002701B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SelectObject 766D6640 5 Bytes JMP 002705F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetTextColor 766D6906 5 Bytes JMP 00270A30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetBkMode 766D69B1 5 Bytes JMP 002708F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!DeleteDC 766D6EAA 5 Bytes JMP 00270170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetDeviceCaps 766D6F7F 5 Bytes JMP 002703B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtSelectClipRgn 766D7114 5 Bytes JMP 002702F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SelectClipRgn 766D7242 5 Bytes JMP 002705B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetStretchBltMode 766D7705 5 Bytes JMP 002706B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetCurrentObject 766D7917 5 Bytes JMP 00270370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextMetricsW 766D7B8F 5 Bytes JMP 00270E30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextAlign 766D7DAF 5 Bytes JMP 00270D70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!IntersectClipRect 766D7DFE 5 Bytes JMP 002703F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtTextOutW 766D8192 5 Bytes JMP 00270970
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetTextAlign 766D828E 5 Bytes JMP 002709F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetClipBox 766D8525 5 Bytes JMP 00270330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!MoveToEx 766D8C21 5 Bytes JMP 00270470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StretchDIBits 766DA53E 5 Bytes JMP 00270770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!RestoreDC 766DA67B 5 Bytes JMP 00270530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SaveDC 766DA74B 5 Bytes JMP 00270570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextExtentPoint32W 766DB4B5 5 Bytes JMP 00270670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextFaceW 766DB73A 2 Bytes JMP 00270D30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextFaceW + 3 766DB73D 2 Bytes [B9, 89]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetFontData 766DBCC4 5 Bytes JMP 00270C70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetWorldTransform 766DC90A 5 Bytes JMP 002706F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateDCA 766DCCA9 5 Bytes JMP 002700B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateDCW 766DCF79 5 Bytes JMP 002700F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateICW 766DCFD0 5 Bytes JMP 00270130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextMetricsA 766DD0F2 5 Bytes JMP 00270DF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!Rectangle 766DF1FF 5 Bytes JMP 002709B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!LineTo 766DF59B 5 Bytes JMP 00270430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetICMMode 766DFAA4 5 Bytes JMP 00270DB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtTextOutA 766E03F9 5 Bytes JMP 00270930
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextExtentPoint32A 766E07B0 5 Bytes JMP 00270630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtEscape 766E2949 5 Bytes JMP 002702B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!Escape 766E3939 5 Bytes JMP 00270270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextFaceA 766E3E6A 5 Bytes JMP 00270CF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetPolyFillMode 766ED851 5 Bytes JMP 00270B30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetMiterLimit 766EDA0D 5 Bytes JMP 00270B70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!EndPage 766F00D7 5 Bytes JMP 00270230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ResetDCW 766F050D 5 Bytes JMP 00270AB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetGlyphOutlineW 766FC1BA 5 Bytes JMP 00270CB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateScalableFontResourceW 766FE817 5 Bytes JMP 00270BB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!AddFontResourceW 766FEC13 5 Bytes JMP 00270BF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!RemoveFontResourceW 766FF109 5 Bytes JMP 00270C30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!AbortDoc 76704C63 5 Bytes JMP 00270030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!EndDoc 767050AA 5 Bytes JMP 002701F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StartPage 76705195 5 Bytes JMP 00270730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StartDocW 76705BB0 5 Bytes JMP 002707F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!BeginPath 7670635D 5 Bytes JMP 00270830
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SelectClipPath 767063B4 5 Bytes JMP 00270AF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CloseFigure 7670640F 5 Bytes JMP 00270070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!EndPath 76706466 5 Bytes JMP 00270A70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StrokePath 76706699 5 Bytes JMP 002707B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!FillPath 76706726 5 Bytes JMP 00270870
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!PolylineTo 76706B94 5 Bytes JMP 002704F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!PolyBezierTo 76706C25 5 Bytes JMP 002704B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!PolyDraw 76706CD7 5 Bytes JMP 002708B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!ActivateKeyboardLayout 76488203 5 Bytes JMP 002804F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!ScreenToClient 7648A506 7 Bytes JMP 00280670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!RegisterClipboardFormatA 7648C091 5 Bytes JMP 002802F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!RegisterClipboardFormatW 7648DF8D 5 Bytes JMP 002802B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetCursor 76493075 5 Bytes JMP 00280530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!MonitorFromWindow 76493622 7 Bytes JMP 00280630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!PostMessageW 7649447B 5 Bytes JMP 002805F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!IsWindowVisible 76494D69 7 Bytes JMP 002806B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClientRect 764954DD 7 Bytes JMP 002805B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!MapWindowPoints 76495CAA 5 Bytes JMP 00280570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetParent 76496029 7 Bytes JMP 002806F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!EmptyClipboard 764A290C 5 Bytes JMP 00280130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetClipboardData 764A2962 5 Bytes JMP 00280170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardData 764A2BA7 5 Bytes JMP 00280030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardFormatNameW 764A5FD2 5 Bytes JMP 00280230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetClipboardViewer 764A6FF6 5 Bytes JMP 002804B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardFormatNameA 764A700A 5 Bytes JMP 00280270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!ChangeClipboardChain 764B147C 5 Bytes JMP 00280430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetTopWindow 764B24D9 7 Bytes JMP 00280730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!CloseClipboard 764B446C 5 Bytes JMP 002800B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!OpenClipboard 764B447E 5 Bytes JMP 00280070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!IsClipboardFormatAvailable 764B44FF 5 Bytes JMP 002800F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardSequenceNumber 764B4513 5 Bytes JMP 00280330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardOwner 764B4525 5 Bytes JMP 00280370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!CountClipboardFormats 764B470A 5 Bytes JMP 002801F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!EnumClipboardFormats 764B47EC 5 Bytes JMP 002801B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetOpenClipboardWindow 764B480B 5 Bytes JMP 002803F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetCursorPos 764CC1B0 5 Bytes JMP 00280770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardViewer 764E4AF7 5 Bytes JMP 00280470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetPriorityClipboardFormat 764E4BF9 5 Bytes JMP 002803B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ole32.dll!OleSetClipboard 76A20045 5 Bytes JMP 00290030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ole32.dll!OleIsCurrentClipboard 76A236B2 5 Bytes JMP 00290070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ole32.dll!OleGetClipboard 76A4FDCD 5 Bytes JMP 002900B0
.text C:\Windows\system32\atieclxx.exe[1288] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\webget\bin\utilwebget.exe[1368] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1428] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1512] kernel32.dll!SetUnhandledExceptionFilter 768AF4FB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1512] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1592] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1712] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1740] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1776] kernel32.dll!SetUnhandledExceptionFilter 768AF4FB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1776] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1856] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\PnkBstrA.exe[1912] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Microsoft\BingBar\SeaPort.EXE[1940] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[2044] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3388] kernel32.dll!SetUnhandledExceptionFilter 768AF4FB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3388] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3460] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\MSI Afterburner\MSIAfterburner.exe[3528] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3880] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[4256] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] ntdll.dll!LdrUnloadDll 778DC86E 5 Bytes JMP 001E03FC
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] ntdll.dll!LdrLoadDll 778E223E 5 Bytes JMP 601F1EB1 C:\Program Files\Mozilla Firefox\mozglue.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!K32GetDeviceDriverBaseNameW + 5D 768A941E 7 Bytes JMP 107784D6 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!QueryPerformanceCounter + 13 768AC435 7 Bytes JMP 107784F9 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!LoadAppInitDlls + 355 768AF4F6 7 Bytes JMP 0FDF3A32 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] GDI32.dll!GetViewportOrgEx + 26C 766D884B 7 Bytes JMP 10778457 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\webget\bin\webget.PurBrowse.exe[4640] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\conhost.exe[4648] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\webget\bin\webget.BrowserAdapter.exe[4696] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!RegisterMessagePumpHook + 2F1 76488B9E 7 Bytes JMP 10029931 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!IsDialogMessageW + 340 76494444 7 Bytes JMP 100299A2 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!GetWindowInfo 76494B5E 5 Bytes JMP 1002D777 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!ToUnicodeEx + 71 764A2223 7 Bytes JMP 100270E4 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Windows\system32\DllHost.exe[4812] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5704] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text D:\Pobrane\bddg2gdy.exe[5776] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[5836] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [746524CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7463562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [746356EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74652546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [746485AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74644D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74645105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [746451DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [74646707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74648301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74648850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [746490B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7464E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74644C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
---- EOF - GMER 2.1 ----
Rootkit scan 2014-05-17 20:24:39
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\00000069 Crucial_ rev.MU05 111,79GB
Running: bddg2gdy.exe; Driver: C:\Users\Odyn\AppData\Local\Temp\uwtcqpoc.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x928FCAA0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x928FD57E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x929095C8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x92909614]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x929097AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x92909536]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x8D1976D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x9290957E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x928FDAB4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x928FDCD0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x92909768]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x928FE36C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x928FCB06]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x92901B40]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x928FC6F2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8D1977B2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x928FCB6C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x92901F36]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x928FEE54]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x929095F2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x92909636]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x929097D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x9290955C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x9290143A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x929096E6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x929095A6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x92901822]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x9290978C]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8D197556]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x928FECC8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x928FE9D6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x928FCBD2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x928FCC38]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x8D1978AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x928FC78C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x928FC95E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x928FC8EC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x928FE536]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x928FE698]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x928FC9E6]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x8D197624]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x928FE1C6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x928FCC9E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x928FD5DA]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 83091A09 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830CB1F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 830D2220 4 Bytes [A0, CA, 8F, 92]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 830D22A8 4 Bytes [7E, D5, 8F, 92]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 830D22FC 8 Bytes [C8, 95, 90, 92, 14, 96, 90, ...] {ENTER 0x9095, 0x92; ADC AL, 0x96; NOP ; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 830D2308 4 Bytes [AE, 97, 90, 92] {SCASB ; XCHG EDI, EAX; NOP ; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 830D2324 4 Bytes [36, 95, 90, 92] {XCHG EBP, EAX; NOP ; XCHG EDX, EAX}
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 8328D4DF 4 Bytes CALL 928FF517 \SystemRoot\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 832A7333 4 Bytes CALL 928FF52D \SystemRoot\system32\drivers\aswSnx.sys
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9B203000, 0x16640A, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\AUDIODG.EXE[176] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\webget\updatewebget.exe[436] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[472] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[552] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[560] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text ...
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateFile + 6 778C55CE 4 Bytes [28, 78, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateFile + B 778C55D3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateKey + 6 778C560E 4 Bytes [68, 79, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateKey + B 778C5613 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateMutant + 6 778C564E 4 Bytes [68, 7A, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateMutant + B 778C5653 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateSection + 6 778C56EE 4 Bytes [A8, 7A, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtCreateSection + B 778C56F3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtMapViewOfSection + B 778C5C33 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenFile + 6 778C5CDE 4 Bytes [68, 78, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenFile + B 778C5CE3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenKey + 6 778C5D0E 4 Bytes [A8, 79, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenKey + B 778C5D13 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenKeyEx + B 778C5D23 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenMutant + 6 778C5D5E 4 Bytes [28, 7A, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenMutant + B 778C5D63 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcess + 6 778C5D8E 4 Bytes [68, 7B, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcess + B 778C5D93 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessToken + 6 778C5D9E 4 Bytes [A8, 7B, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessToken + B 778C5DA3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessTokenEx + 6 778C5DAE 4 Bytes [68, 7C, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenProcessTokenEx + B 778C5DB3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenSection + B 778C5DD3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThread + 6 778C5E0E 4 Bytes [28, 7B, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThread + B 778C5E13 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadToken + 6 778C5E1E 4 Bytes [28, 7C, 07, 00] {SUB [EDI+EAX+0x0], BH}
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadToken + B 778C5E23 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadTokenEx + 6 778C5E2E 4 Bytes [A8, 7C, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtOpenThreadTokenEx + B 778C5E33 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtQueryAttributesFile + 6 778C5F3E 4 Bytes [A8, 78, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtQueryAttributesFile + B 778C5F43 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtQueryFullAttributesFile + B 778C5FF3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtSetInformationFile + 6 778C663E 4 Bytes [28, 79, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtSetInformationFile + B 778C6643 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtSetInformationThread + B 778C66A3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtUnmapViewOfSection + 6 778C69BE 4 Bytes [28, 7D, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ntdll.dll!NtUnmapViewOfSection + B 778C69C3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] kernel32.dll!CreateProcessW 7686204D 5 Bytes JMP 00080030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] kernel32.dll!CreateProcessA 76862082 5 Bytes JMP 00080070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!DeleteObject 766D5F14 5 Bytes JMP 002701B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SelectObject 766D6640 5 Bytes JMP 002705F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetTextColor 766D6906 5 Bytes JMP 00270A30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetBkMode 766D69B1 5 Bytes JMP 002708F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!DeleteDC 766D6EAA 5 Bytes JMP 00270170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetDeviceCaps 766D6F7F 5 Bytes JMP 002703B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtSelectClipRgn 766D7114 5 Bytes JMP 002702F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SelectClipRgn 766D7242 5 Bytes JMP 002705B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetStretchBltMode 766D7705 5 Bytes JMP 002706B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetCurrentObject 766D7917 5 Bytes JMP 00270370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextMetricsW 766D7B8F 5 Bytes JMP 00270E30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextAlign 766D7DAF 5 Bytes JMP 00270D70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!IntersectClipRect 766D7DFE 5 Bytes JMP 002703F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtTextOutW 766D8192 5 Bytes JMP 00270970
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetTextAlign 766D828E 5 Bytes JMP 002709F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetClipBox 766D8525 5 Bytes JMP 00270330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!MoveToEx 766D8C21 5 Bytes JMP 00270470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StretchDIBits 766DA53E 5 Bytes JMP 00270770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!RestoreDC 766DA67B 5 Bytes JMP 00270530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SaveDC 766DA74B 5 Bytes JMP 00270570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextExtentPoint32W 766DB4B5 5 Bytes JMP 00270670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextFaceW 766DB73A 2 Bytes JMP 00270D30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextFaceW + 3 766DB73D 2 Bytes [B9, 89]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetFontData 766DBCC4 5 Bytes JMP 00270C70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetWorldTransform 766DC90A 5 Bytes JMP 002706F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateDCA 766DCCA9 5 Bytes JMP 002700B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateDCW 766DCF79 5 Bytes JMP 002700F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateICW 766DCFD0 5 Bytes JMP 00270130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextMetricsA 766DD0F2 5 Bytes JMP 00270DF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!Rectangle 766DF1FF 5 Bytes JMP 002709B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!LineTo 766DF59B 5 Bytes JMP 00270430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetICMMode 766DFAA4 5 Bytes JMP 00270DB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtTextOutA 766E03F9 5 Bytes JMP 00270930
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextExtentPoint32A 766E07B0 5 Bytes JMP 00270630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ExtEscape 766E2949 5 Bytes JMP 002702B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!Escape 766E3939 5 Bytes JMP 00270270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetTextFaceA 766E3E6A 5 Bytes JMP 00270CF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetPolyFillMode 766ED851 5 Bytes JMP 00270B30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SetMiterLimit 766EDA0D 5 Bytes JMP 00270B70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!EndPage 766F00D7 5 Bytes JMP 00270230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!ResetDCW 766F050D 5 Bytes JMP 00270AB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!GetGlyphOutlineW 766FC1BA 5 Bytes JMP 00270CB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CreateScalableFontResourceW 766FE817 5 Bytes JMP 00270BB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!AddFontResourceW 766FEC13 5 Bytes JMP 00270BF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!RemoveFontResourceW 766FF109 5 Bytes JMP 00270C30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!AbortDoc 76704C63 5 Bytes JMP 00270030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!EndDoc 767050AA 5 Bytes JMP 002701F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StartPage 76705195 5 Bytes JMP 00270730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StartDocW 76705BB0 5 Bytes JMP 002707F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!BeginPath 7670635D 5 Bytes JMP 00270830
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!SelectClipPath 767063B4 5 Bytes JMP 00270AF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!CloseFigure 7670640F 5 Bytes JMP 00270070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!EndPath 76706466 5 Bytes JMP 00270A70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!StrokePath 76706699 5 Bytes JMP 002707B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!FillPath 76706726 5 Bytes JMP 00270870
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!PolylineTo 76706B94 5 Bytes JMP 002704F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!PolyBezierTo 76706C25 5 Bytes JMP 002704B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] GDI32.dll!PolyDraw 76706CD7 5 Bytes JMP 002708B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!ActivateKeyboardLayout 76488203 5 Bytes JMP 002804F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!ScreenToClient 7648A506 7 Bytes JMP 00280670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!RegisterClipboardFormatA 7648C091 5 Bytes JMP 002802F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!RegisterClipboardFormatW 7648DF8D 5 Bytes JMP 002802B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetCursor 76493075 5 Bytes JMP 00280530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!MonitorFromWindow 76493622 7 Bytes JMP 00280630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!PostMessageW 7649447B 5 Bytes JMP 002805F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!IsWindowVisible 76494D69 7 Bytes JMP 002806B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClientRect 764954DD 7 Bytes JMP 002805B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!MapWindowPoints 76495CAA 5 Bytes JMP 00280570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetParent 76496029 7 Bytes JMP 002806F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!EmptyClipboard 764A290C 5 Bytes JMP 00280130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetClipboardData 764A2962 5 Bytes JMP 00280170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardData 764A2BA7 5 Bytes JMP 00280030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardFormatNameW 764A5FD2 5 Bytes JMP 00280230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetClipboardViewer 764A6FF6 5 Bytes JMP 002804B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardFormatNameA 764A700A 5 Bytes JMP 00280270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!ChangeClipboardChain 764B147C 5 Bytes JMP 00280430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetTopWindow 764B24D9 7 Bytes JMP 00280730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!CloseClipboard 764B446C 5 Bytes JMP 002800B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!OpenClipboard 764B447E 5 Bytes JMP 00280070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!IsClipboardFormatAvailable 764B44FF 5 Bytes JMP 002800F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardSequenceNumber 764B4513 5 Bytes JMP 00280330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardOwner 764B4525 5 Bytes JMP 00280370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!CountClipboardFormats 764B470A 5 Bytes JMP 002801F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!EnumClipboardFormats 764B47EC 5 Bytes JMP 002801B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetOpenClipboardWindow 764B480B 5 Bytes JMP 002803F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!SetCursorPos 764CC1B0 5 Bytes JMP 00280770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetClipboardViewer 764E4AF7 5 Bytes JMP 00280470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] USER32.dll!GetPriorityClipboardFormat 764E4BF9 5 Bytes JMP 002803B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ole32.dll!OleSetClipboard 76A20045 5 Bytes JMP 00290030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ole32.dll!OleIsCurrentClipboard 76A236B2 5 Bytes JMP 00290070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[1264] ole32.dll!OleGetClipboard 76A4FDCD 5 Bytes JMP 002900B0
.text C:\Windows\system32\atieclxx.exe[1288] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\webget\bin\utilwebget.exe[1368] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1428] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1512] kernel32.dll!SetUnhandledExceptionFilter 768AF4FB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1512] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1592] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1712] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1740] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1776] kernel32.dll!SetUnhandledExceptionFilter 768AF4FB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1776] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1856] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\PnkBstrA.exe[1912] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Microsoft\BingBar\SeaPort.EXE[1940] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe[2044] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3388] kernel32.dll!SetUnhandledExceptionFilter 768AF4FB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3388] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3460] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\MSI Afterburner\MSIAfterburner.exe[3528] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3880] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[4256] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] ntdll.dll!LdrUnloadDll 778DC86E 5 Bytes JMP 001E03FC
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] ntdll.dll!LdrLoadDll 778E223E 5 Bytes JMP 601F1EB1 C:\Program Files\Mozilla Firefox\mozglue.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!K32GetDeviceDriverBaseNameW + 5D 768A941E 7 Bytes JMP 107784D6 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!QueryPerformanceCounter + 13 768AC435 7 Bytes JMP 107784F9 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!LoadAppInitDlls + 355 768AF4F6 7 Bytes JMP 0FDF3A32 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4584] GDI32.dll!GetViewportOrgEx + 26C 766D884B 7 Bytes JMP 10778457 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\webget\bin\webget.PurBrowse.exe[4640] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\system32\conhost.exe[4648] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\webget\bin\webget.BrowserAdapter.exe[4696] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!RegisterMessagePumpHook + 2F1 76488B9E 7 Bytes JMP 10029931 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!IsDialogMessageW + 340 76494444 7 Bytes JMP 100299A2 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!GetWindowInfo 76494B5E 5 Bytes JMP 1002D777 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4768] USER32.dll!ToUnicodeEx + 71 764A2223 7 Bytes JMP 100270E4 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Windows\system32\DllHost.exe[4812] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5704] KERNEL32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text D:\Pobrane\bddg2gdy.exe[5776] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[5836] kernel32.dll!GetBinaryTypeW + 70 768C69F4 1 Byte [62]
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [746524CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7463562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [746356EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74652546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [746485AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74644D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74645105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [746451DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [74646707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74648301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74648850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [746490B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7464E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
IAT C:\Windows\Explorer.EXE[2980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74644C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll
---- EOF - GMER 2.1 ----
OTL
Spoiler:
OTL logfile created on: 2014-05-17 20:11:41 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Pobrane
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,49 Gb Total Physical Memory | 1,87 Gb Available Physical Memory | 53,44% Memory free
6,98 Gb Paging File | 5,19 Gb Available in Paging File | 74,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 44,56 Gb Free Space | 39,90% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 434,88 Gb Free Space | 93,37% Space Free | Partition Type: NTFS
Computer Name: KOMPODYNA | User Name: Odyn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014-05-17 20:10:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Pobrane\OTL_[www.programosy.pl].exe
PRC - [2014-05-17 20:03:43 | 000,380,416 | ---- | M] () -- D:\Pobrane\bddg2gdy.exe
PRC - [2014-05-17 12:17:16 | 000,317,720 | ---- | M] () -- C:\Program Files\webget\updatewebget.exe
PRC - [2014-05-17 11:44:08 | 000,317,720 | ---- | M] () -- C:\Program Files\webget\bin\utilwebget.exe
PRC - [2014-05-17 03:34:54 | 000,096,536 | ---- | M] () -- C:\Program Files\webget\bin\webget.BrowserAdapter.exe
PRC - [2014-05-16 18:34:48 | 000,239,384 | ---- | M] () -- C:\Program Files\webget\bin\webget.PurBrowse.exe
PRC - [2014-05-16 01:02:42 | 000,109,048 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2014-05-16 01:00:42 | 003,873,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-05-16 01:00:42 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-05-16 00:46:57 | 001,863,856 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
PRC - [2014-05-08 15:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014-05-07 04:26:43 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2014-04-18 03:29:40 | 000,491,520 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2014-04-18 03:29:16 | 000,208,896 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2014-03-27 08:22:58 | 000,465,064 | ---- | M] () -- C:\Program Files\MSI Afterburner\MSIAfterburner.exe
PRC - [2013-08-07 14:24:00 | 000,015,720 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2012-11-30 04:55:25 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011-03-28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010-11-20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010-11-20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2014-05-17 20:03:43 | 000,380,416 | ---- | M] () -- D:\Pobrane\bddg2gdy.exe
MOD - [2014-05-17 03:34:54 | 000,096,536 | ---- | M] () -- C:\Program Files\webget\bin\webget.BrowserAdapter.exe
MOD - [2014-05-16 07:56:27 | 000,250,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\013a0910def084b04290c8d8a1d8a033\WindowsFormsIntegration.ni.dll
MOD - [2014-05-16 07:56:07 | 013,583,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\3d247ccfb800c38a29cf91c27a6339da\System.Web.ni.dll
MOD - [2014-05-16 07:55:02 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\27e8f505ddb7718933b9c029f6f7a3c4\PresentationFramework-SystemXml.ni.dll
MOD - [2014-05-16 01:00:42 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-05-16 00:46:57 | 016,361,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_13_0_0_214.dll
MOD - [2014-05-16 00:45:33 | 007,785,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\668bc5e53fd656dc16c9f40ea15e872e\System.Xml.ni.dll
MOD - [2014-05-16 00:45:29 | 001,873,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f246b71bfd9c1537167b7f6d4f18cd01\System.Xaml.ni.dll
MOD - [2014-05-16 00:45:28 | 012,895,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\ac38cb30c15eb9e4a54459ee01e9f8e6\System.Windows.Forms.ni.dll
MOD - [2014-05-16 00:45:21 | 000,797,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\57d66541f1d5d1c7888058a8d52b0b9c\System.Runtime.Remoting.ni.dll
MOD - [2014-05-16 00:45:21 | 000,218,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\db1c3cbe2929192ad0361f64a25481d5\System.ServiceProcess.ni.dll
MOD - [2014-05-16 00:45:20 | 001,639,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\ce11900fa489575613dc777c7fbb0d7d\System.Drawing.ni.dll
MOD - [2014-05-16 00:45:15 | 000,967,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7ece7799d670cdfc1393b98b0668a046\System.Configuration.ni.dll
MOD - [2014-05-16 00:45:15 | 000,458,240 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\422aaa813823622198be87739142c44e\PresentationFramework.Aero.ni.dll
MOD - [2014-05-16 00:45:14 | 018,753,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\613fd0f86fc699adfe3184b2e746aa18\PresentationFramework.ni.dll
MOD - [2014-05-16 00:45:05 | 011,014,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\eed4ad7c1049e7cf47606479d68ec1de\PresentationCore.ni.dll
MOD - [2014-05-16 00:44:59 | 003,904,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a40acfa4a0c4bb0dbf824ace588583ba\WindowsBase.ni.dll
MOD - [2014-05-16 00:44:56 | 006,982,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\e0fea191b75897ec38735bfc31b89fe0\System.Core.ni.dll
MOD - [2014-05-16 00:44:52 | 010,067,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\b75ba99f72f116d8951b0f2bba8c276a\System.ni.dll
MOD - [2014-05-16 00:44:47 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll
MOD - [2014-05-07 04:27:09 | 003,839,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014-03-27 08:22:58 | 000,465,064 | ---- | M] () -- C:\Program Files\MSI Afterburner\MSIAfterburner.exe
MOD - [2014-03-20 14:13:24 | 000,631,296 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTHAL.dll
