SpyHunter [version: 4.21.18.4608, defs version: 2016.04.27v01] scan log. 2016-04-28 13:00. Scan mode: default THREATS ========================================================================================= wpm HKLM\system\controlset002\services\eventlog\application\wpm 8 EventMessageFile HKLM\system\controlset002\services\eventlog\application\wpm::EventMessageFile 8 TypesSupported HKLM\system\controlset002\services\eventlog\application\wpm::TypesSupported 8 wpm HKLM\system\currentcontrolset\services\eventlog\application\wpm 8 EventMessageFile HKLM\system\currentcontrolset\services\eventlog\application\wpm::EventMessageFile 8 TypesSupported HKLM\system\currentcontrolset\services\eventlog\application\wpm::TypesSupported 8 {3137bc14-d8d7-4b67-8ffa-2e0b2e9d541b} HKCR\interface\{3137bc14-d8d7-4b67-8ffa-2e0b2e9d541b} 9 NumMethods HKCR\interface\{3137bc14-d8d7-4b67-8ffa-2e0b2e9d541b}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{3137bc14-d8d7-4b67-8ffa-2e0b2e9d541b}\ProxyStubClsid32 9 {4ca2ac92-971b-47b1-acb6-357b552155ac} HKCR\interface\{4ca2ac92-971b-47b1-acb6-357b552155ac} 9 NumMethods HKCR\interface\{4ca2ac92-971b-47b1-acb6-357b552155ac}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{4ca2ac92-971b-47b1-acb6-357b552155ac}\ProxyStubClsid32 9 {5d3dcc39-9233-4330-94e9-da92be49ca1a} HKCR\interface\{5d3dcc39-9233-4330-94e9-da92be49ca1a} 9 NumMethods HKCR\interface\{5d3dcc39-9233-4330-94e9-da92be49ca1a}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{5d3dcc39-9233-4330-94e9-da92be49ca1a}\ProxyStubClsid32 9 {615facdf-dadb-440d-ac91-8aab0ae9e3ad} HKCR\interface\{615facdf-dadb-440d-ac91-8aab0ae9e3ad} 9 NumMethods HKCR\interface\{615facdf-dadb-440d-ac91-8aab0ae9e3ad}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{615facdf-dadb-440d-ac91-8aab0ae9e3ad}\ProxyStubClsid32 9 {655847a1-fa36-46ed-923b-a5cd523696ea} HKCR\interface\{655847a1-fa36-46ed-923b-a5cd523696ea} 9 NumMethods HKCR\interface\{655847a1-fa36-46ed-923b-a5cd523696ea}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{655847a1-fa36-46ed-923b-a5cd523696ea}\ProxyStubClsid32 9 {a5acc874-d943-483f-a2d1-14598d51f872} HKCR\interface\{a5acc874-d943-483f-a2d1-14598d51f872} 9 NumMethods HKCR\interface\{a5acc874-d943-483f-a2d1-14598d51f872}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{a5acc874-d943-483f-a2d1-14598d51f872}\ProxyStubClsid32 9 {b0474212-0d9d-4361-90b3-b89d1a44275d} HKCR\interface\{b0474212-0d9d-4361-90b3-b89d1a44275d} 9 NumMethods HKCR\interface\{b0474212-0d9d-4361-90b3-b89d1a44275d}\NumMethods 9 ProxyStubClsid32 HKCR\interface\{b0474212-0d9d-4361-90b3-b89d1a44275d}\ProxyStubClsid32 9 {bfde183a-c6fe-41d2-80f9-586c29210ac2} HKCR\interface\{bfde183a-c6fe-41d2-80f9-586c29210ac2} 9 {fba8498f-b3a0-4942-a2bf-e0cb7bc7e000} HKCR\interface\{fba8498f-b3a0-4942-a2bf-e0cb7bc7e000} 9 Cookie ACOOKIE C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::ACOOKIE_3107a 5 Cookie __upin C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::__upin_25072 5 Cookie idrxvr C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::idrxvr_167 5 Cookie mojo3 C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::mojo3_26510 5 Cookie rts C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::rts_2650f 5 Cookie s_vi C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::s_vi_8173 5 Cookie svid C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\waym27it.default\cookies.sqlite::svid_112ad 5 UNKNOWN OBJECTS ========================================================================================= No unknown objects were found. SAFE OBJECTS ========================================================================================= igfxtray.exe C:\WINDOWS\system32\igfxtray.exe 141336 5bad13e34b172a699c71eff50c262042 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::IgfxTray hkcmd.exe C:\WINDOWS\system32\hkcmd.exe 173592 345847edc34d8e9850a1f1eb88dbd2dc 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::HotKeysCmds virtscrl.exe C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe 101440 dda10d9f1d2892ac5e8ab2a580c3846e 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::LenovoAutoScrollUtility igfxpers.exe C:\WINDOWS\system32\igfxpers.exe 142360 7429aba2fd1eeedb3e8e1ac1b64df24c 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::Persistence smax4pnp.