Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015 Ran by Grzegorz (administrator) on KOMPUTER on 12-05-2015 10:45:54 Running from D:\Users\Grzegorz\Downloads Loaded Profiles: Grzegorz (Available profiles: Grzegorz) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Polski (Polska) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Bitdefender) D:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe (AMD) D:\Windows\System32\atiesrxx.exe (Logitech Inc.) D:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Sandboxie Holdings, LLC) D:\Program Files\Sandboxie\SbieSvc.exe (AMD) D:\Windows\System32\atieclxx.exe (H.D.S. Hungary) D:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe (Advanced Micro Devices, Inc.) D:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Foxit Software Inc.) D:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe (Microsoft Corporation) D:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Realtek Semiconductor) D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Bitdefender) D:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe (Sandboxie Holdings, LLC) D:\Program Files\Sandboxie\SbieCtrl.exe (MicroWorld Technologies Inc.) D:\Program Files (x86)\Common Files\MicroWorld\Agent\MWASER.EXE (MicroWorld Technologies Inc.) D:\Program Files (x86)\Common Files\MicroWorld\Agent\MWAGENT.EXE () D:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe (Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe (Bitdefender) D:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe () D:\Program Files (x86)\EDIMAX\Common\RalinkRegistryWriter.exe (Edimax Technology Co., Ltd.) D:\Program Files (x86)\EDIMAX\Common\RaUI.exe (Microsoft Corporation) D:\Windows\System32\rundll32.exe (Logitech Inc.) D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Advanced Micro Devices Inc.) D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) D:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Bitdefender) D:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Hewlett-Packard Co.) D:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (CyberGhost S.R.L) D:\Program Files\CyberGhost 5\Service.exe (Piriform Ltd) D:\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ATI Technologies Inc.) D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) D:\Windows\System32\dllhost.exe (Microsoft Corporation) D:\Windows\SysWOW64\explorer.exe (Bitdefender) D:\Program Files\Bitdefender\Bitdefender 2015\antispam32\obkagent.exe (Mozilla Corporation) D:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => D:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [Bdagent] => D:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1691112 2015-04-30] (Bitdefender) HKLM-x32\...\Run: [LWS] => D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-08-12] (Logitech Inc.) HKLM-x32\...\Run: [StartCCC] => D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-09-28] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\Run: [SandboxieControl] => D:\Program Files\Sandboxie\SbieCtrl.exe [785416 2015-02-18] (Sandboxie Holdings, LLC) HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\Run: [CCleaner Monitoring] => D:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd) HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\Run: [DAEMON Tools Lite] => D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\Run: [Skype] => D:\Program Files (x86)\Skype\Phone\Skype.exe [31282304 2015-04-17] (Skype Technologies S.A.) HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\Run: [Agent Portfela Bitdefender] => D:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-04-30] (Bitdefender) HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\Run: [omuvyquf] => D:\ProgramData\exoqokut.exe [280618 2015-05-12] () HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\MountPoints2: I - I:\start.exe HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\MountPoints2: {0ba8a48b-7f0f-11e4-9f2e-f82572453232} - G:\Launcher.exe HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\MountPoints2: {8c80120b-5f73-11e3-a03e-002421b73f35} - H:\Startme.exe HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\MountPoints2: {b200300d-1958-11e3-842e-002421b73f35} - H:\start.exe HKU\S-1-5-21-1558899207-2086174334-889782467-1001\...\MountPoints2: {c181bd6f-3c35-11e1-b2e5-002421b73f35} - G:\Launcher.exe Startup: D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wireless Utility.lnk [2012-09-20] ShortcutTarget: Wireless Utility.lnk -> D:\Program Files (x86)\EDIMAX\Common\RaUI.exe (Edimax Technology Co., Ltd.) Startup: D:\Users\Grzegorz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 3520 series (sieć).lnk [2013-08-09] ShortcutTarget: Powiadomienia monitorowania tuszu - HP Deskjet 3520 series (sieć).lnk -> D:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) BootExecute: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1558899207-2086174334-889782467-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-1558899207-2086174334-889782467-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID=119887&babsrc=SP_ss&mntrId=30ED00FFEF4CC11E SearchScopes: HKU\S-1-5-21-1558899207-2086174334-889782467-1001 -> {951265FF-C6C2-4D61-8785-6091AB57CA33} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=BAFFE972-3829-48E6-BDF9-833E7EDB2B69&apn_sauid=AE9ED8C3-B03C-4847-8963-0510F9522738 BHO: Portfel Bitdefender -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> D:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-04-30] (Bitdefender) BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> D:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13] (Advanced Micro Devices) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Portfel Bitdefender -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> D:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-04-30] (Bitdefender) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-10-17] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> D:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-03-02] (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-10-17] (Oracle Corporation) Toolbar: HKLM - Portfel Bitdefender - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-04-30] (Bitdefender) Toolbar: HKLM-x32 - Portfel Bitdefender - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - D:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-04-30] (Bitdefender) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-03-02] (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 109.197.168.2 109.197.168.3 Tcpip\..\Interfaces\{549800F1-12DE-4C67-986D-C232D2CB6E11}: [NameServer] 156.154.70.22,156.154.71.22 Tcpip\..\Interfaces\{CD0A7232-A4BD-43B3-90E4-D2A02430F090}: [NameServer] 156.154.70.22,156.154.71.22 FireFox: ======== FF ProfilePath: D:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\dlq5zuk9.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: FF Homepage: wp.pl FF Plugin: @adobe.com/FlashPlayer -> D:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> D:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> D:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] () FF Plugin-x32: @Bitdefender.com/PasswordManager;version=17.8 -> D:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll No File FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-11-18] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-11-18] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-11-18] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-11-18] (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> D:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-10-17] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> D:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-10-17] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> D:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> D:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> D:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-02-17] (VideoLAN) FF Plugin-x32: Adobe Reader -> D:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: D:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\dlq5zuk9.default\searchplugins\youtube.xml [2014-01-31] FF Extension: Iplex to ALLPlayer - D:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\dlq5zuk9.default\Extensions\IplextoALL@ALLPlayer.org [2012-01-29] FF Extension: Iplex to ALLPlayer - D:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\dlq5zuk9.default\Extensions\IplextoALL@ALLPlayer.org.xpi [2012-01-29] FF Extension: Adblock Plus - D:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\dlq5zuk9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-06-29] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - D:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Program Files\Bitdefender\Bitdefender 2015\bdtbext FF Extension: Bitdefender Antispam Toolbar - D:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2015-04-30] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - D:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - D:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff FF Extension: Bitdefender Wallet - D:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2015-04-30] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - D:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - D:\Program Files\Bitdefender\Bitdefender 2015\bdtbext Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [aaaaojmikegpiepcfdkkjaplodkpfmlo] - D:\Users\Grzegorz\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AeLookupSvc; D:\Windows\System32\aelupsvc.dll [72192 2009-07-14] (Microsoft Corporation) [File not signed] S3 ALG; D:\Windows\System32\alg.exe [79360 2009-07-14] (Microsoft Corporation) [File not signed] R2 AMD External Events Utility; D:\Windows\system32\atiesrxx.exe [236544 2012-04-06] (AMD) [File not signed] R2 AMD FUEL Service; D:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-09-28] (Advanced Micro Devices, Inc.) [File not signed] S3 AppIDSvc; D:\Windows\System32\appidsvc.dll [32256 2009-07-14] (Microsoft Corporation) [File not signed] R3 Appinfo; D:\Windows\System32\appinfo.dll [70144 2013-02-27] (Microsoft Corporation) [File not signed] R3 AppMgmt; D:\Windows\System32\appmgmts.dll [193536 2009-07-14] (Microsoft Corporation) [File not signed] R3 AppMgmt; D:\Windows\SysWOW64\appmgmts.dll [149504 2009-07-14] (Microsoft Corporation) [File not signed] R2 AudioEndpointBuilder; D:\Windows\System32\Audiosrv.dll [679424 2010-11-20] (Microsoft Corporation) [File not signed] R2 AudioSrv; D:\Windows\System32\Audiosrv.dll [679424 2010-11-20] (Microsoft Corporation) [File not signed] S3 AxInstSV; D:\Windows\System32\AxInstSV.dll [114688 2010-11-20] (Microsoft Corporation) [File not signed] S3 BdDesktopParental; D:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2015-04-30] (Bitdefender) S3 BDESVC; D:\Windows\System32\bdesvc.dll [100864 2009-07-14] (Microsoft Corporation) [File not signed] R2 BFE; D:\Windows\System32\bfe.dll [705024 2010-11-20] (Microsoft Corporation) [File not signed] R2 BITS; D:\Windows\System32\qmgr.dll [849920 2010-11-20] (Microsoft Corporation) [File not signed] R3 Browser; D:\Windows\System32\browser.dll [136704 2012-07-05] (Microsoft Corporation) [File not signed] S3 