MOD - [2014-03-20 14:13:02 | 000,216,064 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTCore.dll
MOD - [2014-03-20 14:12:52 | 000,127,488 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTUI.dll
MOD - [2014-03-20 14:12:46 | 000,071,680 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTMUI.dll
MOD - [2014-03-20 14:12:40 | 000,056,832 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTFC.dll
========== Services (SafeList) ==========
SRV - [2014-05-17 12:17:16 | 000,317,720 | ---- | M] () [Auto | Running] -- C:\Program Files\webget\updatewebget.exe -- (Update webget)
SRV - [2014-05-17 11:44:08 | 000,317,720 | ---- | M] () [Auto | Running] -- C:\Program Files\webget\bin\utilwebget.exe -- (Util webget)
SRV - [2014-05-16 07:44:51 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2014-05-16 01:02:42 | 000,109,048 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2014-05-16 01:00:42 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014-05-16 00:46:57 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-05-08 15:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-05-07 04:27:01 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-04-18 03:29:16 | 000,208,896 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2014-02-08 05:18:42 | 000,569,024 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013-08-07 14:24:00 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011-04-01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011-03-28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Odyn\AppData\Local\Temp\uwtcqpoc.sys -- (uwtcqpoc)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2014-05-16 01:46:45 | 000,017,088 | ---- | M] (Glarysoft Ltd) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\GUBootStartup.sys -- (GUBootStartup)
DRV - [2014-05-16 01:02:59 | 000,270,240 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdisFlt.sys -- (aswNdisFlt)
DRV - [2014-05-16 01:02:43 | 000,026,136 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2014-05-16 01:00:59 | 000,777,488 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsnx.sys -- (aswSnx)
DRV - [2014-05-16 01:00:59 | 000,411,680 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsp.sys -- (aswSP)
DRV - [2014-05-16 01:00:59 | 000,068,312 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswstm.sys -- (aswStm)
DRV - [2014-05-16 01:00:43 | 000,180,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014-05-16 01:00:43 | 000,081,768 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014-05-16 01:00:43 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014-05-16 01:00:43 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014-05-16 01:00:43 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2014-05-14 09:02:44 | 000,016,064 | ---- | M] (Glarysoft Ltd) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\BootDefragDriver.sys -- (BootDefragDriver)
DRV - [2014-05-12 16:40:58 | 000,052,920 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys -- ({9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw)
DRV - [2014-04-18 04:35:20 | 013,515,264 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2014-04-18 03:06:30 | 000,512,000 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2013-12-19 18:44:40 | 000,077,824 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2013-08-02 03:38:30 | 000,505,192 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\iaStorA.sys -- (iaStorA)
DRV - [2013-08-02 03:38:26 | 000,025,448 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\iaStorF.sys -- (iaStorF)
DRV - [2013-03-11 03:30:10 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\MSI Afterburner\RTCore32.sys -- (RTCore32)
DRV - [2012-12-29 22:59:38 | 000,024,184 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\Windows\System32\speedfan.sys -- (speedfan)
DRV - [2012-09-01 01:00:02 | 000,027,792 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan620.sys -- (RTVLANPT)
DRV - [2012-07-03 14:32:00 | 000,049,808 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam620.sys -- (RTTEAMPT)
DRV - [2011-12-02 12:38:08 | 000,199,528 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2011-06-15 15:11:20 | 000,033,056 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2011-05-13 03:21:06 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011-05-13 03:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011-05-13 03:21:06 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2011-05-13 03:21:06 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011-05-13 03:21:04 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010-11-20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010-11-20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010-11-20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010-11-20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010-11-20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010-11-20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010-10-19 23:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2010-04-27 16:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2010-04-27 16:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2010-04-27 16:57:24 | 000,031,816 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2010-04-27 16:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2010-04-27 14:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002-01-12 17:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PortTalk.sys -- (PortTalk)
DRV - [2000-01-01 02:00:00 | 000,027,888 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV - [1996-04-03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-281493417-172796843-820964179-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-281493417-172796843-820964179-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-281493417-172796843-820964179-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.pah.org.pl/nasze-dzialania/8/pajacyk"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2018.95
FF - prefs.js..extensions.enabledAddons: %7B9edd0ea8-2819-47c2-8320-b007d5996f8a%7D:1.0.1
FF - prefs.js..extensions.enabledAddons: %7B7b1bf0b6-a1b9-42b0-b75d-252036438bdc%7D:8.4
FF - prefs.js..extensions.enabledAddons: thumbnailZoom%40dadler.github.com:2.7
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.3.2: C:\Program Files\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-16 01:02:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2014-05-15 23:52:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\Extensions
[2014-05-16 14:02:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\Firefox\Profiles\8okhcgbf.default\extensions
[2014-05-16 14:02:05 | 000,168,246 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\thumbnailZoom@dadler.github.com.xpi
[2014-05-16 14:02:05 | 000,059,976 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi
[2014-05-16 13:55:01 | 000,008,893 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\{9edd0ea8-2819-47c2-8320-b007d5996f8a}.xpi
[2014-05-16 13:04:05 | 000,957,880 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-05-15 23:52:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014-05-15 23:52:21 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-05-16 01:02:43 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Error reading preferences file
CHR - Extension: Dokumenty Google = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\
CHR - Extension: Dysk Google = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.1_0\
CHR - Extension: Szukaj w Google = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Photo Zoom for Facebook = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi\1.1312.1.2_0\
CHR - Extension: AdBlock = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.34_0\
CHR - Extension: avast! Online Security = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2018.95_0\
CHR - Extension: Illimitux = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\mamnihopcnbfnbfnnneplcohmnkkpipb\1.0_0\
CHR - Extension: Google Wallet = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009-06-10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (webget) - {dc264a72-fa75-4948-b881-ea8eff8e5dd2} - C:\Program Files\webget\webgetBHO.dll (webget)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-281493417-172796843-820964179-1000..\Run: [GUDelayStartup] C:\Program Files\Glary Utilities 5\StartupManager.exe (Glarysoft Ltd)
O4 - HKU\S-1-5-21-281493417-172796843-820964179-1000..\Run: [MSI Afterburner] C:\Program Files\MSI Afterburner\MSIAfterburner.exe ()
O4 - HKU\S-1-5-21-281493417-172796843-820964179-1000..\Run: [OscarX7Mouse5Mode] C:\Program Files\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-281493417-172796843-820964179-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.60 62.179.1.61
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{43F0E5C3-73B8-42AE-886B-7647F548E943}: DhcpNameServer = 62.179.1.60 62.179.1.61
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (BootDefrag.exe)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014-05-17 19:40:49 | 000,000,000 | ---D | C] -- C:\Program Files\Process Explorer
[2014-05-17 19:38:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
[2014-05-17 19:38:06 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune
[2014-05-17 13:13:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview
[2014-05-17 13:12:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2014-05-17 13:11:16 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2014-05-17 13:09:07 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014-05-17 12:31:10 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2014-05-17 12:31:01 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2014-05-17 12:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2014-05-17 12:29:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014-05-17 12:29:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2014-05-17 12:07:57 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Windows Live
[2014-05-17 12:07:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2014-05-17 12:05:51 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\LSCSHostPolicy.dll
[2014-05-17 12:05:51 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys
[2014-05-17 12:05:51 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2014-05-17 12:05:49 | 001,171,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2014-05-17 12:05:48 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll
[2014-05-17 12:05:48 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll
[2014-05-17 12:05:48 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tssrvlic.dll
[2014-05-17 12:05:47 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2014-05-17 12:05:47 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2014-05-17 12:05:47 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2014-05-17 12:05:46 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2014-05-17 12:05:46 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizui.dll
[2014-05-17 12:05:45 | 003,207,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2014-05-17 12:05:45 | 001,334,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2014-05-17 12:05:45 | 000,520,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcupdate_GenuineIntel.dll
[2014-05-17 12:05:44 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2014-05-17 12:05:44 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2014-05-17 12:05:43 | 005,066,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuthFWSnapin.dll
[2014-05-17 12:05:43 | 001,115,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RacEngn.dll
[2014-05-17 12:05:42 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2014-05-17 12:05:41 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2014-05-17 12:05:41 | 001,828,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d9.dll
[2014-05-17 12:05:41 | 000,505,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2014-05-17 12:05:41 | 000,456,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spinstall.exe
[2014-05-17 12:05:41 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wer.dll
[2014-05-17 12:05:41 | 000,280,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spreview.exe
[2014-05-17 12:05:41 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PushPrinterConnections.exe
[2014-05-17 12:05:40 | 003,367,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSAT.exe
[2014-05-17 12:05:40 | 001,371,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dwmcore.dll
[2014-05-17 12:05:40 | 000,863,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diagperf.dll
[2014-05-17 12:05:40 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWorkspace.dll
[2014-05-17 12:05:40 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsmf.dll
[2014-05-17 12:05:40 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scavengeui.dll
[2014-05-17 12:05:39 | 002,522,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dbgeng.dll
[2014-05-17 12:05:39 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2014-05-17 12:05:39 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpprefcl.dll
[2014-05-17 12:05:39 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2014-05-17 12:05:39 | 000,260,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpshell.exe
[2014-05-17 12:05:38 | 002,151,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcndmgr.dll
[2014-05-17 12:05:38 | 001,792,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2014-05-17 12:05:38 | 001,712,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2014-05-17 12:05:38 | 001,555,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certmgr.dll
[2014-05-17 12:05:38 | 000,974,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppobjs.dll
[2014-05-17 12:05:38 | 000,732,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2fs.dll
[2014-05-17 12:05:38 | 000,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2014-05-17 12:05:38 | 000,508,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2014-05-17 12:05:38 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2014-05-17 12:05:38 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drvstore.dll
[2014-05-17 12:05:38 | 000,252,928 | ---- | C] (Microsoft) -- C:\Windows\System32\DShowRdpFilter.dll
[2014-05-17 12:05:38 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcbuilder.exe
[2014-05-17 12:05:38 | 000,049,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2014-05-17 12:05:37 | 000,442,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2014-05-17 12:05:37 | 000,412,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppwinob.dll
[2014-05-17 12:05:37 | 000,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
[2014-05-17 12:05:37 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
[2014-05-17 12:05:37 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfds.dll
[2014-05-17 12:05:37 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\framedynos.dll
[2014-05-17 12:05:37 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp.dll
[2014-05-17 12:05:36 | 001,063,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\werconcpl.dll
[2014-05-17 12:05:36 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NaturalLanguage6.dll
[2014-05-17 12:05:36 | 000,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\calc.exe
[2014-05-17 12:05:36 | 000,762,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroles.dll
[2014-05-17 12:05:36 | 000,508,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2014-05-17 12:05:36 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\evr.dll
[2014-05-17 12:05:36 | 000,339,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appmgr.dll
[2014-05-17 12:05:36 | 000,335,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSATAPI.dll
[2014-05-17 12:05:36 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2014-05-17 12:05:36 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2014-05-17 12:05:36 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpclip.exe
[2014-05-17 12:05:36 | 000,161,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpinit.exe
[2014-05-17 12:05:36 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2014-05-17 12:05:36 | 000,144,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basecsp.dll
[2014-05-17 12:05:35 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2014-05-17 12:05:35 | 000,778,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlsrv32.dll
[2014-05-17 12:05:35 | 000,477,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lpksetup.exe
[2014-05-17 12:05:35 | 000,271,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fveapi.dll
[2014-05-17 12:05:35 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vpnike.dll
[2014-05-17 12:05:35 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hgprint.dll
[2014-05-17 12:05:35 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tspubwmi.dll
[2014-05-17 12:05:35 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prncache.dll
[2014-05-17 12:05:34 | 002,504,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVCORE.DLL
[2014-05-17 12:05:34 | 001,750,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnidui.dll
[2014-05-17 12:05:34 | 000,690,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ci.dll
[2014-05-17 12:05:34 | 000,464,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrptadm.dll
[2014-05-17 12:05:34 | 000,458,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSDApi.dll
[2014-05-17 12:05:34 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlangpui.dll
[2014-05-17 12:05:34 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpeffects.dll
[2014-05-17 12:05:34 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aepdu.dll
[2014-05-17 12:05:34 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scansetting.dll
[2014-05-17 12:05:34 | 000,213,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MMDevAPI.dll
[2014-05-17 12:05:34 | 000,175,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\vmbus.sys
[2014-05-17 12:05:34 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QSHVHOST.DLL
[2014-05-17 12:05:34 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\net1.exe
[2014-05-17 12:05:34 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpchttp.dll
[2014-05-17 12:05:34 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aitagent.exe
[2014-05-17 12:05:34 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2014-05-17 12:05:34 | 000,101,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2014-05-17 12:05:33 | 002,146,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SyncCenter.dll
[2014-05-17 12:05:33 | 000,907,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdengin2.dll
[2014-05-17 12:05:33 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2ENC.DLL
[2014-05-17 12:05:33 | 000,782,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webservices.dll
[2014-05-17 12:05:33 | 000,727,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcmde.dll
[2014-05-17 12:05:33 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2.dll
[2014-05-17 12:05:33 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netdiagfx.dll
[2014-05-17 12:05:33 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmicsvc.exe
[2014-05-17 12:05:33 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tscfgwmi.dll
[2014-05-17 12:05:33 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscobj.dll
[2014-05-17 12:05:33 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fde.dll
[2014-05-17 12:05:33 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupcl.exe
[2014-05-17 12:05:33 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll
[2014-05-17 12:05:33 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll
[2014-05-17 12:05:32 | 002,217,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bootres.dll
[2014-05-17 12:05:32 | 001,624,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPEncEn.dll
[2014-05-17 12:05:32 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Narrator.exe
[2014-05-17 12:05:32 | 000,679,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoconv.exe
[2014-05-17 12:05:32 | 000,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autofmt.exe
[2014-05-17 12:05:32 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DXPTaskRingtone.dll
[2014-05-17 12:05:32 | 000,303,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msinfo32.exe
[2014-05-17 12:05:32 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
[2014-05-17 12:05:32 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vaultsvc.dll
[2014-05-17 12:05:32 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
[2014-05-17 12:05:32 | 000,194,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\halmacpi.dll
[2014-05-17 12:05:32 | 000,194,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hal.dll
[2014-05-17 12:05:32 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiohlp.dll
[2014-05-17 12:05:32 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
[2014-05-17 12:05:32 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dwmredir.dll
[2014-05-17 12:05:32 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hbaapi.dll
[2014-05-17 12:05:32 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
[2014-05-17 12:05:32 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\proquota.exe
[2014-05-17 12:05:31 | 001,326,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanpref.dll
[2014-05-17 12:05:31 | 001,227,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdc.dll
[2014-05-17 12:05:31 | 001,131,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
[2014-05-17 12:05:31 | 000,933,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Vault.dll
[2014-05-17 12:05:31 | 000,665,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2014-05-17 12:05:31 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercpl.dll
[2014-05-17 12:05:31 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipsmsnap.dll
[2014-05-17 12:05:31 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DXP.dll
[2014-05-17 12:05:31 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\untfs.dll
[2014-05-17 12:05:31 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
[2014-05-17 12:05:31 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
[2014-05-17 12:05:31 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapphost.dll
[2014-05-17 12:05:31 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\framedyn.dll
[2014-05-17 12:05:31 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tcpipcfg.dll
[2014-05-17 12:05:31 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe
[2014-05-17 12:05:31 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QAGENT.DLL
[2014-05-17 12:05:31 | 000,155,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2014-05-17 12:05:31 | 000,132,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ataport.sys
[2014-05-17 12:05:31 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netid.dll
[2014-05-17 12:05:31 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nci.dll
[2014-05-17 12:05:30 | 001,400,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DxpTaskSync.dll
[2014-05-17 12:05:30 | 001,188,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DiagCpl.dll
[2014-05-17 12:05:30 | 001,066,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtctm.dll
[2014-05-17 12:05:30 | 001,040,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Display.dll
[2014-05-17 12:05:30 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMNetMgr.dll
[2014-05-17 12:05:30 | 000,856,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FirewallControlPanel.dll
[2014-05-17 12:05:30 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\biocpl.dll
[2014-05-17 12:05:30 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2014-05-17 12:05:30 | 000,416,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiadefui.dll
[2014-05-17 12:05:30 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\termmgr.dll
[2014-05-17 12:05:30 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\puiobj.dll
[2014-05-17 12:05:30 | 000,316,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sharemediacpl.dll
[2014-05-17 12:05:30 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eudcedit.exe
[2014-05-17 12:05:30 | 000,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msconfig.exe
[2014-05-17 12:05:30 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppcomapi.dll
[2014-05-17 12:05:30 | 000,140,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\scsiport.sys
[2014-05-17 12:05:30 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2014-05-17 12:05:30 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logoncli.dll
[2014-05-17 12:05:30 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shsetup.dll
[2014-05-17 12:05:30 | 000,098,816 | ---- | C] (Microsoft) -- C:\Windows\System32\Robocopy.exe
[2014-05-17 12:05:30 | 000,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\winhv.sys
[2014-05-17 12:05:30 | 000,040,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\vmstorfl.sys
[2014-05-17 12:05:30 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\userinit.exe
[2014-05-17 12:05:29 | 002,202,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SensorsCpl.dll
[2014-05-17 12:05:29 | 002,157,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\themecpl.dll
[2014-05-17 12:05:29 | 001,644,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcenter.dll
[2014-05-17 12:05:29 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mblctr.exe
[2014-05-17 12:05:29 | 000,766,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpccpl.dll
[2014-05-17 12:05:29 | 000,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VAN.dll
[2014-05-17 12:05:29 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PerfCenterCPL.dll
[2014-05-17 12:05:29 | 000,600,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usercpl.dll
[2014-05-17 12:05:29 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2014-05-17 12:05:29 | 000,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscms.dll
[2014-05-17 12:05:29 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\localsec.dll
[2014-05-17 12:05:29 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoScreensaver.scr
[2014-05-17 12:05:29 | 000,410,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanui.dll
[2014-05-17 12:05:29 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SndVol.exe
[2014-05-17 12:05:29 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hgcpl.dll
[2014-05-17 12:05:29 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mprddm.dll
[2014-05-17 12:05:29 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SndVolSSO.dll
[2014-05-17 12:05:29 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FWPUCLNT.DLL
[2014-05-17 12:05:29 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcdsrv.dll
[2014-05-17 12:05:29 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prntvpt.dll
[2014-05-17 12:05:29 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscmmc.dll
[2014-05-17 12:05:29 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2014-05-17 12:05:29 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasacct.dll
[2014-05-17 12:05:29 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\w32tm.exe
[2014-05-17 12:05:29 | 000,028,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storvsc.sys
[2014-05-17 12:05:28 | 003,727,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\accessibilitycpl.dll
[2014-05-17 12:05:28 | 002,130,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkmap.dll
[2014-05-17 12:05:28 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sud.dll
[2014-05-17 12:05:28 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionCenter.dll
[2014-05-17 12:05:28 | 000,516,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\main.cpl
[2014-05-17 12:05:28 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspbda.dll
[2014-05-17 12:05:28 | 000,395,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prnfldr.dll
[2014-05-17 12:05:28 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysmon.ocx
[2014-05-17 12:05:28 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizeng.dll
[2014-05-17 12:05:28 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slui.exe
[2014-05-17 12:05:28 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
[2014-05-17 12:05:28 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wusa.exe
[2014-05-17 12:05:28 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroleui.dll
[2014-05-17 12:05:28 | 000,312,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MCEWMDRMNDBootstrap.dll
[2014-05-17 12:05:28 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iprtrmgr.dll
[2014-05-17 12:05:28 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MediaMetadataHandler.dll
[2014-05-17 12:05:28 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskbarcpl.dll
[2014-05-17 12:05:28 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSAC3ENC.DLL
[2014-05-17 12:05:28 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe
[2014-05-17 12:05:28 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\defaultlocationcpl.dll
[2014-05-17 12:05:28 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OnLineIDCpl.dll
[2014-05-17 12:05:28 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys
[2014-05-17 12:05:28 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsldp.dll
[2014-05-17 12:05:28 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrad.dll
[2014-05-17 12:05:28 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netjoin.dll
[2014-05-17 12:05:28 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdeploy.dll
[2014-05-17 12:05:28 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidclass.sys
[2014-05-17 12:05:28 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
[2014-05-17 12:05:27 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OobeFldr.dll
[2014-05-17 12:05:27 | 000,750,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdcpl.dll
[2014-05-17 12:05:27 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\blackbox.dll
[2014-05-17 12:05:27 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
[2014-05-17 12:05:27 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bthprops.cpl
[2014-05-17 12:05:27 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshwfp.dll
[2014-05-17 12:05:27 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TabletPC.cpl
[2014-05-17 12:05:27 | 000,577,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
[2014-05-17 12:05:27 | 000,537,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionCenterCPL.dll
[2014-05-17 12:05:27 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DeviceCenter.dll
[2014-05-17 12:05:27 | 000,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shwebsvc.dll
[2014-05-17 12:05:27 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\systemcpl.dll
[2014-05-17 12:05:27 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\intl.cpl
[2014-05-17 12:05:27 | 000,297,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntprint.dll
[2014-05-17 12:05:27 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcdedit.exe
[2014-05-17 12:05:27 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sethc.exe
[2014-05-17 12:05:27 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpx.dll
[2014-05-17 12:05:27 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\recdisc.exe
[2014-05-17 12:05:27 | 000,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\efscore.dll
[2014-05-17 12:05:27 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ksproxy.ax
[2014-05-17 12:05:27 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpsrcwp.dll
[2014-05-17 12:05:27 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fvecpl.dll
[2014-05-17 12:05:27 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmartcardCredentialProvider.dll
[2014-05-17 12:05:27 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsutil.dll
[2014-05-17 12:05:27 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ifsutil.dll
[2014-05-17 12:05:27 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcdboot.exe
[2014-05-17 12:05:27 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoplay.dll
[2014-05-17 12:05:27 | 000,137,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\halacpi.dll
[2014-05-17 12:05:27 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\recovery.dll
[2014-05-17 12:05:27 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppnp.dll
[2014-05-17 12:05:27 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPHLPR.DLL
[2014-05-17 12:05:27 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\migisol.dll
[2014-05-17 12:05:27 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\fms.dll
[2014-05-17 12:05:27 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3cfg.dll
[2014-05-17 12:05:27 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSTPager.ax
[2014-05-17 12:05:27 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpsign.exe
[2014-05-17 12:05:27 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ftp.exe
[2014-05-17 12:05:27 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sisbkup.dll
[2014-05-17 12:05:26 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmiEngine.dll
[2014-05-17 12:05:26 | 000,592,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
[2014-05-17 12:05:26 | 000,586,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfrgui.exe
[2014-05-17 12:05:26 | 000,444,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wvc.dll
[2014-05-17 12:05:26 | 000,438,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AdmTmpl.dll
[2014-05-17 12:05:26 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanmsm.dll
[2014-05-17 12:05:26 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wimgapi.dll
[2014-05-17 12:05:26 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshipsec.dll
[2014-05-17 12:05:26 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3ui.dll
[2014-05-17 12:05:26 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ssText3d.scr
[2014-05-17 12:05:26 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srrstr.dll
[2014-05-17 12:05:26 | 000,254,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsqmcons.exe
[2014-05-17 12:05:26 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ReAgent.dll
[2014-05-17 12:05:26 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wavemsp.dll
[2014-05-17 12:05:26 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PkgMgr.exe
[2014-05-17 12:05:26 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qasf.dll
[2014-05-17 12:05:26 | 000,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysclass.dll
[2014-05-17 12:05:26 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ocsetup.exe
[2014-05-17 12:05:26 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qcap.dll
[2014-05-17 12:05:26 | 000,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationSettings.exe
[2014-05-17 12:05:26 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\uxlib.dll
[2014-05-17 12:05:26 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupugc.exe
[2014-05-17 12:05:26 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayServices.dll
[2014-05-17 12:05:26 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\isoburn.exe
[2014-05-17 12:05:26 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
[2014-05-17 12:05:26 | 000,051,200 | ---- | C] (Twain Working Group) -- C:\Windows\twain_32.dll
[2014-05-17 12:05:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzutil.exe
[2014-05-17 12:05:26 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll
[2014-05-17 12:05:25 | 001,111,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\onexui.dll
[2014-05-17 12:05:25 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmsdk.dll
[2014-05-17 12:05:25 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
[2014-05-17 12:05:25 | 000,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmmgrtn.dll
[2014-05-17 12:05:25 | 000,327,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wimserv.exe
[2014-05-17 12:05:25 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nltest.exe
[2014-05-17 12:05:25 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsAnytimeUpgradeResults.exe
[2014-05-17 12:05:25 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskraid.exe
[2014-05-17 12:05:25 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iTVData.dll
[2014-05-17 12:05:25 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DevicePairingFolder.dll
[2014-05-17 12:05:25 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2014-05-17 12:05:25 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\input.dll
[2014-05-17 12:05:25 | 000,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpdwcn.dll
[2014-05-17 12:05:25 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanconn.dll
[2014-05-17 12:05:25 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
[2014-05-17 12:05:25 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ocsetapi.dll
[2014-05-17 12:05:25 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsbas.dll
[2014-05-17 12:05:25 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfmon.exe
[2014-05-17 12:05:25 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nslookup.exe
[2014-05-17 12:05:25 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logagent.exe
[2014-05-17 12:05:25 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2014-05-17 12:05:25 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UserAccountControlSettings.dll
[2014-05-17 12:05:25 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\bfsvc.exe
[2014-05-17 12:05:25 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\runonce.exe
[2014-05-17 12:05:25 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPCRYPT.DLL
[2014-05-17 12:05:25 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\acppage.dll
[2014-05-17 12:05:25 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vpnikeapi.dll
[2014-05-17 12:05:24 | 001,160,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2014-05-17 12:05:24 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMADMOD.DLL
[2014-05-17 12:05:24 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Bubbles.scr
[2014-05-17 12:05:24 | 000,541,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVSDECD.DLL
[2014-05-17 12:05:24 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmdev.dll
[2014-05-17 12:05:24 | 000,436,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmnet.dll
[2014-05-17 12:05:24 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceStatus.dll
[2014-05-17 12:05:24 | 000,350,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2014-05-17 12:05:24 | 000,318,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2014-05-17 12:05:24 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlcese30.dll
[2014-05-17 12:05:24 | 000,283,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdv.dll
[2014-05-17 12:05:24 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
