
Proszę o pomoc w usunięciu problemów:
- wirus policja w wyszukiwarce chrome, nie jest to typowy objaw tego wirusa czyli komunikat w ful screen ale w pojedynczej karcie wyszukiwarki, i nie można przejść do innej karty. IE działa bez problemu.
- strona startowa http://www.sweet-page.com w IE, której nie można zmienić na inną.
- wyskakujące reklamy co jakiś czas w nowej karcie przeglądarki.
Poniżej logi:
Gmer:
- Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-17 09:57:02
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 HITACHI_ rev.JF4Z 698,64GB
Running: qey2u56d.exe; Driver: C:\Users\Marcin\AppData\Local\Temp\awrdrpoc.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800035a4000 65 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594 fffff800035a4042 4 bytes [00, 00, 00, 00]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2940] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\d3d9.dll!Direct3DCreate9Ex 000007fef7282460 5 bytes JMP 000007fefdad02d0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2956] C:\windows\system32\d3d9.dll!Direct3DCreate9 000007fef72b96b0 6 bytes JMP 000007fefdad0298
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdab0038
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\dxgi.dll!CreateDXGIFactory 000007fef575dc88 5 bytes JMP 000007fff57300d8
.text C:\windows\system32\Dwm.exe[3388] C:\windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef575de10 5 bytes JMP 000007fff5730110
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!LoadLibraryExA 00000000769b48db 5 bytes JMP 0000000110002710
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!LoadLibraryW 00000000769b48f3 5 bytes JMP 00000001100027f0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!LoadLibraryExW 00000000769b4925 5 bytes JMP 0000000110002780
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000778f5ea5 5 bytes JMP 0000000172e72c20
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\ole32.dll!CoCreateInstance 0000000077929d0b 5 bytes JMP 0000000172e72bb0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3596] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2560] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\WINMM.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdac02b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\WINMM.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdac0238
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\WINMM.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdac01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1924] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe[3540] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[3624] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\WINMM.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdac02b8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\WINMM.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdac0238
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\WINMM.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdac01b8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[3684] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Windows\System32\igfxtray.exe[3704] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 5 bytes JMP 000007fffdad00b8
.text C:\Windows\System32\igfxtray.exe[3704] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdad0038
.text C:\Windows\System32\igfxtray.exe[3704] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 5 bytes JMP 000007fffdad0138
.text C:\Windows\System32\hkcmd.exe[3660] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 5 bytes JMP 000007fffdad00b8
.text C:\Windows\System32\hkcmd.exe[3660] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdad0038
.text C:\Windows\System32\hkcmd.exe[3660] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 5 bytes JMP 000007fffdad0138
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\Windows\System32\igfxpers.exe[3768] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files\Microsoft Security Client\msseces.exe[3852] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 5 bytes JMP 000007fffdab00b8
.text C:\Program Files\Microsoft Security Client\msseces.exe[3852] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdab0038
.text C:\Program Files\Microsoft Security Client\msseces.exe[3852] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 5 bytes JMP 000007fffdab0138
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!LoadLibraryExA 00000000769b48db 5 bytes JMP 0000000110002710
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!LoadLibraryW 00000000769b48f3 5 bytes JMP 00000001100027f0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!LoadLibraryExW 00000000769b4925 5 bytes JMP 0000000110002780
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3796] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000778f5ea5 5 bytes JMP 0000000172e72c20
.text C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe[3916] C:\windows\syswow64\ole32.dll!CoCreateInstance 0000000077929d0b 5 bytes JMP 0000000172e72bb0
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016ff20228
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016ff20180
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016ff201b8
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016ff20110
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016ff200d8
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016ff20148
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 3 bytes JMP 000000016ff201f0
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\kernel32.dll!RegSetValueExA + 4 0000000077ad87e4 3 bytes [F8, CC, CC]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\WINMM.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdac02b8
