OTL logfile created on: 2012-09-23 17:53:05 - Run 1 OTL by OldTimer - Version 3.2.66.0 Folder = C:\Users\Antoś\Downloads 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 8,00 Gb Total Physical Memory | 6,55 Gb Available Physical Memory | 81,85% Memory free 15,99 Gb Paging File | 14,22 Gb Available in Paging File | 88,89% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 100,58 Gb Total Space | 56,06 Gb Free Space | 55,74% Space Free | Partition Type: NTFS Drive D: | 830,92 Gb Total Space | 99,67 Gb Free Space | 12,00% Space Free | Partition Type: NTFS Drive E: | 1397,26 Gb Total Space | 127,66 Gb Free Space | 9,14% Space Free | Partition Type: NTFS Computer Name: ANTOŚ-KOMPUTER | User Name: Antoś | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-09-23 17:49:56 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Antoś\Downloads\OTL.exe PRC - [2011-09-22 12:03:30 | 000,974,944 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012-08-06 12:24:22 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service) SRV:[b]64bit:[/b] - [2012-07-28 04:09:44 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2011-09-22 12:03:30 | 000,974,944 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn) SRV:[b]64bit:[/b] - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-02-19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012-07-28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2012-07-28 03:14:46 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2012-06-05 13:45:16 | 000,237,968 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService) DRV:[b]64bit:[/b] - [2012-05-14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:[b]64bit:[/b] - [2012-03-30 16:49:08 | 000,056,448 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter) DRV:[b]64bit:[/b] - [2012-03-05 16:04:30 | 000,053,888 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1) DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011-11-03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:[b]64bit:[/b] - [2011-08-09 14:24:52 | 000,202,576 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm) DRV:[b]64bit:[/b] - [2011-08-04 09:20:38 | 000,146,432 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv) DRV:[b]64bit:[/b] - [2011-08-04 09:20:38 | 000,137,144 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr) DRV:[b]64bit:[/b] - [2010-11-21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2010-11-21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-02-18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64) DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2005-09-23 22:18:34 | 000,261,120 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MarvinBus64.sys -- (MarvinBus) DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-1534380035-1692763858-3000215942-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKU\S-1-5-21-1534380035-1692763858-3000215942-1001\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-1534380035-1692763858-3000215942-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1534380035-1692763858-3000215942-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112250&tt=120912_nocpc_3812_3&babsrc=SP_ss&mntrId=2c3725e90000000000006cf04901406e IE - HKU\S-1-5-21-1534380035-1692763858-3000215942-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012-09-23 12:19:17 | 000,000,000 | ---D | M] [2012-09-23 13:35:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions O1 HOSTS File: ([2012-09-23 09:00:40 | 000,001,210 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 practivate.adobe.com O1 - Hosts: 127.0.0.1 lmlicenses.wip4.adobe.com O1 - Hosts: 127.0.0.1 lm.licenses.adobe.com O1 - Hosts: 127.0.0.1 www.nero.com O1 - Hosts: 127.0.0.1 nero.com O1 - Hosts: 127.0.0.1 my.nero.com O1 - Hosts: 127.0.0.1 secure.nero.com O1 - Hosts: 127.0.0.1 support.nero.com O1 - Hosts: 127.0.0.1 www.registernero.com O1 - Hosts: 127.0.0.1 registernero.com O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1534380035-1692763858-3000215942-1001..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5082ADE1-71FF-4E4C-B06B-C4EBA18ADEF6}: DhcpNameServer = 192.168.1.1 O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-09-23 17:41:37 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\ElevatedDiagnostics [2012-09-23 16:41:07 | 000,559,528 | ---- | C] (Helge Klein) -- C:\Windows\SetACL.exe [2012-09-23 14:18:35 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll [2012-09-23 14:18:25 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll [2012-09-23 14:18:25 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll [2012-09-23 14:18:25 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax [2012-09-23 14:18:24 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax [2012-09-23 14:18:20 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll [2012-09-23 14:18:15 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll [2012-09-23 14:18:09 | 000,911,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2012-09-23 14:18:09 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2012-09-23 14:18:09 | 000,609,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2012-09-23 14:17:58 | 000,566,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi [2012-09-23 14:17:57 | 000,642,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi [2012-09-23 14:17:57 | 000,605,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe [2012-09-23 14:17:57 | 000,518,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe [2012-09-23 14:17:57 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll [2012-09-23 14:17:57 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll [2012-09-23 14:17:57 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll [2012-09-23 14:17:45 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll [2012-09-23 14:17:45 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll [2012-09-23 14:12:24 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe [2012-09-23 14:11:08 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll [2012-09-23 14:11:08 | 000,023,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fs_rec.sys [2012-09-23 14:11:07 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2012-09-23 14:09:38 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll [2012-09-23 14:09:30 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcjt32.dll [2012-09-23 14:09:30 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbctrac.dll [2012-09-23 14:09:30 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbctrac.dll [2012-09-23 14:09:30 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll [2012-09-23 14:09:30 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll [2012-09-23 14:09:30 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccu32.dll [2012-09-23 14:09:30 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccr32.dll [2012-09-23 14:09:30 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccu32.dll [2012-09-23 14:09:30 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccr32.dll [2012-09-23 14:09:06 | 001,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll [2012-09-23 14:08:47 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll [2012-09-23 14:08:28 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe [2012-09-23 14:08:28 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe [2012-09-23 14:08:05 | 002,871,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2012-09-23 14:08:04 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe [2012-09-23 14:07:58 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sbe.dll [2012-09-23 14:07:58 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll [2012-09-23 14:07:58 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbe.dll [2012-09-23 14:07:58 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll [2012-09-23 14:07:58 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax [2012-09-23 14:07:58 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax [2012-09-23 14:07:38 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll [2012-09-23 14:07:38 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll [2012-09-23 14:07:38 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll [2012-09-23 14:07:38 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll [2012-09-23 14:07:27 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll [2012-09-23 14:07:20 | 002,315,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll [2012-09-23 14:07:20 | 002,223,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll [2012-09-23 14:07:20 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll [2012-09-23 14:07:19 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll [2012-09-23 14:07:19 | 000,491,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll [2012-09-23 14:07:19 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll [2012-09-23 14:07:19 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe [2012-09-23 14:07:19 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe [2012-09-23 14:07:18 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll [2012-09-23 14:07:18 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll [2012-09-23 14:07:18 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssphtb.dll [2012-09-23 14:07:18 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll [2012-09-23 14:07:18 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscntrs.dll [2012-09-23 14:06:34 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll [2012-09-23 14:06:34 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll [2012-09-23 14:06:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2012-09-23 14:06:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2012-09-23 14:05:55 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll [2012-09-23 14:05:53 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl [2012-09-23 14:05:53 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl [2012-09-23 14:05:49 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll [2012-09-23 14:05:49 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll [2012-09-23 14:05:49 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe [2012-09-23 14:05:43 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll [2012-09-23 14:05:43 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll [2012-09-23 14:05:25 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2012-09-23 14:05:24 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2012-09-23 14:05:23 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2012-09-23 14:05:11 | 001,465,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll [2012-09-23 14:05:11 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll [2012-09-23 14:05:08 | 001,395,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42.dll [2012-09-23 14:05:08 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42u.dll [2012-09-23 14:05:08 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll [2012-09-23 14:05:07 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll [2012-09-23 14:04:54 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys [2012-09-23 14:04:45 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll [2012-09-23 14:04:41 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll [2012-09-23 14:04:41 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll [2012-09-23 14:04:41 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe [2012-09-23 14:03:55 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2012-09-23 14:03:54 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2012-09-23 