proszę o sprawdzenie logów. Komputer od jakiegoś czasu wolno chodzi oraz pojawiły się dziwne strony główne w przeglądarce.
- Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-07-12 21:44:55
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST964042 rev.0001 596,17GB
Running: 9gvjzw5w.exe; Driver: C:\Users\Monika\AppData\Local\Temp\awrdrpog.sys
---- User code sections - GMER 2.1 ----
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076b31401 2 bytes JMP 76d2b21b C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076b31419 2 bytes JMP 76d2b346 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076b31431 2 bytes JMP 76da8f29 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000076b3144a 2 bytes CALL 76d0489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000076b314dd 2 bytes JMP 76da8822 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000076b314f5 2 bytes JMP 76da89f8 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000076b3150d 2 bytes JMP 76da8718 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076b31525 2 bytes JMP 76da8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000076b3153d 2 bytes JMP 76d1fca8 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076b31555 2 bytes JMP 76d268ef C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000076b3156d 2 bytes JMP 76da8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076b31585 2 bytes JMP 76da8b42 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000076b3159d 2 bytes JMP 76da86dc C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000076b315b5 2 bytes JMP 76d1fd41 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000076b315cd 2 bytes JMP 76d2b2dc C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000076b316b2 2 bytes JMP 76da8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000076b316bd 2 bytes JMP 76da8671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076b31401 2 bytes JMP 76d2b21b C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076b31419 2 bytes JMP 76d2b346 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076b31431 2 bytes JMP 76da8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000076b3144a 2 bytes CALL 76d0489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000076b314dd 2 bytes JMP 76da8822 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000076b314f5 2 bytes JMP 76da89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000076b3150d 2 bytes JMP 76da8718 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076b31525 2 bytes JMP 76da8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000076b3153d 2 bytes JMP 76d1fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076b31555 2 bytes JMP 76d268ef C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000076b3156d 2 bytes JMP 76da8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076b31585 2 bytes JMP 76da8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000076b3159d 2 bytes JMP 76da86dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000076b315b5 2 bytes JMP 76d1fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000076b315cd 2 bytes JMP 76d2b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000076b316b2 2 bytes JMP 76da8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\AsScrPro.exe[2288] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000076b316bd 2 bytes JMP 76da8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe[2416] C:\Windows\SysWOW64\ntdll.dll!NtQueryValueKey 000000007793faa4 5 bytes JMP 000000016e562e30
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe[2416] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077940034 5 bytes JMP 000000016e562df0
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes JMP 3f3f3f3f
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\firefox.exe[4432] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[4764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes JMP 3f3f3f3f
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[2492] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes JMP 3f3f3f3f
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[3184] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes JMP 3f3f3f3f
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe[6136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[5240] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000777413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077741544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000777418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077741ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077741bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077741d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077741e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077741f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077742248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000777426f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077742712 8 bytes {JMP 0x10}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007774276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000777427d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077742b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077742be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000777430bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077743248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000777437c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000777438b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077743a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077743fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077744061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000777440d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077744216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077744254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000777444c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000777446ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077744773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077744867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077744986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077744ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077744b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077744d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077744f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077745007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000777451f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077746006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000777461be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000777463ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000777463ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077746404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007774645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077746c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007778dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007778de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007778de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007778df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007778e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007778e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007778e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007778f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000073e713cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000073e7146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000073e716d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000073e719db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000073e719fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Monika\Desktop\9gvjzw5w.exe[1540] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073e71a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Kernel IAT/EAT - GMER 2.1 ----
IAT C:\Windows\System32\win32k.sys[ntoskrnl.exe!KeUserModeCallback] [fffff880048cbef8] \SystemRoot\system32\DRIVERS\klif.sys [PAGE]
---- Processes - GMER 2.1 ----
Process C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (*** suspicious ***) @ C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [1496] (Windows SysTool Svr/SysTool PasSame LIMITED)(2015-06-01 16:58:50) 0000000000290000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\742f6841e1fe
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\742f6841e1fe@c8df7c01ed76 0x53 0x07 0x22 0x5E ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\742f6841e1fe (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\742f6841e1fe@c8df7c01ed76 0x53 0x07 0x22 0x5E ...