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\WINMM.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdac0238
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4048] C:\windows\system32\WINMM.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdac01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\WINMM.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdac02b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\WINMM.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdac0238
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1356] C:\windows\system32\WINMM.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdac01b8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[1512] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[1512] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[1512] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[1512] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[1512] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[1512] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!LoadLibraryExA 00000000769b48db 5 bytes JMP 0000000110002710
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!LoadLibraryW 00000000769b48f3 5 bytes JMP 00000001100027f0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!LoadLibraryExW 00000000769b4925 5 bytes JMP 0000000110002780
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000778f5ea5 5 bytes JMP 0000000172e72c20
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\windows\syswow64\ole32.dll!CoCreateInstance 0000000077929d0b 5 bytes JMP 0000000172e72bb0
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007307adf9 5 bytes JMP 0000000110003390
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\Windows\SysWOW64\WINMM.dll!waveOutPause 0000000073095484 5 bytes JMP 0000000110003430
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[3804] C:\Windows\SysWOW64\WINMM.dll!waveOutRestart 00000000730954b8 5 bytes JMP 00000001100034d0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!LoadLibraryExA 00000000769b48db 5 bytes JMP 0000000100552710
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!LoadLibraryW 00000000769b48f3 5 bytes JMP 00000001005527f0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!LoadLibraryExW 00000000769b4925 5 bytes JMP 0000000100552780
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000778f5ea5 5 bytes JMP 0000000172e72c20
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[116] C:\windows\syswow64\ole32.dll!CoCreateInstance 0000000077929d0b 5 bytes JMP 0000000172e72bb0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!LoadLibraryExA 00000000769b48db 5 bytes JMP 0000000110002710
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!LoadLibraryW 00000000769b48f3 5 bytes JMP 00000001100027f0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!LoadLibraryExW 00000000769b4925 5 bytes JMP 0000000110002780
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000778f5ea5 5 bytes JMP 0000000172e72c20
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\ole32.dll!CoCreateInstance 0000000077929d0b 5 bytes JMP 0000000172e72bb0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3032] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\windows\SysWOW64\RunDll32.exe[5152] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\windows\SysWOW64\RunDll32.exe[5152] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\WINMM.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdac02b8
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\WINMM.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdac0238
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[5236] C:\windows\system32\WINMM.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdac01b8
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!LoadLibraryExA 00000000769b48db 5 bytes JMP 0000000110002710
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!LoadLibraryW 00000000769b48f3 5 bytes JMP 00000001100027f0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!LoadLibraryExW 00000000769b4925 5 bytes JMP 0000000110002780
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000778f5ea5 5 bytes JMP 0000000172e72c20
.text C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe[5584] C:\windows\syswow64\ole32.dll!CoCreateInstance 0000000077929d0b 5 bytes JMP 0000000172e72bb0
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdac0180
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdac00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdac0148
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdab0038
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdac0110
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdac01f0
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdac01b8
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 5 bytes JMP 000007fffdab0138
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\WINMM.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdab02b8
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\WINMM.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdab0238
.text C:\Program Files\Internet Explorer\iexplore.exe[5488] C:\windows\system32\WINMM.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdab01b8
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\user32.DLL!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\user32.DLL!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\user32.DLL!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5036] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdab0038