14:03:54 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll [2012-09-23 14:03:54 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll [2012-09-23 14:03:54 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll [2012-09-23 14:03:35 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys [2012-09-23 14:03:35 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [2012-09-23 14:03:18 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2012-09-23 14:03:18 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2012-09-23 14:03:18 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll [2012-09-23 14:03:18 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll [2012-09-23 14:03:18 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2012-09-23 14:03:18 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2012-09-23 14:03:01 | 000,027,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys [2012-09-23 14:02:57 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll [2012-09-23 14:02:57 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe [2012-09-23 14:02:57 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe [2012-09-23 13:42:47 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll [2012-09-23 13:42:47 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll [2012-09-23 13:42:47 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll [2012-09-23 13:42:09 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll [2012-09-23 13:42:08 | 001,162,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2012-09-23 13:42:08 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2012-09-23 13:42:08 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe [2012-09-23 13:42:08 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2012-09-23 13:42:08 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2012-09-23 13:42:08 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2012-09-23 13:42:08 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2012-09-23 13:42:08 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2012-09-23 13:42:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2012-09-23 13:42:08 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2012-09-23 13:42:08 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2012-09-23 13:42:08 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2012-09-23 13:42:08 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2012-09-23 13:42:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2012-09-23 13:42:08 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2012-09-23 13:42:07 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2012-09-23 13:42:07 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2012-09-23 13:42:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2012-09-23 13:42:07 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2012-09-23 13:42:06 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2012-09-23 13:42:06 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2012-09-23 13:42:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2012-09-23 13:42:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2012-09-23 13:42:06 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2012-09-23 13:42:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2012-09-23 13:42:06 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2012-09-23 13:39:49 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe [2012-09-23 13:39:49 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\devrtl.dll [2012-09-23 13:39:45 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prevhost.exe [2012-09-23 13:39:45 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prevhost.exe [2012-09-23 13:37:23 | 000,356,352 | ---- | C] (eSellerate Inc.) -- C:\Windows\eSellerateEngine.dll [2012-09-23 13:37:16 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FXSCOVER.exe [2012-09-23 13:37:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hot CPU Tester Pro 4 [2012-09-23 13:37:11 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll [2012-09-23 13:36:54 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll [2012-09-23 13:36:44 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll [2012-09-23 13:36:43 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll [2012-09-23 13:36:42 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll [2012-09-23 13:36:42 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll [2012-09-23 13:35:29 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\ESET [2012-09-23 13:35:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2012-09-23 13:34:54 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\URSoft [2012-09-23 13:34:53 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2012-09-23 13:34:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 7 [2012-09-23 13:34:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Your Uninstaller! 7 [2012-09-23 13:34:47 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Babylon [2012-09-23 13:34:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon [2012-09-23 13:31:15 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\WinRAR [2012-09-23 13:30:58 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2012-09-23 13:17:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hot CPU Tester Pro 4 LE [2012-09-23 13:14:23 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll [2012-09-23 13:14:22 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll [2012-09-23 13:13:00 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2012-09-23 13:12:54 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll [2012-09-23 13:12:54 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll [2012-09-23 12:19:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET [2012-09-23 