---- EOF - GMER 2.1 ----
- Kod: Zaznacz wszystko
OTL logfile created on: 2015-07-12 21:46:58 - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Monika\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17843)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
5,91 Gb Total Physical Memory | 2,95 Gb Available Physical Memory | 49,80% Memory free
11,83 Gb Paging File | 8,87 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 250,05 Gb Total Space | 124,42 Gb Free Space | 49,76% Space Free | Partition Type: NTFS
Drive D: | 321,12 Gb Total Space | 217,33 Gb Free Space | 67,68% Space Free | Partition Type: NTFS
Computer Name: MONIKA-KOMPUTER | User Name: Monika | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2015-07-12 21:46:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Monika\Desktop\OTL_[www.programosy.pl].exe
PRC - [2015-07-09 18:55:52 | 000,377,000 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2015-05-29 10:00:26 | 000,346,624 | ---- | M] (SysTool PasSame LIMITED) -- C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
PRC - [2014-12-19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014-08-30 18:48:46 | 000,234,520 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe
PRC - [2014-08-30 18:47:54 | 000,193,128 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
PRC - [2012-02-16 23:24:06 | 003,058,304 | ---- | M] (ASUS) -- C:\Windows\AsScrPro.exe
PRC - [2011-08-31 15:33:32 | 001,545,856 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
PRC - [2011-03-13 11:59:18 | 000,138,400 | ---- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2011-02-22 12:38:52 | 002,009,704 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011-01-25 12:32:28 | 000,166,528 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2010-11-15 11:42:12 | 000,305,792 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
PRC - [2010-10-07 15:05:14 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2010-09-23 17:53:16 | 001,601,536 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
PRC - [2010-08-17 15:55:42 | 005,732,992 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2010-07-09 23:45:00 | 000,984,400 | ---- | M] (Virage Logic Corporation / Sonic Focus) -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
PRC - [2010-01-25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe
PRC - [2009-12-15 11:39:38 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2009-06-19 11:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
PRC - [2009-06-19 11:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
PRC - [2009-06-15 18:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
PRC - [2008-12-22 18:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
PRC - [2008-08-13 22:00:08 | 000,113,208 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2015-05-13 08:09:46 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b3eb55fa5864a2fc7accbbbbe7fa7246\PresentationFramework.Aero.ni.dll
MOD - [2015-05-13 08:09:19 | 014,340,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ea543310204d0addfaf9792d820e958d\PresentationFramework.ni.dll
MOD - [2015-05-13 08:09:01 | 012,438,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6949c4470a81970ec3de0a575d93babc\System.Windows.Forms.ni.dll
MOD - [2015-05-13 08:08:54 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5a401fd2a7689ff13fb54182953f9c40\System.Drawing.ni.dll
MOD - [2015-05-13 08:08:51 | 012,254,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ef204c8310562595a0518e356fb15387\PresentationCore.ni.dll
MOD - [2015-05-13 08:08:38 | 003,348,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1c3513960037508558358652f2d202a1\WindowsBase.ni.dll
MOD - [2015-05-13 08:08:31 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\007fc007edc388d9806dff94ee04f129\System.Configuration.ni.dll
MOD - [2015-01-31 09:24:34 | 000,587,048 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com\npvkplugin.dll
MOD - [2015-01-31 09:24:33 | 000,332,584 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com\nponlinebanking.dll
MOD - [2015-01-31 09:24:32 | 000,459,048 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com\npcontentblocker.dll
MOD - [2014-10-15 20:34:42 | 005,467,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49908aa93a23c84847b1f8b1b667860\System.Xml.ni.dll
MOD - [2014-10-15 20:34:37 | 007,991,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
MOD - [2014-09-13 07:11:07 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
MOD - [2011-08-31 15:33:32 | 000,208,384 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
MOD - [2010-11-13 04:37:37 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010-11-05 03:54:55 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_pl_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2010-09-23 17:53:16 | 001,601,536 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