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 5 bytes JMP 000007fffdab0138
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\winmm.dll!waveOutReset 000007fef7daa38c 5 bytes JMP 000007fefdab02b8
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\winmm.dll!waveOutPause 000007fef7dc4b60 5 bytes JMP 000007fefdab0238
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\winmm.dll!waveOutRestart 000007fef7dc4ba0 5 bytes JMP 000007fefdab01b8
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\dsound.dll!DirectSoundCreate8 000007fef2046944 5 bytes JMP 000007fefdab0438
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\dsound.dll!DirectSoundCreate 000007fef2065a84 5 bytes JMP 000007fefdab0338
.text C:\windows\system32\Macromed\Flash\FlashUtil64_13_0_0_214_ActiveX.exe[1528] C:\windows\system32\d3d9.dll!Direct3DCreate9 000007fef72b96b0 5 bytes JMP 000007fefdab03b8
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\user32.DLL!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\user32.DLL!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\user32.DLL!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[5556] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!RegSetValueExW 0000000077a4a400 7 bytes JMP 000000016fff0228
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!RegQueryValueExW 0000000077a53f20 5 bytes JMP 000000016fff0180
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!LoadLibraryW 0000000077a56440 5 bytes JMP 0000000169ff0038
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!RegDeleteValueW 0000000077a6ffb0 5 bytes JMP 000000016fff01b8
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077a7f2e0 5 bytes JMP 000000016fff0110
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077aa9a30 7 bytes JMP 000000016fff00d8
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!K32GetModuleInformation 0000000077ab94c0 5 bytes JMP 000000016fff0148
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\kernel32.dll!RegSetValueExA 0000000077ad87e0 7 bytes JMP 000000016fff01f0
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefdaebfd0 5 bytes JMP 000007fffdac0038
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\windows\system32\StikyNot.exe[7548] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdae2db0 5 bytes JMP 000007fffdad0180
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdae37d0 7 bytes JMP 000007fffdad00d8
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdae8ef0 6 bytes JMP 000007fffdad0148
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdafaf60 5 bytes JMP 000007fffdad0110
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feffc489e0 8 bytes JMP 000007fffdad01f0
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feffc4be40 8 bytes JMP 000007fffdad01b8
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\ole32.dll!CoCreateInstance 000007feff487490 11 bytes JMP 000007fffdad0228
.text C:\windows\System32\MsSpellCheckingFacility.exe[5208] C:\windows\system32\ole32.dll!CoSetProxyBlanket 000007feff49bf00 7 bytes JMP 000007fffdad0260
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\user32.DLL!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\user32.DLL!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\user32.DLL!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076121465 2 bytes [12, 76]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[12460] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761214bb 2 bytes [12, 76]
.text ... * 2
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!RegQueryValueExW 00000000769b1f0e 7 bytes JMP 0000000172e73550
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!RegSetValueExW 00000000769b5bad 7 bytes JMP 0000000172e737f0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!RegSetValueExA 00000000769c1409 7 bytes JMP 0000000172e73650
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!RegDeleteValueW 00000000769cea45 7 bytes JMP 0000000172e73540
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076a58e24 7 bytes JMP 0000000172e73310
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076a58ea9 5 bytes JMP 0000000172e733c0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076a591ff 5 bytes JMP 0000000172e73320
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075d21d29 5 bytes JMP 0000000172e732b0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075d21dd7 5 bytes JMP 0000000172e73270
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075d22ab1 5 bytes JMP 0000000172e733d0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075d22d17 5 bytes JMP 0000000172e730b0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000760be96b 5 bytes JMP 0000000172e72cd0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000760beba5 5 bytes JMP 0000000172e72ce0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\USER32.dll!CreateWindowExW 0000000075f48a29 5 bytes JMP 0000000172e72c60
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075f54572 5 bytes JMP 0000000172e73030
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075f6e567 5 bytes JMP 0000000172e730a0
.text C:\Users\Marcin\Desktop\Emergency\qey2u56d.exe[16836] C:\windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075fa7a5c 5 bytes JMP 0000000172e73020