bthserv; D:\Windows\system32\bthserv.dll [83968 2009-07-14] (Microsoft Corporation) [File not signed] S3 CertPropSvc; D:\Windows\System32\certprop.dll [80384 2010-11-20] (Microsoft Corporation) [File not signed] R2 CGVPNCliService; D:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L) R2 CryptSvc; D:\Windows\system32\cryptsvc.dll [187904 2014-07-07] (Microsoft Corporation) [File not signed] R2 CryptSvc; D:\Windows\SysWOW64\cryptsvc.dll [143872 2014-07-07] (Microsoft Corporation) [File not signed] R2 CscService; D:\Windows\System32\cscsvc.dll [692224 2010-11-20] (Microsoft Corporation) [File not signed] R2 DcomLaunch; D:\Windows\system32\rpcss.dll [512000 2010-11-20] (Microsoft Corporation) [File not signed] S3 defragsvc; D:\Windows\System32\defragsvc.dll [291328 2009-07-14] (Microsoft Corporation) [File not signed] R2 Dhcp; D:\Windows\system32\dhcpcore.dll [317952 2010-11-20] (Microsoft Corporation) [File not signed] R2 Dhcp; D:\Windows\SysWOW64\dhcpcore.dll [254464 2010-11-20] (Microsoft Corporation) [File not signed] R2 Dnscache; D:\Windows\System32\dnsrslvr.dll [183296 2011-03-03] (Microsoft Corporation) [File not signed] S3 dot3svc; D:\Windows\System32\dot3svc.dll [252416 2010-11-20] (Microsoft Corporation) [File not signed] R2 DPS; D:\Windows\system32\dps.dll [162816 2010-11-20] (Microsoft Corporation) [File not signed] R3 EapHost; D:\Windows\System32\eapsvc.dll [111104 2009-07-14] (Microsoft Corporation) [File not signed] S3 EFS; D:\Windows\System32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed] S3 ehRecvr; D:\Windows\ehome\ehRecvr.exe [696832 2010-11-20] (Microsoft Corporation) [File not signed] S3 ehSched; D:\Windows\ehome\ehsched.exe [127488 2009-07-14] (Microsoft Corporation) [File not signed] R2 eventlog; D:\Windows\System32\wevtsvc.dll [1646080 2010-11-20] (Microsoft Corporation) [File not signed] R2 EventSystem; D:\Windows\system32\es.dll [402944 2009-07-14] (Microsoft Corporation) [File not signed] R2 EventSystem; D:\Windows\SysWOW64\es.dll [271360 2009-07-14] (Microsoft Corporation) [File not signed] S3 Fax; D:\Windows\system32\fxssvc.exe [689152 2010-11-20] (Microsoft Corporation) [File not signed] R3 fdPHost; D:\Windows\system32\fdPHost.dll [16384 2009-07-14] (Microsoft Corporation) [File not signed] R2 FDResPub; D:\Windows\system32\fdrespub.dll [34816 2009-07-14] (Microsoft Corporation) [File not signed] S2 FirebirdGuardianDefaultInstance; D:\Program Files (x86)\Firebird\Firebird_2_0\bin\fbguard.exe [81920 2012-02-21] (FirebirdSQL Project) [File not signed] S3 FirebirdServerDefaultInstance; D:\Program Files (x86)\Firebird\Firebird_2_0\bin\fbserver.exe [2048000 2012-02-21] (FirebirdSQL Project) [File not signed] R2 FontCache; D:\Windows\system32\FntCache.dll [1175552 2013-01-13] (Microsoft Corporation) [File not signed] R2 FoxitCloudUpdateService; D:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [244392 2015-04-10] (Foxit Software Inc.) R2 gpsvc; D:\Windows\System32\gpsvc.dll [777728 2010-11-20] (Microsoft Corporation) [File not signed] R3 hidserv; D:\Windows\system32\hidserv.dll [38912 2009-07-14] (Microsoft Corporation) [File not signed] R3 hidserv; D:\Windows\SysWOW64\hidserv.dll [49152 2009-07-14] (Microsoft Corporation) [File not signed] S3 hkmsvc; D:\Windows\system32\kmsvc.dll [90624 2010-11-20] (Microsoft Corporation) [File not signed] R3 HomeGroupListener; D:\Windows\system32\ListSvc.dll [232448 2010-11-20] (Microsoft Corporation) [File not signed] R3 HomeGroupProvider; D:\Windows\system32\provsvc.dll [187904 2010-11-20] (Microsoft Corporation) [File not signed] R3 HomeGroupProvider; D:\Windows\SysWOW64\provsvc.dll [165376 2010-11-20] (Microsoft Corporation) [File not signed] S3 IEEtwCollectorService; D:\Windows\system32\IEEtwCollector.exe [114688 2014-11-22] (Microsoft Corporation) [File not signed] R2 IKEEXT; D:\Windows\System32\ikeext.dll [859648 2013-10-12] (Microsoft Corporation) [File not signed] S3 IPBusEnum; D:\Windows\system32\ipbusenum.dll [101888 2009-07-14] (Microsoft Corporation) [File not signed] R2 iphlpsvc; D:\Windows\System32\iphlpsvc.dll [569344 2012-10-03] (Microsoft Corporation) [File not signed] R3 KeyIso; D:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed] S3 KtmRm; D:\Windows\system32\msdtckrm.dll [368640 2009-07-14] (Microsoft Corporation) [File not signed] R2 LanmanServer; D:\Windows\system32\srvsvc.dll [236032 2010-11-20] (Microsoft Corporation) [File not signed] R2 LanmanWorkstation; D:\Windows\System32\wkssvc.dll [118784 2010-11-20] (Microsoft Corporation) [File not signed] S3 lltdsvc; D:\Windows\System32\lltdsvc.dll [300032 2009-07-14] (Microsoft Corporation) [File not signed] R2 lmhosts; D:\Windows\System32\lmhsvc.dll [23552 2009-07-14] (Microsoft Corporation) [File not signed] S4 Mcx2Svc; D:\Windows\system32\Mcx2Svc.dll [84992 2010-11-20] (Microsoft Corporation) [File not signed] R2 MMCSS; D:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation) [File not signed] R2 MpsSvc; D:\Windows\system32\mpssvc.dll [828416 2010-11-20] (Microsoft Corporation) [File not signed] S3 MSDTC; D:\Windows\System32\msdtc.exe [141824 2009-07-14] (Microsoft Corporation) [File not signed] S3 MSiSCSI; D:\Windows\system32\iscsiexe.dll [156672 2009-07-14] (Microsoft Corporation) [File not signed] S3 msiserver; D:\Windows\System32\msiexec.exe [128000 2010-11-20] (Microsoft Corporation) [File not signed] S3 msiserver; D:\Windows\SysWOW64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation) [File not signed] R2 MSSQL$ELISOFT; D:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) R2 MWAgent; D:\Program Files (x86)\Common Files\MicroWorld\Agent\MWASER.EXE [858632 2011-12-20] (MicroWorld Technologies Inc.) S3 napagent; D:\Windows\system32\qagentRT.dll [476160 2010-11-20] (Microsoft Corporation) [File not signed] S3 Netlogon; D:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed] R3 Netman; D:\Windows\System32\netman.dll [360448 2009-07-14] (Microsoft Corporation) [File not signed] R3 netprofm; D:\Windows\System32\netprofm.dll [459776 2009-07-14] (Microsoft Corporation) [File not signed] R3 netprofm; D:\Windows\SysWOW64\netprofm.dll [360448 2009-07-14] (Microsoft Corporation) [File not signed] R2 NlaSvc; D:\Windows\System32\nlasvc.dll [303616 2014-12-06] (Microsoft Corporation) [File not signed] R2 nsi; D:\Windows\system32\nsisvc.dll [25600 2009-07-14] (Microsoft Corporation) [File not signed] R2 OMSI download service; D:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] () [File not signed] R3 p2pimsvc; D:\Windows\system32\pnrpsvc.dll [327168 2009-07-14] (Microsoft Corporation) [File not signed] R3 p2psvc; D:\Windows\system32\p2psvc.dll [438784 2009-07-14] (Microsoft Corporation) [File not signed] R2 PcaSvc; D:\Windows\System32\pcasvc.dll [186368 2009-07-14] (Microsoft Corporation) [File not signed] S3 PeerDistSvc; D:\Windows\system32\peerdistsvc.dll [1361920 2009-07-14] (Microsoft Corporation) [File not signed] S3 PerfHost; D:\Windows\SysWow64\perfhost.exe [20992 2009-07-14] (Microsoft Corporation) [File not signed] S3 pla; D:\Windows\system32\pla.dll [1389056 2010-11-20] (Microsoft Corporation) [File not signed] S3 pla; D:\Windows\SysWOW64\pla.dll [1508864 2010-11-20] (Microsoft Corporation) [File not signed] R2 PlugPlay; D:\Windows\system32\umpnpmgr.dll [404480 2011-05-24] (Microsoft Corporation) [File not signed] S3 PNRPAutoReg; D:\Windows\system32\pnrpauto.dll [25088 2009-07-14] (Microsoft Corporation) [File not signed] R3 PNRPsvc; D:\Windows\system32\pnrpsvc.dll [327168 2009-07-14] (Microsoft Corporation) [File not signed] R3 PolicyAgent; D:\Windows\System32\ipsecsvc.dll [501248 2010-11-20] (Microsoft Corporation) [File not signed] R2 Power; D:\Windows\system32\umpo.dll [163840 2009-07-14] (Microsoft Corporation) [File not signed] R2 ProfSvc; D:\Windows\system32\profsvc.dll [210432 2014-12-19] (Microsoft Corporation) [File not signed] R3 ProtectedStorage; D:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed] S3 QWAVE; D:\Windows\system32\qwave.dll [242688 2009-07-14] (Microsoft Corporation) [File not signed] R2 RalinkRegistryWriter; D:\Program Files (x86)\EDIMAX\Common\RalinkRegistryWriter.exe [53760 2007-12-26] () [File not signed] S3 RasAuto; D:\Windows\System32\rasauto.dll [99328 2009-07-14] (Microsoft Corporation) [File not signed] S3 RasMan; D:\Windows\System32\rasmans.dll [344064 2010-11-20] (Microsoft Corporation) [File not signed] S4 RemoteAccess; D:\Windows\System32\mprdim.dll [97792 2009-07-14] (Microsoft Corporation) [File not signed] S4 RemoteAccess; D:\Windows\SysWOW64\mprdim.dll [75264 2009-07-14] (Microsoft Corporation) [File not signed] R2 RemoteRegistry; D:\Windows\system32\regsvc.dll [159232 2009-07-14] (Microsoft Corporation) [File not signed] R2 RpcEptMapper; D:\Windows\System32\RpcEpMap.dll [67072 2009-07-14] (Microsoft Corporation) [File not signed] S3 RpcLocator; D:\Windows\system32\locator.exe [10240 2009-07-14] (Microsoft Corporation) [File not signed] R2 RpcSs; D:\Windows\system32\rpcss.dll [512000 2010-11-20] (Microsoft Corporation) [File not signed] R2 SamSs; D:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed] S3 SandraAgentSrv; D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP1a\RpcAgentSrv.exe [68760 2009-02-04] (SiSoftware) [File not signed] R2 SbieSvc; D:\Program Files\Sandboxie\SbieSvc.exe [175112 2015-02-18] (Sandboxie Holdings, LLC) S3 SCardSvr; D:\Windows\System32\SCardSvr.dll [190976 2009-07-14] (Microsoft Corporation) [File not signed] R2 Schedule; D:\Windows\system32\schedsvc.dll [1110016 2010-11-20] (Microsoft Corporation) [File not signed] S3 SCPolicySvc; D:\Windows\System32\certprop.dll [80384 2010-11-20] (Microsoft Corporation) [File not signed] S3 SDRSVC; D:\Windows\System32\SDRSVC.dll [170496 2010-11-20] (Microsoft Corporation) [File not signed] S3 seclogon; D:\Windows\system32\seclogon.dll [30720 2010-11-20] (Microsoft Corporation) [File not signed] R2 SENS; D:\Windows\System32\sens.dll [64512 2009-07-14] (Microsoft Corporation) [File not signed] R2 SENS; D:\Windows\SysWOW64\sens.dll [49664 2009-07-14] (Microsoft Corporation) [File not signed] S3 SensrSvc; D:\Windows\system32\sensrsvc.dll [29184 2009-07-14] (Microsoft Corporation) [File not signed] S3 SessionEnv; D:\Windows\system32\sessenv.dll [121856 2010-11-20] (Microsoft Corporation) [File not signed] S3 SessionEnv; D:\Windows\SysWOW64\sessenv.dll [113664 2010-11-20] (Microsoft Corporation) [File not signed] S3 SharedAccess; D:\Windows\System32\ipnathlp.dll [359424 2009-07-14] (Microsoft Corporation) [File not signed] R2 ShellHWDetection; D:\Windows\System32\shsvcs.dll [370688 2010-11-20] (Microsoft Corporation) [File not signed] R2 ShellHWDetection; D:\Windows\SysWOW64\shsvcs.dll [328192 2010-11-20] (Microsoft Corporation) [File not signed] S3 SNMPTRAP; D:\Windows\System32\snmptrap.exe [14336 2009-07-14] (Microsoft Corporation) [File not signed] R2 Spooler; D:\Windows\System32\spoolsv.exe [559104 2012-02-11] (Microsoft Corporation) [File not signed] S2 sppsvc; D:\Windows\system32\sppsvc.exe [3524608 2010-11-20] (Microsoft Corporation) [File not signed] S3 sppuinotify; D:\Windows\system32\sppuinotify.dll [65536 2009-07-14] (Microsoft Corporation) [File not signed] R3 SSDPSRV; D:\Windows\System32\ssdpsrv.dll [193024 