[2014-05-17 12:05:24 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapp3hst.dll
[2014-05-17 12:05:24 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mystify.scr
[2014-05-17 12:05:24 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Ribbons.scr
[2014-05-17 12:05:24 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bitsadmin.exe
[2014-05-17 12:05:24 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceSyncProvider.dll
[2014-05-17 12:05:24 | 000,179,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionQueue.dll
[2014-05-17 12:05:24 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFPlay.dll
[2014-05-17 12:05:24 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VBICodec.ax
[2014-05-17 12:05:24 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercfg.cpl
[2014-05-17 12:05:24 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MdSched.exe
[2014-05-17 12:05:24 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EhStorAPI.dll
[2014-05-17 12:05:24 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rmcast.sys
[2014-05-17 12:05:24 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3msm.dll
[2014-05-17 12:05:24 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiavideo.dll
[2014-05-17 12:05:24 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CscMig.dll
[2014-05-17 12:05:24 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shacct.dll
[2014-05-17 12:05:24 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Kswdmcap.ax
[2014-05-17 12:05:24 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QSVRMGMT.DLL
[2014-05-17 12:05:24 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fphc.dll
[2014-05-17 12:05:24 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kstvtune.ax
[2014-05-17 12:05:24 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logman.exe
[2014-05-17 12:05:24 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\olethk32.dll
[2014-05-17 12:05:24 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mapistub.dll
[2014-05-17 12:05:24 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mapi32.dll
[2014-05-17 12:05:24 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tabcal.exe
[2014-05-17 12:05:24 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lpremove.exe
[2014-05-17 12:05:24 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PnPUnattend.exe
[2014-05-17 12:05:24 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncryptui.dll
[2014-05-17 12:05:24 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\djoin.exe
[2014-05-17 12:05:24 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unimdmat.dll
[2014-05-17 12:05:24 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpd3d.dll
[2014-05-17 12:05:24 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\takeown.exe
[2014-05-17 12:05:24 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanprotdim.dll
[2014-05-17 12:05:24 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\utildll.dll
[2014-05-17 12:05:24 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsium.dll
[2014-05-17 12:05:24 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsmproxy.dll
[2014-05-17 12:05:24 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2014-05-17 12:05:23 | 001,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IMJP10.IME
[2014-05-17 12:05:23 | 000,739,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2014-05-17 12:05:23 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSTIFF.dll
[2014-05-17 12:05:23 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2014-05-17 12:05:23 | 000,278,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2014-05-17 12:05:23 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unattend.dll
[2014-05-17 12:05:23 | 000,182,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RelPost.exe
[2014-05-17 12:05:23 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msorcl32.dll
[2014-05-17 12:05:23 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\itircl.dll
[2014-05-17 12:05:23 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsicli.exe
[2014-05-17 12:05:23 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpps.dll
[2014-05-17 12:05:23 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskpart.exe
[2014-05-17 12:05:23 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\desk.cpl
[2014-05-17 12:05:23 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BdeHdCfg.exe
[2014-05-17 12:05:23 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrecst.dll
[2014-05-17 12:05:23 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupcln.dll
[2014-05-17 12:05:23 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppinst.dll
[2014-05-17 12:05:23 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eappgnui.dll
[2014-05-17 12:05:23 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2014-05-17 12:05:23 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2014-05-17 12:05:23 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmstp.exe
[2014-05-17 12:05:23 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QCLIPROV.DLL
[2014-05-17 12:05:23 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MuiUnattend.exe
[2014-05-17 12:05:23 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amstream.dll
[2014-05-17 12:05:23 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tlscsp.dll
[2014-05-17 12:05:23 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cca.dll
[2014-05-17 12:05:23 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertPolEng.dll
[2014-05-17 12:05:23 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\findstr.exe
[2014-05-17 12:05:23 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spbcd.dll
[2014-05-17 12:05:23 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vfwwdm32.dll
[2014-05-17 12:05:23 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MultiDigiMon.exe
[2014-05-17 12:05:23 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsnmp32.dll
[2014-05-17 12:05:23 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\umb.dll
[2014-05-17 12:05:23 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setbcdlocale.dll
[2014-05-17 12:05:23 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ksxbar.ax
[2014-05-17 12:05:23 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wkscli.dll
[2014-05-17 12:05:23 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WavDest.dll
[2014-05-17 12:05:23 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pdhui.dll
[2014-05-17 12:05:23 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basesrv.dll
[2014-05-17 12:05:23 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\relog.exe
[2014-05-17 12:05:23 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciqtz32.dll
[2014-05-17 12:05:23 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiarpc.dll
[2014-05-17 12:05:23 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PrintIsolationProxy.dll
[2014-05-17 12:05:23 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WerFaultSecure.exe
[2014-05-17 12:05:23 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AzSqlExt.dll
[2014-05-17 12:05:23 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qwinsta.exe
[2014-05-17 12:05:23 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiougc.exe
[2014-05-17 12:05:23 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qprocess.exe
[2014-05-17 12:05:23 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msg.exe
[2014-05-17 12:05:23 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netbtugc.exe
[2014-05-17 12:05:23 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quser.exe
[2014-05-17 12:05:23 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tskill.exe
[2014-05-17 12:05:23 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chgport.exe
[2014-05-17 12:05:23 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsdiscon.exe
[2014-05-17 12:05:23 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ReAgentc.exe
[2014-05-17 12:05:23 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chglogon.exe
[2014-05-17 12:05:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tscon.exe
[2014-05-17 12:05:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qappsrv.exe
[2014-05-17 12:05:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logoff.exe
[2014-05-17 12:05:23 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shadow.exe
[2014-05-17 12:05:23 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rwinsta.exe
[2014-05-17 12:05:23 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chgusr.exe
[2014-05-17 12:05:23 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\syssetup.dll
[2014-05-17 12:05:23 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nrpsrv.dll
[2014-05-17 12:05:22 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2014-05-17 12:05:22 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RDPENCDD.dll
[2014-05-17 12:05:22 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppc.dll
[2014-05-17 12:05:22 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2014-05-17 12:05:22 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\napdsnap.dll
[2014-05-17 12:05:22 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\manage-bde.exe
[2014-05-17 12:05:22 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\repair-bde.exe
[2014-05-17 12:05:22 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmicres.dll
[2014-05-17 12:05:22 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetmib1.dll
[2014-05-17 12:05:22 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\g711codc.ax
[2014-05-17 12:05:22 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmbusres.dll
[2014-05-17 12:05:22 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\luainstall.dll
[2014-05-17 12:05:22 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcconf.dll
[2014-05-17 12:05:22 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSMON.dll
[2014-05-17 12:05:22 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmstorfltres.dll
[2014-05-17 12:05:22 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unlodctr.exe
[2014-05-17 12:05:22 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbisurf.ax
[2014-05-17 12:05:22 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdiasqmmodule.dll
[2014-05-17 12:05:22 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdmo.dll
[2014-05-17 12:05:22 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsauth.dll
[2014-05-17 12:05:22 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbrpm.sys
[2014-05-17 12:05:22 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcfg.exe
[2014-05-17 12:05:22 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\HotStartUserAgent.dll
[2014-05-17 12:05:22 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elsTrans.dll
[2014-05-17 12:05:22 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TRAPI.dll
[2014-05-17 12:05:22 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\tdi.sys
[2014-05-17 12:05:22 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdprefdrvapi.dll
[2014-05-17 12:05:22 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spopk.dll
[2014-05-17 12:05:22 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bitsperf.dll
[2014-05-17 12:05:22 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schedcli.dll
[2014-05-17 12:05:22 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfts.dll
[2014-05-17 12:05:22 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\reset.exe
[2014-05-17 12:05:22 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\change.exe
[2014-05-17 12:05:22 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\query.exe
[2014-05-17 12:05:22 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\muifontsetup.dll
[2014-05-17 12:05:21 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imkr80.ime
[2014-05-17 12:05:21 | 000,116,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VmbusCoinstaller.dll
[2014-05-17 12:05:21 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VmdCoinstall.dll
[2014-05-17 12:05:21 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IcCoinstall.dll
[2014-05-17 12:05:21 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmictimeprovider.dll
[2014-05-17 12:05:21 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBCAMD2.sys
[2014-05-17 12:05:21 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBCAMD.sys
[2014-05-17 12:05:21 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsdchngr.dll
[2014-05-17 12:05:21 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\VMBusHID.sys
[2014-05-17 12:05:21 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmbuspipe.dll
[2014-05-17 12:05:21 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshirda.dll
[2014-05-17 12:05:21 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sscore.dll
[2014-05-17 12:05:21 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\riched32.dll
[2014-05-17 12:05:21 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcfgex.dll
[2014-05-17 12:05:21 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
[2014-05-17 12:05:20 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2014-05-17 12:05:20 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlsbres.dll
[2014-05-17 12:05:20 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BlbEvents.dll
[2014-05-17 12:05:20 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pifmgr.dll
[2014-05-17 12:05:20 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RDPREFDD.dll
[2014-05-17 12:05:20 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\C_ISCII.DLL
[2014-05-17 12:05:20 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shunimpl.dll
[2014-05-17 12:05:20 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizres.dll
[2014-05-17 12:05:20 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDSG.DLL
[2014-05-17 12:05:20 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kbdlk41a.dll
[2014-05-17 12:05:20 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDCZ1.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTUQ.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTUF.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDSF.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDPO.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDNEPR.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINBEN.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDGR1.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDGKL.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDUS.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDUGHR1.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTURME.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTAJIK.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDMON.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDMAORI.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDLT1.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINTEL.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINTAM.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINORI.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINMAR.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINKAN.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINHIN.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDBULG.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDBLR.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDBASH.DLL
[2014-05-17 12:05:20 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\vms3cap.sys
[2014-05-17 12:05:20 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDGEO.DLL
[2014-05-17 12:05:20 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2014-05-17 12:05:20 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
[2014-05-17 12:05:17 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdscore.dll
[2014-05-17 12:05:13 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wbemcomn.dll
[2014-05-17 12:05:10 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqmapi.dll
[2014-05-17 11:59:47 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2014-05-17 11:52:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2014-05-17 11:52:19 | 000,031,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msonpmon.dll
[2014-05-17 11:51:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2014-05-17 11:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2014-05-17 11:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2014-05-17 11:51:17 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2014-05-17 11:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2014-05-17 11:49:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Microsoft Help
[2014-05-17 11:49:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2014-05-17 11:49:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2014-05-17 11:49:11 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2014-05-16 20:04:38 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2014-05-16 20:04:38 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2014-05-16 20:04:36 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2014-05-16 20:04:35 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2014-05-16 20:04:09 | 000,231,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2014-05-16 15:19:00 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\2K Sports
[2014-05-16 15:17:26 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\PunkBuster
[2014-05-16 15:17:24 | 000,000,000 | ---D | C] -- C:\Users\Odyn\Documents\Battlefield 3
[2014-05-16 15:16:52 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\ESN
[2014-05-16 15:16:50 | 000,000,000 | ---D | C] -- C:\Program Files\Battlelog Web Plugins
[2014-05-16 14:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Core
[2014-05-16 14:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Logs
[2014-05-16 14:48:56 | 000,000,000 | -H-D | C] -- C:\Program Files\Common Files\EAInstaller
[2014-05-16 14:36:57 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\WinRAR
[2014-05-16 14:26:29 | 000,000,000 | ---D | C] -- C:\Users\Odyn\Documents\Assetto Corsa
[2014-05-16 14:26:11 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2014-05-16 14:26:11 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2014-05-16 14:26:11 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2014-05-16 14:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2014-05-16 14:14:26 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2014-05-16 14:14:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logitech
[2014-05-16 13:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2014-05-16 13:46:18 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Origin
[2014-05-16 13:46:16 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Origin
[2014-05-16 13:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2014-05-16 13:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2014-05-16 13:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2014-05-16 13:28:19 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2014-05-16 13:25:00 | 000,052,920 | ---- | C] (StdLib) -- C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys
[2014-05-16 13:21:21 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\TS3Client
[2014-05-16 13:21:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2014-05-16 13:21:18 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2014-05-16 13:11:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2014-05-16 13:11:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2014-05-16 13:11:10 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2014-05-16 13:07:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014-05-16 13:07:24 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Google
[2014-05-16 13:07:24 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2014-05-16 12:52:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2014-05-16 08:09:44 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2014-05-16 08:09:44 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2014-05-16 08:09:44 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2014-05-16 07:49:24 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2014-05-16 07:49:23 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2014-05-16 07:49:23 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2014-05-16 07:47:55 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2014-05-16 07:47:55 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014-05-16 07:47:55 | 001,806,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014-05-16 07:47:55 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014-05-16 07:47:55 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014-05-16 07:47:55 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014-05-16 07:47:55 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2014-05-16 07:47:55 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014-05-16 07:47:55 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2014-05-16 07:47:55 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014-05-16 07:47:55 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2014-05-16 07:47:55 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014-05-16 07:47:55 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014-05-16 07:47:55 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2014-05-16 07:47:55 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014-05-16 07:47:55 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2014-05-16 07:47:55 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2014-05-16 07:47:55 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2014-05-16 07:47:55 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014-05-16 07:47:55 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2014-05-16 07:47:55 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2014-05-16 07:47:55 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2014-05-16 07:47:55 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2014-05-16 07:47:55 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2014-05-16 07:47:55 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2014-05-16 07:47:55 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014-05-16 07:47:55 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014-05-16 07:47:55 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014-05-16 07:47:55 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2014-05-16 07:47:55 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2014-05-16 07:47:55 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014-05-16 07:47:55 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2014-05-16 07:47:55 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014-05-16 07:47:55 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2014-05-16 07:47:55 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014-05-16 07:47:03 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2014-05-16 02:09:44 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\uTorrent
[2014-05-16 02:08:54 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\vlc
[2014-05-16 02:08:40 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014-05-16 02:08:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014-05-16 02:08:25 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2014-05-16 02:08:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2014-05-16 02:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2014-05-16 02:04:29 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\NapiProjekt
[2014-05-16 02:04:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt
[2014-05-16 02:04:27 | 000,000,000 | ---D | C] -- C:\Program Files\NapiProjekt
[2014-05-16 02:02:31 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\ipla
[2014-05-16 02:02:31 | 000,000,000 | ---D | C] -- C:\ProgramData\ipla
[2014-05-16 02:02:29 | 000,000,000 | ---D | C] -- C:\ProgramData\RDRM
[2014-05-16 02:02:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ipla
[2014-05-16 02:02:12 | 000,000,000 | ---D | C] -- C:\Program Files\ipla
[2014-05-16 02:02:01 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
[2014-05-16 02:02:01 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
[2014-05-16 01:59:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2014-05-16 01:59:50 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2014-05-16 01:58:04 | 000,000,000 | ---D | C] -- C:\Program Files\webget
[2014-05-16 01:58:00 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
[2014-05-16 01:57:08 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Programs
[2014-05-16 01:54:43 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2014-05-16 01:54:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2014-05-16 01:54:42 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2014-05-16 01:46:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
[2014-05-16 01:46:45 | 000,017,088 | ---- | C] (Glarysoft Ltd) -- C:\Windows\System32\drivers\GUBootStartup.sys
[2014-05-16 01:46:45 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\GlarySoft
[2014-05-16 01:46:44 | 000,101,664 | ---- | C] (Glarysoft Ltd) -- C:\Windows\System32\BootDefrag.exe
[2014-05-16 01:46:44 | 000,016,064 | ---- | C] (Glarysoft Ltd) -- C:\Windows\System32\drivers\BootDefragDriver.sys
[2014-05-16 01:46:44 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\DiskDefrag
[2014-05-16 01:46:40 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities 5
[2014-05-16 01:45:51 | 000,000,000 | ---D | C] -- C:\Program Files\Damian Pasternak
[2014-05-16 01:44:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2014-05-16 01:44:40 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2014-05-16 01:43:56 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\rmi
[2014-05-16 01:42:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014-05-16 01:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014-05-16 01:34:04 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\MyPortal
[2014-05-16 01:34:01 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPortal
[2014-05-16 01:33:58 | 000,000,000 | ---D | C] -- C:\Program Files\MyPortal
[2014-05-16 01:33:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
[2014-05-16 01:33:08 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\AIMP3
[2014-05-16 01:33:06 | 000,000,000 | ---D | C] -- C:\Program Files\AIMP3
[2014-05-16 01:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4Tech Software
[2014-05-16 01:29:55 | 000,000,000 | ---D | C] -- C:\Program Files\OscarX7Editor5Mode
[2014-05-16 01:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\5 mode Oscar
[2014-05-16 01:28:21 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
[2014-05-16 01:28:15 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014-05-16 01:28:03 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2014-05-16 01:28:03 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2014-05-16 01:28:03 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnaddr.dll
[2014-05-16 01:27:52 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2014-05-16 01:27:52 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2014-05-16 01:27:51 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2014-05-16 01:27:50 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2014-05-16 01:27:21 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2014-05-16 01:27:21 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2014-05-16 01:27:21 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2014-05-16 01:27:21 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2014-05-16 01:27:21 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2014-05-16 01:27:20 | 000,919,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2014-05-16 01:27:20 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2014-05-16 01:27:06 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2014-05-16 01:27:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2014-05-16 01:26:50 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2014-05-16 01:26:49 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2014-05-16 01:26:17 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2014-05-16 01:26:17 | 000,187,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2014-05-16 01:26:15 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2014-05-16 01:26:12 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2014-05-16 01:26:11 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2014-05-16 01:26:11 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2014-05-16 01:25:55 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2014-05-16 01:25:55 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2014-05-16 01:25:55 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2014-05-16 01:25:55 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2014-05-16 01:25:55 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2014-05-16 01:25:54 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2014-05-16 01:25:47 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2014-05-16 01:25:38 | 000,802,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WFS.exe
[2014-05-16 01:25:38 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2014-05-16 01:25:36 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2014-05-16 01:25:36 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rstrui.exe
[2014-05-16 01:25:33 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2014-05-16 01:25:31 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2014-05-16 01:25:29 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2014-05-16 01:25:25 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2014-05-16 01:25:14 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2014-05-16 01:25:14 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2014-05-16 01:25:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2014-05-16 01:25:08 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2014-05-16 01:25:07 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2014-05-16 01:24:55 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2014-05-16 01:24:52 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2014-05-16 01:24:52 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll
[2014-05-16 01:24:52 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\System32\fpb.rs
[2014-05-16 01:24:52 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc-nz.rs
[2014-05-16 01:24:52 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\System32\pegibbfc.rs
[2014-05-16 01:24:52 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\System32\csrr.rs
[2014-05-16 01:24:52 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\System32\cob-au.rs
[2014-05-16 01:24:52 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\System32\usk.rs
[2014-05-16 01:24:52 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\System32\grb.rs
[2014-05-16 01:24:52 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-pt.rs
[2014-05-16 01:24:52 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi.rs
[2014-05-16 01:24:52 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\System32\djctq.rs
[2014-05-16 01:24:51 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\System32\cero.rs
[2014-05-16 01:24:51 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\System32\esrb.rs
[2014-05-16 01:24:51 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc.rs
[2014-05-16 01:24:51 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-fi.rs
[2014-05-16 01:24:40 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2014-05-16 01:24:39 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2014-05-16 01:24:36 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2014-05-16 01:24:36 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2014-05-16 01:24:36 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2014-05-16 01:24:36 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2014-05-16 01:24:36 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2014-05-16 01:24:34 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2014-05-16 01:24:34 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2014-05-16 01:24:33 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2014-05-16 01:24:33 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2014-05-16 01:24:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2014-05-16 01:24:29 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\profprov.dll
[2014-05-16 01:24:28 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2014-05-16 01:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014-05-16 01:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2014-05-16 01:24:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2014-05-16 01:24:03 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2014-05-16 01:24:02 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2014-05-16 01:24:01 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2014-05-16 01:23:51 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2014-05-16 01:23:50 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2014-05-16 01:23:43 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2014-05-16 01:23:16 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2014-05-16 01:20:24 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2014-05-16 01:20:24 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2014-05-16 01:06:47 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Macromedia
[2014-05-16 01:05:28 | 000,003,567 | ---- | C] (Beyond Logic http://www.beyondlogic.org) -- C:\Windows\System32\drivers\PortTalk.sys
[2014-05-16 01:02:45 | 000,026,136 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2014-05-16 01:02:42 | 000,270,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdisFlt.sys
[2014-05-16 01:01:06 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\AVAST Software
[2014-05-16 01:01:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2014-05-16 01:00:43 | 000,777,488 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014-05-16 01:00:43 | 000,776,976 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys.1400194859281
[2014-05-16 01:00:43 | 000,411,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys
[2014-05-16 01:00:43 | 000,411,552 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys.1400194859281
[2014-05-16 01:00:43 | 000,271,264 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014-05-16 01:00:43 | 000,081,768 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014-05-16 01:00:43 | 000,068,312 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswstm.sys
[2014-05-16 01:00:43 | 000,067,824 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014-05-16 01:00:43 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014-05-16 01:00:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-05-16 00:59:36 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014-05-16 00:56:11 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2014-05-16 00:56:01 | 000,027,888 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\drivers\Smb_driver_Intel.sys
[2014-05-16 00:53:56 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2014-05-16 00:53:56 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll
[2014-05-16 00:48:50 | 000,080,488 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RtNicProp32.dll
[2014-05-16 00:46:46 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Adobe
[2014-05-16 00:45:59 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\SlimWare Utilities Inc
[2014-05-16 00:45:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2014-05-16 00:45:50 | 000,000,000 | ---D | C] -- C:\Program Files\SlimDrivers
[2014-05-16 00:42:35 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\ATI
[2014-05-16 00:42:35 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\ATI