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{BBD2A085-A229-49E0-AEE6-1E749DA3C7AF}\Connection@Name isatap.{54B1E279-D167-4444-A161-923AB4CCDBF2}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{EDD0AB95-4D1B-42F1-8AFC-F6593034AF24}\Connection@Name isatap.{FFF3BD0F-977D-47D9-955C-A305BE017D97}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{D2C0DE2C-CE32-453C-9B5E-A90144F35990}?\Device\{9411477D-CD72-4FDD-B660-656410BE3AD4}?\Device\{16B48FE0-65CC-4A7D-A0F0-8173D287C774}?\Device\{EDD0AB95-4D1B-42F1-8AFC-F6593034AF24}?\Device\{BBD2A085-A229-49E0-AEE6-1E749DA3C7AF}?\Device\{6571B598-8E21-458A-8381-809937CF8BB7}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{D2C0DE2C-CE32-453C-9B5E-A90144F35990}"?"{9411477D-CD72-4FDD-B660-656410BE3AD4}"?"{16B48FE0-65CC-4A7D-A0F0-8173D287C774}"?"{EDD0AB95-4D1B-42F1-8AFC-F6593034AF24}"?"{BBD2A085-A229-49E0-AEE6-1E749DA3C7AF}"?"{6571B598-8E21-458A-8381-809937CF8BB7}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{D2C0DE2C-CE32-453C-9B5E-A90144F35990}?\Device\TCPIP6TUNNEL_{9411477D-CD72-4FDD-B660-656410BE3AD4}?\Device\TCPIP6TUNNEL_{16B48FE0-65CC-4A7D-A0F0-8173D287C774}?\Device\TCPIP6TUNNEL_{EDD0AB95-4D1B-42F1-8AFC-F6593034AF24}?\Device\TCPIP6TUNNEL_{BBD2A085-A229-49E0-AEE6-1E749DA3C7AF}?\Device\TCPIP6TUNNEL_{6571B598-8E21-458A-8381-809937CF8BB7}?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fc1a13
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\64273789d3b8
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{BBD2A085-A229-49E0-AEE6-1E749DA3C7AF}@InterfaceName isatap.{54B1E279-D167-4444-A161-923AB4CCDBF2}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{BBD2A085-A229-49E0-AEE6-1E749DA3C7AF}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{EDD0AB95-4D1B-42F1-8AFC-F6593034AF24}@InterfaceName isatap.{FFF3BD0F-977D-47D9-955C-A305BE017D97}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{EDD0AB95-4D1B-42F1-8AFC-F6593034AF24}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fc1a13 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\64273789d3b8 (not active ControlSet)
---- Files - GMER 2.1 ----
File C:\Users\Marcin\AppData\Local\Temp\~DF93F6658843D96789.TMP 0 bytes
File C:\Users\Marcin\AppData\Local\Temp\~DFD87F209F81061E91.TMP 0 bytes
---- EOF - GMER 2.1 ----
OTL:
- Kod: Zaznacz wszystko
OTL Extras logfile created on: 2014-05-17 09:58:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marcin\Desktop\Emergency
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
7,92 Gb Total Physical Memory | 4,54 Gb Available Physical Memory | 57,32% Memory free
15,83 Gb Paging File | 12,40 Gb Available in Paging File | 78,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 654,69 Gb Total Space | 605,87 Gb Free Space | 92,54% Space Free | Partition Type: NTFS
Drive D: | 29,00 Gb Total Space | 11,73 Gb Free Space | 40,44% Space Free | Partition Type: NTFS
Computer Name: MARCIN-KOMPUTER | User Name: Marcin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[color=#E56717]========== Shell Spawning ==========[/color]
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
[color=#E56717]========== Security Center Settings ==========[/color]
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
[color=#E56717]========== Firewall Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[color=#E56717]========== Authorized Applications List ==========[/color]
[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{098A14B8-99D7-48FD-B233-8F84D3B7C95A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0DCCC8BC-80EF-4AF4-AE17-34EB246580CF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{130400FA-0DEA-4F7E-979B-EB9313AC4295}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{16170AC7-1826-4A4F-912A-D17EA0CFD7DC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{1779D5B5-EEF3-4387-8923-00942E298E44}" = lport=445 | protocol=6 | dir=in | app=system |
"{1D0A0FBD-CF9B-4349-B8E2-5F884E78FFB3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{293B1036-C798-4946-A898-A87C326C3359}" = lport=137 | protocol=17 | dir=in | app=system |
"{3A64103E-D1D1-4B5B-952E-6219C46D5A52}" = lport=138 | protocol=17 | dir=in | app=system |
"{4122D4C7-AA66-468C-8A09-9A5699B4D51B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{469997D7-1596-4FDB-8934-E25C6D24D6C3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{47CD0FFA-8AF5-4907-BCEF-160E21DEC9BB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{55E22E34-0599-44FA-BB1D-4C09543E59B1}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{5EBD0BE5-56C8-4A27-A90A-39B674405A2F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{63E789A8-5CF0-4CA6-B6E2-8D8E61A37E1C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{91A6B0A0-761C-4B9E-B9BD-53DF87336111}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9D6D518E-3BF0-4AC8-A00E-9BC548AA0E82}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A01E510D-4A78-4F06-8495-BF2B5FE83F0A}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{A26C786D-2AF3-4B5D-83E7-AAD9CC044B95}" = rport=445 | protocol=6 | dir=out | app=system |
"{A28174D1-2DA6-4679-8AA9-6B65B1AE60E3}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{A5FAD67D-68BE-498E-9676-97AA94F46F2F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A93C667B-95A4-4FDC-93A3-DE96168A677E}" = rport=139 | protocol=6 | dir=out | app=system |
"{B7CD5C9B-4863-4520-8539-35B5B7E256E2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C0DBECDA-6557-4073-BDFF-B41EC96D8827}" = lport=139 | protocol=6 | dir=in | app=system |
"{C737ECE3-D5A0-4984-8BFC-22E8D8538E42}" = rport=137 | protocol=17 | dir=out | app=system |
"{CC7106C2-941E-4BA7-804D-4058EA8AF9B8}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{D71105A8-A263-4E2D-9F30-12451F1E0EE5}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{EAB7ACFF-8D9F-4500-B437-BAA5DBBD3AE9}" = rport=138 | protocol=17 | dir=out | app=system |
"{F6047913-53DE-4091-9CD1-482637D92CEB}" = lport=10243 | protocol=6 | dir=in | app=system |
"{FA349BA6-6C25-4FF1-B8BD-9A49E94A0703}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