2009-07-14] (Microsoft Corporation) [File not signed] S3 SstpSvc; D:\Windows\system32\sstpsvc.dll [75264 2009-07-14] (Microsoft Corporation) [File not signed] R2 stisvc; D:\Windows\System32\wiaservc.dll [580096 2010-11-20] (Microsoft Corporation) [File not signed] S3 swprv; D:\Windows\System32\swprv.dll [524288 2009-07-14] (Microsoft Corporation) [File not signed] R2 SysMain; D:\Windows\system32\sysmain.dll [1743360 2010-11-20] (Microsoft Corporation) [File not signed] S3 TabletInputService; D:\Windows\System32\TabSvc.dll [92672 2010-11-20] (Microsoft Corporation) [File not signed] S3 TapiSrv; D:\Windows\System32\tapisrv.dll [316928 2010-11-20] (Microsoft Corporation) [File not signed] S3 TapiSrv; D:\Windows\SysWOW64\tapisrv.dll [242176 2010-11-20] (Microsoft Corporation) [File not signed] S3 TBS; D:\Windows\System32\tbssvc.dll [65536 2009-07-14] (Microsoft Corporation) [File not signed] S3 TermService; D:\Windows\System32\termsrv.dll [680960 2010-11-20] (Microsoft Corporation) [File not signed] R2 Themes; D:\Windows\system32\themeservice.dll [44544 2009-07-14] (Microsoft Corporation) [File not signed] S3 THREADORDER; D:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation) [File not signed] R2 TrkWks; D:\Windows\System32\trkwks.dll [119808 2009-07-14] (Microsoft Corporation) [File not signed] S3 TrustedInstaller; D:\Windows\servicing\TrustedInstaller.exe [194048 2010-11-20] (Microsoft Corporation) [File not signed] S3 UI0Detect; D:\Windows\system32\UI0Detect.exe [40960 2009-07-14] (Microsoft Corporation) [File not signed] S3 UmRdpService; D:\Windows\System32\umrdp.dll [214528 2010-11-20] (Microsoft Corporation) [File not signed] R2 UPDATESRV; D:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-10-27] (Bitdefender) R3 upnphost; D:\Windows\System32\upnphost.dll [353792 2009-07-14] (Microsoft Corporation) [File not signed] R3 upnphost; D:\Windows\SysWOW64\upnphost.dll [266752 2009-07-14] (Microsoft Corporation) [File not signed] R2 UxSms; D:\Windows\System32\uxsms.dll [38912 2009-07-14] (Microsoft Corporation) [File not signed] S3 VaultSvc; D:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed] S3 vds; D:\Windows\System32\vds.exe [533504 2010-11-20] (Microsoft Corporation) [File not signed] S3 VSS; D:\Windows\system32\vssvc.exe [1600512 2010-11-20] (Microsoft Corporation) [File not signed] R2 VSSERV; D:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1547936 2015-04-30] (Bitdefender) S3 W32Time; D:\Windows\system32\w32time.dll [381952 2009-07-14] (Microsoft Corporation) [File not signed] S3 wbengine; D:\Windows\system32\wbengine.exe [1504256 2010-11-20] (Microsoft Corporation) [File not signed] S3 WbioSrvc; D:\Windows\System32\wbiosrvc.dll [202240 2009-07-14] (Microsoft Corporation) [File not signed] R3 wcncsvc; D:\Windows\System32\wcncsvc.dll [367104 2010-11-20] (Microsoft Corporation) [File not signed] R3 wcncsvc; D:\Windows\SysWOW64\wcncsvc.dll [276992 2010-11-20] (Microsoft Corporation) [File not signed] S3 WcsPlugInService; D:\Windows\System32\WcsPlugInService.dll [40960 2009-07-14] (Microsoft Corporation) [File not signed] S3 WcsPlugInService; D:\Windows\SysWOW64\WcsPlugInService.dll [32768 2009-07-14] (Microsoft Corporation) [File not signed] R3 WdiServiceHost; D:\Windows\system32\wdi.dll [90624 2009-07-14] (Microsoft Corporation) [File not signed] R3 WdiServiceHost; D:\Windows\SysWOW64\wdi.dll [76288 2009-07-14] (Microsoft Corporation) [File not signed] S3 WdiSystemHost; D:\Windows\system32\wdi.dll [90624 2009-07-14] (Microsoft Corporation) [File not signed] S3 WdiSystemHost; D:\Windows\SysWOW64\wdi.dll [76288 2009-07-14] (Microsoft Corporation) [File not signed] S3 WebClient; D:\Windows\System32\webclnt.dll [259584 2013-07-04] (Microsoft Corporation) [File not signed] S3 WebClient; D:\Windows\SysWOW64\webclnt.dll [205824 2013-07-04] (Microsoft Corporation) [File not signed] S3 Wecsvc; D:\Windows\system32\wecsvc.dll [237568 2009-07-14] (Microsoft Corporation) [File not signed] S3 wercplsupport; D:\Windows\System32\wercplsupport.dll [84480 2009-07-14] (Microsoft Corporation) [File not signed] S3 WerSvc; D:\Windows\System32\WerSvc.dll [76800 2009-07-14] (Microsoft Corporation) [File not signed] S2 WinDefend; D:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) [File not signed] S3 WinHttpAutoProxySvc; D:\Windows\SYSTEM32\winhttp.dll [444416 2010-11-20] (Microsoft Corporation) [File not signed] S3 WinHttpAutoProxySvc; D:\Windows\SysWOW64\winhttp.dll [351232 2010-11-20] (Microsoft Corporation) [File not signed] R2 Winmgmt; D:\Windows\system32\wbem\WMIsvc.dll [242688 2009-07-14] (Microsoft Corporation) [File not signed] S3 WinRM; D:\Windows\system32\WsmSvc.dll [2020352 2014-10-03] (Microsoft Corporation) [File not signed] S3 WinRM; D:\Windows\SysWOW64\WsmSvc.dll [1177088 2014-10-03] (Microsoft Corporation) [File not signed] R2 Wlansvc; D:\Windows\System32\wlansvc.dll [886784 2009-07-14] (Microsoft Corporation) [File not signed] S3 wmiApSrv; D:\Windows\system32\wbem\WmiApSrv.exe [203264 2009-07-14] (Microsoft Corporation) [File not signed] R2 WMPNetworkSvc; D:\Program Files\Windows Media Player\wmpnetwk.exe [1525248 2010-11-20] (Microsoft Corporation) [File not signed] S3 WPCSvc; D:\Windows\System32\wpcsvc.dll [12288 2009-07-14] (Microsoft Corporation) [File not signed] S3 WPCSvc; D:\Windows\SysWOW64\wpcsvc.dll [10752 2009-07-14] (Microsoft Corporation) [File not signed] S3 WPDBusEnum; D:\Windows\system32\wpdbusenum.dll [117248 2010-11-20] (Microsoft Corporation) [File not signed] R2 wscsvc; D:\Windows\System32\wscsvc.dll [97280 2009-07-14] (Microsoft Corporation) [File not signed] R2 WSearch; D:\Windows\system32\SearchIndexer.exe [591872 2011-05-04] (Microsoft Corporation) [File not signed] R2 WSearch; D:\Windows\SysWOW64\SearchIndexer.exe [427520 2011-05-04] (Microsoft Corporation) [File not signed] S3 wudfsvc; D:\Windows\System32\WUDFSvc.dll [84992 2012-07-26] (Microsoft Corporation) [File not signed] S3 WwanSvc; D:\Windows\System32\wwansvc.dll [228864 2014-01-28] (Microsoft Corporation) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 1394ohci; D:\Windows\system32\drivers\1394ohci.sys [229888 2010-11-20] (Microsoft Corporation) [File not signed] S3 AcpiPmi; D:\Windows\system32\drivers\acpipmi.sys [12800 2010-11-20] (Microsoft Corporation) [File not signed] R1 AFD; D:\Windows\system32\drivers\afd.sys [497152 2014-05-30] (Microsoft Corporation) [File not signed] S3 AmdK8; D:\Windows\system32\DRIVERS\amdk8.sys [64512 2009-07-14] (Microsoft Corporation) [File not signed] R3 amdkmdag; D:\Windows\System32\DRIVERS\atikmdag.sys [11174400 2012-04-06] (Advanced Micro Devices, Inc.) [File not signed] R3 amdkmdap; D:\Windows\System32\DRIVERS\atikmpag.sys [343040 2012-04-06] (Advanced Micro Devices, Inc.) [File not signed] R3 AmdPPM; D:\Windows\System32\DRIVERS\amdppm.sys [60928 2009-07-14] (Microsoft Corporation) [File not signed] S3 AppID; D:\Windows\system32\drivers\appid.sys [61440 2010-11-20] (Microsoft Corporation) [File not signed] R3 AsyncMac; D:\Windows\System32\DRIVERS\asyncmac.sys [23040 2009-07-14] (Microsoft Corporation) [File not signed] S3 atikmdag; D:\Windows\System32\DRIVERS\atikmdag.sys [11174400 2012-04-06] (Advanced Micro Devices, Inc.) [File not signed] R0 avc3; D:\Windows\System32\DRIVERS\avc3.sys [1306464 2015-04-30] (BitDefender) R3 avchv; D:\Windows\System32\DRIVERS\avchv.sys [262544 2015-04-30] (BitDefender) R3 avckf; D:\Windows\System32\DRIVERS\avckf.sys [677104 2015-04-30] (BitDefender) S3 b06bdrv; D:\Windows\system32\DRIVERS\bxvbda.sys [468480 2009-06-10] (Broadcom Corporation) [File not signed] S3 b57nd60a; D:\Windows\System32\DRIVERS\b57nd60a.sys [270848 2009-06-10] (Broadcom Corporation) [File not signed] R1 BdfNdisf; d:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2015-04-30] (BitDefender LLC) S3 bdfsfltr; D:\Windows\System32\DRIVERS\bdfsfltr.sys [431176 2011-03-24] (BitDefender) R1 bdfwfpf; D:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107080 2012-10-29] (BitDefender LLC) S3 bdfwfpf_pc; D:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL) S3 BDSandBox; D:\Windows\system32\drivers\bdsandbox.sys [82824 2015-04-30] (BitDefender SRL) R1 blbdrive; D:\Windows\System32\DRIVERS\blbdrive.sys [45056 2009-07-14] (Microsoft Corporation) [File not signed] R3 bowser; D:\Windows\System32\DRIVERS\bowser.sys [90624 2011-02-23] (Microsoft Corporation) [File not signed] S3 BrFiltLo; D:\Windows\system32\DRIVERS\BrFiltLo.sys [18432 2009-06-10] (Brother Industries, Ltd.) [File not signed] S3 BrFiltUp; D:\Windows\system32\DRIVERS\BrFiltUp.sys [8704 2009-06-10] (Brother Industries, Ltd.) [File not signed] S3 Brserid; D:\Windows\System32\Drivers\Brserid.sys [286720 2009-07-14] (Brother Industries Ltd.) [File not signed] S3 BrSerWdm; D:\Windows\System32\Drivers\BrSerWdm.sys [47104 2009-06-10] (Brother Industries Ltd.) [File not signed] S3 BrUsbMdm; D:\Windows\System32\Drivers\BrUsbMdm.sys [14976 2009-06-10] (Brother Industries Ltd.) [File not signed] S3 BrUsbSer; D:\Windows\System32\Drivers\BrUsbSer.sys [14720 2009-06-10] (Brother Industries Ltd.) [File not signed] S3 BTHMODEM; D:\Windows\system32\DRIVERS\bthmodem.sys [72192 2009-07-14] (Microsoft Corporation) [File not signed] R4 cdfs; D:\Windows\System32\DRIVERS\cdfs.sys [92160 2009-07-14] (Microsoft Corporation) [File not signed] R1 cdrom; D:\Windows\System32\DRIVERS\cdrom.sys [147456 2010-11-20] (Microsoft Corporation) [File not signed] S3 circlass; D:\Windows\system32\DRIVERS\circlass.sys [45568 2009-07-14] (Microsoft Corporation) [File not signed] S3 CmBatt; D:\Windows\system32\DRIVERS\CmBatt.sys [17664 2009-07-14] (Microsoft Corporation) [File not signed] R3 CompositeBus; D:\Windows\system32\drivers\CompositeBus.sys [38912 2010-11-20] (Microsoft Corporation) [File not signed] R1 CSC; D:\Windows\System32\drivers\csc.sys [514560 2010-11-20] (Microsoft Corporation) [File not signed] R1 DfsC; D:\Windows\System32\Drivers\dfsc.sys [102400 2010-11-20] (Microsoft Corporation) [File not signed] R1 discache; D:\Windows\System32\drivers\discache.sys [40448 2009-07-14] (Microsoft Corporation) [File not signed] S3 drmkaud; D:\Windows\system32\drivers\drmkaud.sys [5632 2009-07-14] (Microsoft Corporation) [File not signed] R1 dtsoftbus01; D:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-08] (Disc Soft Ltd) S3 ebdrv; D:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) [File not signed] S3 ErrDev; D:\Windows\system32\drivers\errdev.sys [9728 2009-07-14] (Microsoft Corporation) [File not signed] S3 exfat; D:\Windows\System32\Drivers\exfat.sys [195072 2009-07-14] (Microsoft Corporation) [File not signed] S3 fastfat; D:\Windows\System32\Drivers\fastfat.sys [204800 2009-07-14] (Microsoft Corporation) [File not signed] S3 fdc; D:\Windows\system32\DRIVERS\fdc.sys [29696 2009-07-14] (Microsoft Corporation) [File not signed] S3 Filetrace; D:\Windows\System32\drivers\filetrace.sys [34304 2009-07-14] (Microsoft Corporation) [File not signed] S3 flpydisk; D:\Windows\system32\DRIVERS\flpydisk.sys [24576 2009-07-14] (Microsoft Corporation) [File not signed] S1 GLogin; No ImagePath R0 gzflt; D:\Windows\System32\DRIVERS\gzflt.sys [160544 2015-04-30] (BitDefender LLC) S3 hcw85cir; D:\Windows\system32\drivers\hcw85cir.sys [31232 