[2014-05-16 00:42:35 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2014-05-16 00:41:13 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2014-05-16 00:41:12 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014-05-16 00:40:13 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2014-05-16 00:13:58 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2014-05-16 00:13:58 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2014-05-16 00:13:58 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2014-05-16 00:13:58 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2014-05-16 00:13:58 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2014-05-16 00:13:58 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2014-05-16 00:13:58 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2014-05-16 00:13:57 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2014-05-16 00:13:57 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2014-05-16 00:13:57 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2014-05-16 00:13:57 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2014-05-16 00:13:57 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2014-05-16 00:13:57 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2014-05-16 00:13:57 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2014-05-16 00:13:57 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2014-05-16 00:13:57 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2014-05-16 00:13:57 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2014-05-16 00:13:57 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2014-05-16 00:13:57 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2014-05-16 00:13:57 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2014-05-16 00:13:57 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2014-05-16 00:13:57 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2014-05-16 00:13:57 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2014-05-16 00:13:57 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2014-05-16 00:13:57 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2014-05-16 00:13:57 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2014-05-16 00:13:56 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2014-05-16 00:13:56 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2014-05-16 00:13:56 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2014-05-16 00:13:56 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2014-05-16 00:13:56 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2014-05-16 00:13:56 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2014-05-16 00:13:56 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2014-05-16 00:13:56 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2014-05-16 00:13:56 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2014-05-16 00:13:56 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2014-05-16 00:13:56 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2014-05-16 00:13:56 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2014-05-16 00:13:56 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2014-05-16 00:13:56 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2014-05-16 00:13:56 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2014-05-16 00:13:56 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2014-05-16 00:13:56 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2014-05-16 00:13:56 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2014-05-16 00:13:56 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2014-05-16 00:13:56 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2014-05-16 00:13:56 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2014-05-16 00:13:56 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2014-05-16 00:13:56 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2014-05-16 00:13:56 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2014-05-16 00:13:56 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2014-05-16 00:13:56 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2014-05-16 00:13:56 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2014-05-16 00:13:56 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2014-05-16 00:13:55 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2014-05-16 00:13:55 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2014-05-16 00:13:55 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2014-05-16 00:13:55 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2014-05-16 00:13:55 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2014-05-16 00:13:55 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2014-05-16 00:13:55 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2014-05-16 00:13:55 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2014-05-16 00:13:55 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2014-05-16 00:13:55 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2014-05-16 00:13:55 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2014-05-16 00:13:55 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2014-05-16 00:13:55 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2014-05-16 00:13:55 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2014-05-16 00:13:55 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2014-05-16 00:13:55 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2014-05-16 00:13:55 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2014-05-16 00:13:55 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2014-05-16 00:13:55 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2014-05-16 00:13:55 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2014-05-16 00:13:55 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2014-05-16 00:13:55 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2014-05-16 00:13:55 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2014-05-16 00:13:55 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2014-05-16 00:13:55 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2014-05-16 00:13:54 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2014-05-16 00:13:54 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2014-05-16 00:13:54 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2014-05-16 00:13:54 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2014-05-16 00:13:54 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2014-05-16 00:13:54 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2014-05-16 00:13:54 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2014-05-16 00:13:54 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2014-05-16 00:13:54 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2014-05-16 00:13:30 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2014-05-16 00:13:28 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
[2014-05-16 00:13:26 | 000,000,000 | ---D | C] -- C:\Program Files\RivaTuner Statistics Server
[2014-05-16 00:13:14 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2014-05-16 00:13:10 | 000,000,000 | ---D | C] -- C:\Program Files\MSI Afterburner
[2014-05-16 00:05:05 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2014-05-16 00:04:36 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Microsoft Games
[2014-05-16 00:04:27 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2014-05-16 00:04:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\OEM
[2014-05-16 00:03:45 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\library_dir
[2014-05-16 00:03:24 | 000,000,000 | ---D | C] -- C:\Program Files\AMD AVT
[2014-05-16 00:03:24 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2014-05-16 00:03:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2014-05-16 00:03:06 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2014-05-16 00:02:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2014-05-16 00:02:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014-05-16 00:02:28 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2014-05-16 00:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2014-05-16 00:01:31 | 000,000,000 | ---D | C] -- C:\AMD
[2014-05-15 23:52:28 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Mozilla
[2014-05-15 23:52:28 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Mozilla
[2014-05-15 23:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2014-05-15 23:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014-05-15 23:52:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014-05-15 23:49:42 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Macromedia
[2014-05-15 23:49:42 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Adobe
[2014-05-15 23:49:34 | 000,692,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014-05-15 23:49:34 | 000,070,832 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014-05-15 23:49:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2014-05-15 23:46:17 | 001,629,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01011.dll
[2014-05-15 23:46:17 | 000,085,464 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\TeeDriver.sys
[2014-05-15 23:46:16 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\InstallShield
[2014-05-15 23:44:56 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Intel Corporation
[2014-05-15 23:44:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel Corporation
[2014-05-15 23:44:54 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2014-05-15 23:44:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2014-05-15 23:44:48 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2014-05-15 23:44:01 | 000,000,000 | ---D | C] -- C:\Users\Odyn\Intel
[2014-05-15 23:41:05 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2014-05-15 23:41:05 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll
[2014-05-15 23:41:05 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys
[2014-05-15 23:39:15 | 000,025,448 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\iaStorF.sys
[2014-05-15 23:39:14 | 000,505,192 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\iaStorA.sys
[2014-05-15 23:38:25 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2014-05-15 23:38:25 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2014-05-15 23:38:23 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2014-05-15 23:38:23 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2014-05-15 23:38:23 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2014-05-15 23:38:22 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2014-05-15 23:38:22 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2014-05-15 23:37:14 | 000,100,896 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RTNUninst32.dll
[2014-05-15 23:36:08 | 000,049,808 | ---- | C] (Realtek Corporation) -- C:\Windows\System32\drivers\RtTeam620.sys
[2014-05-15 23:36:08 | 000,033,056 | ---- | C] (Realtek ) -- C:\Windows\System32\drivers\RtNdPt60.sys
[2014-05-15 23:36:08 | 000,027,792 | ---- | C] (Realtek Corporation) -- C:\Windows\System32\drivers\RtVlan620.sys
[2014-05-15 23:36:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
[2014-05-15 23:33:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2014-05-15 23:33:46 | 003,320,936 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkHDMI.dll
[2014-05-15 23:33:46 | 003,296,600 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEP32H.dll
[2014-05-15 23:33:46 | 002,275,432 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RHDMIExt.dll
[2014-05-15 23:33:46 | 000,357,720 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32H.dll
[2014-05-15 23:33:46 | 000,345,944 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EED32H.dll
[2014-05-15 23:33:46 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RH3DHT32.dll
[2014-05-15 23:33:46 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RH3DAA32.dll
[2014-05-15 23:33:46 | 000,199,528 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RtHDMIV.sys
[2014-05-15 23:33:46 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32H.dll
[2014-05-15 23:33:46 | 000,103,256 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEL32H.dll
[2014-05-15 23:33:46 | 000,088,408 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEA32H.dll
[2014-05-15 23:33:46 | 000,076,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RHCoInst.dll
[2014-05-15 23:33:46 | 000,076,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32H.dll
[2014-05-15 23:33:46 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32H.dll
[2014-05-15 23:33:46 | 000,061,272 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEG32H.dll
[2014-05-15 23:33:45 | 003,173,008 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll
[2014-05-15 23:33:45 | 002,417,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2014-05-15 23:33:45 | 001,783,056 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2014-05-15 23:33:45 | 001,497,704 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2014-05-15 23:33:45 | 000,753,280 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBAPO32.dll
[2014-05-15 23:33:45 | 000,645,776 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2014-05-15 23:33:45 | 000,359,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2014-05-15 23:33:45 | 000,345,328 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2014-05-15 23:33:45 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2014-05-15 23:33:45 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2014-05-15 23:33:45 | 000,185,584 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2014-05-15 23:33:45 | 000,173,296 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2014-05-15 23:33:45 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2014-05-15 23:33:45 | 000,140,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2014-05-15 23:33:45 | 000,087,696 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2014-05-15 23:33:45 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2014-05-15 23:33:45 | 000,071,808 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBWrp32.dll
[2014-05-15 23:33:45 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2014-05-15 23:33:45 | 000,054,360 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBppld32.dll
[2014-05-15 23:33:45 | 000,050,776 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBPPCn32.dll
[2014-05-15 23:33:45 | 000,013,416 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2014-05-15 23:33:44 | 002,193,472 | ---- | C] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2014-05-15 23:33:44 | 001,836,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2014-05-15 23:33:44 | 000,709,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPOShell.dll
[2014-05-15 23:33:44 | 000,232,792 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2014-05-15 23:33:44 | 000,176,736 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2014-05-15 23:33:44 | 000,132,368 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2014-05-15 23:33:44 | 000,095,840 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2014-05-15 23:33:44 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2014-05-15 23:33:44 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2014-05-15 23:33:25 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2014-05-15 23:33:24 | 001,706,640 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2014-05-15 23:33:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2014-05-15 23:27:50 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll
[2014-05-15 23:27:50 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2014-05-15 23:27:34 | 000,000,000 | ---D | C] -- C:\Intel
[2014-05-15 23:10:47 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014-05-15 23:10:47 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Searches
[2014-05-15 23:10:47 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014-05-15 23:10:41 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Identities
[2014-05-15 23:10:40 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Contacts
[2014-05-15 23:10:37 | 000,000,000 | --SD | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Videos
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Saved Games
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Pictures
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Music
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Links
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Favorites
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Downloads
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Documents
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Desktop
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Ustawienia lokalne
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\AppData\Local\Temporary Internet Files
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Szablony
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\SendTo
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Recent
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\PrintHood
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\NetHood
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Documents\Moje wideo
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Documents\Moje obrazy
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Moje dokumenty
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Documents\Moja muzyka
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Menu Start
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\AppData\Local\Historia
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Dane aplikacji
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\AppData\Local\Dane aplikacji
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Cookies
[2014-05-15 23:10:37 | 000,000,000 | -H-D | C] -- C:\Users\Odyn\AppData
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\VirtualStore
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Temp
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Microsoft
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Media Center Programs
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Recovery
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji
[2014-05-15 23:10:03 | 000,000,000 | ---D | C] -- C:\Windows\SDold
[2014-05-15 23:05:56 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2014-05-15 21:54:02 | 000,000,000 | ---D | C] -- C:\Kalibracja
[2014-05-15 21:27:47 | 000,000,000 | ---D | C] -- C:\Program Files\Victoria 4.46 B
[2014-04-18 04:43:04 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atimpc32.dll
[2014-04-18 04:43:04 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdpcom32.dll
[2014-04-18 04:42:58 | 000,126,336 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiuxpag.dll
[2014-04-18 04:42:56 | 000,099,520 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiu9pag.dll
[2014-04-18 04:42:52 | 001,117,184 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\aticfx32.dll
[2014-04-18 04:42:42 | 008,866,928 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atidxx32.dll
[2014-04-18 04:42:38 | 006,796,592 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdva.dll
[2014-04-18 04:42:34 | 006,799,688 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdag.dll
[2014-04-18 04:39:04 | 000,247,520 | ---- | C] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amdacpksd.sys
[2014-04-18 04:35:20 | 013,515,264 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmdag.sys
[2014-04-18 04:22:48 | 000,083,456 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OpenVideo.dll
[2014-04-18 04:22:38 | 000,073,216 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OVDecode.dll
[2014-04-18 04:19:54 | 024,107,520 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\amdocl.dll
[2014-04-18 04:17:24 | 000,058,880 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2014-04-18 04:13:10 | 000,113,664 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantle32.dll
[2014-04-18 03:58:32 | 004,358,656 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmantle32.dll
[2014-04-18 03:51:44 | 023,409,152 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atioglxx.dll
[2014-04-18 03:46:34 | 000,368,128 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiapfxx.exe
[2014-04-18 03:46:24 | 000,052,224 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalrt.dll
[2014-04-18 03:46:18 | 000,049,152 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalcl.dll
[2014-04-18 03:45:46 | 000,085,504 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantleaxl32.dll
[2014-04-18 03:42:52 | 014,302,208 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticaldd.dll
[2014-04-18 03:33:02 | 000,037,888 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmmcl.dll
[2014-04-18 03:30:14 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atidemgy.dll
[2014-04-18 03:29:58 | 000,030,720 | ---- | C] (AMD) -- C:\Windows\System32\atimuixx.dll
[2014-04-18 03:29:40 | 000,491,520 | ---- | C] (AMD) -- C:\Windows\System32\atieclxx.exe
[2014-04-18 03:29:16 | 000,208,896 | ---- | C] (AMD) -- C:\Windows\System32\atiesrxx.exe
[2014-04-18 03:28:24 | 000,164,352 | ---- | C] (AMD) -- C:\Windows\System32\atitmmxx.dll
[2014-04-18 03:21:26 | 000,616,960 | ---- | C] (AMD) -- C:\Windows\System32\coinst_14.100.dll
[2014-04-18 03:08:56 | 000,848,896 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiadlxx.dll
[2014-04-18 03:07:46 | 000,069,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiglpxx.dll
[2014-04-18 03:07:20 | 000,133,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atigktxx.dll
[2014-04-18 03:06:30 | 000,512,000 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmpag.sys
[2014-04-18 03:04:24 | 000,043,520 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\ati2erec.dll
========== Files - Modified Within 30 Days ==========
[2014-05-17 20:12:00 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-05-17 20:08:04 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-05-17 19:55:36 | 000,013,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-05-17 19:55:36 | 000,013,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-05-17 19:50:57 | 000,740,732 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2014-05-17 19:50:57 | 000,654,564 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014-05-17 19:50:57 | 000,155,804 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2014-05-17 19:50:57 | 000,121,934 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014-05-17 19:47:07 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize 5.job
[2014-05-17 19:46:08 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-05-17 19:45:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-05-17 19:45:56 | 2811,727,872 | -HS- | M] () -- C:\hiberfil.sys
[2014-05-17 19:38:06 | 000,000,892 | ---- | M] () -- C:\Users\Odyn\Desktop\HD Tune.lnk
[2014-05-17 13:21:31 | 000,413,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014-05-17 13:18:18 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msclmd.dll
[2014-05-16 15:17:40 | 000,140,072 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2014-05-16 15:17:33 | 000,280,904 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2014-05-16 14:48:57 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2014-05-16 14:48:41 | 000,138,056 | ---- | M] () -- C:\Users\Odyn\AppData\Roaming\PnkBstrK.sys
[2014-05-16 14:48:13 | 000,189,248 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2014-05-16 14:24:41 | 000,002,245 | ---- | M] () -- C:\Users\Odyn\Desktop\ACS.lnk
[2014-05-16 13:28:21 | 000,000,933 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2014-05-16 13:27:56 | 000,000,216 | ---- | M] () -- C:\Users\Odyn\Desktop\NBA 2K14.url
[2014-05-16 13:21:19 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014-05-16 13:13:20 | 000,000,216 | ---- | M] () -- C:\Users\Odyn\Desktop\Assetto Corsa.url
[2014-05-16 13:11:11 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2014-05-16 13:07:52 | 000,002,203 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014-05-16 13:01:37 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2014-05-16 07:47:55 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2014-05-16 07:47:55 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014-05-16 07:47:55 | 001,806,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014-05-16 07:47:55 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014-05-16 07:47:55 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014-05-16 07:47:55 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014-05-16 07:47:55 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2014-05-16 07:47:55 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014-05-16 07:47:55 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2014-05-16 07:47:55 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014-05-16 07:47:55 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2014-05-16 07:47:55 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014-05-16 07:47:55 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014-05-16 07:47:55 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2014-05-16 07:47:55 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014-05-16 07:47:55 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2014-05-16 07:47:55 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2014-05-16 07:47:55 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2014-05-16 07:47:55 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014-05-16 07:47:55 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2014-05-16 07:47:55 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2014-05-16 07:47:55 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2014-05-16 07:47:55 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2014-05-16 07:47:55 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2014-05-16 07:47:55 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2014-05-16 07:47:55 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014-05-16 07:47:55 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014-05-16 07:47:55 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2014-05-16 07:47:55 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014-05-16 07:47:55 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2014-05-16 07:47:55 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2014-05-16 07:47:55 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014-05-16 07:47:55 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2014-05-16 07:47:55 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014-05-16 07:47:55 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2014-05-16 07:47:55 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014-05-16 07:43:44 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2014-05-16 02:10:37 | 000,000,851 | ---- | M] () -- C:\Users\Odyn\Desktop\µTorrent.lnk
[2014-05-16 02:08:40 | 000,000,971 | ---- | M] () -- C:\Users\Public\Desktop\WinRAR.lnk
[2014-05-16 02:08:23 | 000,001,020 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014-05-16 02:04:29 | 000,000,994 | ---- | M] () -- C:\Users\Odyn\Desktop\NapiProjekt.lnk
[2014-05-16 02:02:29 | 000,000,905 | ---- | M] () -- C:\Users\Public\Desktop\ipla.lnk
[2014-05-16 02:02:01 | 001,700,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
[2014-05-16 02:02:01 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
[2014-05-16 01:54:43 | 000,000,961 | ---- | M] () -- C:\Users\Odyn\Desktop\SpeedFan.lnk
[2014-05-16 01:54:42 | 000,000,045 | ---- | M] () -- C:\Windows\System32\initdebug.nfo
[2014-05-16 01:51:39 | 000,001,018 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2014-05-16 01:46:46 | 000,001,034 | ---- | M] () -- C:\Users\Public\Desktop\Glary Utilities 5.lnk
[2014-05-16 01:46:45 | 000,017,088 | ---- | M] (Glarysoft Ltd) -- C:\Windows\System32\drivers\GUBootStartup.sys
[2014-05-16 01:45:51 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\CWK.lnk
[2014-05-16 01:42:52 | 000,000,961 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014-05-16 01:34:01 | 000,000,804 | ---- | M] () -- C:\Users\Odyn\Desktop\AQQ.lnk
[2014-05-16 01:33:15 | 000,000,871 | ---- | M] () -- C:\Users\Public\Desktop\AIMP3.lnk
[2014-05-16 01:30:21 | 000,001,247 | ---- | M] () -- C:\Users\Odyn\Desktop\OscarEditor.lnk
[2014-05-16 01:24:21 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014-05-16 01:03:09 | 000,002,053 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2014-05-16 01:02:59 | 000,270,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdisFlt.sys
[2014-05-16 01:02:43 | 000,026,136 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2014-05-16 01:00:59 | 000,777,488 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014-05-16 01:00:59 | 000,411,680 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys
[2014-05-16 01:00:59 | 000,068,312 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswstm.sys
[2014-05-16 01:00:43 | 000,776,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys.1400194859281
[2014-05-16 01:00:43 | 000,411,552 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys.1400194859281
[2014-05-16 01:00:43 | 000,271,264 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014-05-16 01:00:43 | 000,180,632 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014-05-16 01:00:43 | 000,081,768 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014-05-16 01:00:43 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014-05-16 01:00:43 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014-05-16 01:00:43 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014-05-16 01:00:43 | 000,024,184 | ---- | M] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014-05-16 00:56:11 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2014-05-16 00:46:57 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014-05-16 00:46:57 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014-05-16 00:45:50 | 000,002,455 | ---- | M] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2014-05-16 00:13:14 | 000,001,040 | ---- | M] () -- C:\Users\Odyn\Desktop\MSI Afterburner.lnk
[2014-05-16 00:05:36 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2014-05-15 23:52:21 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014-05-15 23:26:28 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014-05-15 23:07:48 | 000,067,908 | ---- | M] () -- C:\Windows\System32\license.rtf
[2014-05-14 10:39:20 | 000,101,664 | ---- | M] (Glarysoft Ltd) -- C:\Windows\System32\BootDefrag.exe
[2014-05-14 09:02:44 | 000,016,064 | ---- | M] (Glarysoft Ltd) -- C:\Windows\System32\drivers\BootDefragDriver.sys
[2014-05-12 16:40:58 | 000,052,920 | ---- | M] (StdLib) -- C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys
[2014-04-18 04:43:04 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atimpc32.dll
[2014-04-18 04:43:04 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdpcom32.dll
[2014-04-18 04:42:58 | 000,126,336 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiuxpag.dll
[2014-04-18 04:42:56 | 000,099,520 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiu9pag.dll
[2014-04-18 04:42:52 | 001,117,184 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\aticfx32.dll
[2014-04-18 04:42:42 | 008,866,928 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atidxx32.dll
[2014-04-18 04:42:38 | 006,796,592 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdva.dll
[2014-04-18 04:42:34 | 006,799,688 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdag.dll
[2014-04-18 04:39:04 | 000,247,520 | ---- | M] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amdacpksd.sys
[2014-04-18 04:35:20 | 013,515,264 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmdag.sys
[2014-04-18 04:23:02 | 000,200,704 | ---- | M] () -- C:\Windows\System32\clinfo.exe
[2014-04-18 04:22:56 | 000,995,342 | ---- | M] () -- C:\Windows\System32\amdocl_as32.exe
[2014-04-18 04:22:56 | 000,798,734 | ---- | M] () -- C:\Windows\System32\amdocl_ld32.exe
[2014-04-18 04:22:48 | 000,083,456 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OpenVideo.dll
[2014-04-18 04:22:38 | 000,073,216 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OVDecode.dll
[2014-04-18 04:19:54 | 024,107,520 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\amdocl.dll
[2014-04-18 04:17:24 | 000,058,880 | ---- | M] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2014-04-18 04:13:10 | 000,113,664 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantle32.dll
[2014-04-18 03:58:32 | 004,358,656 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmantle32.dll
[2014-04-18 03:51:44 | 023,409,152 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atioglxx.dll
[2014-04-18 03:46:56 | 000,580,816 | ---- | M] () -- C:\Windows\System32\atiapfxx.blb
[2014-04-18 03:46:34 | 000,368,128 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiapfxx.exe
[2014-04-18 03:46:24 | 000,052,224 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalrt.dll
[2014-04-18 03:46:18 | 000,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalcl.dll
[2014-04-18 03:45:46 | 000,085,504 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantleaxl32.dll
[2014-04-18 03:42:52 | 014,302,208 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticaldd.dll
[2014-04-18 03:33:02 | 000,037,888 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmmcl.dll
[2014-04-18 03:30:14 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atidemgy.dll
[2014-04-18 03:29:58 | 000,030,720 | ---- | M] (AMD) -- C:\Windows\System32\atimuixx.dll
[2014-04-18 03:29:40 | 000,491,520 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
[2014-04-18 03:29:16 | 000,208,896 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
[2014-04-18 03:28:24 | 000,164,352 | ---- | M] (AMD) -- C:\Windows\System32\atitmmxx.dll
[2014-04-18 03:21:26 | 000,616,960 | ---- | M] (AMD) -- C:\Windows\System32\coinst_14.100.dll
[2014-04-18 03:17:36 | 003,471,376 | ---- | M] () -- C:\Windows\System32\atiumdva.cap
[2014-04-18 03:14:36 | 000,204,952 | ---- | M] () -- C:\Windows\System32\ativvsvl.dat
[2014-04-18 03:14:36 | 000,157,144 | ---- | M] () -- C:\Windows\System32\ativvsva.dat
[2014-04-18 03:08:56 | 000,848,896 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiadlxx.dll
[2014-04-18 03:07:46 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiglpxx.dll
[2014-04-18 03:07:20 | 000,133,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atigktxx.dll
[2014-04-18 03:06:30 | 000,512,000 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmpag.sys
[2014-04-18 03:04:24 | 000,043,520 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\ati2erec.dll
[2014-04-17 22:28:30 | 000,038,912 | ---- | M] () -- C:\Windows\System32\kdbsdk32.dll
========== Files Created - No Company Name ==========
[2014-05-17 19:38:06 | 000,000,892 | ---- | C] () -- C:\Users\Odyn\Desktop\HD Tune.lnk
[2014-05-17 12:05:48 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2014-05-17 12:05:42 | 000,146,852 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
[2014-05-17 12:05:23 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2014-05-17 12:05:22 | 000,010,429 | ---- | C] () -- C:\Windows\System32\ScavengeSpace.xml
[2014-05-17 12:05:20 | 000,105,559 | ---- | C] () -- C:\Windows\System32\RacRules.xml
[2014-05-16 15:17:33 | 000,280,904 | ---- | C] () -- C:\Windows\System32\PnkBstrB.xtr
[2014-05-16 14:48:57 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2014-05-16 14:48:41 | 000,140,072 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2014-05-16 14:48:41 | 000,138,056 | ---- | C] () -- C:\Users\Odyn\AppData\Roaming\PnkBstrK.sys
[2014-05-16 14:48:09 | 000,280,904 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2014-05-16 14:48:09 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.ex0
[2014-05-16 14:48:08 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2014-05-16 14:24:11 | 000,002,245 | ---- | C] () -- C:\Users\Odyn\Desktop\ACS.lnk
[2014-05-16 13:28:21 | 000,000,933 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2014-05-16 13:27:56 | 000,000,216 | ---- | C] () -- C:\Users\Odyn\Desktop\NBA 2K14.url
[2014-05-16 13:21:19 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014-05-16 13:13:20 | 000,000,216 | ---- | C] () -- C:\Users\Odyn\Desktop\Assetto Corsa.url
[2014-05-16 13:11:11 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2014-05-16 13:07:52 | 000,002,203 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014-05-16 13:07:24 | 000,001,032 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-05-16 13:07:24 | 000,001,028 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-05-16 07:49:23 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2014-05-16 07:47:55 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2014-05-16 07:43:44 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2014-05-16 02:10:37 | 000,000,851 | ---- | C] () -- C:\Users\Odyn\Desktop\µTorrent.lnk
[2014-05-16 02:08:40 | 000,000,971 | ---- | C] () -- C:\Users\Public\Desktop\WinRAR.lnk
[2014-05-16 02:08:23 | 000,001,020 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014-05-16 02:04:29 | 000,000,994 | ---- | C] () -- C:\Users\Odyn\Desktop\NapiProjekt.lnk
[2014-05-16 02:02:29 | 000,000,905 | ---- | C] () -- C:\Users\Public\Desktop\ipla.lnk
[2014-05-16 01:59:53 | 000,218,200 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2014-05-16 01:54:43 | 000,000,961 | ---- | C] () -- C:\Users\Odyn\Desktop\SpeedFan.lnk
[2014-05-16 01:54:41 | 000,000,045 | ---- | C] () -- C:\Windows\System32\initdebug.nfo
[2014-05-16 01:46:46 | 000,001,046 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
[2014-05-16 01:46:46 | 000,001,034 | ---- | C] () -- C:\Users\Public\Desktop\Glary Utilities 5.lnk
[2014-05-16 01:46:46 | 000,000,316 | ---- | C] () -- C:\Windows\tasks\GlaryInitialize 5.job
[2014-05-16 01:45:51 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CWK.lnk
[2014-05-16 01:45:51 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\CWK.lnk
[2014-05-16 01:44:41 | 000,001,018 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2014-05-16 01:42:52 | 000,000,961 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014-05-16 01:34:01 | 000,000,804 | ---- | C] () -- C:\Users\Odyn\Desktop\AQQ.lnk
[2014-05-16 01:33:15 | 000,000,871 | ---- | C] () -- C:\Users\Public\Desktop\AIMP3.lnk
[2014-05-16 01:30:21 | 000,001,247 | ---- | C] () -- C:\Users\Odyn\Desktop\OscarEditor.lnk
[2014-05-16 01:24:21 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014-05-16 01:24:21 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014-05-16 01:03:09 | 000,002,053 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2014-05-16 01:00:43 | 000,180,632 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014-05-16 01:00:43 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014-05-16 01:00:43 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014-05-16 00:56:11 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2014-05-16 00:53:56 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2014-05-16 00:46:03 | 000,000,384 | ---- | C] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2014-05-16 00:45:50 | 000,002,455 | ---- | C] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2014-05-16 00:13:14 | 000,001,040 | ---- | C] () -- C:\Users\Odyn\Desktop\MSI Afterburner.lnk
[2014-05-16 00:05:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014-05-15 23:52:21 | 000,001,113 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2014-05-15 23:52:21 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014-05-15 23:49:35 | 000,000,930 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-05-15 23:33:45 | 000,293,889 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2014-05-15 23:26:28 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014-05-15 23:10:48 | 000,001,417 | ---- | C] () -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-05-15 23:07:46 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2014-05-15 23:07:41 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2014-05-15 23:05:49 | 2811,727,872 | -HS- | C] () -- C:\hiberfil.sys
[2014-04-18 04:23:02 | 000,200,704 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2014-04-18 04:22:56 | 000,995,342 | ---- | C] () -- C:\Windows\System32\amdocl_as32.exe
[2014-04-18 04:22:56 | 000,798,734 | ---- | C] () -- C:\Windows\System32\amdocl_ld32.exe
[2014-04-18 03:46:56 | 000,580,816 | ---- | C] () -- C:\Windows\System32\atiapfxx.blb
[2014-04-18 03:17:36 | 003,471,376 | ---- | C] () -- C:\Windows\System32\atiumdva.cap
[2014-04-18 03:14:36 | 000,204,952 | ---- | C] () -- C:\Windows\System32\ativvsvl.dat
[2014-04-18 03:14:36 | 000,157,144 | ---- | C] () -- C:\Windows\System32\ativvsva.dat
[2014-04-17 22:28:30 | 000,038,912 | ---- | C] () -- C:\Windows\System32\kdbsdk32.dll
[2014-04-10 19:58:46 | 000,082,128 | ---- | C] () -- C:\Windows\System32\ativce02.dat
[2014-04-01 00:06:22 | 000,234,804 | ---- | C] () -- C:\Windows\System32\ativvaxy_cik.dat
[2014-04-01 00:04:42 | 000,233,008 | ---- | C] () -- C:\Windows\System32\ativvaxy_cik_nd.dat
[2014-02-06 17:45:58 | 000,134,192 | ---- | C] () -- C:\Windows\System32\ativce03.dat
[2014-01-16 19:00:46 | 000,273,712 | ---- | C] () -- C:\Windows\System32\ativvaxy_vi_nd.dat
[2014-01-16 18:59:20 | 000,275,124 | ---- | C] () -- C:\Windows\System32\ativvaxy_vi.dat
[2014-01-16 10:34:52 | 000,723,841 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2012-09-28 21:45:16 | 000,246,272 | ---- | C] () -- C:\Windows\System32\rtvcvfw64.dll
[2012-09-28 21:45:06 | 000,247,296 | ---- | C] () -- C:\Windows\System32\rtvcvfw32.dll
========== ZeroAccess Check ==========
[2009-07-14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014-05-16 01:58:00 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
[2014-05-16 15:19:00 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\2K Sports
[2014-05-16 01:33:23 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\AIMP3