[color=#E56717]========== Vista Active Application Exception List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{132E86B1-863F-4655-973C-139D02F862B8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{193B930D-5779-4EF6-A546-068BC3C659EE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{245E242D-6764-4F52-BA61-C341E3693183}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2F70559C-6E98-4DDE-AFD0-4692CB176A3B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{301BBE09-A288-46DF-AF1C-C21389D83486}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3763CD33-F16D-482F-9004-BB72C1C71A63}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4CCDA4ED-27F9-4A8E-9665-85ED6AC93FB4}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{5D8D1F9E-118C-48D2-82BF-41AE4EA2E9D4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6C4E8B32-57A2-45FD-87CF-65F8E73229C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6E12FCD9-EBF0-4276-B0CB-05B4BEFC9919}" = protocol=6 | dir=out | app=system |
"{77314B34-4E83-48C6-BD17-24C0ECCEC052}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{818BF532-AA31-4B29-BEEE-3C9431DF8127}" = dir=in | app=c:\program files (x86)\intel corporation\intel wireless display\widiapp.exe |
"{85612B12-AA19-4970-A8A1-CE45485F2879}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{89792C42-EF16-40C7-9000-417F0C608F9D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{8BC1DE07-E429-40DE-9956-6D078A7ABB93}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{9B507B69-2954-4EBA-AC64-DE6896E8E3D0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A90B2147-6D41-4CE4-885B-75D4F7F1F8C8}" = dir=in | app=c:\users\marcin\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{B2AF2F7D-8598-4722-9628-45941AD66A32}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B7A4836C-39C9-471F-BFB4-AF511F081107}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B9647180-8CD4-48A1-A929-9772C2932669}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{BAB300D4-52D8-4228-A62D-35A8D3D3B7C4}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{BE14B783-39AC-4E93-BEE1-9883329BC8A9}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{C0E9CCD7-CBB2-44DA-AB73-062329EE67B6}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{C6AA24D5-6737-4217-8A3C-A134B219D2E2}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{C7B30F4A-677C-47C9-8A8F-A338B1A9DD3A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C9C3EEF8-B02A-4352-86E6-F0E99025637A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CA38B87A-8954-47D9-80F7-6585093FAF62}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{CF1FD111-5F21-4D92-BA29-9B666E100190}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{DFCE235E-AC14-4474-A8C4-815AFA334C3A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{E0F50FC5-BCC4-4FD5-A7A4-E7CFBE75C7A2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E417B704-4CFB-487D-BD04-96E13D51A375}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E9D41D90-E8A7-444E-A67B-6084781FBA98}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F8C8813A-35CD-4E22-BD5E-02F5599DB051}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FADD48C7-F142-4E62-A642-F57C5E9C66D9}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources
"{25EE6AF4-8FD6-4E09-AD9B-3ACC0B81D902}" = SRS Control Panel
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = Lenovo Bluetooth with Enhanced Data Rate Software
"{45F1F774-38B4-3CC3-BAAF-051E6D19E48E}" = Microsoft .NET Framework 4.5.1 (PLK)
"{4681CBC7-F304-4EF1-BBE9-B5CFCADCD3DA}" = Intel® PROSet/Wireless WiFi Software
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{55edfa54-e764-453a-9014-144255fb40d3}" = Intel(R) PRO/Wireless Driver
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6F280399-F8BD-4F2E-BCA4-207BEBCDE33A}" = Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 334.89
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 334.89
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.2.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus Update 11.10.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.13.1220
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 11.10.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamC" = GeForce Experience NvStream Client Components
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 11.10.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.20
"{BFAE8D5B-F918-486F-B74E-90762DF11C5C}" = Microsoft Security Client
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF1A8490-3CD2-4878-92BE-F746D7CCACC1}" = AVG 2014
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"CCleaner" = CCleaner
"EA12B1FB53CE4E387C31A85236C41EF559B5E392" = Pakiet sterowników systemu Windows - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1)
"Lenovo EE Boot Optimizer" = Lenovo EE Boot Optimizer
"Microsoft Security Client" = Microsoft Security Essentials
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.20 (64-bitowy)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217051FF}" = Java 7 Update 55
"{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources
"{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{440d014b-4444-4533-b96d-2910e1ca2bcf}" = Oprogramowanie Intel® PROSet/Wireless
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live
"{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A2804FE8-4101-48a0-AE1A-575B99014BF4}-Mio-7.50" = MioMore Desktop 7.50
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.07) - Polish
"{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera
"{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych
"{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh
"{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = Podręcznik użytkownika