12:19:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET [2012-09-23 12:19:11 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012-09-23 09:05:15 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Nero_AG [2012-09-23 09:05:09 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Nero [2012-09-23 09:05:08 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Nero [2012-09-23 08:59:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero [2012-09-23 08:59:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero [2012-09-23 08:58:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero [2012-09-23 08:58:41 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012-09-23 08:55:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET [2012-09-23 08:54:21 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll [2012-09-23 08:54:21 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dcsx_43.dll [2012-09-23 08:54:20 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll [2012-09-23 08:54:20 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_43.dll [2012-09-23 08:54:20 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx11_43.dll [2012-09-23 08:54:12 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_42.dll [2012-09-23 08:54:03 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll [2012-09-23 08:53:55 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll [2012-09-23 08:53:39 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll [2012-09-23 08:53:23 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll [2012-09-23 08:53:07 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll [2012-09-23 08:52:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nero [2012-09-23 08:49:32 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Apple Computer [2012-09-22 23:10:40 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy [2012-09-22 23:10:38 | 000,000,000 | ---D | C] -- C:\Users\Antoś\Documents\Adobe [2012-09-22 23:07:33 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe [2012-09-22 23:02:16 | 000,056,208 | ---- | C] (Rovi Corporation) -- C:\Windows\SysNative\drivers\PxHlpa64.sys [2012-09-22 23:02:16 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys [2012-09-22 23:02:16 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys [2012-09-22 23:02:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared [2012-09-22 23:02:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2012-09-22 23:02:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name [2012-09-22 23:01:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2012-09-22 23:01:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2012-09-22 23:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe [2012-09-22 23:00:54 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2012-09-22 23:00:47 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2012-09-22 23:00:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2012-09-22 22:59:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2012-09-22 22:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2012-09-22 22:56:29 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Adobe [2012-09-22 22:54:07 | 000,000,000 | ---D | C] -- C:\Users\Antoś\Documents\Pinnacle Studio [2012-09-22 22:54:00 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Macromedia [2012-09-22 22:54:00 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Adobe [2012-09-22 22:53:57 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Pinnacle [2012-09-22 22:53:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Ultimate Collection [2012-09-22 22:52:43 | 000,090,112 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe [2012-09-22 22:52:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Studio Plugins [2012-09-22 22:51:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Pinnacle [2012-09-22 22:51:14 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Downloaded Installations [2012-09-22 22:50:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Ultimate [2012-09-22 22:49:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle Studio 15 [2012-09-22 22:49:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\My Projects [2012-09-22 22:48:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Yahoo! [2012-09-22 22:48:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Studio 15 [2012-09-22 22:48:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Plus [2012-09-22 22:48:54 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Pinnacle [2012-09-22 22:48:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pinnacle [2012-09-22 22:48:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Pegasus Imaging [2012-09-22 22:44:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle [2012-09-22 22:43:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\proDAD [2012-09-22 22:43:01 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\proDAD [2012-09-22 22:43:00 | 000,000,000 | ---D | C] -- C:\Program Files\proDAD [2012-09-22 22:42:40 | 000,000,000 | ---D | C] -- C:\ProgramData\proDAD [2012-09-22 22:40:16 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Publish Providers [2012-09-22 22:29:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony [2012-09-22 22:29:03 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Sony [2012-09-22 22:29:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony [2012-09-22 22:29:03 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2012-09-22 22:29:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony [2012-09-22 22:28:25 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Sony [2012-09-22 22:25:58 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Apple Computer [2012-09-22 22:24:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2012-09-22 