[2014-05-16 01:01:06 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\AVAST Software
[2014-05-16 02:15:55 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\DiskDefrag
[2014-05-16 01:46:45 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\GlarySoft
[2014-05-16 02:02:40 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\ipla
[2014-05-16 00:03:45 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\library_dir
[2014-05-16 02:04:29 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\NapiProjekt
[2014-05-16 15:25:54 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Origin
[2014-05-16 01:44:28 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\rmi
[2014-05-16 13:28:17 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\TS3Client
[2014-05-17 19:45:18 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\uTorrent
========== Purity Check ==========
< End of report >
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Pobrane
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,49 Gb Total Physical Memory | 1,87 Gb Available Physical Memory | 53,44% Memory free
6,98 Gb Paging File | 5,19 Gb Available in Paging File | 74,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 44,56 Gb Free Space | 39,90% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 434,88 Gb Free Space | 93,37% Space Free | Partition Type: NTFS
Computer Name: KOMPODYNA | User Name: Odyn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014-05-17 20:10:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Pobrane\OTL_[www.programosy.pl].exe
PRC - [2014-05-17 20:03:43 | 000,380,416 | ---- | M] () -- D:\Pobrane\bddg2gdy.exe
PRC - [2014-05-17 12:17:16 | 000,317,720 | ---- | M] () -- C:\Program Files\webget\updatewebget.exe
PRC - [2014-05-17 11:44:08 | 000,317,720 | ---- | M] () -- C:\Program Files\webget\bin\utilwebget.exe
PRC - [2014-05-17 03:34:54 | 000,096,536 | ---- | M] () -- C:\Program Files\webget\bin\webget.BrowserAdapter.exe
PRC - [2014-05-16 18:34:48 | 000,239,384 | ---- | M] () -- C:\Program Files\webget\bin\webget.PurBrowse.exe
PRC - [2014-05-16 01:02:42 | 000,109,048 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2014-05-16 01:00:42 | 003,873,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-05-16 01:00:42 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-05-16 00:46:57 | 001,863,856 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
PRC - [2014-05-08 15:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014-05-07 04:26:43 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2014-04-18 03:29:40 | 000,491,520 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2014-04-18 03:29:16 | 000,208,896 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2014-03-27 08:22:58 | 000,465,064 | ---- | M] () -- C:\Program Files\MSI Afterburner\MSIAfterburner.exe
PRC - [2013-08-07 14:24:00 | 000,015,720 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2012-11-30 04:55:25 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011-03-28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010-11-20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010-11-20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2014-05-17 20:03:43 | 000,380,416 | ---- | M] () -- D:\Pobrane\bddg2gdy.exe
MOD - [2014-05-17 03:34:54 | 000,096,536 | ---- | M] () -- C:\Program Files\webget\bin\webget.BrowserAdapter.exe
MOD - [2014-05-16 07:56:27 | 000,250,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\013a0910def084b04290c8d8a1d8a033\WindowsFormsIntegration.ni.dll
MOD - [2014-05-16 07:56:07 | 013,583,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\3d247ccfb800c38a29cf91c27a6339da\System.Web.ni.dll
MOD - [2014-05-16 07:55:02 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\27e8f505ddb7718933b9c029f6f7a3c4\PresentationFramework-SystemXml.ni.dll
MOD - [2014-05-16 01:00:42 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-05-16 00:46:57 | 016,361,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_13_0_0_214.dll
MOD - [2014-05-16 00:45:33 | 007,785,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\668bc5e53fd656dc16c9f40ea15e872e\System.Xml.ni.dll
MOD - [2014-05-16 00:45:29 | 001,873,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f246b71bfd9c1537167b7f6d4f18cd01\System.Xaml.ni.dll
MOD - [2014-05-16 00:45:28 | 012,895,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\ac38cb30c15eb9e4a54459ee01e9f8e6\System.Windows.Forms.ni.dll
MOD - [2014-05-16 00:45:21 | 000,797,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\57d66541f1d5d1c7888058a8d52b0b9c\System.Runtime.Remoting.ni.dll
MOD - [2014-05-16 00:45:21 | 000,218,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\db1c3cbe2929192ad0361f64a25481d5\System.ServiceProcess.ni.dll
MOD - [2014-05-16 00:45:20 | 001,639,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\ce11900fa489575613dc777c7fbb0d7d\System.Drawing.ni.dll
MOD - [2014-05-16 00:45:15 | 000,967,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7ece7799d670cdfc1393b98b0668a046\System.Configuration.ni.dll
MOD - [2014-05-16 00:45:15 | 000,458,240 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\422aaa813823622198be87739142c44e\PresentationFramework.Aero.ni.dll
MOD - [2014-05-16 00:45:14 | 018,753,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\613fd0f86fc699adfe3184b2e746aa18\PresentationFramework.ni.dll
MOD - [2014-05-16 00:45:05 | 011,014,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\eed4ad7c1049e7cf47606479d68ec1de\PresentationCore.ni.dll
MOD - [2014-05-16 00:44:59 | 003,904,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a40acfa4a0c4bb0dbf824ace588583ba\WindowsBase.ni.dll
MOD - [2014-05-16 00:44:56 | 006,982,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\e0fea191b75897ec38735bfc31b89fe0\System.Core.ni.dll
MOD - [2014-05-16 00:44:52 | 010,067,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\b75ba99f72f116d8951b0f2bba8c276a\System.ni.dll
MOD - [2014-05-16 00:44:47 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll
MOD - [2014-05-07 04:27:09 | 003,839,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014-03-27 08:22:58 | 000,465,064 | ---- | M] () -- C:\Program Files\MSI Afterburner\MSIAfterburner.exe
MOD - [2014-03-20 14:13:24 | 000,631,296 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTHAL.dll
MOD - [2014-03-20 14:13:02 | 000,216,064 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTCore.dll
MOD - [2014-03-20 14:12:52 | 000,127,488 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTUI.dll
MOD - [2014-03-20 14:12:46 | 000,071,680 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTMUI.dll
MOD - [2014-03-20 14:12:40 | 000,056,832 | ---- | M] () -- C:\Program Files\MSI Afterburner\RTFC.dll
========== Services (SafeList) ==========
SRV - [2014-05-17 12:17:16 | 000,317,720 | ---- | M] () [Auto | Running] -- C:\Program Files\webget\updatewebget.exe -- (Update webget)
SRV - [2014-05-17 11:44:08 | 000,317,720 | ---- | M] () [Auto | Running] -- C:\Program Files\webget\bin\utilwebget.exe -- (Util webget)
SRV - [2014-05-16 07:44:51 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2014-05-16 01:02:42 | 000,109,048 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2014-05-16 01:00:42 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014-05-16 00:46:57 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-05-08 15:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-05-07 04:27:01 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-04-18 03:29:16 | 000,208,896 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2014-02-08 05:18:42 | 000,569,024 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013-08-07 14:24:00 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011-04-01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011-03-28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Odyn\AppData\Local\Temp\uwtcqpoc.sys -- (uwtcqpoc)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2014-05-16 01:46:45 | 000,017,088 | ---- | M] (Glarysoft Ltd) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\GUBootStartup.sys -- (GUBootStartup)
DRV - [2014-05-16 01:02:59 | 000,270,240 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdisFlt.sys -- (aswNdisFlt)
DRV - [2014-05-16 01:02:43 | 000,026,136 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2014-05-16 01:00:59 | 000,777,488 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsnx.sys -- (aswSnx)
DRV - [2014-05-16 01:00:59 | 000,411,680 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsp.sys -- (aswSP)
DRV - [2014-05-16 01:00:59 | 000,068,312 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswstm.sys -- (aswStm)
DRV - [2014-05-16 01:00:43 | 000,180,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014-05-16 01:00:43 | 000,081,768 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014-05-16 01:00:43 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014-05-16 01:00:43 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014-05-16 01:00:43 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2014-05-14 09:02:44 | 000,016,064 | ---- | M] (Glarysoft Ltd) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\BootDefragDriver.sys -- (BootDefragDriver)
DRV - [2014-05-12 16:40:58 | 000,052,920 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys -- ({9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw)
DRV - [2014-04-18 04:35:20 | 013,515,264 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2014-04-18 03:06:30 | 000,512,000 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2013-12-19 18:44:40 | 000,077,824 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2013-08-02 03:38:30 | 000,505,192 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\iaStorA.sys -- (iaStorA)
DRV - [2013-08-02 03:38:26 | 000,025,448 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\iaStorF.sys -- (iaStorF)
DRV - [2013-03-11 03:30:10 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\MSI Afterburner\RTCore32.sys -- (RTCore32)
DRV - [2012-12-29 22:59:38 | 000,024,184 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\Windows\System32\speedfan.sys -- (speedfan)
DRV - [2012-09-01 01:00:02 | 000,027,792 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan620.sys -- (RTVLANPT)
DRV - [2012-07-03 14:32:00 | 000,049,808 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam620.sys -- (RTTEAMPT)
DRV - [2011-12-02 12:38:08 | 000,199,528 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2011-06-15 15:11:20 | 000,033,056 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2011-05-13 03:21:06 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011-05-13 03:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011-05-13 03:21:06 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2011-05-13 03:21:06 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011-05-13 03:21:04 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010-11-20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010-11-20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010-11-20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010-11-20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010-11-20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010-11-20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010-10-19 23:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2010-04-27 16:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2010-04-27 16:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2010-04-27 16:57:24 | 000,031,816 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2010-04-27 16:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2010-04-27 14:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002-01-12 17:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PortTalk.sys -- (PortTalk)
DRV - [2000-01-01 02:00:00 | 000,027,888 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV - [1996-04-03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-281493417-172796843-820964179-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-281493417-172796843-820964179-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-281493417-172796843-820964179-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.pah.org.pl/nasze-dzialania/8/pajacyk"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2018.95
FF - prefs.js..extensions.enabledAddons: %7B9edd0ea8-2819-47c2-8320-b007d5996f8a%7D:1.0.1
FF - prefs.js..extensions.enabledAddons: %7B7b1bf0b6-a1b9-42b0-b75d-252036438bdc%7D:8.4
FF - prefs.js..extensions.enabledAddons: thumbnailZoom%40dadler.github.com:2.7
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.3.2: C:\Program Files\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-16 01:02:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2014-05-15 23:52:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\Extensions
[2014-05-16 14:02:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\Firefox\Profiles\8okhcgbf.default\extensions
[2014-05-16 14:02:05 | 000,168,246 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\thumbnailZoom@dadler.github.com.xpi
[2014-05-16 14:02:05 | 000,059,976 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi
[2014-05-16 13:55:01 | 000,008,893 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\{9edd0ea8-2819-47c2-8320-b007d5996f8a}.xpi
[2014-05-16 13:04:05 | 000,957,880 | ---- | M] () (No name found) -- C:\Users\Odyn\AppData\Roaming\mozilla\firefox\profiles\8okhcgbf.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-05-15 23:52:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014-05-15 23:52:21 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-05-16 01:02:43 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Error reading preferences file
CHR - Extension: Dokumenty Google = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\
CHR - Extension: Dysk Google = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.1_0\
CHR - Extension: Szukaj w Google = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Photo Zoom for Facebook = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi\1.1312.1.2_0\
CHR - Extension: AdBlock = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.34_0\
CHR - Extension: avast! Online Security = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2018.95_0\
CHR - Extension: Illimitux = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\mamnihopcnbfnbfnnneplcohmnkkpipb\1.0_0\
CHR - Extension: Google Wallet = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Odyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009-06-10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (webget) - {dc264a72-fa75-4948-b881-ea8eff8e5dd2} - C:\Program Files\webget\webgetBHO.dll (webget)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-281493417-172796843-820964179-1000..\Run: [GUDelayStartup] C:\Program Files\Glary Utilities 5\StartupManager.exe (Glarysoft Ltd)
O4 - HKU\S-1-5-21-281493417-172796843-820964179-1000..\Run: [MSI Afterburner] C:\Program Files\MSI Afterburner\MSIAfterburner.exe ()
O4 - HKU\S-1-5-21-281493417-172796843-820964179-1000..\Run: [OscarX7Mouse5Mode] C:\Program Files\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-281493417-172796843-820964179-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.60 62.179.1.61
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{43F0E5C3-73B8-42AE-886B-7647F548E943}: DhcpNameServer = 62.179.1.60 62.179.1.61
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (BootDefrag.exe)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014-05-17 19:40:49 | 000,000,000 | ---D | C] -- C:\Program Files\Process Explorer
[2014-05-17 19:38:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
[2014-05-17 19:38:06 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune
[2014-05-17 13:13:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview
[2014-05-17 13:12:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2014-05-17 13:11:16 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2014-05-17 13:09:07 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014-05-17 12:31:10 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2014-05-17 12:31:01 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2014-05-17 12:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2014-05-17 12:29:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014-05-17 12:29:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2014-05-17 12:07:57 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Windows Live
[2014-05-17 12:07:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2014-05-17 12:05:51 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\LSCSHostPolicy.dll
[2014-05-17 12:05:51 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys
[2014-05-17 12:05:51 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2014-05-17 12:05:49 | 001,171,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2014-05-17 12:05:48 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll
[2014-05-17 12:05:48 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll
[2014-05-17 12:05:48 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tssrvlic.dll
[2014-05-17 12:05:47 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2014-05-17 12:05:47 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2014-05-17 12:05:47 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2014-05-17 12:05:46 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2014-05-17 12:05:46 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizui.dll
[2014-05-17 12:05:45 | 003,207,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2014-05-17 12:05:45 | 001,334,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2014-05-17 12:05:45 | 000,520,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcupdate_GenuineIntel.dll
[2014-05-17 12:05:44 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2014-05-17 12:05:44 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2014-05-17 12:05:43 | 005,066,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuthFWSnapin.dll
[2014-05-17 12:05:43 | 001,115,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RacEngn.dll
[2014-05-17 12:05:42 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2014-05-17 12:05:41 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2014-05-17 12:05:41 | 001,828,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d9.dll
[2014-05-17 12:05:41 | 000,505,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2014-05-17 12:05:41 | 000,456,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spinstall.exe
[2014-05-17 12:05:41 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wer.dll
[2014-05-17 12:05:41 | 000,280,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spreview.exe
[2014-05-17 12:05:41 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PushPrinterConnections.exe
[2014-05-17 12:05:40 | 003,367,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSAT.exe
[2014-05-17 12:05:40 | 001,371,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dwmcore.dll
[2014-05-17 12:05:40 | 000,863,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diagperf.dll
[2014-05-17 12:05:40 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWorkspace.dll
[2014-05-17 12:05:40 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsmf.dll
[2014-05-17 12:05:40 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scavengeui.dll
[2014-05-17 12:05:39 | 002,522,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dbgeng.dll
[2014-05-17 12:05:39 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2014-05-17 12:05:39 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpprefcl.dll
[2014-05-17 12:05:39 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2014-05-17 12:05:39 | 000,260,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpshell.exe
[2014-05-17 12:05:38 | 002,151,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcndmgr.dll
[2014-05-17 12:05:38 | 001,792,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2014-05-17 12:05:38 | 001,712,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2014-05-17 12:05:38 | 001,555,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certmgr.dll
[2014-05-17 12:05:38 | 000,974,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppobjs.dll
[2014-05-17 12:05:38 | 000,732,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2fs.dll
[2014-05-17 12:05:38 | 000,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2014-05-17 12:05:38 | 000,508,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2014-05-17 12:05:38 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2014-05-17 12:05:38 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drvstore.dll
[2014-05-17 12:05:38 | 000,252,928 | ---- | C] (Microsoft) -- C:\Windows\System32\DShowRdpFilter.dll
[2014-05-17 12:05:38 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcbuilder.exe
[2014-05-17 12:05:38 | 000,049,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2014-05-17 12:05:37 | 000,442,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2014-05-17 12:05:37 | 000,412,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppwinob.dll
[2014-05-17 12:05:37 | 000,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
[2014-05-17 12:05:37 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
[2014-05-17 12:05:37 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfds.dll
[2014-05-17 12:05:37 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\framedynos.dll
[2014-05-17 12:05:37 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp.dll
[2014-05-17 12:05:36 | 001,063,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\werconcpl.dll
[2014-05-17 12:05:36 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NaturalLanguage6.dll
[2014-05-17 12:05:36 | 000,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\calc.exe
[2014-05-17 12:05:36 | 000,762,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroles.dll
[2014-05-17 12:05:36 | 000,508,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2014-05-17 12:05:36 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\evr.dll
[2014-05-17 12:05:36 | 000,339,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appmgr.dll
[2014-05-17 12:05:36 | 000,335,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSATAPI.dll
[2014-05-17 12:05:36 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2014-05-17 12:05:36 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2014-05-17 12:05:36 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpclip.exe
[2014-05-17 12:05:36 | 000,161,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpinit.exe
[2014-05-17 12:05:36 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2014-05-17 12:05:36 | 000,144,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basecsp.dll
[2014-05-17 12:05:35 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2014-05-17 12:05:35 | 000,778,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlsrv32.dll
[2014-05-17 12:05:35 | 000,477,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lpksetup.exe
[2014-05-17 12:05:35 | 000,271,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fveapi.dll
[2014-05-17 12:05:35 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vpnike.dll
[2014-05-17 12:05:35 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hgprint.dll
[2014-05-17 12:05:35 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tspubwmi.dll
[2014-05-17 12:05:35 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prncache.dll
[2014-05-17 12:05:34 | 002,504,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVCORE.DLL
[2014-05-17 12:05:34 | 001,750,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnidui.dll
[2014-05-17 12:05:34 | 000,690,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ci.dll
[2014-05-17 12:05:34 | 000,464,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrptadm.dll
[2014-05-17 12:05:34 | 000,458,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSDApi.dll
[2014-05-17 12:05:34 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlangpui.dll
[2014-05-17 12:05:34 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpeffects.dll
[2014-05-17 12:05:34 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aepdu.dll
[2014-05-17 12:05:34 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scansetting.dll
[2014-05-17 12:05:34 | 000,213,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MMDevAPI.dll
[2014-05-17 12:05:34 | 000,175,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\vmbus.sys
[2014-05-17 12:05:34 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QSHVHOST.DLL
[2014-05-17 12:05:34 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\net1.exe
[2014-05-17 12:05:34 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpchttp.dll
[2014-05-17 12:05:34 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aitagent.exe
[2014-05-17 12:05:34 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2014-05-17 12:05:34 | 000,101,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2014-05-17 12:05:33 | 002,146,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SyncCenter.dll
[2014-05-17 12:05:33 | 000,907,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdengin2.dll
[2014-05-17 12:05:33 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2ENC.DLL
[2014-05-17 12:05:33 | 000,782,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webservices.dll
[2014-05-17 12:05:33 | 000,727,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcmde.dll
[2014-05-17 12:05:33 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2.dll
[2014-05-17 12:05:33 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netdiagfx.dll
[2014-05-17 12:05:33 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmicsvc.exe
[2014-05-17 12:05:33 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tscfgwmi.dll
[2014-05-17 12:05:33 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscobj.dll
[2014-05-17 12:05:33 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fde.dll
[2014-05-17 12:05:33 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupcl.exe
[2014-05-17 12:05:33 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll
[2014-05-17 12:05:33 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll
[2014-05-17 12:05:32 | 002,217,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bootres.dll
[2014-05-17 12:05:32 | 001,624,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPEncEn.dll
[2014-05-17 12:05:32 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Narrator.exe
[2014-05-17 12:05:32 | 000,679,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoconv.exe
[2014-05-17 12:05:32 | 000,658,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autofmt.exe
[2014-05-17 12:05:32 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DXPTaskRingtone.dll
[2014-05-17 12:05:32 | 000,303,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msinfo32.exe
[2014-05-17 12:05:32 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
[2014-05-17 12:05:32 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vaultsvc.dll
[2014-05-17 12:05:32 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
[2014-05-17 12:05:32 | 000,194,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\halmacpi.dll
[2014-05-17 12:05:32 | 000,194,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hal.dll
[2014-05-17 12:05:32 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiohlp.dll
[2014-05-17 12:05:32 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
[2014-05-17 12:05:32 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dwmredir.dll
[2014-05-17 12:05:32 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hbaapi.dll
[2014-05-17 12:05:32 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
[2014-05-17 12:05:32 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\proquota.exe
[2014-05-17 12:05:31 | 001,326,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanpref.dll
[2014-05-17 12:05:31 | 001,227,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdc.dll
[2014-05-17 12:05:31 | 001,131,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
[2014-05-17 12:05:31 | 000,933,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Vault.dll
[2014-05-17 12:05:31 | 000,665,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2014-05-17 12:05:31 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercpl.dll
[2014-05-17 12:05:31 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipsmsnap.dll
[2014-05-17 12:05:31 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DXP.dll
[2014-05-17 12:05:31 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\untfs.dll
[2014-05-17 12:05:31 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
[2014-05-17 12:05:31 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
[2014-05-17 12:05:31 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapphost.dll
[2014-05-17 12:05:31 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\framedyn.dll
[2014-05-17 12:05:31 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tcpipcfg.dll
[2014-05-17 12:05:31 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe
[2014-05-17 12:05:31 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QAGENT.DLL
[2014-05-17 12:05:31 | 000,155,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
[2014-05-17 12:05:31 | 000,132,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ataport.sys
[2014-05-17 12:05:31 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netid.dll
[2014-05-17 12:05:31 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nci.dll
[2014-05-17 12:05:30 | 001,400,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DxpTaskSync.dll
[2014-05-17 12:05:30 | 001,188,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DiagCpl.dll
[2014-05-17 12:05:30 | 001,066,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtctm.dll
[2014-05-17 12:05:30 | 001,040,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Display.dll
[2014-05-17 12:05:30 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMNetMgr.dll
[2014-05-17 12:05:30 | 000,856,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FirewallControlPanel.dll
[2014-05-17 12:05:30 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\biocpl.dll
[2014-05-17 12:05:30 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2014-05-17 12:05:30 | 000,416,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiadefui.dll
[2014-05-17 12:05:30 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\termmgr.dll
[2014-05-17 12:05:30 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\puiobj.dll
[2014-05-17 12:05:30 | 000,316,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sharemediacpl.dll
[2014-05-17 12:05:30 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eudcedit.exe
[2014-05-17 12:05:30 | 000,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msconfig.exe
[2014-05-17 12:05:30 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppcomapi.dll
[2014-05-17 12:05:30 | 000,140,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\scsiport.sys
[2014-05-17 12:05:30 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2014-05-17 12:05:30 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logoncli.dll
[2014-05-17 12:05:30 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shsetup.dll
[2014-05-17 12:05:30 | 000,098,816 | ---- | C] (Microsoft) -- C:\Windows\System32\Robocopy.exe
[2014-05-17 12:05:30 | 000,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\winhv.sys
[2014-05-17 12:05:30 | 000,040,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\vmstorfl.sys
[2014-05-17 12:05:30 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\userinit.exe
[2014-05-17 12:05:29 | 002,202,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SensorsCpl.dll
[2014-05-17 12:05:29 | 002,157,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\themecpl.dll
[2014-05-17 12:05:29 | 001,644,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcenter.dll
[2014-05-17 12:05:29 | 000,941,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mblctr.exe
[2014-05-17 12:05:29 | 000,766,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpccpl.dll
[2014-05-17 12:05:29 | 000,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VAN.dll
[2014-05-17 12:05:29 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PerfCenterCPL.dll
[2014-05-17 12:05:29 | 000,600,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usercpl.dll
[2014-05-17 12:05:29 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2014-05-17 12:05:29 | 000,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscms.dll
[2014-05-17 12:05:29 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\localsec.dll
[2014-05-17 12:05:29 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoScreensaver.scr
[2014-05-17 12:05:29 | 000,410,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanui.dll
[2014-05-17 12:05:29 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SndVol.exe
[2014-05-17 12:05:29 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hgcpl.dll
[2014-05-17 12:05:29 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mprddm.dll
[2014-05-17 12:05:29 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SndVolSSO.dll
[2014-05-17 12:05:29 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FWPUCLNT.DLL
[2014-05-17 12:05:29 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcdsrv.dll
[2014-05-17 12:05:29 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prntvpt.dll
[2014-05-17 12:05:29 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscmmc.dll
[2014-05-17 12:05:29 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
[2014-05-17 12:05:29 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasacct.dll
[2014-05-17 12:05:29 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\w32tm.exe
[2014-05-17 12:05:29 | 000,028,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storvsc.sys
[2014-05-17 12:05:28 | 003,727,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\accessibilitycpl.dll
[2014-05-17 12:05:28 | 002,130,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkmap.dll
[2014-05-17 12:05:28 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sud.dll
[2014-05-17 12:05:28 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionCenter.dll
[2014-05-17 12:05:28 | 000,516,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\main.cpl
[2014-05-17 12:05:28 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspbda.dll
[2014-05-17 12:05:28 | 000,395,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prnfldr.dll
[2014-05-17 12:05:28 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysmon.ocx
[2014-05-17 12:05:28 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizeng.dll
[2014-05-17 12:05:28 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slui.exe
[2014-05-17 12:05:28 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
[2014-05-17 12:05:28 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wusa.exe
[2014-05-17 12:05:28 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroleui.dll
[2014-05-17 12:05:28 | 000,312,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MCEWMDRMNDBootstrap.dll
[2014-05-17 12:05:28 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iprtrmgr.dll
[2014-05-17 12:05:28 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MediaMetadataHandler.dll
[2014-05-17 12:05:28 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskbarcpl.dll
[2014-05-17 12:05:28 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSAC3ENC.DLL
[2014-05-17 12:05:28 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe
[2014-05-17 12:05:28 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\defaultlocationcpl.dll
[2014-05-17 12:05:28 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OnLineIDCpl.dll
[2014-05-17 12:05:28 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys
[2014-05-17 12:05:28 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsldp.dll
[2014-05-17 12:05:28 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrad.dll
[2014-05-17 12:05:28 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netjoin.dll
[2014-05-17 12:05:28 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdeploy.dll
[2014-05-17 12:05:28 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidclass.sys
[2014-05-17 12:05:28 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
[2014-05-17 12:05:27 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OobeFldr.dll
[2014-05-17 12:05:27 | 000,750,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdcpl.dll
[2014-05-17 12:05:27 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\blackbox.dll
[2014-05-17 12:05:27 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
[2014-05-17 12:05:27 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bthprops.cpl
[2014-05-17 12:05:27 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshwfp.dll
[2014-05-17 12:05:27 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TabletPC.cpl
[2014-05-17 12:05:27 | 000,577,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
[2014-05-17 12:05:27 | 000,537,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionCenterCPL.dll
[2014-05-17 12:05:27 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DeviceCenter.dll
[2014-05-17 12:05:27 | 000,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shwebsvc.dll
[2014-05-17 12:05:27 | 000,410,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\systemcpl.dll
[2014-05-17 12:05:27 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\intl.cpl
[2014-05-17 12:05:27 | 000,297,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntprint.dll
[2014-05-17 12:05:27 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcdedit.exe
[2014-05-17 12:05:27 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sethc.exe
[2014-05-17 12:05:27 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpx.dll
[2014-05-17 12:05:27 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\recdisc.exe
[2014-05-17 12:05:27 | 000,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\efscore.dll
[2014-05-17 12:05:27 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ksproxy.ax
[2014-05-17 12:05:27 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpsrcwp.dll
[2014-05-17 12:05:27 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fvecpl.dll
[2014-05-17 12:05:27 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmartcardCredentialProvider.dll
[2014-05-17 12:05:27 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsutil.dll
[2014-05-17 12:05:27 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ifsutil.dll
[2014-05-17 12:05:27 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcdboot.exe
[2014-05-17 12:05:27 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoplay.dll
[2014-05-17 12:05:27 | 000,137,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\halacpi.dll
[2014-05-17 12:05:27 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\recovery.dll
[2014-05-17 12:05:27 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppnp.dll