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker
"{F84906ED-BB54-4889-B131-FED9C9056FC8}" = Intel(R) Wireless Display
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"InstallShield_{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater
"InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide
"Polski VAG 2.5_is1" = Polski VAG 2.5
"VeriFace" = VeriFace
"WinLiveSuite" = Podstawowe programy Windows Live
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OpenFM" = OpenFM
[color=#E56717]========== Last 20 Event Log Errors ==========[/color]
[ Application Events ]
Error - 2014-05-10 09:37:26 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-11 03:15:02 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-12 02:09:05 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-12 15:43:11 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-13 01:52:15 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-14 02:12:54 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-14 02:14:24 | Computer Name = Marcin-Komputer | Source = MsiInstaller | ID = 1024
Description =
Error - 2014-05-15 02:27:32 | Computer Name = Marcin-Komputer | Source = WinMgmt | ID = 10
Description =
Error - 2014-05-15 02:29:01 | Computer Name = Marcin-Komputer | Source = MsiInstaller | ID = 1024
Description =
Error - 2014-05-15 15:11:28 | Computer Name = Marcin-Komputer | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 2014-05-16 13:01:57 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:01:57 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:01:57 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:00 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:00 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:01 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:01 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:01 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:15 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
Error - 2014-05-16 13:03:15 | Computer Name = Marcin-Komputer | Source = Schannel | ID = 36888
Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego:
252.
< End of report >
OTL logfile created on: 2014-05-17 09:58:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marcin\Desktop\Emergency
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
7,92 Gb Total Physical Memory | 4,54 Gb Available Physical Memory | 57,32% Memory free
15,83 Gb Paging File | 12,40 Gb Available in Paging File | 78,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 654,69 Gb Total Space | 605,87 Gb Free Space | 92,54% Space Free | Partition Type: NTFS
Drive D: | 29,00 Gb Total Space | 11,73 Gb Free Space | 40,44% Space Free | Partition Type: NTFS
Computer Name: MARCIN-KOMPUTER | User Name: Marcin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2014-05-17 09:17:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\Emergency\OTL_[www.programosy.pl].exe
PRC - [2014-02-05 11:32:47 | 002,234,144 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014-02-05 11:32:34 | 001,593,632 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2013-12-21 08:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012-04-02 17:47:03 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
PRC - [2012-04-02 17:44:23 | 000,329,056 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2011-02-15 14:26:42 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010-12-20 12:30:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010-12-20 12:30:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010-12-05 03:39:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2014-02-08 20:34:51 | 000,013,088 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
MOD - [2012-04-02 17:47:03 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
MOD - [2012-04-02 17:44:22 | 000,013,664 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010-11-11 12:39:46 | 000,133,024 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll
MOD - [2010-11-11 12:38:44 | 000,161,696 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2014-03-11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:[b]64bit:[/b] - [2014-03-11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:[b]64bit:[/b] - [2014-03-06 10:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014-02-05 11:32:24 | 016,941,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:[b]64bit:[/b] - [2013-11-20 19:00:20 | 003,674,864 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV:[b]64bit:[/b] - [2013-11-20 18:59:58 | 000,284,912 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:[b]64bit:[/b] - [2013-11-20 18:59:38 | 000,631,024 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:[b]64bit:[/b] - [2013-11-20 18:58:50 | 000,154,864 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:[b]64bit:[/b] - [2013-07-29 05:01:08 | 000,772,064 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV:[b]64bit:[/b] - [2013-05-27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2012-09-12 19:07:06 | 000,135,984 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV:[b]64bit:[/b] - [2011-02-15 14:26:42 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:[b]64bit:[/b] - [2010-09-22 20:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2014-05-14 00:10:20 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-02-05 11:32:34 | 001,593,632 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014-01-30 00:02:44 | 000,279,000 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2013-12-21 08:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013-11-11 23:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013-10-23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-09-24 02:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013-09-11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-12-20 12:30:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010-12-20 12:30:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2014-03-11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:[b]64bit:[/b] - [2014-02-08 20:34:51 | 000,032,544 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:[b]64bit:[/b] - [2014-01-30 00:02:28 | 005,363,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2014-01-14 10:52:20 | 000,086,376 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ftser2k.sys -- (FTSER2K)
