13:33:26,4186085 ekrn.exe 1044 IRP_MJ_CREATE C:\WINDOWS\system32\usp10.dll SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: PL\moiz78, OpenResult: Opened
13:33:26,4192639 ekrn.exe 1044 IRP_MJ_QUERY_VOLUME_INFORMATION C:\WINDOWS\system32\usp10.dll BUFFER OVERFLOW Type: QueryInformationVolume, VolumeCreationTime: 2009-10-05 22:53:15, VolumeSerialNumber: E83F-70AA, SupportsObjects: True, VolumeLabel: sysٱ
13:33:26,4198617 ekrn.exe 1044 IRP_MJ_QUERY_INFORMATION C:\WINDOWS\system32\usp10.dll SUCCESS Type: QueryFileInternalInformationFile, IndexNumber: 0x170000000049b6
13:33:26,4204540 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\usp10.dll SUCCESS Type: QueryBasicInformationFile, CreationTime: 2008-04-14 21:50:58, LastAccessTime: 2011-10-30 13:20:03, LastWriteTime: 2010-04-16 16:38:53, ChangeTime: 2010-09-15 05:13:18, FileAttributes: ANCI
13:33:26,4210521 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\usp10.dll SUCCESS Type: QueryStandardInformationFile, AllocationSize: 409Â 600, EndOfFile: 406Â 016, NumberOfLinks: 1, DeletePending: False, Directory: False
13:33:26,4217846 ekrn.exe 1044 IRP_MJ_CLEANUP C:\WINDOWS\system32\usp10.dll SUCCESS
13:33:26,4219235 ekrn.exe 1044 IRP_MJ_CLOSE C:\WINDOWS\system32\usp10.dll SUCCESS
13:33:26,4226490 ekrn.exe 1044 IRP_MJ_CREATE C:\WINDOWS\system32\usp10.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: PL\moiz78, OpenResult: Opened
13:33:26,4234547 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\usp10.dll SUCCESS Type: QueryStandardInformationFile, AllocationSize: 409Â 600, EndOfFile: 406Â 016, NumberOfLinks: 1, DeletePending: False, Directory: False
13:33:26,4240662 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\usp10.dll SUCCESS Offset: 0, Length: 4Â 096
13:33:26,4249878 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\usp10.dll SUCCESS Offset: 276Â 736, Length: 1Â 029
13:33:26,4250023 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\usp10.dll SUCCESS Operation: Read, Offset: 276Â 736, Length: 1Â 029
13:33:26,4250264 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\usp10.dll SUCCESS Offset: 274Â 432, Length: 4Â 096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
13:33:26,4520778 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\usp10.dll SUCCESS Offset: 118Â 784, Length: 6Â 656
13:33:26,4520926 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\usp10.dll SUCCESS Operation: Read, Offset: 118Â 784, Length: 6Â 656
13:33:26,4521150 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\usp10.dll SUCCESS Offset: 118Â 784, Length: 8Â 192, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
13:33:26,4644487 ekrn.exe 1044 IRP_MJ_CLEANUP C:\WINDOWS\system32\usp10.dll SUCCESS
13:33:26,4711783 ekrn.exe 1044 IRP_MJ_CREATE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: PL\moiz78, OpenResult: Opened
13:33:26,4719231 ekrn.exe 1044 IRP_MJ_QUERY_VOLUME_INFORMATION C:\WINDOWS\system32\hhctrl.ocx BUFFER OVERFLOW Type: QueryInformationVolume, VolumeCreationTime: 2009-10-05 22:53:15, VolumeSerialNumber: E83F-70AA, SupportsObjects: True, VolumeLabel: sysٱ
13:33:26,4725332 ekrn.exe 1044 IRP_MJ_QUERY_INFORMATION C:\WINDOWS\system32\hhctrl.ocx SUCCESS Type: QueryFileInternalInformationFile, IndexNumber: 0x100000000089c
13:33:26,4731590 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\hhctrl.ocx SUCCESS Type: QueryBasicInformationFile, CreationTime: 2008-04-14 21:35:48, LastAccessTime: 2011-10-30 11:47:54, LastWriteTime: 2008-04-14 21:35:48, ChangeTime: 2010-05-06 18:48:39, FileAttributes: ANCI
13:33:26,4737507 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\hhctrl.ocx SUCCESS Type: QueryStandardInformationFile, AllocationSize: 548Â 864, EndOfFile: 545Â 280, NumberOfLinks: 1, DeletePending: False, Directory: False
13:33:26,4743497 ekrn.exe 1044 IRP_MJ_CLEANUP C:\WINDOWS\system32\hhctrl.ocx SUCCESS
13:33:26,4744854 ekrn.exe 1044 IRP_MJ_CLOSE C:\WINDOWS\system32\hhctrl.ocx SUCCESS
13:33:26,4752925 ekrn.exe 1044 IRP_MJ_CREATE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: PL\moiz78, OpenResult: Opened