2009-06-10] (Hauppauge Computer Works, Inc.) [File not signed] S3 HdAudAddService; D:\Windows\System32\drivers\HdAudio.sys [350208 2010-11-20] (Microsoft Corporation) [File not signed] R3 HDAudBus; D:\Windows\system32\drivers\HDAudBus.sys [122368 2010-11-20] (Microsoft Corporation) [File not signed] S3 HidBatt; D:\Windows\system32\DRIVERS\HidBatt.sys [26624 2009-07-14] (Microsoft Corporation) [File not signed] S3 HidBth; D:\Windows\system32\DRIVERS\hidbth.sys [100864 2009-07-14] (Microsoft Corporation) [File not signed] S3 HidIr; D:\Windows\system32\DRIVERS\hidir.sys [46592 2009-07-14] (Microsoft Corporation) [File not signed] R3 HidUsb; D:\Windows\system32\drivers\hidusb.sys [30208 2010-11-20] (Microsoft Corporation) [File not signed] S3 HTCAND64; D:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed] R3 HTTP; D:\Windows\System32\drivers\HTTP.sys [753664 2010-11-20] (Microsoft Corporation) [File not signed] R1 HWiNFO32; D:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2013-12-27] (REALiX(tm)) S3 i8042prt; D:\Windows\system32\drivers\i8042prt.sys [105472 2009-07-14] (Microsoft Corporation) [File not signed] S3 intelppm; D:\Windows\system32\DRIVERS\intelppm.sys [62464 2009-07-14] (Microsoft Corporation) [File not signed] S3 IpFilterDriver; D:\Windows\System32\DRIVERS\ipfltdrv.sys [82944 2010-11-20] (Microsoft Corporation) [File not signed] S3 IPMIDRV; D:\Windows\system32\drivers\IPMIDrv.sys [78848 2010-11-20] (Microsoft Corporation) [File not signed] S3 IPNAT; D:\Windows\System32\drivers\ipnat.sys [116224 2009-07-14] (Microsoft Corporation) [File not signed] S3 IRENUM; D:\Windows\System32\drivers\irenum.sys [17920 2009-07-14] (Microsoft Corporation) [File not signed] R3 kbdhid; D:\Windows\System32\DRIVERS\kbdhid.sys [33280 2010-11-20] (Microsoft Corporation) [File not signed] R3 ksthunk; D:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-14] (Microsoft Corporation) [File not signed] R2 lltdio; D:\Windows\System32\DRIVERS\lltdio.sys [60928 2009-07-14] (Microsoft Corporation) [File not signed] R2 luafv; D:\Windows\system32\drivers\luafv.sys [113152 2009-07-14] (Microsoft Corporation) [File not signed] S3 Modem; D:\Windows\System32\drivers\modem.sys [40448 2009-07-14] (Microsoft Corporation) [File not signed] R3 monitor; D:\Windows\System32\DRIVERS\monitor.sys [30208 2009-07-14] (Microsoft Corporation) [File not signed] R3 mouhid; D:\Windows\System32\DRIVERS\mouhid.sys [31232 2009-07-14] (Microsoft Corporation) [File not signed] R3 mpsdrv; D:\Windows\System32\drivers\mpsdrv.sys [77312 2009-07-14] (Microsoft Corporation) [File not signed] S3 MRxDAV; D:\Windows\system32\drivers\mrxdav.sys [141312 2014-12-19] (Microsoft Corporation) [File not signed] R3 mrxsmb; D:\Windows\System32\DRIVERS\mrxsmb.sys [158208 2011-04-27] (Microsoft Corporation) [File not signed] R3 mrxsmb10; D:\Windows\System32\DRIVERS\mrxsmb10.sys [288768 2011-07-09] (Microsoft Corporation) [File not signed] R3 mrxsmb20; D:\Windows\System32\DRIVERS\mrxsmb20.sys [128000 2011-04-27] (Microsoft Corporation) [File not signed] S3 mshidkmdf; D:\Windows\System32\drivers\mshidkmdf.sys [8192 2009-07-14] (Microsoft Corporation) [File not signed] S3 MSKSSRV; D:\Windows\System32\drivers\MSKSSRV.sys [11136 2009-07-14] (Microsoft Corporation) [File not signed] S3 MSPCLOCK; D:\Windows\System32\drivers\MSPCLOCK.sys [7168 2009-07-14] (Microsoft Corporation) [File not signed] S3 MSPQM; D:\Windows\System32\drivers\MSPQM.sys [6784 2009-07-14] (Microsoft Corporation) [File not signed] S3 MSTEE; D:\Windows\System32\drivers\MSTEE.sys [8064 2009-07-14] (Microsoft Corporation) [File not signed] S3 MTConfig; D:\Windows\system32\DRIVERS\MTConfig.sys [15360 2009-07-14] (Microsoft Corporation) [File not signed] R3 NativeWifiP; D:\Windows\System32\DRIVERS\nwifi.sys [318976 2009-07-14] (Microsoft Corporation) [File not signed] S3 NdisCap; D:\Windows\System32\DRIVERS\ndiscap.sys [35328 2009-07-14] (Microsoft Corporation) [File not signed] R3 NdisTapi; D:\Windows\System32\DRIVERS\ndistapi.sys [24064 2009-07-14] (Microsoft Corporation) [File not signed] R3 Ndisuio; D:\Windows\System32\DRIVERS\ndisuio.sys [56832 2010-11-20] (Microsoft Corporation) [File not signed] R3 NdisWan; D:\Windows\System32\DRIVERS\ndiswan.sys [164352 2010-11-20] (Microsoft Corporation) [File not signed] R1 NetBIOS; D:\Windows\System32\DRIVERS\netbios.sys [44544 2009-07-14] (Microsoft Corporation) [File not signed] R1 NetBT; D:\Windows\System32\DRIVERS\netbt.sys [261632 2010-11-20] (Microsoft Corporation) [File not signed] R1 nsiproxy; D:\Windows\System32\drivers\nsiproxy.sys [24576 2009-07-14] (Microsoft Corporation) [File not signed] S3 NTIOLib_1_0_6; D:\Program Files (x86)\Setup Files\Ms7597v1A0\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed] R1 Null; D:\Windows\System32\Drivers\Null.sys [6144 2009-07-14] (Microsoft Corporation) [File not signed] S3 NVENETFD; D:\Windows\System32\DRIVERS\nvm62x64.sys [408960 2009-06-10] (NVIDIA Corporation) [File not signed] S3 ohci1394; D:\Windows\system32\drivers\ohci1394.sys [72832 2009-07-14] (Microsoft Corporation) [File not signed] R3 Parport; D:\Windows\System32\DRIVERS\parport.sys [97280 2009-07-14] (Microsoft Corporation) [File not signed] R2 PEAUTH; D:\Windows\System32\drivers\peauth.sys [651264 2009-07-14] (Microsoft Corporation) [File not signed] R3 PptpMiniport; D:\Windows\System32\DRIVERS\raspptp.sys [111104 2010-11-20] (Microsoft Corporation) [File not signed] S3 Processor; D:\Windows\system32\DRIVERS\processr.sys [60416 2009-07-14] (Microsoft Corporation) [File not signed] R1 Psched; D:\Windows\System32\DRIVERS\pacer.sys [131584 2010-11-20] (Microsoft Corporation) [File not signed] S3 QWAVEdrv; D:\Windows\system32\drivers\qwavedrv.sys [46592 2009-07-14] (Microsoft Corporation) [File not signed] S3 RasAcd; D:\Windows\System32\DRIVERS\rasacd.sys [14848 2009-07-14] (Microsoft Corporation) [File not signed] R3 RasAgileVpn; D:\Windows\System32\DRIVERS\AgileVpn.sys [60416 2009-07-14] (Microsoft Corporation) [File not signed] R3 Rasl2tp; D:\Windows\System32\DRIVERS\rasl2tp.sys [129536 2010-11-20] (Microsoft Corporation) [File not signed] R3 RasPppoe; D:\Windows\System32\DRIVERS\raspppoe.sys [92672 2009-07-14] (Microsoft Corporation) [File not signed] R3 RasSstp; D:\Windows\System32\DRIVERS\rassstp.sys [83968 2009-07-14] (Microsoft Corporation) [File not signed] R1 rdbss; D:\Windows\System32\DRIVERS\rdbss.sys [309248 2010-11-20] (Microsoft Corporation) [File not signed] R3 rdpbus; D:\Windows\System32\DRIVERS\rdpbus.sys [24064 2009-07-14] (Microsoft Corporation) [File not signed] R1 RDPCDD; D:\Windows\System32\DRIVERS\RDPCDD.sys [7680 2009-07-14] (Microsoft Corporation) [File not signed] S3 RDPDR; D:\Windows\System32\drivers\rdpdr.sys [165888 2010-11-20] (Microsoft Corporation) [File not signed] R1 RDPENCDD; D:\Windows\System32\drivers\rdpencdd.sys [7680 2009-07-14] (Microsoft Corporation) [File not signed] R1 RDPREFMP; D:\Windows\System32\drivers\rdprefmp.sys [8192 2009-07-14] (Microsoft Corporation) [File not signed] S3 RdpVideoMiniport; D:\Windows\System32\drivers\rdpvideominiport.sys [20992 2010-11-20] (Microsoft Corporation) [File not signed] R2 rspndr; D:\Windows\System32\DRIVERS\rspndr.sys [76800 2009-07-14] (Microsoft Corporation) [File not signed] S3 s0017bus; D:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation) S3 s0017mdfl; D:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation) S3 s0017mdm; D:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation) S3 s0017mgmt; D:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation) S3 s0017nd5; D:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation) S3 s0017obex; D:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation) S3 s0017unic; D:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation) S3 s3017bus; D:\Windows\System32\DRIVERS\s3017bus.sys [109096 2007-12-10] (MCCI Corporation) S3 s3017mdfl; D:\Windows\System32\DRIVERS\s3017mdfl.sys [19496 2007-12-10] (MCCI Corporation) S3 s3017mdm; D:\Windows\System32\DRIVERS\s3017mdm.sys [146984 2007-12-10] (MCCI Corporation) S3 s3017mgmt; D:\Windows\System32\DRIVERS\s3017mgmt.sys [130600 2007-12-10] (MCCI Corporation) S3 s3017nd5; D:\Windows\System32\DRIVERS\s3017nd5.sys [34344 2007-12-10] (MCCI Corporation) S3 s3017obex; D:\Windows\System32\DRIVERS\s3017obex.sys [125480 2007-12-10] (MCCI Corporation) S3 s3017unic; D:\Windows\System32\DRIVERS\s3017unic.sys [144936 2007-12-10] (MCCI Corporation) S3 s3cap; D:\Windows\system32\drivers\vms3cap.sys [6656 2010-11-20] (Microsoft Corporation) [File not signed] R3 SbieDrv; D:\Program Files\Sandboxie\SbieDrv.sys [237064 2015-02-18] (Sandboxie Holdings, LLC) S3 scfilter; D:\Windows\System32\DRIVERS\scfilter.sys [29696 2010-11-20] (Microsoft Corporation) [File not signed] R3 seehcri; D:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications) [File not signed] R3 Serenum; D:\Windows\System32\DRIVERS\serenum.sys [23552 2009-07-14] (Microsoft Corporation) [File not signed] R1 Serial; D:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Microsoft Corporation) [File not signed] S3 sermouse; D:\Windows\system32\DRIVERS\sermouse.sys [26624 2009-07-14] (Microsoft Corporation) [File not signed] S3 sffdisk; D:\Windows\system32\drivers\sffdisk.sys [14336 2009-07-14] (Microsoft Corporation) [File not signed] S3 sffp_mmc; D:\Windows\system32\drivers\sffp_mmc.sys [13824 2009-07-14] (Microsoft Corporation) [File not signed] S3 sffp_sd; D:\Windows\system32\drivers\sffp_sd.sys [14336 2010-11-20] (Microsoft Corporation) [File not signed] S3 sfloppy; D:\Windows\system32\DRIVERS\sfloppy.sys [16896 2009-07-14] (Microsoft Corporation) [File not signed] S3 Smb; D:\Windows\System32\DRIVERS\smb.sys [93184 2009-07-14] (Microsoft Corporation) [File not signed] R3 srv; D:\Windows\System32\DRIVERS\srv.sys [467456 2011-04-29] (Microsoft Corporation) [File not signed] R3 srv2; D:\Windows\System32\DRIVERS\srv2.sys [410112 2011-04-29] (Microsoft Corporation) [File not signed] R3 srvnet; D:\Windows\System32\DRIVERS\srvnet.sys [168448 2011-04-29] (Microsoft Corporation) [File not signed] R3 StillCam; D:\Windows\system32\drivers\serscan.sys [12288 2009-07-14] (Microsoft Corporation) [File not signed] R2 tcpipreg; D:\Windows\System32\drivers\tcpipreg.sys [45568 2012-10-03] (Microsoft Corporation) [File not signed] S3 TDPIPE; D:\Windows\System32\drivers\tdpipe.sys [15872 2009-07-14] (Microsoft Corporation) [File not signed] S3 TDTCP; D:\Windows\System32\drivers\tdtcp.sys [23552 2012-02-17] (Microsoft Corporation) [File not signed] R1 tdx; D:\Windows\System32\DRIVERS\tdx.sys [119296 2014-11-11] (Microsoft Corporation) [File not signed] R0 trufos; D:\Windows\System32\DRIVERS\trufos.sys [452040 2014-10-15] (BitDefender S.R.L.) S3 tssecsrv; D:\Windows\System32\DRIVERS\tssecsrv.sys [39936 2013-06-15] (Microsoft Corporation) [File not signed] S3 TsUsbFlt; D:\Windows\System32\drivers\tsusbflt.sys [59392 2010-11-20] (Microsoft Corporation) [File not signed] R3 tunnel; D:\Windows\System32\DRIVERS\tunnel.sys [125440 2010-11-20] (Microsoft Corporation) [File not signed] S4 udfs; D:\Windows\System32\DRIVERS\udfs.sys [328192 2010-11-20] (Microsoft Corporation) [File not signed] R3 umbus; D:\Windows\System32\DRIVERS\umbus.sys [48640 