MOD - [2009-02-27 17:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2015-06-09 12:22:46 | 000,041,760 | ---- | M] (Microsoft) [Auto | Stopped] -- C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe -- (NovaPdfServer)
SRV:[b]64bit:[/b] - [2015-05-22 20:47:34 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2013-05-27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2011-03-03 17:57:58 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:[b]64bit:[/b] - [2010-04-16 17:07:42 | 000,134,928 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2015-07-09 20:15:17 | 000,268,464 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015-07-09 18:55:52 | 000,148,136 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015-05-29 10:00:26 | 000,346,624 | ---- | M] (SysTool PasSame LIMITED) [Auto | Running] -- C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -- (WindowsMangerProtect)
SRV - [2014-12-19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-08-30 18:48:46 | 000,234,520 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe -- (AVP15.0.1)
SRV - [2014-03-21 00:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2011-03-13 11:59:18 | 000,138,400 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2011-03-13 11:58:30 | 000,074,912 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe -- (AtherosSvc)
SRV - [2011-02-22 12:38:52 | 002,009,704 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010-03-18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-01-25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files (x86)\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2009-12-15 11:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009-06-15 18:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
SRV - [2007-05-31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2015-03-11 22:20:13 | 000,819,896 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF)
DRV:[b]64bit:[/b] - [2015-01-31 09:24:44 | 000,077,512 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klwtp.sys -- (Klwtp)
DRV:[b]64bit:[/b] - [2015-01-31 09:24:39 | 000,150,536 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klflt.sys -- (klflt)
DRV:[b]64bit:[/b] - [2014-08-12 19:33:02 | 000,246,456 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klhk.sys -- (klhk)
DRV:[b]64bit:[/b] - [2014-07-09 17:23:54 | 000,179,776 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kneps.sys -- (kneps)
DRV:[b]64bit:[/b] - [2014-07-02 17:10:38 | 000,046,144 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\kldisk.sys -- (kldisk)
DRV:[b]64bit:[/b] - [2014-06-05 20:02:08 | 000,055,872 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kltdi.sys -- (kltdi)
DRV:[b]64bit:[/b] - [2014-03-31 12:47:10 | 000,468,576 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (kl1)
DRV:[b]64bit:[/b] - [2014-03-28 18:51:04 | 000,028,768 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klkbdflt.sys -- (klkbdflt)
DRV:[b]64bit:[/b] - [2014-02-25 14:09:02 | 000,030,304 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6)
DRV:[b]64bit:[/b] - [2013-08-08 18:11:00 | 000,029,280 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt)
DRV:[b]64bit:[/b] - [2013-04-12 16:34:48 | 000,015,456 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klpd.sys -- (klpd)
DRV:[b]64bit:[/b] - [2013-01-14 22:10:52 | 000,238,288 | ---- | M] (Kaspersky Lab UK Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cm_km_w.sys -- (cm_km_w)
DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:44 | 000,280,224 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:44 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:44 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:44 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:42 | 000,298,656 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:42 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:[b]64bit:[/b] - [2011-03-13 11:58:42 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2011-02-21 10:07:54 | 000,025,960 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:[b]64bit:[/b] - [2011-01-27 02:57:12 | 012,273,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2011-01-13 13:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2010-12-13 23:12:40 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:[b]64bit:[/b] - [2010-11-20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010-11-20 15:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010-11-20 15:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2010-11-20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010-10-14 18:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010-09-22 03:59:38 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2010-09-13 12:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2010-08-03 20:43:14 | 000,290,920 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:[b]64bit:[/b] - [2010-07-08 03:03:48 | 002,228,736 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:[b]64bit:[/b] - [2010-04-16 17:07:28 | 000,013,832 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2009-10-22 16:10:30 | 000,069,320 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\opcomusb.sys -- (FTDIBUS)