22:24:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime [2012-09-22 22:24:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2012-09-22 22:24:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple [2012-09-22 22:24:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update [2012-09-22 22:24:01 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Apple [2012-09-22 22:24:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2012-09-22 22:08:03 | 007,163,744 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEP64H.dll [2012-09-22 22:08:03 | 003,746,408 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkHDM64.dll [2012-09-22 22:08:03 | 002,526,824 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RHDMEx64.dll [2012-09-22 22:08:03 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EED64H.dll [2012-09-22 22:08:03 | 000,372,056 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64H.dll [2012-09-22 22:08:03 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RH3DHT64.dll [2012-09-22 22:08:03 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RH3DAA64.dll [2012-09-22 22:08:03 | 000,237,968 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\drivers\RtHDMIVX.sys [2012-09-22 22:08:03 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64H.dll [2012-09-22 22:08:03 | 000,141,152 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEL64H.dll [2012-09-22 22:08:03 | 000,123,744 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEA64H.dll [2012-09-22 22:08:03 | 000,097,624 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64H.dll [2012-09-22 22:08:03 | 000,092,264 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RHCoInst64.dll [2012-09-22 22:08:03 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64H.dll [2012-09-22 22:08:03 | 000,074,592 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEG64H.dll [2012-09-22 22:06:12 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM [2012-09-22 22:06:12 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2012-09-22 22:06:04 | 002,080,120 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib64.dll [2012-09-22 22:06:04 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll [2012-09-22 22:06:04 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll [2012-09-22 22:06:03 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll [2012-09-22 22:06:03 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll [2012-09-22 22:06:01 | 002,743,440 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll [2012-09-22 22:06:01 | 001,561,744 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl [2012-09-22 22:06:01 | 000,331,880 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll [2012-09-22 22:06:00 | 000,149,608 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll [2012-09-22 22:06:00 | 000,014,952 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCoLDR64.dll [2012-09-22 22:05:59 | 003,643,024 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll [2012-09-22 22:05:59 | 001,264,272 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll [2012-09-22 22:05:59 | 000,881,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll [2012-09-22 22:05:59 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll [2012-09-22 22:05:59 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll [2012-09-22 22:05:59 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll [2012-09-22 22:05:59 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll [2012-09-22 22:05:59 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll [2012-09-22 22:05:59 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll [2012-09-22 22:05:58 | 000,109,712 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInstII64.dll [2012-09-22 22:05:57 | 000,083,072 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBWrp64.dll [2012-09-22 22:05:56 | 000,897,152 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBAPO64.dll [2012-09-22 22:05:56 | 000,753,280 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysWow64\MBAPO32.dll [2012-09-22 22:05:56 | 000,065,112 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBppld64.dll [2012-09-22 22:05:56 | 000,060,504 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\MBPPCn64.dll [2012-09-22 22:05:55 | 002,028,920 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ64.dll [2012-09-22 22:05:55 | 000,834,936 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPOShell64.dll [2012-09-22 22:05:55 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll [2012-09-22 22:05:51 | 002,533,952 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll [2012-09-22 22:05:49 | 000,110,592 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll [2012-09-22 22:05:48 | 000,202,336 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAC64.dll [2012-09-22 22:05:48 | 000,108,640 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAR64.dll [2012-09-22 22:05:48 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information [2012-09-22 22:05:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek [2012-09-22 22:05:46 | 001,706,640 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll [2012-09-22 22:05:46 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp [2012-09-22 22:05:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield [2012-09-22 22:01:23 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\AMD [2012-09-22 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\ATI [2012-09-22 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\ATI [2012-09-22 22:01:13 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI [2012-09-22 22:01:09 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD [2012-09-22 21:59:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP [2012-09-22 21:59:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies [2012-09-22 21:59:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies [2012-09-22 21:59:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center [2012-09-22 21:59:25 | 000,046,136 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdiox64.sys [2012-09-22 21:59:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies [2012-09-22 21:56:34 | 000,056,448 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\usbfilter.sys [2012-09-22 21:56:34 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2012-09-22 21:56:00 | 000,000,000 | ---D | C] -- C:\AMD [2012-09-22 21:55:32 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2012-09-22 21:55:19 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies [2012-09-22 21:55:18 | 000,000,000 | ---D | C] -- C:\Program Files\ATI [2012-09-22 21:55:02 | 000,000,000 | ---D | C] -- C:\ATI [2012-09-22 21:46:12 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2012-09-22 21:45:59 | 000,000,000 | -HSD | C] -- C:\Boot [2012-09-22 21:31:43 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll [2012-09-22 21:31:43 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll [2012-09-22 21:11:13 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe [2012-09-22 21:11:13 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll [2012-09-22 21:11:12 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll [2012-09-22 21:11:09 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll [2012-09-22 21:11:09 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll [2012-09-22 21:11:09 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll [2012-09-22 21:11:04 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll [2012-09-22 21:11:04 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe [2012-09-22 20:53:34 | 000,000,000 | R--D | C] -- C:\Users\Antoś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2012-09-22 20:53:34 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Searches [2012-09-22 20:53:34 | 000,000,000 | R--D | C] -- C:\Users\Antoś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2012-09-22 20:53:27 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Identities [2012-09-22 20:53:25 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Contacts [2012-09-22 20:53:24 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\VirtualStore [2012-09-22 20:53:17 | 000,000,000 | --SD | C] -- C:\Users\Antoś\AppData\Roaming\Microsoft [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Videos [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Saved Games [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Pictures [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Music [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Links [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Favorites [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Downloads [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Documents [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\Desktop [2012-09-22 20:53:17 | 000,000,000 | R--D | C] -- C:\Users\Antoś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Ustawienia lokalne [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\AppData\Local\Temporary Internet Files [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Szablony [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\SendTo [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Recent [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\PrintHood [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\NetHood [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Documents\Moje wideo [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Documents\Moje obrazy [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Moje dokumenty [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Documents\Moja muzyka [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Menu Start [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\AppData\Local\Historia [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Dane aplikacji [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\AppData\Local\Dane aplikacji [2012-09-22 20:53:17 | 000,000,000 | -HSD | C] -- C:\Users\Antoś\Cookies [2012-09-22 20:53:17 | 000,000,000 | -H-D | C] -- C:\Users\Antoś\AppData [2012-09-22 20:53:17 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Temp [2012-09-22 20:53:17 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Local\Microsoft [2012-09-22 20:53:17 | 000,000,000 | ---D | C] -- C:\Users\Antoś\AppData\Roaming\Media Center Programs [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\Recovery [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty [2012-09-22 20:53:06 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji [2012-09-22 20:49:50 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012-09-22 20:47:43 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2012-09-22 20:47:05 | 000,000,000 | -HSD | C] -- C:\System Volume Information [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-09-23 17:38:12 | 000,026,352 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-09-23 17:38:12 | 000,026,352 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-09-23 17:37:14 | 000,003,165 | ---- | M] () -- C:\Users\Antoś\Desktop\fix.reg [2012-09-23 17:35:23 | 001,549,696 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012-09-23 17:35:23 | 000,697,674 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2012-09-23 17:35:23 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012-09-23 17:35:23 | 000,134,784 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2012-09-23 17:35:23 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012-09-23 17:30:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-09-23 17:30:45 | 2145,558,527 | -HS- | M] () -- C:\hiberfil.sys [2012-09-23 16:26:41 | 000,007,500 | ---- | M] () -- C:\Users\Antoś\Desktop\MpsSvc.reg [2012-09-23 16:26:29 | 000,172,952 | ---- | M] () -- C:\Users\Antoś\Desktop\BFE.reg [2012-09-23 16:16:45 | 000,001,421 | ---- | M] () -- C:\Users\Antoś\Desktop\Internet Explorer (64-bit).lnk [2012-09-23 14:23:09 | 000,001,754 | ---- | M] () -- C:\Users\Public\Desktop\Wybór przeglądarki.lnk [2012-09-23 14:22:31 | 004,961,648 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012-09-23 13:37:23 | 000,356,352 | ---- | M] (eSellerate Inc.) -- C:\Windows\eSellerateEngine.dll [2012-09-23 13:34:53 | 000,001,076 | ---- | M] () -- C:\Users\Antoś\Desktop\Your Unin-staller!.lnk [2012-09-23 13:31:05 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\WinRAR.lnk [2012-09-23 12:34:05 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI [2012-09-23 09:00:41 | 000,000,378 | ---- | M] () -- C:\Windows\SysWow64\ipnathlp.ocx [2012-09-23 08:59:53 | 000,002,797 | ---- | M] () -- C:\Users\Public\Desktop\Nero Video 11.lnk [2012-09-23 08:59:45 | 000,002,109 | ---- | M] () -- C:\Users\Public\Desktop\Nero Kwik Media.lnk [2012-09-23 08:58:41 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012-09-22 23:07:30 | 000,001,223 | ---- | M] () -- C:\Users\Antoś\Desktop\Adobe Premiere Pro CS6.lnk [2012-09-22 22:49:39 | 000,001,194 | ---- | M] () -- C:\Users\Public\Desktop\Pinnacle Studio 15.lnk [2012-09-22 22:43:06 | 000,001,126 | ---- | M] () -- C:\Users\Public\Desktop\Heroglyph 4.0.lnk [2012-09-22 22:29:08 | 000,001,038 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Pro 11.0 (64-bit).lnk [2012-09-22 22:24:45 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2012-09-22 22:00:54 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin [2012-09-22 21:50:47 | 000,204,528 | RHS- | M] () -- C:\GRLDR [2012-09-22 21:46:00 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2012-09-22 20:50:45 | 000,188,313 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2012-09-22 20:50:45 | 000,188,313 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2012-09-22 20:49:04 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2012-09-10 22:23:46 | 000,559,528 | ---- | M] (Helge Klein) -- C:\Windows\SetACL.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-09-23 17:17:45 | 000,172,952 | ---- | C] () -- C:\Users\Antoś\Desktop\BFE.reg [2012-09-23 16:42:07 | 000,003,165 | ---- | C] () -- C:\Users\Antoś\Desktop\fix.reg [2012-09-23 16:28:00 | 000,007,500 | ---- | C] () -- C:\Users\Antoś\Desktop\MpsSvc.reg [2012-09-23 16:16:45 | 000,001,421 | ---- | C] () -- C:\Users\Antoś\Desktop\Internet Explorer (64-bit).lnk [2012-09-23 14:23:09 | 000,001,754 | ---- | C] () -- C:\Users\Public\Desktop\Wybór przeglądarki.lnk [2012-09-23 13:34:53 | 000,001,076 | ---- | C] () -- C:\Users\Antoś\Desktop\Your Unin-staller!.lnk [2012-09-23 13:31:05 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\WinRAR.lnk [2012-09-23 09:00:41 | 000,000,378 | ---- | C] () -- C:\Windows\SysWow64\ipnathlp.ocx [2012-09-23 08:59:53 | 000,002,797 | ---- | C] () -- C:\Users\Public\Desktop\Nero Video 11.lnk [2012-09-23 08:59:45 | 000,002,109 | ---- | C] () -- C:\Users\Public\Desktop\Nero Kwik Media.lnk [2012-09-22 23:07:21 | 000,001,223 | ---- | C] () -- C:\Users\Antoś\Desktop\Adobe Premiere Pro CS6.lnk [2012-09-22 23:01:25 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk [2012-09-22 22:49:39 | 000,001,194 | ---- | C] () -- C:\Users\Public\Desktop\Pinnacle Studio 15.lnk [2012-09-22 22:45:13 | 000,000,349 | ---- | C] () -- C:\Users\Public\Documents\PCLECHAL.INI [2012-09-22 22:43:06 | 000,001,126 | ---- | C] () -- C:\Users\Public\Desktop\Heroglyph 4.0.lnk [2012-09-22 22:29:08 | 000,001,038 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Pro 11.0 (64-bit).lnk [2012-09-22 22:24:45 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk [2012-09-22 22:24:01 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2012-09-22 22:05:59 | 000,334,357 | ---- | C] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT [2012-09-22 22:00:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2012-09-22 21:50:47 | 000,204,528 | RHS- | C] () -- C:\GRLDR [2012-09-22 21:46:00 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK [2012-09-22 21:45:59 | 000,383,786 | RHS- | C] () -- C:\bootmgr [2012-09-22 20:53:39 | 000,001,421 | ---- | C] () -- C:\Users\Antoś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2012-09-22 20:53:36 | 000,001,455 | ---- | C] () -- C:\Users\Antoś\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012-09-22 20:50:24 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2012-09-22 20:50:19 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2012-09-22 20:49:04 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf [2012-09-22 20:47:05 | 2145,558,527 | -HS- | C] () -- C:\hiberfil.sys [2012-07-28 03:39:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012-07-28 03:39:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2011-09-13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2012-09-23 13:34:47 | 000,000,000 | ---D | M] -- C:\Users\Antoś\AppData\Roaming\Babylon [2012-09-22 22:43:01 | 000,000,000 | ---D | M] -- C:\Users\Antoś\AppData\Roaming\proDAD [2012-09-22 22:40:16 | 000,000,000 | ---D | M] -- C:\Users\Antoś\AppData\Roaming\Publish Providers [2012-09-22 22:40:14 | 000,000,000 | ---D | M] -- C:\Users\Antoś\AppData\Roaming\Sony [2012-09-23 13:34:54 | 000,000,000 | ---D | M] -- C:\Users\Antoś\AppData\Roaming\URSoft [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 176 bytes -> C:\ProgramData\TEMP:1CE11B51 @Alternate Data Stream - 1231 bytes -> C:\Users\Antoś\AppData\Local\Temp:259tv5bzIceTot6DnRn8gKBkOb @Alternate Data Stream - 1079 bytes -> C:\Users\Antoś\AppData\Local\Temp:WLb4Cm5rl39mPB4mnI1Ja < End of report >