2010-11-20] (Microsoft Corporation) [File not signed] S3 UmPass; D:\Windows\system32\DRIVERS\umpass.sys [9728 2009-07-14] (Microsoft Corporation) [File not signed] R3 usbaudio; D:\Windows\system32\drivers\usbaudio.sys [109824 2013-07-12] (Microsoft Corporation) [File not signed] R3 usbccgp; D:\Windows\System32\DRIVERS\usbccgp.sys [99840 2013-11-27] (Microsoft Corporation) [File not signed] S3 usbcir; D:\Windows\system32\drivers\usbcir.sys [100864 2013-07-12] (Microsoft Corporation) [File not signed] R3 usbehci; D:\Windows\System32\DRIVERS\usbehci.sys [53248 2013-11-27] (Microsoft Corporation) [File not signed] R3 usbhub; D:\Windows\system32\drivers\usbhub.sys [343040 2013-11-27] (Microsoft Corporation) [File not signed] R3 usbohci; D:\Windows\System32\DRIVERS\usbohci.sys [25600 2013-11-27] (Microsoft Corporation) [File not signed] S3 usbprint; D:\Windows\System32\DRIVERS\usbprint.sys [25088 2009-07-14] (Microsoft Corporation) [File not signed] S3 usbser; D:\Windows\System32\drivers\usbser.sys [32768 2010-11-20] (Microsoft Corporation) [File not signed] S3 USBSTOR; D:\Windows\System32\DRIVERS\USBSTOR.SYS [91648 2011-03-11] (Microsoft Corporation) [File not signed] S3 usbuhci; D:\Windows\system32\drivers\usbuhci.sys [30720 2013-11-27] (Microsoft Corporation) [File not signed] S3 usbvideo; D:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation) [File not signed] S3 usb_rndisx; D:\Windows\System32\DRIVERS\usb8023x.sys [19968 2013-02-12] (Microsoft Corporation) [File not signed] S3 vga; D:\Windows\System32\DRIVERS\vgapnp.sys [29184 2009-07-14] (Microsoft Corporation) [File not signed] R1 VgaSave; D:\Windows\System32\drivers\vga.sys [29184 2009-07-14] (Microsoft Corporation) [File not signed] S3 VMBusHID; D:\Windows\system32\drivers\VMBusHID.sys [21760 2010-11-20] (Microsoft Corporation) [File not signed] R3 vwifibus; D:\Windows\System32\DRIVERS\vwifibus.sys [24576 2009-07-14] (Microsoft Corporation) [File not signed] R1 vwififlt; D:\Windows\System32\DRIVERS\vwififlt.sys [59904 2009-07-14] (Microsoft Corporation) [File not signed] R3 vwifimp; D:\Windows\System32\DRIVERS\vwifimp.sys [17920 2009-07-14] (Microsoft Corporation) [File not signed] S3 WacomPen; D:\Windows\system32\DRIVERS\wacompen.sys [27776 2009-07-14] (Microsoft Corporation) [File not signed] S3 WANARP; D:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-20] (Microsoft Corporation) [File not signed] R1 Wanarpv6; D:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-20] (Microsoft Corporation) [File not signed] R1 WfpLwf; D:\Windows\System32\DRIVERS\wfplwf.sys [12800 2009-07-14] (Microsoft Corporation) [File not signed] S3 WINUSB; D:\Windows\System32\DRIVERS\WinUsb.sys [41984 2010-11-20] (Microsoft Corporation) [File not signed] S3 WmiAcpi; D:\Windows\system32\drivers\wmiacpi.sys [14336 2009-07-14] (Microsoft Corporation) [File not signed] S4 ws2ifsl; D:\Windows\system32\drivers\ws2ifsl.sys [21504 2009-07-14] (Microsoft Corporation) [File not signed] S3 WudfPf; D:\Windows\System32\drivers\WudfPf.sys [87040 2012-07-26] (Microsoft Corporation) [File not signed] S3 WUDFRd; D:\Windows\System32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) [File not signed] S3 clwvd; system32\DRIVERS\clwvd.sys [X] S3 EraserUtilDrv11220; \??\D:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [X] S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X] S3 MSI_MSIBIOS_010507; \??\D:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X] S3 NTIOLib_1_0_4; \??\D:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] S3 Prot6Flt; system32\DRIVERS\Prot6Flt.sys [X] U0 SR; No ImagePath U2 SRService; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-12 10:45 - 2015-05-12 10:48 - 00057307 _____ () D:\Users\Grzegorz\Downloads\FRST.txt 2015-05-12 10:40 - 2015-05-12 10:40 - 02102784 _____ (Farbar) D:\Users\Grzegorz\Downloads\FRST64.exe 2015-05-12 10:33 - 2015-05-12 10:33 - 00007698 _____ () D:\Users\Public\DECRYPT_INSTRUCTIONS.html 2015-05-12 10:33 - 2015-05-12 10:33 - 00007698 _____ () D:\Users\Grzegorz\Downloads\DECRYPT_INSTRUCTIONS.html 2015-05-12 10:33 - 2015-05-12 10:33 - 00007698 _____ () D:\Users\Grzegorz\Documents\DECRYPT_INSTRUCTIONS.html 2015-05-12 10:33 - 2015-05-12 10:33 - 00003203 _____ () D:\Users\Public\DECRYPT_INSTRUCTIONS.txt 2015-05-12 10:33 - 2015-05-12 10:33 - 00003203 _____ () D:\Users\Grzegorz\Downloads\DECRYPT_INSTRUCTIONS.txt 2015-05-12 10:33 - 2015-05-12 10:33 - 00003203 _____ () D:\Users\Grzegorz\Documents\DECRYPT_INSTRUCTIONS.txt 2015-05-12 10:30 - 2015-05-12 10:30 - 00007698 _____ () D:\Users\Grzegorz\AppData\DECRYPT_INSTRUCTIONS.html 2015-05-12 10:30 - 2015-05-12 10:30 - 00003203 _____ () D:\Users\Grzegorz\AppData\DECRYPT_INSTRUCTIONS.txt 2015-05-12 09:34 - 2015-05-12 09:34 - 00007698 _____ () D:\Users\Grzegorz\Desktop\DECRYPT_INSTRUCTIONS.html 2015-05-12 09:34 - 2015-05-12 09:34 - 00003203 _____ () D:\Users\Grzegorz\Desktop\DECRYPT_INSTRUCTIONS.txt 2015-05-12 09:33 - 2015-05-12 10:00 - 00000000 ____D () D:\ProgramData\abekelataheficij 2015-05-12 09:33 - 2015-05-12 09:33 - 00280618 _____ () D:\ProgramData\exoqokut.exe 2015-05-12 09:26 - 2015-05-12 09:26 - 00002740 _____ () D:\Windows\System32\Tasks\AutoKMSDaily 2015-05-03 08:38 - 2015-05-12 09:26 - 00010791 _____ () D:\Windows\AutoKMS.log 2015-05-02 22:22 - 2015-05-12 09:23 - 00154840 _____ () D:\Windows\setupact.log 2015-05-02 22:22 - 2015-05-02 22:22 - 00000000 _____ () D:\Windows\setuperr.log 2015-04-30 12:03 - 2015-04-30 12:03 - 00160544 _____ (BitDefender LLC) D:\Windows\system32\Drivers\gzflt.sys 2015-04-30 12:03 - 2015-04-30 12:03 - 00082824 _____ (BitDefender SRL) D:\Windows\system32\Drivers\bdsandbox.sys 2015-04-30 12:03 - 2015-04-30 12:03 - 00076944 _____ (BitDefender) D:\Windows\system32\Drivers\bdvedisk.sys 2015-04-30 11:34 - 2015-04-30 11:34 - 00668097 _____ () D:\ProgramData\1430385785.bdinstall.bin 2015-04-30 11:33 - 2015-04-30 11:33 - 00000684 ____H () D:\bdr-cf01 2015-04-30 11:32 - 2015-04-30 12:03 - 01306464 _____ (BitDefender) D:\Windows\system32\Drivers\avc3.sys 2015-04-30 11:32 - 2015-04-30 12:03 - 00677104 _____ (BitDefender) D:\Windows\system32\Drivers\avckf.sys 2015-04-30 11:32 - 2015-04-30 12:03 - 00262544 _____ (BitDefender) D:\Windows\system32\Drivers\avchv.sys 2015-04-30 11:32 - 2015-04-30 11:32 - 00002122 _____ () D:\Users\Public\Desktop\Bitdefender Internet Security 2015.lnk 2015-04-30 11:32 - 2015-04-30 11:32 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015 2015-04-30 11:32 - 2013-11-13 15:41 - 00093600 _____ (BitDefender LLC) D:\Windows\system32\Drivers\BdfNdisf6.sys 2015-04-30 11:26 - 2015-04-30 11:38 - 00000000 ____D () D:\Users\Grzegorz\AppData\Roaming\Bitdefender 2015-04-30 11:26 - 2015-04-30 11:33 - 00253404 ____H () D:\bdr-ld01 2015-04-30 11:26 - 2015-04-30 11:33 - 00009216 ____H () D:\bdr-ld01.mbr 2015-04-30 11:26 - 2014-07-04 17:49 - 49563064 ____H () D:\bdr-im01.gz 2015-04-30 11:26 - 2013-08-13 13:38 - 03271472 ____H () D:\bdr-bz01 2015-04-30 11:23 - 2014-10-15 17:14 - 00452040 _____ (BitDefender S.R.L.) D:\Windows\system32\Drivers\trufos.sys 2015-04-30 11:13 - 2015-04-30 11:22 - 378343192 _____ () D:\Users\Grzegorz\Downloads\BDIS_x64.exe 2015-04-27 17:50 - 2015-05-12 09:34 - 52390564 _____ () D:\Users\Grzegorz\Desktop\MOV_0145.mp4.encrypted 2015-04-24 12:11 - 2015-04-24 12:11 - 06484352 _____ (Piriform Ltd) D:\Users\Grzegorz\Downloads\ccsetup505.exe 2015-04-24 11:29 - 2015-04-24 11:29 - 00000000 ____D () D:\Program Files (x86)\Mozilla Firefox 2015-04-23 11:49 - 2015-04-23 11:49 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2015-04-19 13:07 - 2015-04-19 13:07 - 03109248 _____ (Enigma Software Group USA, LLC.) D:\Users\Grzegorz\Downloads\SpyHunter-Installer.exe 2015-04-19 12:43 - 2015-04-19 12:44 - 02797948 _____ () D:\Users\Grzegorz\Downloads\RemoveWAT 2.2.exe 2015-04-15 20:33 - 2015-04-15 20:33 - 18178736 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-04-14 21:52 - 2015-04-14 21:55 - 00000000 ____D () D:\ProgramData\{a479e98a-190a-2b2c-a479-9e98a190a628} 2015-04-14 21:46 - 2015-05-12 09:26 - 00078848 _____ () D:\Windows\KMSEmulator.exe 2015-04-14 21:46 - 2015-05-12 09:26 - 00000206 _____ () D:\Windows\Tasks\AutoKMS.job 2015-04-14 21:46 - 2015-05-12 09:26 - 00000202 _____ () D:\Windows\Tasks\AutoKMSDaily.job 2015-04-14 21:46 - 2015-04-14 21:46 - 00647168 _____ () D:\Windows\AutoKMS.exe 2015-04-14 21:46 - 2015-04-14 21:46 - 00002438 _____ () D:\Windows\System32\Tasks\AutoKMS 2015-04-14 21:46 - 2015-04-14 21:46 - 00000184 _____ () D:\Windows\AutoKMS.ini 2015-04-14 21:31 - 2015-04-14 21:31 - 00000000 ____D () D:\Program Files (x86)\Windows Loader 2015-04-14 10:20 - 2015-04-14 10:29 - 00000000 ____D () D:\ProgramData\{808801f6-940f-1c0f-8088-801f694007da} ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-12 10:46 - 2014-12-04 10:58 - 00000000 ____D () D:\FRST 2015-05-12 10:35 - 2012-12-11 11:47 - 01532941 _____ () D:\Windows\WindowsUpdate.log 2015-05-12 10:33 - 2015-02-25 18:52 - 00484246 _____ () D:\Users\Grzegorz\Documents\Scan0002.pdf.encrypted 2015-05-12 10:33 - 2015-01-22 17:48 - 00714243 _____ () D:\Users\Grzegorz\Downloads\kasiulao9_cv.pdf.encrypted 2015-05-12 10:33 - 2015-01-12 18:11 - 00008977 _____ () D:\Users\Grzegorz\Documents\PODn.pdf.encrypted 2015-05-12 10:33 - 2015-01-07 14:01 - 00030214 _____ () D:\Users\Grzegorz\Downloads\CVdopracy.pl - Klasyczny - wzór drugi.docx.encrypted 2015-05-12 10:33 - 2014-12-22 15:06 - 00369789 _____ () D:\Users\Grzegorz\Documents\polisa.pdf.encrypted 2015-05-12 10:33 - 2014-12-22 15:05 - 00370190 _____ () D:\Users\Grzegorz\Documents\Scan0001.pdf.encrypted 2015-05-12 10:33 - 2014-12-01 10:23 - 00120955 _____ () D:\Users\Grzegorz\Downloads\Wydruk.pdf.encrypted 2015-05-12 10:33 - 2014-10-30 10:27 - 00008328 _____ () D:\Users\Grzegorz\Downloads\potwierdzenie_wysłania_dokumentu_rejestracjizgłoszenia_do_re.zip.encrypted 2015-05-12 10:33 - 2014-10-05 16:30 - 00016411 _____ () D:\Users\Grzegorz\Documents\On Saturday.docx.encrypted 2015-05-12 10:33 - 2014-09-21 13:45 - 00015276 _____ () D:\Users\Grzegorz\Documents\Tuja brabant.docx.encrypted 2015-05-12 10:33 - 2014-09-21 13:33 - 00013957 _____ () D:\Users\Grzegorz\Documents\Wrotycz pospolity.docx.encrypted 2015-05-12 10:33 - 2014-09-17 16:19 - 00865799 _____ () D:\Users\Grzegorz\Documents\paryż.docx.encrypted 2015-05-12 10:33 - 2014-09-17 07:13 - 00013507 _____ () D:\Users\Grzegorz\Documents\Upoważniam córkę Monikę Ochwat do wybrania syna Arkadiusza Ochwat z przedszkola w dniu 17.docx.encrypted 2015-05-12 10:33 - 2014-09-16 18:21 - 00013924 _____ () D:\Users\Grzegorz\Documents\Orzech włoski.docx.encrypted 2015-05-12 10:33 - 2014-09-09 10:08 - 00111650 _____ () D:\Users\Grzegorz\Downloads\Wielkie Żarcie - Przepis - Piersi z kurczaka a la strogonow.htm.encrypted 2015-05-12 10:33 - 2014-09-09 10:08 - 00000000 ____D () D:\Users\Grzegorz\Downloads\Wielkie Żarcie - Przepis - Piersi z kurczaka a la strogonow_pliki 2015-05-12 10:33 - 2014-09-02 20:53 - 00014331 _____ () D:\Users\Grzegorz\Documents\Sosna zwyczajna.docx.encrypted 2015-05-12 10:33 - 2014-09-02 20:53 - 00013987 _____ () D:\Users\Grzegorz\Documents\Świerk pospolity.docx.encrypted 2015-05-12 10:33 - 2014-09-02 20:52 - 00014315 _____ () D:\Users\Grzegorz\Documents\Świerk srebrny.docx.encrypted 