DRV:[b]64bit:[/b] - [2009-07-20 11:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009-07-14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2008-09-26 19:02:36 | 000,115,328 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:[b]64bit:[/b] - [2008-05-23 18:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2010-07-26 14:57:20 | 000,017,024 | ---- | M] (ASUS) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009-07-02 18:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1432625443&z=81edfca302a580e26dea601g4zbc0o1q6ocw4z0zco&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1432625443&z=81edfca302a580e26dea601g4zbc0o1q6ocw4z0zco&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1432625443&z=81edfca302a580e26dea601g4zbc0o1q6ocw4z0zco&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1432625443&z=81edfca302a580e26dea601g4zbc0o1q6ocw4z0zco&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1432625443&z=81edfca302a580e26dea601g4zbc0o1q6ocw4z0zco&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&q={searchTerms}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1432625443&z=81edfca302a580e26dea601g4zbc0o1q6ocw4z0zco&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&q={searchTerms}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\..\SearchScopes\{02BE384A-7CAA-411F-9E80-519E9D787323}: "URL" = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&ts=1422187404&type=default&q={searchTerms}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&ts=1422187404&type=default&q={searchTerms}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\..\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}: "URL" = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&ts=1422187404&type=default&q={searchTerms}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\..\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}: "URL" = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9640423AS_5WS1JTV5XXXX5WS1JTV5&ts=1422187404&type=default&q={searchTerms}
IE - HKU\S-1-5-21-1653579745-25035085-109708339-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.countryCode: "PL"
FF - prefs.js..browser.search.defaultenginename: "delta-homes"
FF - prefs.js..browser.search.hiddenOneOffs: "Allegro,DuckDuckGo,Encyklopedia PWN,Merlin,Wikipedia (pl),Wolne Lektury,WP"
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.region: "PL"
FF - prefs.js..browser.search.searchengine.alias: "delta-homes"
FF - prefs.js..browser.search.searchengine.desc: "this is my first firefox searchEngine"
FF - prefs.js..browser.search.searchengine.iconURL: "http://search.delta-homes.com/favicon.ico"
FF - prefs.js..browser.search.searchengine.name: "delta-homes"
FF - prefs.js..browser.search.searchengine.ptid: "wpm06013"
FF - prefs.js..browser.search.searchengine.uid: "3219913727_132775_98D6546D"
FF - prefs.js..browser.search.searchengine.url: "http://search.delta-homes.com/web/?type=ds&ts=1433177942&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm06013&uid=3219913727_132775_98D6546D&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "delta-homes"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledAddons: online_banking_69A4E213815F42BD863D889007201D82%40kaspersky.com:4.5.3.8
FF - prefs.js..extensions.enabledAddons: content_blocker_6418E0D362104DADA084DC312DFA8ABC%40kaspersky.com:4.5.3.8
FF - prefs.js..extensions.enabledAddons: virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB%40kaspersky.com:4.5.3.8
FF - prefs.js..extensions.enabledAddons: defsearchp%40gmail.com:1.0.0.1038
FF - prefs.js..extensions.enabledAddons: default_newtabff%40gmail.com:5.4.18
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:39.0
FF - user.js - File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_191.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_191.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.31.2: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2015-01-31 09:42:49 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@kaspersky.com/online_banking_69A4E213815F42BD863D889007201D82: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2015-01-31 09:42:49 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2015-01-31 09:42:49 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fftoolbar2014@etech.com: C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\7uh1r875.default\extensions\fftoolbar2014@etech.com