DRV:[b]64bit:[/b] - [2014-01-14 10:52:20 | 000,079,592 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ftdibus.sys -- (FTDIBUS)
DRV:[b]64bit:[/b] - [2013-12-27 20:42:26 | 000,039,200 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:[b]64bit:[/b] - [2013-07-29 05:01:24 | 000,164,832 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:[b]64bit:[/b] - [2013-07-29 05:01:24 | 000,164,832 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:[b]64bit:[/b] - [2013-05-29 06:10:52 | 011,524,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwsw00.sys -- (NETwNs64)
DRV:[b]64bit:[/b] - [2013-02-12 06:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:[b]64bit:[/b] - [2012-04-02 17:58:34 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:[b]64bit:[/b] - [2012-04-02 17:58:32 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:[b]64bit:[/b] - [2012-04-02 17:45:48 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:[b]64bit:[/b] - [2012-04-02 17:45:48 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011-09-29 05:23:24 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011-09-29 05:23:24 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011-02-18 10:11:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2011-02-15 08:45:16 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:[b]64bit:[/b] - [2011-02-15 08:45:12 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:[b]64bit:[/b] - [2011-02-15 08:45:12 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:[b]64bit:[/b] - [2011-02-15 08:45:12 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:[b]64bit:[/b] - [2011-02-15 08:45:12 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:[b]64bit:[/b] - [2010-12-22 14:19:58 | 001,407,024 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2010-12-05 03:39:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:[b]64bit:[/b] - [2010-12-01 07:02:22 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:[b]64bit:[/b] - [2010-11-30 08:40:04 | 000,307,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:[b]64bit:[/b] - [2010-11-21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2010-10-19 10:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2010-10-14 19:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010-05-31 05:46:50 | 000,333,928 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2009-07-21 16:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1395471506&from=wpc&uid=HITACHIXHTS727575A9E364_J3740084H7AJ9EH7AJ9EX&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Marcin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
[2013-04-21 01:41:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcin\AppData\Roaming\mozilla\Extensions
O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:[b]64bit:[/b] - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe (Lenovo(beijing) Limited)
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\windows\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\windows\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:[b]64bit:[/b] - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe (CyberLink Corp.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Marcin\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\windows\system32\StikyNot.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
O8:[b]64bit:[/b] - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:[b]64bit:[/b] - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:[b]64bit:[/b] - Extra Button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: PokerStars.eu - {07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe File not found
O9 - Extra Button: Wyślij do interfejsu Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Wyślij do urządzenia &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6FE02644-9ADC-4E7B-BE34-6ECAC087EEF0}: DhcpNameServer = 192.168.1.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (c:\windows\syswow64\nvinit.dll) - c:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2014-05-15 08:10:12 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2014-05-15 08:10:12 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2014-05-14 08:19:49 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\aepdu.dll
[2014-05-14 08:19:49 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\aeinv.dll
[2014-05-14 08:19:37 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\lsasrv.dll
[2014-05-14 08:19:36 | 003,969,984 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntkrnlpa.exe
[2014-05-14 08:19:36 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntoskrnl.exe
[2014-05-14 08:19:36 | 000,722,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\objsel.dll
[2014-05-14 08:19:36 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winlogon.exe
[2014-05-14 08:19:35 | 005,550,016 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe
[2014-05-14 08:19:35 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\objsel.dll