2015-05-12 10:33 - 2014-09-02 11:14 - 00014283 _____ () D:\Users\Grzegorz\Documents\wniosek do starostwa Jasło.docx.encrypted 2015-05-12 10:33 - 2014-08-18 09:00 - 00004231 _____ () D:\Users\Grzegorz\Downloads\Dotpay - Bezpieczne transakcje internetowe.htm.encrypted 2015-05-12 10:33 - 2014-08-18 09:00 - 00000000 ____D () D:\Users\Grzegorz\Downloads\Dotpay - Bezpieczne transakcje internetowe_pliki 2015-05-12 10:33 - 2014-06-12 17:54 - 00028776 _____ () D:\Users\Grzegorz\Documents\Wpisz brakujące litery.docx.encrypted 2015-05-12 10:33 - 2013-12-30 09:34 - 00106714 _____ () D:\Users\Grzegorz\Downloads\HistoriaOperacji_2013-12-30_08-34-07.pdf.encrypted 2015-05-12 10:33 - 2013-12-08 21:48 - 00000000 ____D () D:\Users\Grzegorz\Downloads\Bitdefender Safepay 2015-05-12 10:33 - 2013-12-03 18:44 - 08025651 _____ () D:\Users\Grzegorz\Documents\Ptaki- prezentacja.pptx.encrypted 2015-05-12 10:33 - 2013-12-03 18:38 - 02117713 _____ () D:\Users\Grzegorz\Documents\Zima -2013.pptx.encrypted 2015-05-12 10:33 - 2013-12-03 15:53 - 01883419 _____ () D:\Users\Grzegorz\Documents\szadź.pptx.encrypted 2015-05-12 10:33 - 2013-12-02 16:19 - 00214450 _____ () D:\Users\Grzegorz\Documents\obuw3.jpg.encrypted 2015-05-12 10:33 - 2013-12-02 16:19 - 00154715 _____ () D:\Users\Grzegorz\Documents\obuw2.jpg.encrypted 2015-05-12 10:33 - 2013-12-02 16:18 - 00163647 _____ () D:\Users\Grzegorz\Documents\obuw1.jpg.encrypted 2015-05-12 10:33 - 2013-11-30 19:55 - 00121061 _____ () D:\Users\Grzegorz\Documents\rybki.jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:53 - 00133701 _____ () D:\Users\Grzegorz\Documents\swete.jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:52 - 00149034 _____ () D:\Users\Grzegorz\Documents\swet.jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:52 - 00114019 _____ () D:\Users\Grzegorz\Documents\żyrafa.jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:51 - 00098733 _____ () D:\Users\Grzegorz\Documents\paski.jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:48 - 00195028 _____ () D:\Users\Grzegorz\Documents\ogrod..jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:48 - 00172334 _____ () D:\Users\Grzegorz\Documents\ogrodniczki.jpg.encrypted 2015-05-12 10:33 - 2013-11-11 19:47 - 00163197 _____ () D:\Users\Grzegorz\Documents\spodnie z czerw.jpg.encrypted 2015-05-12 10:33 - 2013-11-09 21:59 - 00000000 ____D () D:\Users\Grzegorz\logi skanowania bitdefender 2015-05-12 10:33 - 2013-09-15 20:49 - 00015543 _____ () D:\Users\Grzegorz\Documents\plan zajec.docx.encrypted 2015-05-12 10:33 - 2013-08-26 14:47 - 00015516 _____ () D:\Users\Grzegorz\Documents\Pierogi z mięsem i kaszą inaczej.docx.encrypted 2015-05-12 10:33 - 2013-08-21 15:41 - 00087413 _____ () D:\Users\Grzegorz\Downloads\cv Kata..pdf.encrypted 2015-05-12 10:33 - 2013-08-21 14:38 - 00087751 _____ () D:\Users\Grzegorz\Downloads\cvGO.pdf.encrypted 2015-05-12 10:33 - 2013-08-14 13:08 - 00000000 ___SD () D:\Users\Grzegorz\GG dysk 2015-05-12 10:33 - 2013-07-15 11:14 - 00000776 _____ () D:\Users\Grzegorz\Downloads\hdsentinel.key.encrypted 2015-05-12 10:33 - 2013-06-07 13:58 - 00000426 ____H () D:\Users\Grzegorz\Documents\~$rriculum Vitae.odt.encrypted 2015-05-12 10:33 - 2013-05-05 14:55 - 00015252 _____ () D:\Users\Grzegorz\Documents\Twaróg z dodatkami.docx.encrypted 2015-05-12 10:33 - 2013-05-04 21:12 - 00013554 _____ () D:\Users\Grzegorz\Documents\Przepis na sałatkę owocową.docx.encrypted 2015-05-12 10:33 - 2013-05-04 20:21 - 00013319 _____ () D:\Users\Grzegorz\Documents\Przepis na zdrową kanapkę.docx.encrypted 2015-05-12 10:33 - 2013-05-04 18:16 - 00013583 _____ () D:\Users\Grzegorz\Documents\Przepis na serek biały z dodatkami.docx.encrypted 2015-05-12 10:33 - 2013-04-24 20:20 - 07160553 _____ () D:\Users\Grzegorz\Documents\ZOO KRAKÓ2.docx.encrypted 2015-05-12 10:33 - 2013-04-24 12:39 - 04634897 _____ () D:\Users\Grzegorz\Documents\ZOO KRAKÓ1.docx.encrypted 2015-05-12 10:33 - 2013-04-16 14:41 - 05266608 _____ () D:\Users\Grzegorz\Documents\ZOO KRAKÓW.docx.encrypted 2015-05-12 10:33 - 2013-03-20 16:50 - 00017889 _____ () D:\Users\Grzegorz\Documents\Park Narodowy Bory Tucholskie.docx.encrypted 2015-05-12 10:33 - 2013-03-20 16:50 - 00000426 ____H () D:\Users\Grzegorz\Documents\~$rk Narodowy Bory Tucholskie.docx.encrypted 2015-05-12 10:33 - 2013-03-14 19:41 - 00013661 _____ () D:\Users\Grzegorz\Documents\opowiadanie.docx.encrypted 2015-05-12 10:33 - 2013-03-08 21:32 - 00000000 ____D () D:\Users\Grzegorz\Documents\Nowy folder 2015-05-12 10:33 - 2013-02-27 12:30 - 00015911 _____ () D:\Users\Grzegorz\Documents\Ochwat Grzegorz.docx.encrypted 2015-05-12 10:33 - 2013-01-31 15:42 - 00063321 _____ () D:\Users\Grzegorz\Downloads\cv.pdf.encrypted 2015-05-12 10:33 - 2012-12-28 20:16 - 00081063 _____ () D:\Users\Grzegorz\Documents\załoncznik.jpg.encrypted 2015-05-12 10:33 - 2012-12-17 16:21 - 00013801 _____ () D:\Users\Grzegorz\Documents\Sałatka z tortellini mięsnym.docx.encrypted 2015-05-12 10:33 - 2012-11-11 15:48 - 24912369 _____ () D:\Users\Grzegorz\Downloads\fotki z nowego aparatu.rar.encrypted 2015-05-12 10:33 - 2012-11-08 13:48 - 00000426 ____H () D:\Users\Grzegorz\Documents\~$pn.docx.encrypted 2015-05-12 10:33 - 2012-11-07 14:20 - 00037260 _____ () D:\Users\Grzegorz\Documents\pn.docx.encrypted 2015-05-12 10:33 - 2012-11-03 18:26 - 00019783 _____ () D:\Users\Grzegorz\Documents\sienkiewicz.docx.encrypted 2015-05-12 10:33 - 2012-09-06 13:47 - 00000426 ____H () D:\Users\Grzegorz\Downloads\~$gulamin programu Atlantic SMS Club.doc.encrypted 2015-05-12 10:33 - 2012-08-18 17:37 - 20978611 _____ () D:\Users\Grzegorz\Downloads\fotki_z_Hiszpanii_cz_1.zip.encrypted 2015-05-12 10:33 - 2012-08-18 17:36 - 20971784 _____ () D:\Users\Grzegorz\Downloads\fotki.part1.rar.encrypted 2015-05-12 10:33 - 2012-04-07 20:56 - 00015189 _____ () D:\Users\Grzegorz\Documents\Sałatka z ryżem.docx.encrypted 2015-05-12 10:33 - 2012-04-02 14:04 - 00016358 _____ () D:\Users\Grzegorz\Documents\Przepisy marynaty.docx.encrypted 2015-05-12 10:33 - 2009-07-14 05:20 - 00000000 __RHD () D:\Users\Public\Libraries 2015-05-12 10:32 - 2015-01-22 17:38 - 00392020 _____ () D:\Users\Grzegorz\Documents\kasiulao9_cv.pdf.encrypted 2015-05-12 10:32 - 2015-01-22 09:35 - 00013380 _____ () D:\Users\Grzegorz\Documents\Grzegorz Ochwat Trzcinica 261.docx.encrypted 2015-05-12 10:32 - 2014-09-24 16:16 - 00014755 _____ () D:\Users\Grzegorz\Documents\Myślami przeniesę się dziś do najpiękniejszego miejsca na Ziemi są to Rafy Koralowe.docx.encrypted 2015-05-12 10:32 - 2014-09-21 13:52 - 00013809 _____ () D:\Users\Grzegorz\Documents\Lilak pospolity.docx.encrypted 2015-05-12 10:32 - 2014-09-16 18:32 - 00013488 _____ () D:\Users\Grzegorz\Documents\Nazwa łacińska.docx.encrypted 2015-05-12 10:32 - 2014-09-16 18:09 - 00013976 _____ () D:\Users\Grzegorz\Documents\Koniczyna biała.docx.encrypted 2015-05-12 10:32 - 2014-09-16 17:57 - 00013926 _____ () D:\Users\Grzegorz\Documents\Mniszek pospolity.docx.encrypted 2015-05-12 10:32 - 2014-09-16 17:48 - 00014144 _____ () D:\Users\Grzegorz\Documents\Leszczyna pospolita.docx.encrypted 2015-05-12 10:32 - 2014-09-16 17:35 - 00014274 _____ () D:\Users\Grzegorz\Documents\Grab pospolity.docx.encrypted 2015-05-12 10:32 - 2014-09-16 17:26 - 00014087 _____ () D:\Users\Grzegorz\Documents\Jodła pospolita.docx.encrypted 2015-05-12 10:32 - 2014-09-02 20:53 - 00014392 _____ () D:\Users\Grzegorz\Documents\Modrzew europejski.docx.encrypted 2015-05-12 10:32 - 2014-08-29 21:51 - 00060925 _____ () D:\Users\Grzegorz\Documents\Inne.docx.encrypted 2015-05-12 10:32 - 2014-08-29 21:49 - 00341380 _____ () D:\Users\Grzegorz\Documents\Krzewy.docx.encrypted 2015-05-12 10:32 - 2014-08-28 10:48 - 00015245 _____ () D:\Users\Grzegorz\Documents\Nazwa.docx.encrypted 2015-05-12 10:32 - 2013-12-02 16:18 - 00196015 _____ () D:\Users\Grzegorz\Documents\kurtn0.jpg.encrypted 2015-05-12 10:32 - 2013-12-02 16:17 - 00187747 _____ () D:\Users\Grzegorz\Documents\kurtk2.jpg.encrypted 2015-05-12 10:32 - 2013-12-02 16:16 - 00182747 _____ () D:\Users\Grzegorz\Documents\kurt1.jpg.encrypted 2015-05-12 10:32 - 2013-11-30 19:54 - 00093829 _____ () D:\Users\Grzegorz\Documents\kopar.jpg.encrypted 2015-05-12 10:32 - 2013-11-21 15:52 - 00142252 _____ () D:\Users\Grzegorz\Documents\kurtk1.jpg.encrypted 2015-05-12 10:32 - 2013-11-21 15:51 - 00135144 _____ () D:\Users\Grzegorz\Documents\kurt3.jpg.encrypted 2015-05-12 10:32 - 2013-11-21 15:50 - 00149601 _____ () D:\Users\Grzegorz\Documents\kurt2.jpg.encrypted 2015-05-12 10:32 - 2013-11-21 15:49 - 00225917 _____ () D:\Users\Grzegorz\Documents\kurtka1.jpg.encrypted 2015-05-12 10:32 - 2013-11-21 15:48 - 00226508 _____ () D:\Users\Grzegorz\Documents\komplet1.jpg.encrypted 2015-05-12 10:32 - 2013-11-21 15:47 - 00125973 _____ () D:\Users\Grzegorz\Documents\kompletm.jpg.encrypted 2015-05-12 10:32 - 2013-11-11 19:50 - 00179537 _____ () D:\Users\Grzegorz\Documents\koszula.jpg.encrypted 2015-05-12 10:32 - 2013-11-11 19:50 - 00164162 _____ () D:\Users\Grzegorz\Documents\kosz.jpg.encrypted 2015-05-12 10:32 - 2013-11-11 19:49 - 00093829 _____ () D:\Users\Grzegorz\Documents\kopara.jpg.encrypted 2015-05-12 10:32 - 2013-04-10 16:37 - 00016985 _____ () D:\Users\Grzegorz\Documents\Gdy bociany przylecą na wiosnę to składają jaja.docx.encrypted 2015-05-12 10:32 - 2013-03-08 21:35 - 00014251 _____ () D:\Users\Grzegorz\Documents\list motywacyjny..docx.encrypted 2015-05-12 10:32 - 2012-12-16 22:12 - 00016409 _____ () D:\Users\Grzegorz\Documents\Justyna Kowalczyk.docx.encrypted 2015-05-12 10:32 - 2012-12-15 12:31 - 00019314 _____ () D:\Users\Grzegorz\Documents\Justyna Kowalczyk mistrzyni i multimedalistka olimpijska.docx.encrypted 2015-05-12 10:32 - 2012-11-07 14:14 - 00613244 _____ () D:\Users\Grzegorz\Documents\nalka.docx.encrypted 2015-05-12 10:32 - 2012-10-23 14:15 - 00041453 _____ () D:\Users\Grzegorz\Documents\monikśka.docx.encrypted 2015-05-12 10:32 - 2012-10-23 14:15 - 00041448 _____ () D:\Users\Grzegorz\Documents\kjkjkkkkkkkk.docx.encrypted 2015-05-12 10:32 - 2012-10-23 13:27 - 00130812 _____ () D:\Users\Grzegorz\Documents\moje ulubione.docx.encrypted 2015-05-12 10:31 - 2014-09-02 17:53 - 00014560 _____ () D:\Users\Grzegorz\Documents\Dąb.docx.encrypted 2015-05-12 10:31 - 2014-08-01 13:28 - 03352689 _____ () D:\Users\Grzegorz\Documents\DSC04066.JPG.encrypted 2015-05-12 10:31 - 2014-08-01 13:28 - 03260108 _____ () D:\Users\Grzegorz\Documents\DSC04065.JPG.encrypted 2015-05-12 10:31 - 2014-01-21 13:08 - 03397880 _____ () D:\Users\Grzegorz\Documents\DSC04006.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:10 - 03297020 _____ () D:\Users\Grzegorz\Documents\DSC03956.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03323581 _____ () D:\Users\Grzegorz\Documents\DSC03963.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03312362 _____ () D:\Users\Grzegorz\Documents\DSC03964.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03301123 _____ () D:\Users\Grzegorz\Documents\DSC03962.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03268358 _____ () D:\Users\Grzegorz\Documents\DSC03966.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03247070 _____ () D:\Users\Grzegorz\Documents\DSC03957.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03198409 _____ () D:\Users\Grzegorz\Documents\DSC03965.JPG.encrypted 2015-05-12 10:31 - 2013-12-02 16:09 - 03175645 _____ () D:\Users\Grzegorz\Documents\DSC03958.