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker_6418E0D362104DADA084DC312DFA8ABC@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2015-01-31 09:42:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2015-01-31 09:42:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking_69A4E213815F42BD863D889007201D82@kaspersky.com: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2015-01-31 09:42:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\quick_searchff@gmail.com: C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qgomyjlb.default-1422738746209\extensions\quick_searchff@gmail.com
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sweetsearch@gmail.com: C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\qgomyjlb.default-1422738746209\extensions\sweetsearch@gmail.com
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 39.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2015-06-02 18:33:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 39.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2015-06-02 18:33:52 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 39.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2015-06-02 18:33:52 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 39.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2015-06-02 18:33:52 | 000,000,000 | ---D | M]
[2012-02-16 23:44:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Monika\AppData\Roaming\mozilla\Extensions
[2015-07-09 18:55:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Monika\AppData\Roaming\mozilla\Firefox\Profiles\qgomyjlb.default-1422738746209\extensions
[2015-07-09 18:55:56 | 000,000,000 | ---D | M] ("Default NewTab") -- C:\Users\Monika\AppData\Roaming\mozilla\Firefox\Profiles\qgomyjlb.default-1422738746209\extensions\default_newtabff@gmail.com
[2015-07-09 18:55:55 | 000,015,309 | ---- | M] () (No name found) -- C:\Users\Monika\AppData\Roaming\mozilla\firefox\profiles\qgomyjlb.default-1422738746209\extensions\defsearchp@gmail.com.xpi
[2015-07-12 20:28:15 | 000,002,129 | ---- | M] () -- C:\Users\Monika\AppData\Roaming\mozilla\firefox\profiles\qgomyjlb.default-1422738746209\searchplugins\delta-homes.xml
[2015-06-02 18:33:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2015-07-09 18:55:52 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2015-01-31 09:42:49 | 000,000,000 | ---D | M] (Модуль блокування небезпечних веб-сайтів) -- C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.1\FFEXT\CONTENT_BLOCKER@KASPERSKY.COM
[2015-01-31 09:42:49 | 000,000,000 | ---D | M] (Безпечні платежі) -- C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.1\FFEXT\ONLINE_BANKING@KASPERSKY.COM
[2015-01-31 09:42:49 | 000,000,000 | ---D | M] (Віртуальна клавіатура) -- C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 15.0.1\FFEXT\VIRTUAL_KEYBOARD@KASPERSKY.COM
O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Content Blocker Plugin) - {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O2:[b]64bit:[/b] - BHO: (Virtual Keyboard Plugin) - {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O2:[b]64bit:[/b] - BHO: (Safe Money Plugin) - {E3D96E85-529D-4269-AC6A-97CF9E2221E3} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Content Blocker Plugin) - {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {2c774641-5504-46a8-b63f-6715ae3fe376} - No CLSID value found.
O2 - BHO: (IETabPage Class) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll (Thinknice Co. Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Virtual Keyboard Plugin) - {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Safe Money Plugin) - {E3D96E85-529D-4269-AC6A-97CF9E2221E3} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Monika\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O4:[b]64bit:[/b] - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:[b]64bit:[/b] - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1653579745-25035085-109708339-1000..\Run: [ISUSPM Startup] c:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup File not found
O4 - HKU\S-1-5-21-1653579745-25035085-109708339-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1653579745-25035085-109708339-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HDDlife.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9:[b]64bit:[/b] - Extra Button: Klawiatura wirtualna - {09A10376-994C-4BBF-9121-F50CF7BA237E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Klawiatura wirtualna - {09A10376-994C-4BBF-9121-F50CF7BA237E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.60 62.179.1.61
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39BD49FF-4255-4B69-9E03-0FFB97E7320C}: DhcpNameServer = 62.179.1.60 62.179.1.61