[2014-05-17 12:05:27 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPHLPR.DLL
[2014-05-17 12:05:27 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\migisol.dll
[2014-05-17 12:05:27 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\fms.dll
[2014-05-17 12:05:27 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3cfg.dll
[2014-05-17 12:05:27 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSTPager.ax
[2014-05-17 12:05:27 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpsign.exe
[2014-05-17 12:05:27 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ftp.exe
[2014-05-17 12:05:27 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sisbkup.dll
[2014-05-17 12:05:26 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmiEngine.dll
[2014-05-17 12:05:26 | 000,592,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
[2014-05-17 12:05:26 | 000,586,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfrgui.exe
[2014-05-17 12:05:26 | 000,444,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wvc.dll
[2014-05-17 12:05:26 | 000,438,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AdmTmpl.dll
[2014-05-17 12:05:26 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanmsm.dll
[2014-05-17 12:05:26 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wimgapi.dll
[2014-05-17 12:05:26 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshipsec.dll
[2014-05-17 12:05:26 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3ui.dll
[2014-05-17 12:05:26 | 000,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ssText3d.scr
[2014-05-17 12:05:26 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srrstr.dll
[2014-05-17 12:05:26 | 000,254,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsqmcons.exe
[2014-05-17 12:05:26 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ReAgent.dll
[2014-05-17 12:05:26 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wavemsp.dll
[2014-05-17 12:05:26 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PkgMgr.exe
[2014-05-17 12:05:26 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qasf.dll
[2014-05-17 12:05:26 | 000,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysclass.dll
[2014-05-17 12:05:26 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ocsetup.exe
[2014-05-17 12:05:26 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qcap.dll
[2014-05-17 12:05:26 | 000,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationSettings.exe
[2014-05-17 12:05:26 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\uxlib.dll
[2014-05-17 12:05:26 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupugc.exe
[2014-05-17 12:05:26 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayServices.dll
[2014-05-17 12:05:26 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\isoburn.exe
[2014-05-17 12:05:26 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
[2014-05-17 12:05:26 | 000,051,200 | ---- | C] (Twain Working Group) -- C:\Windows\twain_32.dll
[2014-05-17 12:05:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzutil.exe
[2014-05-17 12:05:26 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll
[2014-05-17 12:05:25 | 001,111,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\onexui.dll
[2014-05-17 12:05:25 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmsdk.dll
[2014-05-17 12:05:25 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
[2014-05-17 12:05:25 | 000,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmmgrtn.dll
[2014-05-17 12:05:25 | 000,327,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wimserv.exe
[2014-05-17 12:05:25 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nltest.exe
[2014-05-17 12:05:25 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsAnytimeUpgradeResults.exe
[2014-05-17 12:05:25 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskraid.exe
[2014-05-17 12:05:25 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iTVData.dll
[2014-05-17 12:05:25 | 000,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DevicePairingFolder.dll
[2014-05-17 12:05:25 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2014-05-17 12:05:25 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\input.dll
[2014-05-17 12:05:25 | 000,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpdwcn.dll
[2014-05-17 12:05:25 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanconn.dll
[2014-05-17 12:05:25 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
[2014-05-17 12:05:25 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ocsetapi.dll
[2014-05-17 12:05:25 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsbas.dll
[2014-05-17 12:05:25 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfmon.exe
[2014-05-17 12:05:25 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nslookup.exe
[2014-05-17 12:05:25 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logagent.exe
[2014-05-17 12:05:25 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2014-05-17 12:05:25 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UserAccountControlSettings.dll
[2014-05-17 12:05:25 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\bfsvc.exe
[2014-05-17 12:05:25 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\runonce.exe
[2014-05-17 12:05:25 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPCRYPT.DLL
[2014-05-17 12:05:25 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\acppage.dll
[2014-05-17 12:05:25 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vpnikeapi.dll
[2014-05-17 12:05:24 | 001,160,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2014-05-17 12:05:24 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMADMOD.DLL
[2014-05-17 12:05:24 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Bubbles.scr
[2014-05-17 12:05:24 | 000,541,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVSDECD.DLL
[2014-05-17 12:05:24 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmdev.dll
[2014-05-17 12:05:24 | 000,436,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmnet.dll
[2014-05-17 12:05:24 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceStatus.dll
[2014-05-17 12:05:24 | 000,350,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2014-05-17 12:05:24 | 000,318,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2014-05-17 12:05:24 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlcese30.dll
[2014-05-17 12:05:24 | 000,283,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdv.dll
[2014-05-17 12:05:24 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
[2014-05-17 12:05:24 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapp3hst.dll
[2014-05-17 12:05:24 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mystify.scr
[2014-05-17 12:05:24 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Ribbons.scr
[2014-05-17 12:05:24 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bitsadmin.exe
[2014-05-17 12:05:24 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceSyncProvider.dll
[2014-05-17 12:05:24 | 000,179,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ActionQueue.dll
[2014-05-17 12:05:24 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFPlay.dll
[2014-05-17 12:05:24 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VBICodec.ax
[2014-05-17 12:05:24 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercfg.cpl
[2014-05-17 12:05:24 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MdSched.exe
[2014-05-17 12:05:24 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EhStorAPI.dll
[2014-05-17 12:05:24 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rmcast.sys
[2014-05-17 12:05:24 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3msm.dll
[2014-05-17 12:05:24 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiavideo.dll
[2014-05-17 12:05:24 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CscMig.dll
[2014-05-17 12:05:24 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shacct.dll
[2014-05-17 12:05:24 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Kswdmcap.ax
[2014-05-17 12:05:24 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QSVRMGMT.DLL
[2014-05-17 12:05:24 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fphc.dll
[2014-05-17 12:05:24 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kstvtune.ax
[2014-05-17 12:05:24 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logman.exe
[2014-05-17 12:05:24 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\olethk32.dll
[2014-05-17 12:05:24 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mapistub.dll
[2014-05-17 12:05:24 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mapi32.dll
[2014-05-17 12:05:24 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tabcal.exe
[2014-05-17 12:05:24 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lpremove.exe
[2014-05-17 12:05:24 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PnPUnattend.exe
[2014-05-17 12:05:24 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncryptui.dll
[2014-05-17 12:05:24 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\djoin.exe
[2014-05-17 12:05:24 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unimdmat.dll
[2014-05-17 12:05:24 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpd3d.dll
[2014-05-17 12:05:24 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\takeown.exe
[2014-05-17 12:05:24 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanprotdim.dll
[2014-05-17 12:05:24 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\utildll.dll
[2014-05-17 12:05:24 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsium.dll
[2014-05-17 12:05:24 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsmproxy.dll
[2014-05-17 12:05:24 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2014-05-17 12:05:23 | 001,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IMJP10.IME
[2014-05-17 12:05:23 | 000,739,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2014-05-17 12:05:23 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSTIFF.dll
[2014-05-17 12:05:23 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2014-05-17 12:05:23 | 000,278,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2014-05-17 12:05:23 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unattend.dll
[2014-05-17 12:05:23 | 000,182,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RelPost.exe
[2014-05-17 12:05:23 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msorcl32.dll
[2014-05-17 12:05:23 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\itircl.dll
[2014-05-17 12:05:23 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsicli.exe
[2014-05-17 12:05:23 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpps.dll
[2014-05-17 12:05:23 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskpart.exe
[2014-05-17 12:05:23 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\desk.cpl
[2014-05-17 12:05:23 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BdeHdCfg.exe
[2014-05-17 12:05:23 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrecst.dll
[2014-05-17 12:05:23 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setupcln.dll
[2014-05-17 12:05:23 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppinst.dll
[2014-05-17 12:05:23 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eappgnui.dll
[2014-05-17 12:05:23 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2014-05-17 12:05:23 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2014-05-17 12:05:23 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmstp.exe
[2014-05-17 12:05:23 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\QCLIPROV.DLL
[2014-05-17 12:05:23 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MuiUnattend.exe
[2014-05-17 12:05:23 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amstream.dll
[2014-05-17 12:05:23 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tlscsp.dll
[2014-05-17 12:05:23 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cca.dll
[2014-05-17 12:05:23 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertPolEng.dll
[2014-05-17 12:05:23 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\findstr.exe
[2014-05-17 12:05:23 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spbcd.dll
[2014-05-17 12:05:23 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vfwwdm32.dll
[2014-05-17 12:05:23 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MultiDigiMon.exe
[2014-05-17 12:05:23 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsnmp32.dll
[2014-05-17 12:05:23 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\umb.dll
[2014-05-17 12:05:23 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\setbcdlocale.dll
[2014-05-17 12:05:23 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ksxbar.ax
[2014-05-17 12:05:23 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wkscli.dll
[2014-05-17 12:05:23 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WavDest.dll
[2014-05-17 12:05:23 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pdhui.dll
[2014-05-17 12:05:23 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basesrv.dll
[2014-05-17 12:05:23 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\relog.exe
[2014-05-17 12:05:23 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciqtz32.dll
[2014-05-17 12:05:23 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiarpc.dll
[2014-05-17 12:05:23 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PrintIsolationProxy.dll
[2014-05-17 12:05:23 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WerFaultSecure.exe
[2014-05-17 12:05:23 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AzSqlExt.dll
[2014-05-17 12:05:23 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qwinsta.exe
[2014-05-17 12:05:23 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiougc.exe
[2014-05-17 12:05:23 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qprocess.exe
[2014-05-17 12:05:23 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msg.exe
[2014-05-17 12:05:23 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netbtugc.exe
[2014-05-17 12:05:23 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quser.exe
[2014-05-17 12:05:23 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tskill.exe
[2014-05-17 12:05:23 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chgport.exe
[2014-05-17 12:05:23 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsdiscon.exe
[2014-05-17 12:05:23 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ReAgentc.exe
[2014-05-17 12:05:23 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chglogon.exe
[2014-05-17 12:05:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tscon.exe
[2014-05-17 12:05:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qappsrv.exe
[2014-05-17 12:05:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logoff.exe
[2014-05-17 12:05:23 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shadow.exe
[2014-05-17 12:05:23 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rwinsta.exe
[2014-05-17 12:05:23 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chgusr.exe
[2014-05-17 12:05:23 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\syssetup.dll
[2014-05-17 12:05:23 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nrpsrv.dll
[2014-05-17 12:05:22 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2014-05-17 12:05:22 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RDPENCDD.dll
[2014-05-17 12:05:22 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppc.dll
[2014-05-17 12:05:22 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2014-05-17 12:05:22 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\napdsnap.dll
[2014-05-17 12:05:22 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\manage-bde.exe
[2014-05-17 12:05:22 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\repair-bde.exe
[2014-05-17 12:05:22 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmicres.dll
[2014-05-17 12:05:22 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetmib1.dll
[2014-05-17 12:05:22 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\g711codc.ax
[2014-05-17 12:05:22 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmbusres.dll
[2014-05-17 12:05:22 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\luainstall.dll
[2014-05-17 12:05:22 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcconf.dll
[2014-05-17 12:05:22 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSMON.dll
[2014-05-17 12:05:22 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmstorfltres.dll
[2014-05-17 12:05:22 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unlodctr.exe
[2014-05-17 12:05:22 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbisurf.ax
[2014-05-17 12:05:22 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdiasqmmodule.dll
[2014-05-17 12:05:22 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdmo.dll
[2014-05-17 12:05:22 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsauth.dll
[2014-05-17 12:05:22 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbrpm.sys
[2014-05-17 12:05:22 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcfg.exe
[2014-05-17 12:05:22 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\HotStartUserAgent.dll
[2014-05-17 12:05:22 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elsTrans.dll
[2014-05-17 12:05:22 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TRAPI.dll
[2014-05-17 12:05:22 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\tdi.sys
[2014-05-17 12:05:22 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdprefdrvapi.dll
[2014-05-17 12:05:22 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spopk.dll
[2014-05-17 12:05:22 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bitsperf.dll
[2014-05-17 12:05:22 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schedcli.dll
[2014-05-17 12:05:22 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\perfts.dll
[2014-05-17 12:05:22 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\reset.exe
[2014-05-17 12:05:22 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\change.exe
[2014-05-17 12:05:22 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\query.exe
[2014-05-17 12:05:22 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\muifontsetup.dll
[2014-05-17 12:05:21 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imkr80.ime
[2014-05-17 12:05:21 | 000,116,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VmbusCoinstaller.dll
[2014-05-17 12:05:21 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VmdCoinstall.dll
[2014-05-17 12:05:21 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IcCoinstall.dll
[2014-05-17 12:05:21 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmictimeprovider.dll
[2014-05-17 12:05:21 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBCAMD2.sys
[2014-05-17 12:05:21 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBCAMD.sys
[2014-05-17 12:05:21 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsdchngr.dll
[2014-05-17 12:05:21 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\VMBusHID.sys
[2014-05-17 12:05:21 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vmbuspipe.dll
[2014-05-17 12:05:21 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshirda.dll
[2014-05-17 12:05:21 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sscore.dll
[2014-05-17 12:05:21 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\riched32.dll
[2014-05-17 12:05:21 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcfgex.dll
[2014-05-17 12:05:21 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
[2014-05-17 12:05:20 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2014-05-17 12:05:20 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlsbres.dll
[2014-05-17 12:05:20 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BlbEvents.dll
[2014-05-17 12:05:20 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pifmgr.dll
[2014-05-17 12:05:20 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RDPREFDD.dll
[2014-05-17 12:05:20 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\C_ISCII.DLL
[2014-05-17 12:05:20 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shunimpl.dll
[2014-05-17 12:05:20 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizres.dll
[2014-05-17 12:05:20 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDSG.DLL
[2014-05-17 12:05:20 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kbdlk41a.dll
[2014-05-17 12:05:20 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDCZ1.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTUQ.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTUF.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDSF.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDPO.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDNEPR.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINBEN.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDGR1.DLL
[2014-05-17 12:05:20 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDGKL.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDUS.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDUGHR1.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTURME.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDTAJIK.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDMON.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDMAORI.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDLT1.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINTEL.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINTAM.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINORI.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINMAR.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINKAN.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDINHIN.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDBULG.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDBLR.DLL
[2014-05-17 12:05:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDBASH.DLL
[2014-05-17 12:05:20 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\vms3cap.sys
[2014-05-17 12:05:20 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDGEO.DLL
[2014-05-17 12:05:20 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2014-05-17 12:05:20 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
[2014-05-17 12:05:17 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdscore.dll
[2014-05-17 12:05:13 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wbemcomn.dll
[2014-05-17 12:05:10 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqmapi.dll
[2014-05-17 11:59:47 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2014-05-17 11:52:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2014-05-17 11:52:19 | 000,031,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msonpmon.dll
[2014-05-17 11:51:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2014-05-17 11:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2014-05-17 11:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2014-05-17 11:51:17 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2014-05-17 11:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2014-05-17 11:49:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Microsoft Help
[2014-05-17 11:49:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2014-05-17 11:49:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2014-05-17 11:49:11 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2014-05-16 20:04:38 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2014-05-16 20:04:38 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2014-05-16 20:04:36 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2014-05-16 20:04:35 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2014-05-16 20:04:09 | 000,231,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2014-05-16 15:19:00 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\2K Sports
[2014-05-16 15:17:26 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\PunkBuster
[2014-05-16 15:17:24 | 000,000,000 | ---D | C] -- C:\Users\Odyn\Documents\Battlefield 3
[2014-05-16 15:16:52 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\ESN
[2014-05-16 15:16:50 | 000,000,000 | ---D | C] -- C:\Program Files\Battlelog Web Plugins
[2014-05-16 14:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Core
[2014-05-16 14:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Logs
[2014-05-16 14:48:56 | 000,000,000 | -H-D | C] -- C:\Program Files\Common Files\EAInstaller
[2014-05-16 14:36:57 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\WinRAR
[2014-05-16 14:26:29 | 000,000,000 | ---D | C] -- C:\Users\Odyn\Documents\Assetto Corsa
[2014-05-16 14:26:11 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2014-05-16 14:26:11 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2014-05-16 14:26:11 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2014-05-16 14:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2014-05-16 14:14:26 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2014-05-16 14:14:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logitech
[2014-05-16 13:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2014-05-16 13:46:18 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Origin
[2014-05-16 13:46:16 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Origin
[2014-05-16 13:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2014-05-16 13:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2014-05-16 13:28:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2014-05-16 13:28:19 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2014-05-16 13:25:00 | 000,052,920 | ---- | C] (StdLib) -- C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys
[2014-05-16 13:21:21 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\TS3Client
[2014-05-16 13:21:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2014-05-16 13:21:18 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2014-05-16 13:11:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2014-05-16 13:11:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2014-05-16 13:11:10 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2014-05-16 13:07:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014-05-16 13:07:24 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Google
[2014-05-16 13:07:24 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2014-05-16 12:52:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2014-05-16 08:09:44 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2014-05-16 08:09:44 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2014-05-16 08:09:44 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2014-05-16 07:49:24 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2014-05-16 07:49:23 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2014-05-16 07:49:23 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2014-05-16 07:47:55 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2014-05-16 07:47:55 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014-05-16 07:47:55 | 001,806,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014-05-16 07:47:55 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014-05-16 07:47:55 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014-05-16 07:47:55 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014-05-16 07:47:55 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2014-05-16 07:47:55 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014-05-16 07:47:55 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2014-05-16 07:47:55 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014-05-16 07:47:55 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2014-05-16 07:47:55 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014-05-16 07:47:55 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014-05-16 07:47:55 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2014-05-16 07:47:55 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014-05-16 07:47:55 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2014-05-16 07:47:55 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2014-05-16 07:47:55 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2014-05-16 07:47:55 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014-05-16 07:47:55 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2014-05-16 07:47:55 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2014-05-16 07:47:55 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2014-05-16 07:47:55 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2014-05-16 07:47:55 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2014-05-16 07:47:55 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2014-05-16 07:47:55 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014-05-16 07:47:55 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014-05-16 07:47:55 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014-05-16 07:47:55 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2014-05-16 07:47:55 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2014-05-16 07:47:55 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014-05-16 07:47:55 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2014-05-16 07:47:55 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014-05-16 07:47:55 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2014-05-16 07:47:55 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014-05-16 07:47:03 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2014-05-16 02:09:44 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\uTorrent
[2014-05-16 02:08:54 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\vlc
[2014-05-16 02:08:40 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014-05-16 02:08:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014-05-16 02:08:25 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2014-05-16 02:08:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2014-05-16 02:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2014-05-16 02:04:29 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\NapiProjekt
[2014-05-16 02:04:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt
[2014-05-16 02:04:27 | 000,000,000 | ---D | C] -- C:\Program Files\NapiProjekt
[2014-05-16 02:02:31 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\ipla
[2014-05-16 02:02:31 | 000,000,000 | ---D | C] -- C:\ProgramData\ipla
[2014-05-16 02:02:29 | 000,000,000 | ---D | C] -- C:\ProgramData\RDRM
[2014-05-16 02:02:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ipla
[2014-05-16 02:02:12 | 000,000,000 | ---D | C] -- C:\Program Files\ipla
[2014-05-16 02:02:01 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
[2014-05-16 02:02:01 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
[2014-05-16 01:59:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2014-05-16 01:59:50 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2014-05-16 01:58:04 | 000,000,000 | ---D | C] -- C:\Program Files\webget
[2014-05-16 01:58:00 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
[2014-05-16 01:57:08 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Programs
[2014-05-16 01:54:43 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2014-05-16 01:54:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2014-05-16 01:54:42 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2014-05-16 01:46:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
[2014-05-16 01:46:45 | 000,017,088 | ---- | C] (Glarysoft Ltd) -- C:\Windows\System32\drivers\GUBootStartup.sys
[2014-05-16 01:46:45 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\GlarySoft
[2014-05-16 01:46:44 | 000,101,664 | ---- | C] (Glarysoft Ltd) -- C:\Windows\System32\BootDefrag.exe
[2014-05-16 01:46:44 | 000,016,064 | ---- | C] (Glarysoft Ltd) -- C:\Windows\System32\drivers\BootDefragDriver.sys
[2014-05-16 01:46:44 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\DiskDefrag
[2014-05-16 01:46:40 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities 5
[2014-05-16 01:45:51 | 000,000,000 | ---D | C] -- C:\Program Files\Damian Pasternak
[2014-05-16 01:44:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2014-05-16 01:44:40 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2014-05-16 01:43:56 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\rmi
[2014-05-16 01:42:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014-05-16 01:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014-05-16 01:34:04 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\MyPortal
[2014-05-16 01:34:01 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPortal
[2014-05-16 01:33:58 | 000,000,000 | ---D | C] -- C:\Program Files\MyPortal
[2014-05-16 01:33:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
[2014-05-16 01:33:08 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\AIMP3
[2014-05-16 01:33:06 | 000,000,000 | ---D | C] -- C:\Program Files\AIMP3
[2014-05-16 01:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4Tech Software
[2014-05-16 01:29:55 | 000,000,000 | ---D | C] -- C:\Program Files\OscarX7Editor5Mode
[2014-05-16 01:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\5 mode Oscar
[2014-05-16 01:28:21 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
[2014-05-16 01:28:15 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014-05-16 01:28:03 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2014-05-16 01:28:03 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2014-05-16 01:28:03 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnaddr.dll
[2014-05-16 01:27:52 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2014-05-16 01:27:52 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2014-05-16 01:27:51 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2014-05-16 01:27:50 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2014-05-16 01:27:21 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2014-05-16 01:27:21 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2014-05-16 01:27:21 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2014-05-16 01:27:21 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2014-05-16 01:27:21 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2014-05-16 01:27:20 | 000,919,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2014-05-16 01:27:20 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2014-05-16 01:27:06 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2014-05-16 01:27:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2014-05-16 01:26:50 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2014-05-16 01:26:49 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2014-05-16 01:26:17 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2014-05-16 01:26:17 | 000,187,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2014-05-16 01:26:15 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2014-05-16 01:26:12 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2014-05-16 01:26:11 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2014-05-16 01:26:11 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2014-05-16 01:26:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2014-05-16 01:26:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2014-05-16 01:25:55 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2014-05-16 01:25:55 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2014-05-16 01:25:55 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2014-05-16 01:25:55 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2014-05-16 01:25:55 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2014-05-16 01:25:54 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2014-05-16 01:25:47 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2014-05-16 01:25:38 | 000,802,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WFS.exe
[2014-05-16 01:25:38 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2014-05-16 01:25:36 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2014-05-16 01:25:36 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rstrui.exe
[2014-05-16 01:25:33 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2014-05-16 01:25:31 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2014-05-16 01:25:29 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2014-05-16 01:25:25 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2014-05-16 01:25:14 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2014-05-16 01:25:14 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2014-05-16 01:25:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2014-05-16 01:25:08 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2014-05-16 01:25:07 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2014-05-16 01:24:55 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2014-05-16 01:24:52 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2014-05-16 01:24:52 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll
[2014-05-16 01:24:52 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\System32\fpb.rs
[2014-05-16 01:24:52 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc-nz.rs
[2014-05-16 01:24:52 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\System32\pegibbfc.rs
[2014-05-16 01:24:52 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\System32\csrr.rs
[2014-05-16 01:24:52 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\System32\cob-au.rs
[2014-05-16 01:24:52 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\System32\usk.rs
[2014-05-16 01:24:52 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\System32\grb.rs
[2014-05-16 01:24:52 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-pt.rs
[2014-05-16 01:24:52 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi.rs
[2014-05-16 01:24:52 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\System32\djctq.rs
[2014-05-16 01:24:51 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\System32\cero.rs
[2014-05-16 01:24:51 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\System32\esrb.rs
[2014-05-16 01:24:51 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc.rs
[2014-05-16 01:24:51 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-fi.rs
[2014-05-16 01:24:40 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2014-05-16 01:24:39 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2014-05-16 01:24:36 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2014-05-16 01:24:36 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2014-05-16 01:24:36 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2014-05-16 01:24:36 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2014-05-16 01:24:36 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2014-05-16 01:24:34 | 000,219,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2014-05-16 01:24:34 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2014-05-16 01:24:33 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2014-05-16 01:24:33 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2014-05-16 01:24:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2014-05-16 01:24:29 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\profprov.dll