13:33:26,4762312 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\hhctrl.ocx SUCCESS Type: QueryStandardInformationFile, AllocationSize: 548Â 864, EndOfFile: 545Â 280, NumberOfLinks: 1, DeletePending: False, Directory: False
13:33:26,4768427 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 0, Length: 4Â 096
13:33:26,4778007 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 432Â 768, Length: 310
13:33:26,4778163 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Operation: Read, Offset: 432Â 768, Length: 310
13:33:26,4778403 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 430Â 080, Length: 4Â 096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
13:33:26,4824918 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 399Â 872, Length: 6Â 656
13:33:26,4825041 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Operation: Read, Offset: 399Â 872, Length: 6Â 656
13:33:26,4825203 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 397Â 312, Length: 12Â 288, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
13:33:26,4933968 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 4Â 096, Length: 5Â 120
13:33:26,4934119 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Operation: Read, Offset: 4Â 096, Length: 5Â 120
13:33:26,4952582 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 423Â 668, Length: 5Â 120
13:33:26,4952713 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Operation: Read, Offset: 423Â 668, Length: 5Â 120
13:33:26,4952942 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 421Â 888, Length: 8Â 192, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
13:33:26,4962759 ekrn.exe 1044 FASTIO_READ C:\WINDOWS\system32\hhctrl.ocx SUCCESS Offset: 428Â 788, Length: 4Â 364
13:33:26,4962874 ekrn.exe 1044 FASTIO_CHECK_IF_POSSIBLE C:\WINDOWS\system32\hhctrl.ocx SUCCESS Operation: Read, Offset: 428Â 788, Length: 4Â 364
13:33:26,4970975 ekrn.exe 1044 IRP_MJ_CLEANUP C:\WINDOWS\system32\hhctrl.ocx SUCCESS
13:33:26,5096041 ekrn.exe 1044 IRP_MJ_CREATE C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: PL\moiz78, OpenResult: Opened
13:33:26,5111270 ekrn.exe 1044 IRP_MJ_QUERY_VOLUME_INFORMATION C:\WINDOWS\system32\mui\0015\hhctrlui.dll BUFFER OVERFLOW Type: QueryInformationVolume, VolumeCreationTime: 2009-10-05 22:53:15, VolumeSerialNumber: E83F-70AA, SupportsObjects: True, VolumeLabel: sysٱ
13:33:26,5124805 ekrn.exe 1044 IRP_MJ_QUERY_INFORMATION C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Type: QueryFileInternalInformationFile, IndexNumber: 0x10000000001f3
13:33:26,5140234 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Type: QueryBasicInformationFile, CreationTime: 2001-10-26 18:28:00, LastAccessTime: 2011-10-30 11:47:54, LastWriteTime: 2001-10-26 18:28:00, ChangeTime: 2010-05-06 18:48:57, FileAttributes: ANCI
13:33:26,5162198 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Type: QueryStandardInformationFile, AllocationSize: 90Â 112, EndOfFile: 89Â 088, NumberOfLinks: 1, DeletePending: False, Directory: False
13:33:26,5177203 ekrn.exe 1044 IRP_MJ_CLEANUP C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS
13:33:26,5179214 ekrn.exe 1044 IRP_MJ_CLOSE C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS
13:33:26,5194277 ekrn.exe 1044 IRP_MJ_CREATE C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: PL\moiz78, OpenResult: Opened
13:33:26,5210503 ekrn.exe 1044 FASTIO_QUERY_INFORMATION C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Type: QueryStandardInformationFile, AllocationSize: 90Â 112, EndOfFile: 89Â 088, NumberOfLinks: 1, DeletePending: False, Directory: False
13:33:26,5225259 ekrn.exe 1044 IRP_MJ_READ C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS Offset: 0, Length: 4Â 096
13:33:26,5303224 ekrn.exe 1044 IRP_MJ_CLEANUP C:\WINDOWS\system32\mui\0015\hhctrlui.dll SUCCESS
Jakie filtry można zastosować na noda i operę? W operze wyłączyłem katalog profilu (cache jest w innym miejscu) i katalog w którym jest opera, można coś jeszcze?