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msdaipp - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2015-01-27 22:24:58 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{04ff4539-919a-11e4-a09d-14dae914c6e0}\Shell - "" = AutoRun
O33 - MountPoints2\{04ff4539-919a-11e4-a09d-14dae914c6e0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{147022f0-d6fe-11e1-99ad-742f6841e1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{147022f0-d6fe-11e1-99ad-742f6841e1fe}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{49eb34d3-cb43-11e1-a73d-742f6841e1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{49eb34d3-cb43-11e1-a73d-742f6841e1fe}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{59d83b4b-4b9b-11e3-85e0-14dae914c6e0}\Shell - "" = AutoRun
O33 - MountPoints2\{59d83b4b-4b9b-11e3-85e0-14dae914c6e0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{5b149eae-f6da-11e3-bb82-14dae914c6e0}\Shell - "" = AutoRun
O33 - MountPoints2\{5b149eae-f6da-11e3-bb82-14dae914c6e0}\Shell\AutoRun\command - "" = G:\LGAutoRun.exe
O33 - MountPoints2\{7849f0c9-6e78-11e1-8425-742f6841e1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{7849f0c9-6e78-11e1-8425-742f6841e1fe}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a8852ab3-58e4-11e1-b140-742f6841e1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{a8852ab3-58e4-11e1-b140-742f6841e1fe}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a8852ba9-58e4-11e1-b140-742f6841e1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{a8852ba9-58e4-11e1-b140-742f6841e1fe}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2015-07-12 21:46:01 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Monika\Desktop\OTL_[www.programosy.pl].exe
[2015-07-09 12:11:47 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\Nowy folder (2)
[2015-07-07 20:28:37 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\Nowy folder
[2015-06-28 20:56:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\doPDF 8
[2015-06-28 20:54:48 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.2008-09.org.wixtoolset
[2015-06-28 20:54:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2015-06-27 06:48:37 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\Dzwoneczek i bestia z nibylandi
[2015-06-21 19:04:47 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\.thumbnails
[2015-06-21 19:03:58 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\100LGDSC
[2015-06-21 19:03:49 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\skuubcio ;)
[2015-06-21 19:03:43 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\Facebook
[2015-06-21 19:03:33 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\jaaa ;)
[2015-06-21 19:03:26 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\Misiuulek ;)
[2015-06-19 08:41:40 | 001,730,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01009.dll
[2015-06-19 08:41:40 | 001,011,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller2.dll
[1 C:\Users\Monika\Desktop\*.tmp files -> C:\Users\Monika\Desktop\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2015-07-12 21:46:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Monika\Desktop\OTL_[www.programosy.pl].exe
[2015-07-12 21:15:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015-07-12 20:37:17 | 000,015,504 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015-07-12 20:37:17 | 000,015,504 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015-07-12 20:26:44 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2015-07-12 20:26:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015-07-12 20:26:05 | 467,496,959 | -HS- | M] () -- C:\hiberfil.sys
[2015-07-12 20:25:17 | 000,000,309 | ---- | M] () -- C:\Windows\wininit.ini
[2015-07-11 20:15:18 | 001,692,176 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015-07-11 20:15:18 | 000,747,802 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2015-07-11 20:15:18 | 000,661,128 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015-07-11 20:15:18 | 000,160,362 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2015-07-11 20:15:18 | 000,125,318 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015-07-09 20:15:17 | 000,778,416 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015-07-09 20:15:17 | 000,142,512 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015-07-09 19:04:34 | 000,045,042 | ---- | M] () -- C:\Users\Monika\Desktop\20150708143119-26.pdf
[2015-07-09 19:02:45 | 000,057,406 | ---- | M] () -- C:\Users\Monika\Desktop\20150708133107-15.pdf
[2015-07-08 10:59:07 | 000,180,634 | ---- | M] () -- C:\Users\Monika\Desktop\anonse,op-get_attachment,id-36744,aid-20677-1.jpg
[2015-06-29 06:04:18 | 000,001,457 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2015-06-28 22:49:59 | 000,136,752 | ---- | M] () -- C:\Users\Monika\Desktop\CV_Monika Tarnowska.pdf