[2014-05-14 08:19:34 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\KernelBase.dll
[2014-05-14 08:19:34 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cngprovider.dll
[2014-05-14 08:19:34 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\adprovider.dll
[2014-05-14 08:19:34 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dimsroam.dll
[2014-05-14 08:19:34 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dimsroam.dll
[2014-05-14 08:19:33 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\sspicli.dll
[2014-05-14 08:19:33 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\capiprovider.dll
[2014-05-14 08:19:33 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dpapiprovider.dll
[2014-05-14 08:19:33 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\cngprovider.dll
[2014-05-14 08:19:33 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\adprovider.dll
[2014-05-14 08:19:33 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\capiprovider.dll
[2014-05-14 08:19:33 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dpapiprovider.dll
[2014-05-14 08:19:33 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wincredprovider.dll
[2014-05-14 08:19:32 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wincredprovider.dll
[2014-05-14 08:19:32 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\sspisrv.dll
[2014-05-14 08:19:32 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\secur32.dll
[2014-05-10 17:17:09 | 000,000,000 | -HSD | C] -- C:\Users\Marcin\AppData\Local\EmieUserList
[2014-05-10 17:17:09 | 000,000,000 | -HSD | C] -- C:\Users\Marcin\AppData\Local\EmieSiteList
[2014-05-07 23:20:39 | 000,000,000 | --SD | C] -- C:\windows\SysNative\CompatTel
[2014-05-07 08:19:59 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\Macromedia
[2014-05-07 08:19:57 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\OpenFM
[2014-05-06 22:08:49 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\GG
[2014-05-06 22:08:42 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\GG
[2014-05-06 22:08:41 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\OpenFM
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2014-05-17 09:10:00 | 000,000,930 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014-05-17 08:18:08 | 000,021,280 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-05-17 08:18:08 | 000,021,280 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-05-17 08:03:05 | 000,000,932 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2631643345-423519317-2816179767-1002UA.job
[2014-05-17 08:03:03 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2014-05-16 18:48:52 | 000,000,910 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2631643345-423519317-2816179767-1002Core.job
[2014-05-15 08:33:39 | 001,670,590 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2014-05-15 08:33:39 | 000,740,688 | ---- | M] () -- C:\windows\SysNative\perfh015.dat
[2014-05-15 08:33:39 | 000,654,480 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2014-05-15 08:33:39 | 000,156,230 | ---- | M] () -- C:\windows\SysNative\perfc015.dat
[2014-05-15 08:33:39 | 000,122,352 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2014-05-15 08:28:06 | 000,524,664 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2014-05-14 00:10:20 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe
[2014-05-14 00:10:20 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2014-05-11 01:34:07 | 000,010,293 | ---- | M] () -- C:\Users\Marcin\Desktop\1517700_764254753604697_999939387_n.jpg
[2014-05-11 01:28:52 | 000,006,923 | ---- | M] () -- C:\Users\Marcin\Desktop\1536452_764258243604348_895079122_n.jpg
[2014-05-09 08:14:03 | 000,477,184 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\aepdu.dll
[2014-05-09 08:11:23 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\aeinv.dll
[2014-05-06 22:08:43 | 000,001,186 | ---- | M] () -- C:\Users\Marcin\Desktop\OpenFM.lnk
[2014-05-06 05:00:47 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2014-05-06 04:10:52 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2014-05-11 01:37:40 | 000,010,293 | ---- | C] () -- C:\Users\Marcin\Desktop\1517700_764254753604697_999939387_n.jpg
[2014-05-11 01:29:08 | 000,006,923 | ---- | C] () -- C:\Users\Marcin\Desktop\1536452_764258243604348_895079122_n.jpg
[2014-05-06 22:08:43 | 000,001,186 | ---- | C] () -- C:\Users\Marcin\Desktop\OpenFM.lnk
[2014-05-06 22:08:42 | 000,001,194 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenFM.lnk
[2014-02-26 22:57:40 | 000,002,560 | ---- | C] () -- C:\windows\_MSRSTRT.EXE
[2014-01-30 00:02:42 | 000,272,928 | ---- | C] () -- C:\windows\SysWow64\igvpkrng600.bin
[2014-01-30 00:02:22 | 000,077,312 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2014-01-30 00:02:20 | 000,963,452 | ---- | C] () -- C:\windows\SysWow64\igcodeckrng600.bin
[2013-07-27 02:21:21 | 000,000,114 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\WB.CFG
[2013-07-05 22:22:44 | 000,000,005 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\WBPU-Q3-TTL.DAT
[2013-06-18 22:11:27 | 000,000,005 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\WBPU-Q2-TTL.DAT
[2013-06-12 22:03:11 | 000,000,006 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\WBPU-TTL.DAT
[2013-05-22 08:14:07 | 001,643,196 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2013-03-28 21:36:07 | 000,000,139 | ---- | C] () -- C:\windows\disney.ini
[2013-03-28 21:11:00 | 000,003,592 | ---- | C] () -- C:\Users\Marcin\AppData\Local\HH.SAV
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-03-25 04:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-03-25 04:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:A9662AE0
< End of report >