[2014-05-16 01:24:28 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2014-05-16 01:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014-05-16 01:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2014-05-16 01:24:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2014-05-16 01:24:03 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2014-05-16 01:24:02 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2014-05-16 01:24:01 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2014-05-16 01:23:51 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2014-05-16 01:23:50 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2014-05-16 01:23:43 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2014-05-16 01:23:16 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2014-05-16 01:20:24 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2014-05-16 01:20:24 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2014-05-16 01:06:47 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Macromedia
[2014-05-16 01:05:28 | 000,003,567 | ---- | C] (Beyond Logic http://www.beyondlogic.org) -- C:\Windows\System32\drivers\PortTalk.sys
[2014-05-16 01:02:45 | 000,026,136 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2014-05-16 01:02:42 | 000,270,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdisFlt.sys
[2014-05-16 01:01:06 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\AVAST Software
[2014-05-16 01:01:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2014-05-16 01:00:43 | 000,777,488 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014-05-16 01:00:43 | 000,776,976 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys.1400194859281
[2014-05-16 01:00:43 | 000,411,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys
[2014-05-16 01:00:43 | 000,411,552 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys.1400194859281
[2014-05-16 01:00:43 | 000,271,264 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014-05-16 01:00:43 | 000,081,768 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014-05-16 01:00:43 | 000,068,312 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswstm.sys
[2014-05-16 01:00:43 | 000,067,824 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014-05-16 01:00:43 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014-05-16 01:00:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-05-16 00:59:36 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014-05-16 00:56:11 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2014-05-16 00:56:01 | 000,027,888 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\drivers\Smb_driver_Intel.sys
[2014-05-16 00:53:56 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2014-05-16 00:53:56 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll
[2014-05-16 00:48:50 | 000,080,488 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RtNicProp32.dll
[2014-05-16 00:46:46 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Adobe
[2014-05-16 00:45:59 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\SlimWare Utilities Inc
[2014-05-16 00:45:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2014-05-16 00:45:50 | 000,000,000 | ---D | C] -- C:\Program Files\SlimDrivers
[2014-05-16 00:42:35 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\ATI
[2014-05-16 00:42:35 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\ATI
[2014-05-16 00:42:35 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2014-05-16 00:41:13 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2014-05-16 00:41:12 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014-05-16 00:40:13 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2014-05-16 00:13:58 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2014-05-16 00:13:58 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2014-05-16 00:13:58 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2014-05-16 00:13:58 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2014-05-16 00:13:58 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2014-05-16 00:13:58 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2014-05-16 00:13:58 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2014-05-16 00:13:57 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2014-05-16 00:13:57 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2014-05-16 00:13:57 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2014-05-16 00:13:57 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2014-05-16 00:13:57 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2014-05-16 00:13:57 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2014-05-16 00:13:57 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2014-05-16 00:13:57 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2014-05-16 00:13:57 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2014-05-16 00:13:57 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2014-05-16 00:13:57 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2014-05-16 00:13:57 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2014-05-16 00:13:57 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2014-05-16 00:13:57 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2014-05-16 00:13:57 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2014-05-16 00:13:57 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2014-05-16 00:13:57 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2014-05-16 00:13:57 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2014-05-16 00:13:57 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2014-05-16 00:13:56 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2014-05-16 00:13:56 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2014-05-16 00:13:56 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2014-05-16 00:13:56 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2014-05-16 00:13:56 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2014-05-16 00:13:56 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2014-05-16 00:13:56 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2014-05-16 00:13:56 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2014-05-16 00:13:56 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2014-05-16 00:13:56 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2014-05-16 00:13:56 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2014-05-16 00:13:56 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2014-05-16 00:13:56 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2014-05-16 00:13:56 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2014-05-16 00:13:56 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2014-05-16 00:13:56 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2014-05-16 00:13:56 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2014-05-16 00:13:56 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2014-05-16 00:13:56 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2014-05-16 00:13:56 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2014-05-16 00:13:56 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2014-05-16 00:13:56 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2014-05-16 00:13:56 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2014-05-16 00:13:56 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2014-05-16 00:13:56 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2014-05-16 00:13:56 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2014-05-16 00:13:56 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2014-05-16 00:13:56 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2014-05-16 00:13:55 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2014-05-16 00:13:55 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2014-05-16 00:13:55 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2014-05-16 00:13:55 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2014-05-16 00:13:55 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2014-05-16 00:13:55 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2014-05-16 00:13:55 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2014-05-16 00:13:55 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2014-05-16 00:13:55 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2014-05-16 00:13:55 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2014-05-16 00:13:55 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2014-05-16 00:13:55 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2014-05-16 00:13:55 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2014-05-16 00:13:55 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2014-05-16 00:13:55 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2014-05-16 00:13:55 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2014-05-16 00:13:55 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2014-05-16 00:13:55 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2014-05-16 00:13:55 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2014-05-16 00:13:55 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2014-05-16 00:13:55 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2014-05-16 00:13:55 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2014-05-16 00:13:55 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2014-05-16 00:13:55 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2014-05-16 00:13:55 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2014-05-16 00:13:54 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2014-05-16 00:13:54 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2014-05-16 00:13:54 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2014-05-16 00:13:54 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2014-05-16 00:13:54 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2014-05-16 00:13:54 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2014-05-16 00:13:54 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2014-05-16 00:13:54 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2014-05-16 00:13:54 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2014-05-16 00:13:30 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2014-05-16 00:13:28 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
[2014-05-16 00:13:26 | 000,000,000 | ---D | C] -- C:\Program Files\RivaTuner Statistics Server
[2014-05-16 00:13:14 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2014-05-16 00:13:10 | 000,000,000 | ---D | C] -- C:\Program Files\MSI Afterburner
[2014-05-16 00:05:05 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2014-05-16 00:04:36 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Microsoft Games
[2014-05-16 00:04:27 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2014-05-16 00:04:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\OEM
[2014-05-16 00:03:45 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\library_dir
[2014-05-16 00:03:24 | 000,000,000 | ---D | C] -- C:\Program Files\AMD AVT
[2014-05-16 00:03:24 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2014-05-16 00:03:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2014-05-16 00:03:06 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2014-05-16 00:02:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2014-05-16 00:02:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014-05-16 00:02:28 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2014-05-16 00:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2014-05-16 00:01:31 | 000,000,000 | ---D | C] -- C:\AMD
[2014-05-15 23:52:28 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Mozilla
[2014-05-15 23:52:28 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Mozilla
[2014-05-15 23:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2014-05-15 23:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014-05-15 23:52:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014-05-15 23:49:42 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Macromedia
[2014-05-15 23:49:42 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Adobe
[2014-05-15 23:49:34 | 000,692,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014-05-15 23:49:34 | 000,070,832 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014-05-15 23:49:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2014-05-15 23:46:17 | 001,629,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01011.dll
[2014-05-15 23:46:17 | 000,085,464 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\TeeDriver.sys
[2014-05-15 23:46:16 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\InstallShield
[2014-05-15 23:44:56 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Intel Corporation
[2014-05-15 23:44:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel Corporation
[2014-05-15 23:44:54 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2014-05-15 23:44:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2014-05-15 23:44:48 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2014-05-15 23:44:01 | 000,000,000 | ---D | C] -- C:\Users\Odyn\Intel
[2014-05-15 23:41:05 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2014-05-15 23:41:05 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll
[2014-05-15 23:41:05 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys
[2014-05-15 23:39:15 | 000,025,448 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\iaStorF.sys
[2014-05-15 23:39:14 | 000,505,192 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\iaStorA.sys
[2014-05-15 23:38:25 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2014-05-15 23:38:25 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2014-05-15 23:38:23 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2014-05-15 23:38:23 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2014-05-15 23:38:23 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2014-05-15 23:38:22 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2014-05-15 23:38:22 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2014-05-15 23:37:14 | 000,100,896 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RTNUninst32.dll
[2014-05-15 23:36:08 | 000,049,808 | ---- | C] (Realtek Corporation) -- C:\Windows\System32\drivers\RtTeam620.sys
[2014-05-15 23:36:08 | 000,033,056 | ---- | C] (Realtek ) -- C:\Windows\System32\drivers\RtNdPt60.sys
[2014-05-15 23:36:08 | 000,027,792 | ---- | C] (Realtek Corporation) -- C:\Windows\System32\drivers\RtVlan620.sys
[2014-05-15 23:36:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
[2014-05-15 23:33:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2014-05-15 23:33:46 | 003,320,936 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkHDMI.dll
[2014-05-15 23:33:46 | 003,296,600 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEP32H.dll
[2014-05-15 23:33:46 | 002,275,432 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RHDMIExt.dll
[2014-05-15 23:33:46 | 000,357,720 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32H.dll
[2014-05-15 23:33:46 | 000,345,944 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EED32H.dll
[2014-05-15 23:33:46 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RH3DHT32.dll
[2014-05-15 23:33:46 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RH3DAA32.dll
[2014-05-15 23:33:46 | 000,199,528 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RtHDMIV.sys
[2014-05-15 23:33:46 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32H.dll
[2014-05-15 23:33:46 | 000,103,256 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEL32H.dll
[2014-05-15 23:33:46 | 000,088,408 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEA32H.dll
[2014-05-15 23:33:46 | 000,076,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RHCoInst.dll
[2014-05-15 23:33:46 | 000,076,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32H.dll
[2014-05-15 23:33:46 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32H.dll
[2014-05-15 23:33:46 | 000,061,272 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEG32H.dll
[2014-05-15 23:33:45 | 003,173,008 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll
[2014-05-15 23:33:45 | 002,417,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2014-05-15 23:33:45 | 001,783,056 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2014-05-15 23:33:45 | 001,497,704 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2014-05-15 23:33:45 | 000,753,280 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBAPO32.dll
[2014-05-15 23:33:45 | 000,645,776 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2014-05-15 23:33:45 | 000,359,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2014-05-15 23:33:45 | 000,345,328 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2014-05-15 23:33:45 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2014-05-15 23:33:45 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2014-05-15 23:33:45 | 000,185,584 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2014-05-15 23:33:45 | 000,173,296 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2014-05-15 23:33:45 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2014-05-15 23:33:45 | 000,140,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2014-05-15 23:33:45 | 000,087,696 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2014-05-15 23:33:45 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2014-05-15 23:33:45 | 000,071,808 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBWrp32.dll
[2014-05-15 23:33:45 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2014-05-15 23:33:45 | 000,054,360 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBppld32.dll
[2014-05-15 23:33:45 | 000,050,776 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\MBPPCn32.dll
[2014-05-15 23:33:45 | 000,013,416 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2014-05-15 23:33:44 | 002,193,472 | ---- | C] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2014-05-15 23:33:44 | 001,836,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2014-05-15 23:33:44 | 000,709,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPOShell.dll
[2014-05-15 23:33:44 | 000,232,792 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2014-05-15 23:33:44 | 000,176,736 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2014-05-15 23:33:44 | 000,132,368 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2014-05-15 23:33:44 | 000,095,840 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2014-05-15 23:33:44 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2014-05-15 23:33:44 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2014-05-15 23:33:25 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2014-05-15 23:33:24 | 001,706,640 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2014-05-15 23:33:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2014-05-15 23:27:50 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll
[2014-05-15 23:27:50 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2014-05-15 23:27:34 | 000,000,000 | ---D | C] -- C:\Intel
[2014-05-15 23:10:47 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014-05-15 23:10:47 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Searches
[2014-05-15 23:10:47 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014-05-15 23:10:41 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Identities
[2014-05-15 23:10:40 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Contacts
[2014-05-15 23:10:37 | 000,000,000 | --SD | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Videos
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Saved Games
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Pictures
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Music
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Links
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Favorites
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Downloads
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Documents
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\Desktop
[2014-05-15 23:10:37 | 000,000,000 | R--D | C] -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Ustawienia lokalne
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\AppData\Local\Temporary Internet Files
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Szablony
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\SendTo
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Recent
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\PrintHood
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\NetHood
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Documents\Moje wideo
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Documents\Moje obrazy
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Moje dokumenty
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Documents\Moja muzyka
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Menu Start
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\AppData\Local\Historia
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Dane aplikacji
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\AppData\Local\Dane aplikacji
[2014-05-15 23:10:37 | 000,000,000 | -HSD | C] -- C:\Users\Odyn\Cookies
[2014-05-15 23:10:37 | 000,000,000 | -H-D | C] -- C:\Users\Odyn\AppData
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\VirtualStore
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Temp
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\Microsoft
[2014-05-15 23:10:37 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Roaming\Media Center Programs
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Recovery
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2014-05-15 23:10:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji
[2014-05-15 23:10:03 | 000,000,000 | ---D | C] -- C:\Windows\SDold
[2014-05-15 23:05:56 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2014-05-15 21:54:02 | 000,000,000 | ---D | C] -- C:\Kalibracja
[2014-05-15 21:27:47 | 000,000,000 | ---D | C] -- C:\Program Files\Victoria 4.46 B
[2014-04-18 04:43:04 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atimpc32.dll
[2014-04-18 04:43:04 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdpcom32.dll
[2014-04-18 04:42:58 | 000,126,336 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiuxpag.dll
[2014-04-18 04:42:56 | 000,099,520 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiu9pag.dll
[2014-04-18 04:42:52 | 001,117,184 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\aticfx32.dll
[2014-04-18 04:42:42 | 008,866,928 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atidxx32.dll
[2014-04-18 04:42:38 | 006,796,592 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdva.dll
[2014-04-18 04:42:34 | 006,799,688 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdag.dll
[2014-04-18 04:39:04 | 000,247,520 | ---- | C] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amdacpksd.sys
[2014-04-18 04:35:20 | 013,515,264 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmdag.sys
[2014-04-18 04:22:48 | 000,083,456 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OpenVideo.dll
[2014-04-18 04:22:38 | 000,073,216 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OVDecode.dll
[2014-04-18 04:19:54 | 024,107,520 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\amdocl.dll
[2014-04-18 04:17:24 | 000,058,880 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2014-04-18 04:13:10 | 000,113,664 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantle32.dll
[2014-04-18 03:58:32 | 004,358,656 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmantle32.dll
[2014-04-18 03:51:44 | 023,409,152 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atioglxx.dll
[2014-04-18 03:46:34 | 000,368,128 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiapfxx.exe
[2014-04-18 03:46:24 | 000,052,224 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalrt.dll
[2014-04-18 03:46:18 | 000,049,152 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalcl.dll
[2014-04-18 03:45:46 | 000,085,504 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantleaxl32.dll
[2014-04-18 03:42:52 | 014,302,208 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticaldd.dll
[2014-04-18 03:33:02 | 000,037,888 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmmcl.dll
[2014-04-18 03:30:14 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atidemgy.dll
[2014-04-18 03:29:58 | 000,030,720 | ---- | C] (AMD) -- C:\Windows\System32\atimuixx.dll
[2014-04-18 03:29:40 | 000,491,520 | ---- | C] (AMD) -- C:\Windows\System32\atieclxx.exe
[2014-04-18 03:29:16 | 000,208,896 | ---- | C] (AMD) -- C:\Windows\System32\atiesrxx.exe
[2014-04-18 03:28:24 | 000,164,352 | ---- | C] (AMD) -- C:\Windows\System32\atitmmxx.dll
[2014-04-18 03:21:26 | 000,616,960 | ---- | C] (AMD) -- C:\Windows\System32\coinst_14.100.dll
[2014-04-18 03:08:56 | 000,848,896 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiadlxx.dll
[2014-04-18 03:07:46 | 000,069,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiglpxx.dll
[2014-04-18 03:07:20 | 000,133,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atigktxx.dll
[2014-04-18 03:06:30 | 000,512,000 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmpag.sys
[2014-04-18 03:04:24 | 000,043,520 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\ati2erec.dll
========== Files - Modified Within 30 Days ==========
[2014-05-17 20:12:00 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-05-17 20:08:04 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-05-17 19:55:36 | 000,013,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-05-17 19:55:36 | 000,013,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-05-17 19:50:57 | 000,740,732 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2014-05-17 19:50:57 | 000,654,564 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014-05-17 19:50:57 | 000,155,804 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2014-05-17 19:50:57 | 000,121,934 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014-05-17 19:47:07 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize 5.job
[2014-05-17 19:46:08 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-05-17 19:45:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-05-17 19:45:56 | 2811,727,872 | -HS- | M] () -- C:\hiberfil.sys
[2014-05-17 19:38:06 | 000,000,892 | ---- | M] () -- C:\Users\Odyn\Desktop\HD Tune.lnk
[2014-05-17 13:21:31 | 000,413,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014-05-17 13:18:18 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msclmd.dll
[2014-05-16 15:17:40 | 000,140,072 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2014-05-16 15:17:33 | 000,280,904 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2014-05-16 14:48:57 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2014-05-16 14:48:41 | 000,138,056 | ---- | M] () -- C:\Users\Odyn\AppData\Roaming\PnkBstrK.sys
[2014-05-16 14:48:13 | 000,189,248 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2014-05-16 14:24:41 | 000,002,245 | ---- | M] () -- C:\Users\Odyn\Desktop\ACS.lnk
[2014-05-16 13:28:21 | 000,000,933 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2014-05-16 13:27:56 | 000,000,216 | ---- | M] () -- C:\Users\Odyn\Desktop\NBA 2K14.url
[2014-05-16 13:21:19 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014-05-16 13:13:20 | 000,000,216 | ---- | M] () -- C:\Users\Odyn\Desktop\Assetto Corsa.url
[2014-05-16 13:11:11 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2014-05-16 13:07:52 | 000,002,203 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014-05-16 13:01:37 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2014-05-16 07:47:55 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2014-05-16 07:47:55 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014-05-16 07:47:55 | 001,806,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014-05-16 07:47:55 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014-05-16 07:47:55 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014-05-16 07:47:55 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014-05-16 07:47:55 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2014-05-16 07:47:55 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014-05-16 07:47:55 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2014-05-16 07:47:55 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014-05-16 07:47:55 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2014-05-16 07:47:55 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014-05-16 07:47:55 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014-05-16 07:47:55 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2014-05-16 07:47:55 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014-05-16 07:47:55 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2014-05-16 07:47:55 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2014-05-16 07:47:55 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2014-05-16 07:47:55 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014-05-16 07:47:55 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2014-05-16 07:47:55 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2014-05-16 07:47:55 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2014-05-16 07:47:55 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2014-05-16 07:47:55 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2014-05-16 07:47:55 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2014-05-16 07:47:55 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2014-05-16 07:47:55 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014-05-16 07:47:55 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014-05-16 07:47:55 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2014-05-16 07:47:55 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014-05-16 07:47:55 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2014-05-16 07:47:55 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2014-05-16 07:47:55 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014-05-16 07:47:55 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2014-05-16 07:47:55 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014-05-16 07:47:55 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2014-05-16 07:47:55 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014-05-16 07:43:44 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2014-05-16 02:10:37 | 000,000,851 | ---- | M] () -- C:\Users\Odyn\Desktop\µTorrent.lnk
[2014-05-16 02:08:40 | 000,000,971 | ---- | M] () -- C:\Users\Public\Desktop\WinRAR.lnk
[2014-05-16 02:08:23 | 000,001,020 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014-05-16 02:04:29 | 000,000,994 | ---- | M] () -- C:\Users\Odyn\Desktop\NapiProjekt.lnk
[2014-05-16 02:02:29 | 000,000,905 | ---- | M] () -- C:\Users\Public\Desktop\ipla.lnk
[2014-05-16 02:02:01 | 001,700,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
[2014-05-16 02:02:01 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
[2014-05-16 01:54:43 | 000,000,961 | ---- | M] () -- C:\Users\Odyn\Desktop\SpeedFan.lnk
[2014-05-16 01:54:42 | 000,000,045 | ---- | M] () -- C:\Windows\System32\initdebug.nfo
[2014-05-16 01:51:39 | 000,001,018 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2014-05-16 01:46:46 | 000,001,034 | ---- | M] () -- C:\Users\Public\Desktop\Glary Utilities 5.lnk
[2014-05-16 01:46:45 | 000,017,088 | ---- | M] (Glarysoft Ltd) -- C:\Windows\System32\drivers\GUBootStartup.sys
[2014-05-16 01:45:51 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\CWK.lnk
[2014-05-16 01:42:52 | 000,000,961 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014-05-16 01:34:01 | 000,000,804 | ---- | M] () -- C:\Users\Odyn\Desktop\AQQ.lnk
[2014-05-16 01:33:15 | 000,000,871 | ---- | M] () -- C:\Users\Public\Desktop\AIMP3.lnk
[2014-05-16 01:30:21 | 000,001,247 | ---- | M] () -- C:\Users\Odyn\Desktop\OscarEditor.lnk
[2014-05-16 01:24:21 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014-05-16 01:03:09 | 000,002,053 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2014-05-16 01:02:59 | 000,270,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdisFlt.sys
[2014-05-16 01:02:43 | 000,026,136 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2014-05-16 01:00:59 | 000,777,488 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys
[2014-05-16 01:00:59 | 000,411,680 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys
[2014-05-16 01:00:59 | 000,068,312 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswstm.sys
[2014-05-16 01:00:43 | 000,776,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsnx.sys.1400194859281
[2014-05-16 01:00:43 | 000,411,552 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswsp.sys.1400194859281
[2014-05-16 01:00:43 | 000,271,264 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2014-05-16 01:00:43 | 000,180,632 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014-05-16 01:00:43 | 000,081,768 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2014-05-16 01:00:43 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2014-05-16 01:00:43 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014-05-16 01:00:43 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014-05-16 01:00:43 | 000,024,184 | ---- | M] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014-05-16 00:56:11 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2014-05-16 00:46:57 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014-05-16 00:46:57 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014-05-16 00:45:50 | 000,002,455 | ---- | M] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2014-05-16 00:13:14 | 000,001,040 | ---- | M] () -- C:\Users\Odyn\Desktop\MSI Afterburner.lnk
[2014-05-16 00:05:36 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2014-05-15 23:52:21 | 000,001,101 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014-05-15 23:26:28 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014-05-15 23:07:48 | 000,067,908 | ---- | M] () -- C:\Windows\System32\license.rtf
[2014-05-14 10:39:20 | 000,101,664 | ---- | M] (Glarysoft Ltd) -- C:\Windows\System32\BootDefrag.exe
[2014-05-14 09:02:44 | 000,016,064 | ---- | M] (Glarysoft Ltd) -- C:\Windows\System32\drivers\BootDefragDriver.sys
[2014-05-12 16:40:58 | 000,052,920 | ---- | M] (StdLib) -- C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys
[2014-04-18 04:43:04 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atimpc32.dll
[2014-04-18 04:43:04 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdpcom32.dll
[2014-04-18 04:42:58 | 000,126,336 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiuxpag.dll
[2014-04-18 04:42:56 | 000,099,520 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiu9pag.dll
[2014-04-18 04:42:52 | 001,117,184 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\aticfx32.dll
[2014-04-18 04:42:42 | 008,866,928 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atidxx32.dll
[2014-04-18 04:42:38 | 006,796,592 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdva.dll
[2014-04-18 04:42:34 | 006,799,688 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdag.dll
[2014-04-18 04:39:04 | 000,247,520 | ---- | M] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amdacpksd.sys
[2014-04-18 04:35:20 | 013,515,264 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmdag.sys
[2014-04-18 04:23:02 | 000,200,704 | ---- | M] () -- C:\Windows\System32\clinfo.exe
[2014-04-18 04:22:56 | 000,995,342 | ---- | M] () -- C:\Windows\System32\amdocl_as32.exe
[2014-04-18 04:22:56 | 000,798,734 | ---- | M] () -- C:\Windows\System32\amdocl_ld32.exe
[2014-04-18 04:22:48 | 000,083,456 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OpenVideo.dll
[2014-04-18 04:22:38 | 000,073,216 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\OVDecode.dll
[2014-04-18 04:19:54 | 024,107,520 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\amdocl.dll
[2014-04-18 04:17:24 | 000,058,880 | ---- | M] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2014-04-18 04:13:10 | 000,113,664 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantle32.dll
[2014-04-18 03:58:32 | 004,358,656 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmantle32.dll
[2014-04-18 03:51:44 | 023,409,152 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atioglxx.dll
[2014-04-18 03:46:56 | 000,580,816 | ---- | M] () -- C:\Windows\System32\atiapfxx.blb
[2014-04-18 03:46:34 | 000,368,128 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiapfxx.exe
[2014-04-18 03:46:24 | 000,052,224 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalrt.dll
[2014-04-18 03:46:18 | 000,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalcl.dll
[2014-04-18 03:45:46 | 000,085,504 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantleaxl32.dll
[2014-04-18 03:42:52 | 014,302,208 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticaldd.dll
[2014-04-18 03:33:02 | 000,037,888 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmmcl.dll
[2014-04-18 03:30:14 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atidemgy.dll
[2014-04-18 03:29:58 | 000,030,720 | ---- | M] (AMD) -- C:\Windows\System32\atimuixx.dll
[2014-04-18 03:29:40 | 000,491,520 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
[2014-04-18 03:29:16 | 000,208,896 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
[2014-04-18 03:28:24 | 000,164,352 | ---- | M] (AMD) -- C:\Windows\System32\atitmmxx.dll
[2014-04-18 03:21:26 | 000,616,960 | ---- | M] (AMD) -- C:\Windows\System32\coinst_14.100.dll
[2014-04-18 03:17:36 | 003,471,376 | ---- | M] () -- C:\Windows\System32\atiumdva.cap
[2014-04-18 03:14:36 | 000,204,952 | ---- | M] () -- C:\Windows\System32\ativvsvl.dat
[2014-04-18 03:14:36 | 000,157,144 | ---- | M] () -- C:\Windows\System32\ativvsva.dat
[2014-04-18 03:08:56 | 000,848,896 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiadlxx.dll
[2014-04-18 03:07:46 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiglpxx.dll
[2014-04-18 03:07:20 | 000,133,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atigktxx.dll
[2014-04-18 03:06:30 | 000,512,000 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmpag.sys
[2014-04-18 03:04:24 | 000,043,520 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\ati2erec.dll
[2014-04-17 22:28:30 | 000,038,912 | ---- | M] () -- C:\Windows\System32\kdbsdk32.dll
========== Files Created - No Company Name ==========
[2014-05-17 19:38:06 | 000,000,892 | ---- | C] () -- C:\Users\Odyn\Desktop\HD Tune.lnk