[2015-06-23 20:16:58 | 499,995,942 | ---- | M] () -- C:\Users\Monika\Desktop\Scooby Doo i Frankenstrachy.avi
[2015-06-21 19:08:55 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2015-06-21 12:41:06 | 008,800,569 | ---- | M] () -- C:\Users\Monika\Desktop\MOV_0005.mp4
[2015-06-21 12:39:57 | 012,156,753 | ---- | M] () -- C:\Users\Monika\Desktop\MOV_0004.mp4
[2015-06-19 08:41:40 | 001,730,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01009.dll
[2015-06-19 08:41:40 | 001,011,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller2.dll
[1 C:\Users\Monika\Desktop\*.tmp files -> C:\Users\Monika\Desktop\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2015-07-09 19:04:34 | 000,045,042 | ---- | C] () -- C:\Users\Monika\Desktop\20150708143119-26.pdf
[2015-07-09 19:02:45 | 000,057,406 | ---- | C] () -- C:\Users\Monika\Desktop\20150708133107-15.pdf
[2015-07-09 12:39:51 | 000,180,634 | ---- | C] () -- C:\Users\Monika\Desktop\anonse,op-get_attachment,id-36744,aid-20677-1.jpg
[2015-06-28 22:49:56 | 000,136,752 | ---- | C] () -- C:\Users\Monika\Desktop\CV_Monika Tarnowska.pdf
[2015-06-23 20:10:21 | 499,995,942 | ---- | C] () -- C:\Users\Monika\Desktop\Scooby Doo i Frankenstrachy.avi
[2015-06-21 19:08:55 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2015-06-21 19:00:51 | 012,156,753 | ---- | C] () -- C:\Users\Monika\Desktop\MOV_0004.mp4
[2015-06-21 19:00:47 | 008,800,569 | ---- | C] () -- C:\Users\Monika\Desktop\MOV_0005.mp4
[2014-08-04 12:04:45 | 000,446,464 | ---- | C] ( ) -- C:\Windows\SysWow64\lexlog.dll
[2014-08-04 11:05:12 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\HPPLVS.dll
[2014-08-04 11:04:01 | 001,668,314 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014-08-04 11:02:42 | 000,000,707 | ---- | C] () -- C:\Windows\hpntwksetup.ini
[2014-03-02 18:40:14 | 000,707,504 | ---- | C] () -- C:\Users\Monika\AppData\Local\unins000.exe
[2014-03-02 18:40:14 | 000,011,761 | ---- | C] () -- C:\Users\Monika\AppData\Local\unins000.msg
[2014-03-02 18:40:14 | 000,003,187 | ---- | C] () -- C:\Users\Monika\AppData\Local\unins000.dat
[2013-09-30 20:22:17 | 000,000,309 | ---- | C] () -- C:\Windows\wininit.ini
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015-02-13 07:22:33 | 014,177,280 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015-02-13 07:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[color=#E56717]========== LOP Check ==========[/color]
[2013-09-30 10:56:42 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013-09-30 10:56:42 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2015-01-25 14:25:30 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Audacity
[2014-12-14 10:50:26 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\BinarySense
[2014-03-02 19:05:04 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\e-Deklaracje
[2013-03-05 22:26:55 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1
[2013-03-02 19:00:25 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\efile.epity2012
[2013-03-18 23:27:17 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\FileZilla
[2014-06-11 22:00:12 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\FreeHideIP
[2012-02-16 23:47:13 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Gadu-Gadu 10
[2012-02-16 23:45:20 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\GHISLER
[2014-09-23 02:58:44 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\IrfanView
[2013-11-16 20:37:02 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\JCommerce
[2014-02-02 22:51:00 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\KW
[2014-02-02 12:54:51 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\newnext.me
[2013-02-10 20:47:01 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Nowe Gadu-Gadu
[2012-06-10 23:11:24 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\OmegaSys Generator WNA
[2012-12-15 14:58:05 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\OpenFM
[2012-04-01 14:00:52 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\OpenOffice.org
[2014-12-14 10:48:53 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Opera Software
[2012-04-06 14:56:07 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\PhotoFiltre 7
[2012-04-06 14:55:27 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\PhotoScape
[2013-03-02 18:34:33 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Podatnik.info
[2015-04-03 18:07:19 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Softland
[2013-09-29 13:42:57 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\TuneUp Software
[2015-02-15 21:27:58 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\uTorrent
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:55B41E6A
< End of report >