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:41 - 03190263 _____ () D:\Users\Grzegorz\Documents\DSC03943.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:40 - 03196292 _____ () D:\Users\Grzegorz\Documents\DSC03952.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:40 - 03099137 _____ () D:\Users\Grzegorz\Documents\DSC03950.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:40 - 03047606 _____ () D:\Users\Grzegorz\Documents\DSC03951.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:39 - 03403927 _____ () D:\Users\Grzegorz\Documents\DSC03954.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:39 - 03201902 _____ () D:\Users\Grzegorz\Documents\DSC03955.JPG.encrypted 2015-05-12 10:31 - 2013-11-21 15:39 - 03141281 _____ () D:\Users\Grzegorz\Documents\DSC03953.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:51 - 00078310 _____ () D:\Users\Grzegorz\Documents\eleg.jpg.encrypted 2015-05-12 10:31 - 2013-11-11 19:43 - 03345660 _____ () D:\Users\Grzegorz\Documents\DSC03936.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:43 - 03323286 _____ () D:\Users\Grzegorz\Documents\DSC03930.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:43 - 03298325 _____ () D:\Users\Grzegorz\Documents\DSC03934.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:43 - 03209259 _____ () D:\Users\Grzegorz\Documents\DSC03935.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:43 - 03124633 _____ () D:\Users\Grzegorz\Documents\DSC03929.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:43 - 03104459 _____ () D:\Users\Grzegorz\Documents\DSC03931.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:42 - 03362406 _____ () D:\Users\Grzegorz\Documents\DSC03913.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:42 - 03288771 _____ () D:\Users\Grzegorz\Documents\DSC03914.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:42 - 03228545 _____ () D:\Users\Grzegorz\Documents\DSC03928.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:42 - 03191419 _____ () D:\Users\Grzegorz\Documents\DSC03912.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03328982 _____ () D:\Users\Grzegorz\Documents\DSC03918.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03310414 _____ () D:\Users\Grzegorz\Documents\DSC03919.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03294017 _____ () D:\Users\Grzegorz\Documents\DSC03916.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03293092 _____ () D:\Users\Grzegorz\Documents\DSC03915.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03250589 _____ () D:\Users\Grzegorz\Documents\DSC03917.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03240712 _____ () D:\Users\Grzegorz\Documents\DSC03922.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03164778 _____ () D:\Users\Grzegorz\Documents\DSC03920.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:41 - 03099349 _____ () D:\Users\Grzegorz\Documents\DSC03921.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:40 - 03304183 _____ () D:\Users\Grzegorz\Documents\DSC03927.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:40 - 03300347 _____ () D:\Users\Grzegorz\Documents\DSC03924.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:40 - 03271173 _____ () D:\Users\Grzegorz\Documents\DSC03925.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:40 - 03259442 _____ () D:\Users\Grzegorz\Documents\DSC03933.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:40 - 03143548 _____ () D:\Users\Grzegorz\Documents\DSC03926.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:40 - 03019511 _____ () D:\Users\Grzegorz\Documents\DSC03923.JPG.encrypted 2015-05-12 10:31 - 2013-11-11 19:39 - 03211457 _____ () D:\Users\Grzegorz\Documents\DSC03932.JPG.encrypted 2015-05-12 10:31 - 2013-05-06 10:46 - 03398972 _____ () D:\Users\Grzegorz\Documents\DSC03669.JPG.encrypted 2015-05-12 10:31 - 2013-05-06 10:46 - 03291751 _____ () D:\Users\Grzegorz\Documents\DSC03667.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:20 - 03355618 _____ () D:\Users\Grzegorz\Documents\DSC03664.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:20 - 03342913 _____ () D:\Users\Grzegorz\Documents\DSC03665.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03411953 _____ () D:\Users\Grzegorz\Documents\DSC03658.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03374294 _____ () D:\Users\Grzegorz\Documents\DSC03660.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03358927 _____ () D:\Users\Grzegorz\Documents\DSC03655.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03343366 _____ () D:\Users\Grzegorz\Documents\DSC03661.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03318593 _____ () D:\Users\Grzegorz\Documents\DSC03659.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03279764 _____ () D:\Users\Grzegorz\Documents\DSC03657.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:05 - 03212483 _____ () D:\Users\Grzegorz\Documents\DSC03656.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:04 - 03159425 _____ () D:\Users\Grzegorz\Documents\DSC03663.JPG.encrypted 2015-05-12 10:31 - 2013-04-30 11:04 - 03111421 _____ () D:\Users\Grzegorz\Documents\DSC03662.JPG.encrypted 2015-05-12 10:31 - 2013-04-16 09:50 - 03163440 _____ () D:\Users\Grzegorz\Documents\DSC03652.JPG.encrypted 2015-05-12 10:31 - 2013-04-16 09:50 - 03155662 _____ () D:\Users\Grzegorz\Documents\DSC03651.JPG.encrypted 2015-05-12 10:31 - 2013-04-16 09:50 - 03153587 _____ () D:\Users\Grzegorz\Documents\DSC03648.JPG.encrypted 2015-05-12 10:31 - 2013-04-16 09:50 - 03128757 _____ () D:\Users\Grzegorz\Documents\DSC03650.JPG.encrypted 2015-05-12 10:31 - 2013-04-16 09:50 - 03121845 _____ () D:\Users\Grzegorz\Documents\DSC03649.JPG.encrypted 2015-05-12 10:31 - 2013-04-16 09:49 - 03276332 _____ () D:\Users\Grzegorz\Documents\DSC03654.JPG.encrypted 2015-05-12 10:31 - 2013-03-20 15:24 - 03224979 _____ () D:\Users\Grzegorz\Documents\DSC03599.JPG.encrypted 2015-05-12 10:31 - 2013-03-20 15:24 - 03114012 _____ () D:\Users\Grzegorz\Documents\DSC03604.JPG.encrypted 2015-05-12 10:31 - 2013-03-20 15:24 - 03026483 _____ () D:\Users\Grzegorz\Documents\DSC03603.JPG.encrypted 2015-05-12 10:31 - 2013-03-20 15:24 - 03015633 _____ () D:\Users\Grzegorz\Documents\DSC03601.JPG.encrypted 2015-05-12 10:31 - 2013-03-20 15:24 - 03009614 _____ () D:\Users\Grzegorz\Documents\DSC03605.JPG.encrypted 2015-05-12 10:31 - 2013-03-20 15:24 - 02729729 _____ () D:\Users\Grzegorz\Documents\DSC03602.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:47 - 03303800 _____ () D:\Users\Grzegorz\Documents\DSC03592.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:46 - 03302369 _____ () D:\Users\Grzegorz\Documents\DSC03598.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:46 - 03283092 _____ () D:\Users\Grzegorz\Documents\DSC03594.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:46 - 03272272 _____ () D:\Users\Grzegorz\Documents\DSC03596.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:46 - 03199558 _____ () D:\Users\Grzegorz\Documents\DSC03597.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:46 - 03103055 _____ () D:\Users\Grzegorz\Documents\DSC03595.JPG.encrypted 2015-05-12 10:31 - 2013-03-15 12:46 - 03082641 _____ () D:\Users\Grzegorz\Documents\DSC03593.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:56 - 03392559 _____ () D:\Users\Grzegorz\Documents\DSC03580.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:56 - 03256193 _____ () D:\Users\Grzegorz\Documents\DSC03584.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:56 - 03231329 _____ () D:\Users\Grzegorz\Documents\DSC03582.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:56 - 03191326 _____ () D:\Users\Grzegorz\Documents\DSC03581.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:55 - 03399702 _____ () D:\Users\Grzegorz\Documents\DSC03587.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:55 - 03374688 _____ () D:\Users\Grzegorz\Documents\DSC03586.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:55 - 03204224 _____ () D:\Users\Grzegorz\Documents\DSC03585.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 19:55 - 03099263 _____ () D:\Users\Grzegorz\Documents\DSC03588.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 16:42 - 03191923 _____ () D:\Users\Grzegorz\Documents\DSC03576.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 16:42 - 03146504 _____ () D:\Users\Grzegorz\Documents\DSC03577.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 16:42 - 03063622 _____ () D:\Users\Grzegorz\Documents\DSC03579.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 16:41 - 03374946 _____ () D:\Users\Grzegorz\Documents\DSC03578.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:39 - 03054667 _____ () D:\Users\Grzegorz\Documents\DSC03537.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:39 - 03029568 _____ () D:\Users\Grzegorz\Documents\DSC03538.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 03191673 _____ () D:\Users\Grzegorz\Documents\DSC03565.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 03164501 _____ () D:\Users\Grzegorz\Documents\DSC03569.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 03145963 _____ () D:\Users\Grzegorz\Documents\DSC03564.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 03097680 _____ () D:\Users\Grzegorz\Documents\DSC03567.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 03094143 _____ () D:\Users\Grzegorz\Documents\DSC03568.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 03017092 _____ () D:\Users\Grzegorz\Documents\DSC03563.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:38 - 02939054 _____ () D:\Users\Grzegorz\Documents\DSC03566.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:37 - 03272373 _____ () D:\Users\Grzegorz\Documents\DSC03570.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:37 - 03270603 _____ () D:\Users\Grzegorz\Documents\DSC03575.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:37 - 02865200 _____ () D:\Users\Grzegorz\Documents\DSC03571.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:37 - 02821172 _____ () D:\Users\Grzegorz\Documents\DSC03573.JPG.encrypted 2015-05-12 10:31 - 2013-02-20 14:37 - 02771345 _____ () D:\Users\Grzegorz\Documents\DSC03572.JPG.encrypted 2015-05-12 10:31 - 2012-11-27 10:29 - 03353466 _____ () D:\Users\Grzegorz\Documents\DSC03534.JPG.encrypted 2015-05-12 10:31 - 2012-11-27 10:29 - 03247271 _____ () D:\Users\Grzegorz\Documents\DSC03533.JPG.encrypted 2015-05-12 10:31 - 2012-11-27 10:29 - 03021412 _____ () D:\Users\Grzegorz\Documents\DSC03532.JPG.encrypted 2015-05-12 10:31 - 2012-11-27 10:29 - 02894419 _____ () D:\Users\Grzegorz\Documents\DSC03535.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:28 - 03286549 _____ () D:\Users\Grzegorz\Documents\DSC03525.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:28 - 03272337 _____ () D:\Users\Grzegorz\Documents\DSC03523.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:28 - 03252039 _____ () D:\Users\Grzegorz\Documents\DSC03526.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:28 - 03213666 _____ () D:\Users\Grzegorz\Documents\DSC03524.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:27 - 03293339 _____ () D:\Users\Grzegorz\Documents\DSC03531.