[2014-05-17 12:05:48 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2014-05-17 12:05:42 | 000,146,852 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
[2014-05-17 12:05:23 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2014-05-17 12:05:22 | 000,010,429 | ---- | C] () -- C:\Windows\System32\ScavengeSpace.xml
[2014-05-17 12:05:20 | 000,105,559 | ---- | C] () -- C:\Windows\System32\RacRules.xml
[2014-05-16 15:17:33 | 000,280,904 | ---- | C] () -- C:\Windows\System32\PnkBstrB.xtr
[2014-05-16 14:48:57 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2014-05-16 14:48:41 | 000,140,072 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2014-05-16 14:48:41 | 000,138,056 | ---- | C] () -- C:\Users\Odyn\AppData\Roaming\PnkBstrK.sys
[2014-05-16 14:48:09 | 000,280,904 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2014-05-16 14:48:09 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.ex0
[2014-05-16 14:48:08 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2014-05-16 14:24:11 | 000,002,245 | ---- | C] () -- C:\Users\Odyn\Desktop\ACS.lnk
[2014-05-16 13:28:21 | 000,000,933 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2014-05-16 13:27:56 | 000,000,216 | ---- | C] () -- C:\Users\Odyn\Desktop\NBA 2K14.url
[2014-05-16 13:21:19 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014-05-16 13:13:20 | 000,000,216 | ---- | C] () -- C:\Users\Odyn\Desktop\Assetto Corsa.url
[2014-05-16 13:11:11 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2014-05-16 13:07:52 | 000,002,203 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014-05-16 13:07:24 | 000,001,032 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-05-16 13:07:24 | 000,001,028 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-05-16 07:49:23 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2014-05-16 07:47:55 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2014-05-16 07:43:44 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2014-05-16 02:10:37 | 000,000,851 | ---- | C] () -- C:\Users\Odyn\Desktop\µTorrent.lnk
[2014-05-16 02:08:40 | 000,000,971 | ---- | C] () -- C:\Users\Public\Desktop\WinRAR.lnk
[2014-05-16 02:08:23 | 000,001,020 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014-05-16 02:04:29 | 000,000,994 | ---- | C] () -- C:\Users\Odyn\Desktop\NapiProjekt.lnk
[2014-05-16 02:02:29 | 000,000,905 | ---- | C] () -- C:\Users\Public\Desktop\ipla.lnk
[2014-05-16 01:59:53 | 000,218,200 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2014-05-16 01:54:43 | 000,000,961 | ---- | C] () -- C:\Users\Odyn\Desktop\SpeedFan.lnk
[2014-05-16 01:54:41 | 000,000,045 | ---- | C] () -- C:\Windows\System32\initdebug.nfo
[2014-05-16 01:46:46 | 000,001,046 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
[2014-05-16 01:46:46 | 000,001,034 | ---- | C] () -- C:\Users\Public\Desktop\Glary Utilities 5.lnk
[2014-05-16 01:46:46 | 000,000,316 | ---- | C] () -- C:\Windows\tasks\GlaryInitialize 5.job
[2014-05-16 01:45:51 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CWK.lnk
[2014-05-16 01:45:51 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\CWK.lnk
[2014-05-16 01:44:41 | 000,001,018 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2014-05-16 01:42:52 | 000,000,961 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014-05-16 01:34:01 | 000,000,804 | ---- | C] () -- C:\Users\Odyn\Desktop\AQQ.lnk
[2014-05-16 01:33:15 | 000,000,871 | ---- | C] () -- C:\Users\Public\Desktop\AIMP3.lnk
[2014-05-16 01:30:21 | 000,001,247 | ---- | C] () -- C:\Users\Odyn\Desktop\OscarEditor.lnk
[2014-05-16 01:24:21 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014-05-16 01:24:21 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014-05-16 01:03:09 | 000,002,053 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2014-05-16 01:00:43 | 000,180,632 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014-05-16 01:00:43 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2014-05-16 01:00:43 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014-05-16 00:56:11 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2014-05-16 00:53:56 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2014-05-16 00:46:03 | 000,000,384 | ---- | C] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2014-05-16 00:45:50 | 000,002,455 | ---- | C] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
[2014-05-16 00:13:14 | 000,001,040 | ---- | C] () -- C:\Users\Odyn\Desktop\MSI Afterburner.lnk
[2014-05-16 00:05:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014-05-15 23:52:21 | 000,001,113 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2014-05-15 23:52:21 | 000,001,101 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014-05-15 23:49:35 | 000,000,930 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-05-15 23:33:45 | 000,293,889 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2014-05-15 23:26:28 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014-05-15 23:10:48 | 000,001,417 | ---- | C] () -- C:\Users\Odyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-05-15 23:07:46 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2014-05-15 23:07:41 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2014-05-15 23:05:49 | 2811,727,872 | -HS- | C] () -- C:\hiberfil.sys
[2014-04-18 04:23:02 | 000,200,704 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2014-04-18 04:22:56 | 000,995,342 | ---- | C] () -- C:\Windows\System32\amdocl_as32.exe
[2014-04-18 04:22:56 | 000,798,734 | ---- | C] () -- C:\Windows\System32\amdocl_ld32.exe
[2014-04-18 03:46:56 | 000,580,816 | ---- | C] () -- C:\Windows\System32\atiapfxx.blb
[2014-04-18 03:17:36 | 003,471,376 | ---- | C] () -- C:\Windows\System32\atiumdva.cap
[2014-04-18 03:14:36 | 000,204,952 | ---- | C] () -- C:\Windows\System32\ativvsvl.dat
[2014-04-18 03:14:36 | 000,157,144 | ---- | C] () -- C:\Windows\System32\ativvsva.dat
[2014-04-17 22:28:30 | 000,038,912 | ---- | C] () -- C:\Windows\System32\kdbsdk32.dll
[2014-04-10 19:58:46 | 000,082,128 | ---- | C] () -- C:\Windows\System32\ativce02.dat
[2014-04-01 00:06:22 | 000,234,804 | ---- | C] () -- C:\Windows\System32\ativvaxy_cik.dat
[2014-04-01 00:04:42 | 000,233,008 | ---- | C] () -- C:\Windows\System32\ativvaxy_cik_nd.dat
[2014-02-06 17:45:58 | 000,134,192 | ---- | C] () -- C:\Windows\System32\ativce03.dat
[2014-01-16 19:00:46 | 000,273,712 | ---- | C] () -- C:\Windows\System32\ativvaxy_vi_nd.dat
[2014-01-16 18:59:20 | 000,275,124 | ---- | C] () -- C:\Windows\System32\ativvaxy_vi.dat
[2014-01-16 10:34:52 | 000,723,841 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2012-09-28 21:45:16 | 000,246,272 | ---- | C] () -- C:\Windows\System32\rtvcvfw64.dll
[2012-09-28 21:45:06 | 000,247,296 | ---- | C] () -- C:\Windows\System32\rtvcvfw32.dll
========== ZeroAccess Check ==========
[2009-07-14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014-05-16 01:58:00 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\0F1F1C2Y1H1P1C0I0T
[2014-05-16 15:19:00 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\2K Sports
[2014-05-16 01:33:23 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\AIMP3
[2014-05-16 01:01:06 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\AVAST Software
[2014-05-16 02:15:55 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\DiskDefrag
[2014-05-16 01:46:45 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\GlarySoft
[2014-05-16 02:02:40 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\ipla
[2014-05-16 00:03:45 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\library_dir
[2014-05-16 02:04:29 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\NapiProjekt
[2014-05-16 15:25:54 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Origin
[2014-05-16 01:44:28 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\rmi
[2014-05-16 13:28:17 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\TS3Client
[2014-05-17 19:45:18 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\uTorrent
========== Purity Check ==========
< End of report >
Extras
Spoiler:
OTL Extras logfile created on: 2014-05-17 20:11:41 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Pobrane
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,49 Gb Total Physical Memory | 1,87 Gb Available Physical Memory | 53,44% Memory free
6,98 Gb Paging File | 5,19 Gb Available in Paging File | 74,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 44,56 Gb Free Space | 39,90% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 434,88 Gb Free Space | 93,37% Space Free | Partition Type: NTFS
Computer Name: KOMPODYNA | User Name: Odyn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-281493417-172796843-820964179-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" ()
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F3D9D1-55F0-48ED-B28D-D5AF83EAE569}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A1FE3A7-097E-4317-B348-95FF71154270}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0F6E2660-7088-4381-B21F-15D06FBA2E38}" = lport=138 | protocol=17 | dir=in | app=system |
"{22575D9C-7B0B-49FC-8C70-9358ECE66A22}" = lport=137 | protocol=17 | dir=in | app=system |
"{29C5C638-D2E8-416A-BBEC-4F4F1362B994}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5A8D90B3-057A-4C7B-BB67-C41B3D767EAD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{64C07599-B84C-4D85-BCD3-785D9C959EE9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{671C2361-5E38-4951-BA39-DA731FAF8B10}" = lport=445 | protocol=6 | dir=in | app=system |
"{6A5800B0-F034-499D-9878-3083481BD7B8}" = lport=10243 | protocol=6 | dir=in | app=system |
"{931D7FD3-4508-44F1-A31A-960A92D257AF}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{9353EA99-9F32-479B-B011-6AD400886747}" = rport=139 | protocol=6 | dir=out | app=system |
"{BB1C1D04-B45E-4523-AE3C-732359C237C2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BC351E53-251B-4110-873E-17174F08D0D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{CBE37509-CEE0-412C-ACDC-1EE9C6BB7112}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DF1F2211-3D6C-4A01-9F38-16B4F2BB96CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EA3FCDDA-E8FB-4A42-A969-B08DD58C1A36}" = lport=139 | protocol=6 | dir=in | app=system |
"{EDC57DB0-EB97-41A5-A227-F5F3AEE8F695}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F1AE0864-DFE2-4798-94C5-905644757544}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F46A6FDC-3D37-4563-B625-BF747836B15B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F7368009-4B40-4E48-992D-F6E86F12E12E}" = rport=445 | protocol=6 | dir=out | app=system |
"{FC588C78-6FBD-4218-9092-A6DB67926F19}" = rport=138 | protocol=17 | dir=out | app=system |
"{FE8F9023-6E84-4044-A768-7B27639EA448}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B9F78E1-3405-4A24-948A-D949D5950930}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba2k14\nba2k14.exe |
"{0D2D7C73-A037-446A-83FF-75C6F601722F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{10797817-0E94-44B4-B86C-DBFC7C272F33}" = protocol=6 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{12552F4E-9686-4E74-BDF6-38589E1D2619}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{12C21DA0-F9E3-483A-BD0C-4F68EE4B32AE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3446963E-E972-4B70-8941-BC23B89431E1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{34FEA892-3EBF-422B-9B7A-DA18D961F718}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{358672DD-672D-4B62-BB97-785F5A0A6AD2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3AFCF168-660A-4EB3-81B8-6344C41DF4BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3B27CD18-4ABF-4589-911F-0108971F41D0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3E96BFA3-3525-46C4-8778-6F45FE25F3B7}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\assettocorsa.exe |
"{4331D1E8-0DD9-4D97-8C3D-D5D044A8AE61}" = protocol=17 | dir=in | app=c:\program files\origin games\battlefield 3\bf3.exe |
"{45464AA2-CD2C-43E6-B484-8C756CAE26B8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{47B38482-A9F4-4C26-9B64-1A6DB3C25AA8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{49EC2F53-B874-4DB6-81EA-069DA0A06913}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{4C5EB4DF-9608-45D7-B40D-6925B328F352}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba2k14\nba2k14.exe |
"{613101D5-5798-46F5-934A-F94F431198AB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\assettocorsa.exe |
"{628062EE-BCC9-421A-90DE-CDFC3A20F43C}" = protocol=6 | dir=in | app=c:\users\odyn\appdata\roaming\utorrent\utorrent.exe |
"{647FB7AC-9D76-423F-AE86-A51B3B731A6D}" = protocol=6 | dir=in | app=c:\program files\napiprojekt\napisy.exe |
"{64E63BBF-1FEA-4B2A-91D3-9B247E9D75F7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{73D66A12-BD4C-4061-8F7E-E6FB9A5B298A}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{74ED8E97-127C-4E6C-8B78-C89170A99024}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7978B644-AF7C-4B5A-9555-17C8B223107E}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{85362F88-A0A9-47E7-A7A8-244A9600F921}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{867A3B79-CC6C-43BF-BAAA-67152752651F}" = protocol=17 | dir=in | app=c:\users\odyn\appdata\roaming\utorrent\utorrent.exe |
"{93AC18FD-DC5B-434C-98AF-75D299CC987B}" = protocol=6 | dir=in | app=c:\program files\origin games\battlefield 3\bf3.exe |
"{9DEA91E4-75E8-490C-81C0-D31B76962DD7}" = protocol=17 | dir=in | app=c:\program files\napiprojekt\napisy.exe |
"{AB20FB99-0934-4454-BDBC-8BF6EB8ECA49}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AD01F2DE-66C5-4CC1-9EBA-6BE7998C1DED}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B0BB36F8-2B8A-439A-B0DD-28FE6A54E3ED}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{B2A4FECE-12F6-494B-954D-C932626B1AB5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E173115B-5688-41FC-99D0-EA5C0133D9F6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E1AA6BE2-ECEC-4FE4-816C-512FA7494AFC}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{E3B934D7-EBD0-4701-B327-A6D9E7D4E5D5}" = protocol=17 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{E7BCD87A-7443-4A47-8A6F-DCBE30D9D7D2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E8E28BFF-B0C8-459A-838C-012DD109B438}" = protocol=6 | dir=out | app=system |
"{F5FD45D9-AA21-4766-A3BD-CC0E0FA38DC0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FD7B810A-2122-42A3-8204-6A59BB0A1624}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{B6AE4D23-BB14-4EA2-94B4-426C2C44F652}C:\program files\steam\steamapps\common\assettocorsa\acs.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\acs.exe |
"UDP Query User{178ECA0B-CFD9-4DE6-ABF9-C9EBA182E060}C:\program files\steam\steamapps\common\assettocorsa\acs.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\acs.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{031F80EB-1FE5-45EF-9DE2-E2F5AF01259F}" = CCC Help Spanish
"{0B15A8C3-3B8A-F229-A880-82EA62908425}" = CCC Help Dutch
"{1A6752E1-966B-9D1F-F6B7-DDBCA6FC87ED}" = CCC Help Russian
"{2058DA53-D5F2-D8D9-7325-39B0E367D1E1}" = CCC Help Swedish
"{2090B6D0-E025-5A67-9838-8F1D5768E643}" = CCC Help Chinese Standard
"{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding
"{2AD4FF67-43E9-77AD-D90C-584F950E2D12}" = CCC Help French
"{2CC34925-D47D-BD10-AA1E-FAA76F3B5D82}" = AMD Wireless Display v3.0
"{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{3911CF56-9EF2-39BA-846A-C27BD3CD0685}" = Microsoft .NET Framework 4.5.2
"{3A577334-7C90-55BC-1878-F5862FA268B2}" = CCC Help Korean
"{3BF289E3-933B-F421-3B59-F6BB0D285B09}" = CCC Help Hungarian
"{3CB6BA0C-6BC5-E543-221A-AA4DEBB6F4B5}" = CCC Help Polish
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{430E2D32-6EA9-E6E4-80A1-84047694A45B}" = CCC Help Czech
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{467BD8D1-2A8D-4366-911A-14146F07A91C}" = Intel(R) Rapid Storage Technology
"{4A6A8D33-09CD-FD44-4BF0-999E8A6E93C8}" = CCC Help Italian
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{60D32CDC-E3BE-4578-BA10-29322307CDDC}" = Logitech Gaming Software 5.10
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6EBDE2A2-0CFB-9134-A859-68A0002B3FA6}" = CCC Help Thai
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{769E98DC-2BB0-83A7-51C9-306F30232345}" = Catalyst Control Center Graphics Previews Common
"{80F52BC0-7AC5-17C3-F34B-8613E213D44D}" = AMD Accelerated Video Transcoding
"{8181B50E-0E33-DE07-AAB2-E71BBBDBF288}" = CCC Help Portuguese
"{83FB054C-7DA5-1C76-BFB2-423426DC35BB}" = AMD Catalyst Control Center
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A640069-9784-701E-AC8E-84F62C42D1A3}" = CCC Help English
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2
"{93098E43-2743-1551-447F-2699E9591E9C}" = CCC Help Danish
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{99415B03-525E-3FEA-2A60-359FD6BCD368}" = ccc-utility
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BB76948-12B0-97E4-1954-DF52AAA4EFF9}" = AMD Drag and Drop Transcoding
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3703A3B-FDCF-4349-4B2E-A189A2B90B51}" = CCC Help Chinese Traditional
"{A5457401-D56A-43F2-9524-78E54A7FC07A}" = SlimDrivers
"{A619A488-A4BA-F2A0-72FA-4C484B93DC0F}" = CCC Help Greek
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.07) - Polish
"{C4799AAA-CE52-D2F1-63C8-E6D5106C78E0}" = CCC Help Norwegian
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C6182116-5F2D-9949-B42B-06073E86A98A}" = CCC Help German
"{CC6C7F05-AF23-65BD-702D-705EAB723578}" = CCC Help Japanese
"{D5B7F1A3-2CA6-4C5C-EFB6-4AA5772F5310}" = CCC Help Turkish
"{DADC7AB0-E554-4705-9F6A-83EA82ED708E}" = Realtek Ethernet Diagnostic Utility
"{DBA6B3EF-A8C0-4EB2-9554-3A7879838580}" = Catalyst Control Center Localization All
"{DC7723BE-A2BB-58A0-4820-5630F9B82198}" = AMD Catalyst Install Manager
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4A6308C-55E6-57DF-95BB-AEEF374B469A}" = CCC Help Finnish
"{F543B0F9-D1F9-25D1-993C-8430BEC9D889}" = Catalyst Control Center InstallProxy
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Afterburner" = MSI Afterburner 3.0.0 Beta 19
"AIMP3" = AIMP3
"AQQ" = AQQ
"Avast" = avast! Internet Security
"Battlelog Web Plugins" = Battlelog Web Plugins
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.69.2
"CWK" = CWK (Czasowy Wyłącznik Komputera)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESN Sonar-0.70.4" = ESN Sonar
"Glary Utilities 5" = Glary Utilities PRO 5.0
"Google Chrome" = Google Chrome
"HD Tune_is1" = HD Tune 2.55
"ipla" = ipla 2.7
"KLiteCodecPack_is1" = K-Lite Codec Pack 10.4.8 Full
"Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 29.0.1 (x86 pl)" = Mozilla Firefox 29.0.1 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NapiProjekt_is1" = NapiProjekt (2.2.0.2399)
"Origin" = Origin
"OscarX7Mouse5Mode" = 5-Mode Oscar Editor
"PunkBusterSvc" = PunkBuster Services
"RTSS" = RivaTuner Statistics Server 6.1.0
"SpeedFan" = SpeedFan (remove only)
"Steam" = Steam
"Steam App 244210" = Assetto Corsa
"Steam App 255480" = NBA 2K14
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VLC media player" = VLC media player 2.1.3
"webget" = webget
"WinRAR archiver" = WinRAR 5.10 beta 4 (32-bit)
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-281493417-172796843-820964179-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"K-Lite Codec Pack Packages" = K-Lite Codec Pack Packages
"uTorrent" = µTorrent
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2014-05-16 06:53:04 | Computer Name = KompOdyna | Source = Microsoft-Windows-CertificateServicesClient | ID = 1003
Description = Klient usług certyfikatów nie może wywołać dostawców w odpowiedzi
na zdarzenie 256. Kod błędu 2147942432.
Error - 2014-05-16 17:00:12 | Computer Name = KompOdyna | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: acs.exe, wersja: 0.0.0.0, sygnatura
czasowa: 0x5372302a Nazwa modułu powodującego błąd: kernel32.dll, wersja: 6.1.7600.17206,
sygnatura czasowa: 0x50e65f4e Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000c678c
Identyfikator
procesu powodującego błąd: 0x1dd8 Godzina uruchomienia aplikacji powodującej błąd:
0x01cf71467212ba7a Ścieżka aplikacji powodującej błąd: C:\Program Files\Steam\SteamApps\common\assettocorsa\acs.exe
Ścieżka
modułu powodującego błąd: C:\Windows\system32\kernel32.dll Identyfikator raportu:
123ccbe1-dd3d-11e3-ab8a-50e549267fb4
Error - 2014-05-17 05:49:04 | Computer Name = KompOdyna | Source = VSS | ID = 8194
Description =
Error - 2014-05-17 06:32:01 | Computer Name = KompOdyna | Source = MsiInstaller | ID = 1043
Description =
Error - 2014-05-17 07:10:05 | Computer Name = KompOdyna | Source = MsiInstaller | ID = 11935
Description =
Error - 2014-05-17 07:10:57 | Computer Name = KompOdyna | Source = MsiInstaller | ID = 1024
Description =
Error - 2014-05-17 07:21:41 | Computer Name = KompOdyna | Source = ESENT | ID = 215
Description = WinMail (3472) WindowsMail0: Tworzenie kopii zapasowej zostało zatrzymane,
ponieważ zostało przerwane przez klienta lub nie można nawiązać połączenia z klientem.
Error - 2014-05-17 07:41:51 | Computer Name = KompOdyna | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\glary
utilities 5\DPInst64.exe". Nie można odnaleźć zestawu zależnego Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.
Error - 2014-05-17 07:42:05 | Computer Name = KompOdyna | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\rivatuner
statistics server\EncoderServer64.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.
Error - 2014-05-17 07:42:06 | Computer Name = KompOdyna | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\rivatuner
statistics server\RTSSHooksLoader64.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.
[ System Events ]
Error - 2014-05-15 18:59:36 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi rixbzitc z powodu następującego błędu:
%%2
Error - 2014-05-15 19:34:29 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7023
Description = Usługa Wstępne ładowanie do pamięci zakończyła działanie; wystąpił
następujący błąd: %%1062
Error - 2014-05-15 19:44:52 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7031
Description = Usługa avast! Antivirus niespodziewanie zakończyła pracę. Wystąpiło
to razy: 1. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna:
Uruchom usługę ponownie.
Error - 2014-05-16 06:54:33 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7023
Description = Usługa Instalator modułów systemu Windows zakończyła działanie; wystąpił
następujący błąd: %%16405
Error - 2014-05-16 06:57:27 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja listy
widoku zgodności programu Internet Explorer 8 dla systemu Windows 7 (KB2598845).
Error - 2014-05-16 06:57:27 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja systemu
Windows 7 (KB2703157).
Error - 2014-05-17 05:39:53 | Computer Name = KompOdyna | Source = Microsoft-Windows-Directory-Services-SAM | ID = 12291
Description = Modułowi SAM nie powiodło się uruchomienie wątku nasłuchu TCP/IP lub
SPX/IPX.
Error - 2014-05-17 07:11:02 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Dodatek Service Pack
3 (SP3) dla pakietu Microsoft Office 2007.
Error - 2014-05-17 07:24:23 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Uaktualnienie pakietu
Podstawowe programy Windows Live 2011 (KB2434419).
Error - 2014-05-17 07:24:23 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja dla systemu
Windows 7 (KB976422).
< End of report >
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Pobrane
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,49 Gb Total Physical Memory | 1,87 Gb Available Physical Memory | 53,44% Memory free
6,98 Gb Paging File | 5,19 Gb Available in Paging File | 74,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 44,56 Gb Free Space | 39,90% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 434,88 Gb Free Space | 93,37% Space Free | Partition Type: NTFS
Computer Name: KOMPODYNA | User Name: Odyn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-281493417-172796843-820964179-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" ()
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F3D9D1-55F0-48ED-B28D-D5AF83EAE569}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A1FE3A7-097E-4317-B348-95FF71154270}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0F6E2660-7088-4381-B21F-15D06FBA2E38}" = lport=138 | protocol=17 | dir=in | app=system |
"{22575D9C-7B0B-49FC-8C70-9358ECE66A22}" = lport=137 | protocol=17 | dir=in | app=system |
"{29C5C638-D2E8-416A-BBEC-4F4F1362B994}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5A8D90B3-057A-4C7B-BB67-C41B3D767EAD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{64C07599-B84C-4D85-BCD3-785D9C959EE9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{671C2361-5E38-4951-BA39-DA731FAF8B10}" = lport=445 | protocol=6 | dir=in | app=system |
"{6A5800B0-F034-499D-9878-3083481BD7B8}" = lport=10243 | protocol=6 | dir=in | app=system |
"{931D7FD3-4508-44F1-A31A-960A92D257AF}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{9353EA99-9F32-479B-B011-6AD400886747}" = rport=139 | protocol=6 | dir=out | app=system |
"{BB1C1D04-B45E-4523-AE3C-732359C237C2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BC351E53-251B-4110-873E-17174F08D0D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{CBE37509-CEE0-412C-ACDC-1EE9C6BB7112}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DF1F2211-3D6C-4A01-9F38-16B4F2BB96CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EA3FCDDA-E8FB-4A42-A969-B08DD58C1A36}" = lport=139 | protocol=6 | dir=in | app=system |
"{EDC57DB0-EB97-41A5-A227-F5F3AEE8F695}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F1AE0864-DFE2-4798-94C5-905644757544}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F46A6FDC-3D37-4563-B625-BF747836B15B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F7368009-4B40-4E48-992D-F6E86F12E12E}" = rport=445 | protocol=6 | dir=out | app=system |
"{FC588C78-6FBD-4218-9092-A6DB67926F19}" = rport=138 | protocol=17 | dir=out | app=system |
"{FE8F9023-6E84-4044-A768-7B27639EA448}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B9F78E1-3405-4A24-948A-D949D5950930}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba2k14\nba2k14.exe |
"{0D2D7C73-A037-446A-83FF-75C6F601722F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{10797817-0E94-44B4-B86C-DBFC7C272F33}" = protocol=6 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{12552F4E-9686-4E74-BDF6-38589E1D2619}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{12C21DA0-F9E3-483A-BD0C-4F68EE4B32AE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3446963E-E972-4B70-8941-BC23B89431E1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{34FEA892-3EBF-422B-9B7A-DA18D961F718}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{358672DD-672D-4B62-BB97-785F5A0A6AD2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3AFCF168-660A-4EB3-81B8-6344C41DF4BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3B27CD18-4ABF-4589-911F-0108971F41D0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3E96BFA3-3525-46C4-8778-6F45FE25F3B7}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\assettocorsa.exe |
"{4331D1E8-0DD9-4D97-8C3D-D5D044A8AE61}" = protocol=17 | dir=in | app=c:\program files\origin games\battlefield 3\bf3.exe |
"{45464AA2-CD2C-43E6-B484-8C756CAE26B8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{47B38482-A9F4-4C26-9B64-1A6DB3C25AA8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{49EC2F53-B874-4DB6-81EA-069DA0A06913}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{4C5EB4DF-9608-45D7-B40D-6925B328F352}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba2k14\nba2k14.exe |
"{613101D5-5798-46F5-934A-F94F431198AB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\assettocorsa.exe |
"{628062EE-BCC9-421A-90DE-CDFC3A20F43C}" = protocol=6 | dir=in | app=c:\users\odyn\appdata\roaming\utorrent\utorrent.exe |
"{647FB7AC-9D76-423F-AE86-A51B3B731A6D}" = protocol=6 | dir=in | app=c:\program files\napiprojekt\napisy.exe |
"{64E63BBF-1FEA-4B2A-91D3-9B247E9D75F7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{73D66A12-BD4C-4061-8F7E-E6FB9A5B298A}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{74ED8E97-127C-4E6C-8B78-C89170A99024}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7978B644-AF7C-4B5A-9555-17C8B223107E}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{85362F88-A0A9-47E7-A7A8-244A9600F921}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{867A3B79-CC6C-43BF-BAAA-67152752651F}" = protocol=17 | dir=in | app=c:\users\odyn\appdata\roaming\utorrent\utorrent.exe |
"{93AC18FD-DC5B-434C-98AF-75D299CC987B}" = protocol=6 | dir=in | app=c:\program files\origin games\battlefield 3\bf3.exe |
"{9DEA91E4-75E8-490C-81C0-D31B76962DD7}" = protocol=17 | dir=in | app=c:\program files\napiprojekt\napisy.exe |
"{AB20FB99-0934-4454-BDBC-8BF6EB8ECA49}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AD01F2DE-66C5-4CC1-9EBA-6BE7998C1DED}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B0BB36F8-2B8A-439A-B0DD-28FE6A54E3ED}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{B2A4FECE-12F6-494B-954D-C932626B1AB5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E173115B-5688-41FC-99D0-EA5C0133D9F6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E1AA6BE2-ECEC-4FE4-816C-512FA7494AFC}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{E3B934D7-EBD0-4701-B327-A6D9E7D4E5D5}" = protocol=17 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{E7BCD87A-7443-4A47-8A6F-DCBE30D9D7D2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E8E28BFF-B0C8-459A-838C-012DD109B438}" = protocol=6 | dir=out | app=system |
"{F5FD45D9-AA21-4766-A3BD-CC0E0FA38DC0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FD7B810A-2122-42A3-8204-6A59BB0A1624}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{B6AE4D23-BB14-4EA2-94B4-426C2C44F652}C:\program files\steam\steamapps\common\assettocorsa\acs.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\acs.exe |
"UDP Query User{178ECA0B-CFD9-4DE6-ABF9-C9EBA182E060}C:\program files\steam\steamapps\common\assettocorsa\acs.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assettocorsa\acs.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{031F80EB-1FE5-45EF-9DE2-E2F5AF01259F}" = CCC Help Spanish
"{0B15A8C3-3B8A-F229-A880-82EA62908425}" = CCC Help Dutch
"{1A6752E1-966B-9D1F-F6B7-DDBCA6FC87ED}" = CCC Help Russian
"{2058DA53-D5F2-D8D9-7325-39B0E367D1E1}" = CCC Help Swedish
"{2090B6D0-E025-5A67-9838-8F1D5768E643}" = CCC Help Chinese Standard
"{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding
"{2AD4FF67-43E9-77AD-D90C-584F950E2D12}" = CCC Help French
"{2CC34925-D47D-BD10-AA1E-FAA76F3B5D82}" = AMD Wireless Display v3.0
"{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{3911CF56-9EF2-39BA-846A-C27BD3CD0685}" = Microsoft .NET Framework 4.5.2
"{3A577334-7C90-55BC-1878-F5862FA268B2}" = CCC Help Korean
"{3BF289E3-933B-F421-3B59-F6BB0D285B09}" = CCC Help Hungarian
"{3CB6BA0C-6BC5-E543-221A-AA4DEBB6F4B5}" = CCC Help Polish
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{430E2D32-6EA9-E6E4-80A1-84047694A45B}" = CCC Help Czech
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{467BD8D1-2A8D-4366-911A-14146F07A91C}" = Intel(R) Rapid Storage Technology
"{4A6A8D33-09CD-FD44-4BF0-999E8A6E93C8}" = CCC Help Italian
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{60D32CDC-E3BE-4578-BA10-29322307CDDC}" = Logitech Gaming Software 5.10
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6EBDE2A2-0CFB-9134-A859-68A0002B3FA6}" = CCC Help Thai
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{769E98DC-2BB0-83A7-51C9-306F30232345}" = Catalyst Control Center Graphics Previews Common
"{80F52BC0-7AC5-17C3-F34B-8613E213D44D}" = AMD Accelerated Video Transcoding
"{8181B50E-0E33-DE07-AAB2-E71BBBDBF288}" = CCC Help Portuguese
"{83FB054C-7DA5-1C76-BFB2-423426DC35BB}" = AMD Catalyst Control Center
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A640069-9784-701E-AC8E-84F62C42D1A3}" = CCC Help English
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2
"{93098E43-2743-1551-447F-2699E9591E9C}" = CCC Help Danish
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{99415B03-525E-3FEA-2A60-359FD6BCD368}" = ccc-utility
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BB76948-12B0-97E4-1954-DF52AAA4EFF9}" = AMD Drag and Drop Transcoding
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3703A3B-FDCF-4349-4B2E-A189A2B90B51}" = CCC Help Chinese Traditional
"{A5457401-D56A-43F2-9524-78E54A7FC07A}" = SlimDrivers
"{A619A488-A4BA-F2A0-72FA-4C484B93DC0F}" = CCC Help Greek
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.07) - Polish
"{C4799AAA-CE52-D2F1-63C8-E6D5106C78E0}" = CCC Help Norwegian
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C6182116-5F2D-9949-B42B-06073E86A98A}" = CCC Help German
"{CC6C7F05-AF23-65BD-702D-705EAB723578}" = CCC Help Japanese
"{D5B7F1A3-2CA6-4C5C-EFB6-4AA5772F5310}" = CCC Help Turkish
"{DADC7AB0-E554-4705-9F6A-83EA82ED708E}" = Realtek Ethernet Diagnostic Utility
"{DBA6B3EF-A8C0-4EB2-9554-3A7879838580}" = Catalyst Control Center Localization All
"{DC7723BE-A2BB-58A0-4820-5630F9B82198}" = AMD Catalyst Install Manager
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4A6308C-55E6-57DF-95BB-AEEF374B469A}" = CCC Help Finnish
"{F543B0F9-D1F9-25D1-993C-8430BEC9D889}" = Catalyst Control Center InstallProxy
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Afterburner" = MSI Afterburner 3.0.0 Beta 19
"AIMP3" = AIMP3
"AQQ" = AQQ
"Avast" = avast! Internet Security
"Battlelog Web Plugins" = Battlelog Web Plugins
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.69.2
"CWK" = CWK (Czasowy Wyłącznik Komputera)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESN Sonar-0.70.4" = ESN Sonar
"Glary Utilities 5" = Glary Utilities PRO 5.0
"Google Chrome" = Google Chrome
"HD Tune_is1" = HD Tune 2.55
"ipla" = ipla 2.7
"KLiteCodecPack_is1" = K-Lite Codec Pack 10.4.8 Full
"Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 29.0.1 (x86 pl)" = Mozilla Firefox 29.0.1 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NapiProjekt_is1" = NapiProjekt (2.2.0.2399)
"Origin" = Origin
"OscarX7Mouse5Mode" = 5-Mode Oscar Editor
"PunkBusterSvc" = PunkBuster Services
"RTSS" = RivaTuner Statistics Server 6.1.0
"SpeedFan" = SpeedFan (remove only)
"Steam" = Steam
"Steam App 244210" = Assetto Corsa
"Steam App 255480" = NBA 2K14
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VLC media player" = VLC media player 2.1.3
"webget" = webget
"WinRAR archiver" = WinRAR 5.10 beta 4 (32-bit)
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-281493417-172796843-820964179-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"K-Lite Codec Pack Packages" = K-Lite Codec Pack Packages
"uTorrent" = µTorrent
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2014-05-16 06:53:04 | Computer Name = KompOdyna | Source = Microsoft-Windows-CertificateServicesClient | ID = 1003
Description = Klient usług certyfikatów nie może wywołać dostawców w odpowiedzi
na zdarzenie 256. Kod błędu 2147942432.
Error - 2014-05-16 17:00:12 | Computer Name = KompOdyna | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: acs.exe, wersja: 0.0.0.0, sygnatura
czasowa: 0x5372302a Nazwa modułu powodującego błąd: kernel32.dll, wersja: 6.1.7600.17206,
sygnatura czasowa: 0x50e65f4e Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000c678c
Identyfikator
procesu powodującego błąd: 0x1dd8 Godzina uruchomienia aplikacji powodującej błąd:
0x01cf71467212ba7a Ścieżka aplikacji powodującej błąd: C:\Program Files\Steam\SteamApps\common\assettocorsa\acs.exe
Ścieżka
modułu powodującego błąd: C:\Windows\system32\kernel32.dll Identyfikator raportu:
123ccbe1-dd3d-11e3-ab8a-50e549267fb4
Error - 2014-05-17 05:49:04 | Computer Name = KompOdyna | Source = VSS | ID = 8194
Description =
Error - 2014-05-17 06:32:01 | Computer Name = KompOdyna | Source = MsiInstaller | ID = 1043
Description =
Error - 2014-05-17 07:10:05 | Computer Name = KompOdyna | Source = MsiInstaller | ID = 11935
Description =
Error - 2014-05-17 07:10:57 | Computer Name = KompOdyna | Source = MsiInstaller | ID = 1024
Description =
Error - 2014-05-17 07:21:41 | Computer Name = KompOdyna | Source = ESENT | ID = 215
Description = WinMail (3472) WindowsMail0: Tworzenie kopii zapasowej zostało zatrzymane,
ponieważ zostało przerwane przez klienta lub nie można nawiązać połączenia z klientem.
Error - 2014-05-17 07:41:51 | Computer Name = KompOdyna | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\glary
utilities 5\DPInst64.exe". Nie można odnaleźć zestawu zależnego Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.
Error - 2014-05-17 07:42:05 | Computer Name = KompOdyna | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\rivatuner
statistics server\EncoderServer64.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.
Error - 2014-05-17 07:42:06 | Computer Name = KompOdyna | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\rivatuner
statistics server\RTSSHooksLoader64.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.
[ System Events ]
Error - 2014-05-15 18:59:36 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi rixbzitc z powodu następującego błędu:
%%2
Error - 2014-05-15 19:34:29 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7023
Description = Usługa Wstępne ładowanie do pamięci zakończyła działanie; wystąpił
następujący błąd: %%1062
Error - 2014-05-15 19:44:52 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7031
Description = Usługa avast! Antivirus niespodziewanie zakończyła pracę. Wystąpiło
to razy: 1. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna:
Uruchom usługę ponownie.
Error - 2014-05-16 06:54:33 | Computer Name = KompOdyna | Source = Service Control Manager | ID = 7023
Description = Usługa Instalator modułów systemu Windows zakończyła działanie; wystąpił
następujący błąd: %%16405
Error - 2014-05-16 06:57:27 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja listy
widoku zgodności programu Internet Explorer 8 dla systemu Windows 7 (KB2598845).
Error - 2014-05-16 06:57:27 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja systemu
Windows 7 (KB2703157).
Error - 2014-05-17 05:39:53 | Computer Name = KompOdyna | Source = Microsoft-Windows-Directory-Services-SAM | ID = 12291
Description = Modułowi SAM nie powiodło się uruchomienie wątku nasłuchu TCP/IP lub
SPX/IPX.
Error - 2014-05-17 07:11:02 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Dodatek Service Pack
3 (SP3) dla pakietu Microsoft Office 2007.
Error - 2014-05-17 07:24:23 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Uaktualnienie pakietu
Podstawowe programy Windows Live 2011 (KB2434419).
Error - 2014-05-17 07:24:23 | Computer Name = KompOdyna | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja dla systemu
Windows 7 (KB976422).
< End of report >
Pozdrawiam