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:27 - 03090807 _____ () D:\Users\Grzegorz\Documents\DSC03529.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:27 - 02830506 _____ () D:\Users\Grzegorz\Documents\DSC03527.JPG.encrypted 2015-05-12 10:31 - 2012-11-26 14:27 - 02807081 _____ () D:\Users\Grzegorz\Documents\DSC03528.JPG.encrypted 2015-05-12 10:31 - 2012-11-12 18:34 - 03228100 _____ () D:\Users\Grzegorz\Documents\DSC03514.JPG.encrypted 2015-05-12 10:31 - 2012-10-24 10:09 - 00000000 ____D () D:\Users\Grzegorz\Documents\Faery - Legends of Avalon 2015-05-12 10:30 - 2014-09-21 14:03 - 00013889 _____ () D:\Users\Grzegorz\Documents\Bez czarny.docx.encrypted 2015-05-12 10:30 - 2014-09-16 18:04 - 00014034 _____ () D:\Users\Grzegorz\Documents\Bodziszek łąkowy.docx.encrypted 2015-05-12 10:30 - 2014-09-16 17:43 - 00015508 _____ () D:\Users\Grzegorz\Documents\Brzoza brodawkowata.docx.encrypted 2015-05-12 10:30 - 2014-08-29 21:53 - 00812597 _____ () D:\Users\Grzegorz\Documents\Dok5.docx.encrypted 2015-05-12 10:30 - 2014-08-29 21:49 - 00154592 _____ () D:\Users\Grzegorz\Documents\Drzewa.docx.encrypted 2015-05-12 10:30 - 2014-08-29 21:49 - 00082922 _____ () D:\Users\Grzegorz\Documents\Drzewa1.docx.encrypted 2015-05-12 10:30 - 2014-08-22 13:20 - 00013783 _____ () D:\Users\Grzegorz\Documents\Aktywacja pakietu Mobilka Family Flat.docx I NR KONTA.docx.encrypted 2015-05-12 10:30 - 2014-06-13 14:33 - 00230259 _____ () D:\Users\Grzegorz\Documents\Beschäftigungsnachweiß Katarzyna.jpg.encrypted 2015-05-12 10:30 - 2013-11-11 20:30 - 00153086 _____ () D:\Users\Grzegorz\Documents\dres2.jpg.encrypted 2015-05-12 10:30 - 2013-11-11 20:28 - 00125553 _____ () D:\Users\Grzegorz\Documents\dres1.jpg.encrypted 2015-05-12 10:30 - 2013-11-11 20:27 - 00146651 _____ () D:\Users\Grzegorz\Documents\dres.jpg.encrypted 2015-05-12 10:30 - 2013-11-11 19:49 - 00077411 _____ () D:\Users\Grzegorz\Documents\auto.jpg.encrypted 2015-05-12 10:30 - 2013-11-11 19:47 - 00082233 _____ () D:\Users\Grzegorz\Documents\body.jpg.encrypted 2015-05-12 10:30 - 2013-11-09 18:22 - 00000649 _____ () D:\Users\Grzegorz\AppData\Roaminguser_gensett.xml.encrypted 2015-05-12 10:30 - 2013-11-09 18:17 - 00000000 ____D () D:\Users\Grzegorz\AppData\Temp 2015-05-12 10:30 - 2013-08-25 12:50 - 00018778 _____ () D:\Users\Grzegorz\Documents\beton b15.docx.encrypted 2015-05-12 10:30 - 2013-08-14 21:49 - 00111989 _____ () D:\Users\Grzegorz\Documents\dane_Faktury7_2013-08-14.zip.encrypted 2015-05-12 10:30 - 2013-06-15 12:27 - 00017126 _____ () D:\Users\Grzegorz\Documents\Cudowna Podróż.docx.encrypted 2015-05-12 10:30 - 2013-04-24 11:40 - 00016343 _____ () D:\Users\Grzegorz\Documents\Droga Ziemio.docx.encrypted 2015-05-12 10:30 - 2013-03-08 20:35 - 00016530 _____ () D:\Users\Grzegorz\Documents\cv Katarzyna bez zdjęcia .docx.encrypted 2015-05-12 10:30 - 2013-02-19 20:33 - 00000000 ____D () D:\Users\Grzegorz\Documents\Ashampoo Home Designer Pro 2015-05-12 10:30 - 2013-01-22 11:31 - 00007710 _____ () D:\Users\Grzegorz\Documents\12222.odt.encrypted 2015-05-12 10:30 - 2012-12-28 19:54 - 00030672 _____ () D:\Users\Grzegorz\Documents\2013.jpg.encrypted 2015-05-12 10:30 - 2012-11-28 17:56 - 03449817 _____ () D:\Users\Grzegorz\Documents\DSC00499.JPG.encrypted 2015-05-12 10:30 - 2012-11-28 17:55 - 03224988 _____ () D:\Users\Grzegorz\Documents\DSC00497.JPG.encrypted 2015-05-12 10:30 - 2012-11-28 17:55 - 03051010 _____ () D:\Users\Grzegorz\Documents\DSC00498.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:34 - 03372094 _____ () D:\Users\Grzegorz\Documents\DSC03513.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:34 - 03203818 _____ () D:\Users\Grzegorz\Documents\DSC03510.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:34 - 03066842 _____ () D:\Users\Grzegorz\Documents\DSC03511.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:34 - 02962957 _____ () D:\Users\Grzegorz\Documents\DSC03512.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:17 - 03336384 _____ () D:\Users\Grzegorz\Documents\DSC03506.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:17 - 03327083 _____ () D:\Users\Grzegorz\Documents\DSC03508.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:17 - 03226411 _____ () D:\Users\Grzegorz\Documents\DSC03507.JPG.encrypted 2015-05-12 10:30 - 2012-11-12 18:17 - 03149373 _____ () D:\Users\Grzegorz\Documents\DSC03509.JPG.encrypted 2015-05-12 10:30 - 2012-10-26 17:28 - 00056849 _____ () D:\Users\Grzegorz\Documents\Curriculum Vitae.odt.encrypted 2015-05-12 10:30 - 2012-10-24 09:47 - 00000000 ____D () D:\Users\Grzegorz\Documents\ArcaniA - Gothic 4 2015-05-12 10:30 - 2012-04-22 11:47 - 00016488 _____ () D:\Users\Grzegorz\Documents\Calineczka wita wiosnę.docx.encrypted 2015-05-12 10:30 - 2012-04-10 12:33 - 00000000 ____D () D:\Users\Grzegorz\.VirtualBox 2015-05-12 10:30 - 2012-02-12 22:13 - 00000000 ____D () D:\Users\Grzegorz\Documents\BFBC2 2015-05-12 10:30 - 2009-11-13 21:29 - 00000000 ____D () D:\Programy 2015-05-12 10:25 - 2012-01-08 17:15 - 00000000 ____D () D:\Users\Grzegorz\AppData\Roaming\Skype 2015-05-12 09:34 - 2015-04-09 14:21 - 00009236 _____ () D:\Users\Grzegorz\Desktop\marekScan.jpg.encrypted 2015-05-12 09:34 - 2015-04-08 20:25 - 00026295 _____ () D:\Users\Grzegorz\Desktop\CV MAREK.docx.encrypted 2015-05-12 09:34 - 2015-01-12 18:02 - 00008565 _____ () D:\Users\Grzegorz\Desktop\PODPIS.pdf.encrypted 2015-05-12 09:34 - 2015-01-12 16:50 - 00225419 _____ () D:\Users\Grzegorz\Desktop\Kwestionariusz-Osobowy-Holandia.pdf.encrypted 2015-05-12 09:34 - 2015-01-09 18:24 - 00030214 _____ () D:\Users\Grzegorz\Desktop\CV Grzegorz.docx.encrypted 2015-05-12 09:34 - 2014-12-12 11:11 - 00000426 ____H () D:\Users\Grzegorz\Desktop\~$zegorz Ochwat Trzcinica 261.docx.encrypted 2015-05-12 09:34 - 2014-10-22 13:00 - 00000000 ____D () D:\Users\Grzegorz\Desktop\mamy na sprzedaż 2015-05-12 09:34 - 2014-02-17 11:08 - 00013380 _____ () D:\Users\Grzegorz\Desktop\Grzegorz Ochwat Trzcinica 261.docx.encrypted 2015-05-12 09:34 - 2014-02-14 23:17 - 00013285 _____ () D:\Users\Grzegorz\Desktop\ITI Neovision.docx.encrypted 2015-05-12 09:34 - 2014-01-17 21:48 - 00003701 _____ () D:\Users\Grzegorz\Desktop\transaction.js.encrypted 2015-05-12 09:34 - 2014-01-01 22:38 - 00087751 _____ () D:\Users\Grzegorz\Desktop\cvGO.pdf.encrypted 2015-05-12 09:34 - 2013-08-21 15:16 - 00138161 _____ () D:\Users\Grzegorz\Desktop\Katarzyna-US Loteria wizowa DV-2014 -600x600 px.jpg.encrypted 2015-05-12 09:34 - 2013-07-15 11:21 - 00000776 _____ () D:\Users\Grzegorz\Desktop\hdsentinel.key.encrypted 2015-05-12 09:34 - 2012-07-12 16:31 - 00024328 _____ () D:\Users\Grzegorz\Desktop\Wypowiedzenie umowy z telewizją N.doc.encrypted 2015-05-12 09:34 - 2012-07-02 13:07 - 00700990 _____ () D:\Users\Grzegorz\Desktop\wypowiedzenie1.jpg.encrypted 2015-05-12 09:34 - 2012-07-02 10:45 - 00039707 _____ () D:\Users\Grzegorz\Desktop\160028628460.PDF.encrypted 2015-05-12 09:33 - 2012-04-30 15:33 - 00000930 _____ () D:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-12 09:32 - 2009-07-14 06:45 - 00019792 ____H () D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-12 09:32 - 2009-07-14 06:45 - 00019792 ____H () D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-12 09:24 - 2009-07-14 04:34 - 00000667 _____ () D:\Windows\win.ini 2015-05-12 09:23 - 2009-07-14 07:08 - 00000006 ____H () D:\Windows\Tasks\SA.DAT 2015-05-10 12:18 - 2012-01-08 17:14 - 00000000 ____D () D:\ProgramData\Skype 2015-05-07 17:36 - 2013-07-09 15:41 - 00003106 _____ () D:\Windows\Sandboxie.ini 2015-05-02 21:17 - 2012-10-02 09:15 - 00000000 ____D () D:\Users\Grzegorz\AppData\Local\CrashDumps 2015-04-30 12:03 - 2015-02-10 21:05 - 00084848 _____ (BitDefender SRL) D:\Windows\system32\bdsandboxuiskin.dll 2015-04-30 12:03 - 2014-12-17 20:14 - 00033360 _____ (BitDefender SRL) D:\Windows\system32\bdsandboxuh.dll 2015-04-30 11:34 - 2014-02-20 16:10 - 00000000 ____D () D:\ProgramData\Bitdefender 2015-04-30 11:23 - 2014-12-04 16:59 - 00000000 ____D () D:\Program Files\Bitdefender 2015-04-30 11:23 - 2013-11-09 17:44 - 00000000 ____D () D:\Program Files\Common Files\Bitdefender 2015-04-27 16:39 - 2009-07-14 19:55 - 00800174 _____ () D:\Windows\system32\perfh015.dat 2015-04-27 16:39 - 2009-07-14 19:55 - 00178306 _____ () D:\Windows\system32\perfc015.dat 2015-04-27 16:39 - 2009-07-14 07:13 - 01829754 _____ () D:\Windows\system32\PerfStringBackup.INI 2015-04-24 13:37 - 2014-01-08 11:44 - 00000000 ____D () D:\Program Files (x86)\Mozilla Maintenance Service 2015-04-24 12:12 - 2012-01-12 15:26 - 00000822 _____ () D:\Users\Public\Desktop\CCleaner.lnk 2015-04-24 12:12 - 2012-01-12 15:26 - 00000000 ____D () D:\Program Files\CCleaner 2015-04-15 20:33 - 2012-04-30 15:33 - 00003868 _____ () D:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-15 20:33 - 2012-04-30 15:32 - 00778416 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-15 20:33 - 2011-11-21 17:27 - 00142512 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-15 17:09 - 2012-01-11 13:27 - 00000000 ____D () D:\ProgramData\Microsoft Help 2015-04-15 17:07 - 2013-12-14 19:18 - 01801424 _____ () D:\Windows\SysWOW64\PerfStringBackup.INI 2015-04-15 17:06 - 2013-08-14 22:18 - 00000000 ____D () D:\Windows\system32\MRT 2015-04-15 17:02 - 2012-01-09 20:05 - 128913832 _____ (Microsoft Corporation) D:\Windows\system32\MRT.exe 2015-04-14 21:53 - 2009-07-14 05:20 - 00000000 ____D () D:\Windows\registration 2015-04-14 10:45 - 2009-07-14 05:20 - 00000000 ____D () D:\Windows\rescache 2015-04-13 08:10 - 2009-07-14 07:08 - 00032604 _____ () D:\Windows\Tasks\SCHEDLGU.TXT ==================== Files in the root of some directories ======= 2013-02-11 12:03 - 2013-02-11 12:14 - 13144064 _____ () D:\Users\Grzegorz\AppData\Roaming\Sandra.mdb 2012-07-24 09:51 - 2014-11-03 23:08 - 0022016 _____ () D:\Users\Grzegorz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-07-20 10:56 - 2012-07-20 10:56 - 0017408 _____ () D:\Users\Grzegorz\AppData\Local\WebpageIcons.db 2015-04-30 11:34 - 2015-04-30 11:34 - 0668097 _____ () D:\ProgramData\1430385785.bdinstall.bin 2015-05-12 09:33 - 2015-05-12 09:33 - 0280618 _____ () D:\ProgramData\exoqokut.exe 2012-10-04 11:19 - 2012-10-04 11:19 - 0148736 _____ (Avanquest Software) D:\ProgramData\hpeC2D1.dll 2012-01-12 09:30 - 2014-11-10 15:58 - 0030237 _____ () D:\ProgramData\hpzinstall.log Files to move or delete: ==================== D:\ProgramData\exoqokut.exe D:\ProgramData\hpeC2D1.dll Some content of TEMP: ==================== D:\Users\Grzegorz\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) D:\Windows\System32\winlogon.exe => MD5 is legit D:\Windows\System32\wininit.exe => MD5 is legit D:\Windows\SysWOW64\wininit.exe => MD5 is legit D:\Windows\explorer.exe => MD5 is legit D:\Windows\SysWOW64\explorer.exe => MD5 is legit D:\Windows\System32\svchost.exe => MD5 is legit D:\Windows\SysWOW64\svchost.exe => MD5 is legit D:\Windows\System32\services.exe => MD5 is legit D:\Windows\System32\User32.dll => MD5 is legit D:\Windows\SysWOW64\User32.dll => MD5 is legit D:\Windows\System32\userinit.exe => MD5 is legit D:\Windows\SysWOW64\userinit.exe => MD5 is legit D:\Windows\System32\rpcss.dll => MD5 is legit D:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-15 16:34 ==================== End Of Log ============================