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe 1044480 23f44e9f050a1672b4f4401849348440 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::SoundMAXPnP Smax4.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe 884736 9e617cab2c9d19f3fc0a5f182180d4b4 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::SoundMAX SynTPEnh.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 2350392 8a55a1cac77978198c9129dff16d814c 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::SynTPEnh PWRMGRTR.DLL C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL 3712064 edf1d3bed97269d8113e1a180ac8424d 3 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::PWRMGRTR scheduler_proxy.exe C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe 1093632 929bb319103c7179ed66b74601cdf96d 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::TVT Scheduler Proxy avgui.exe C:\Program Files\AVG\Av\avgui.exe 3930384 a00b83ba9b4409733f565a7add7696af 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::AVG_UI dumprep.exe C:\WINDOWS\system32\dumprep.exe 10752 891d5c5bf17ed4690acc6384f512c7d1 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::KernelFaultCheck LXBXtime.dll C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll 69632 619571ea15ca306000610602c11dbf79 3 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::LXBXCATS ISHelper.exe C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe 1667072 802e8648cb3dee245fd46963bb3cd253 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::iSkysoft Helper Compact.exe Lightshot.exe C:\Program Files\Skillbrains\lightshot\Lightshot.exe 226560 53c6c41356d532fefd8056ab2906d129 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::Lightshot avguirnx.exe C:\Program Files\AVG\Framework\Common\avguirnx.exe 186640 3e59bfa27ae80351311b454e4b8e07f2 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::AvgUi SpyHunter4.exe C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe 7252864 b915dfd852fa1e8e6753645d1f6efb00 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::SpyHunter Security Suite CTFMON.EXE C:\WINDOWS\system32\CTFMON.EXE 15360 1bd41eda5b869afc99895c39a8de36e1 3 -> HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::CTFMON.EXE -> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::CTFMON.EXE ouc.exe C:\Program Files\T-Mobile\InternetManager_H\UpdateDog\ouc.exe 110592 75f26de6cfcc49ad02d99bb9922d863b 15 -> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run::HW_OPENEYE_OUC_T-Mobile Internet Manager -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HW_OPENEYE_OUC_T-Mobile Internet Manager advapi32.dll C:\WINDOWS\system32\advapi32.dll 686592 afce55c392a9676bd24a287d5ed1c777 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::advapi32 -> HKLM\SYSTEM\CurrentControlSet\Services\Wmi\Parameters comdlg32.dll C:\WINDOWS\system32\comdlg32.dll 280064 5e6d485b4ba2fd043aa5d473c79f5df6 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::comdlg32 gdi32.dll C:\WINDOWS\system32\gdi32.dll 287744 d7ba512b4ec52057532b86b47a2c1fdf 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::gdi32 imagehlp.dll C:\WINDOWS\system32\imagehlp.dll 150528 9e7fed2d89e756ffbf85443cd83a8d63 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::imagehlp kernel32.dll C:\WINDOWS\system32\kernel32.dll 1021952 a6a274ef18f781a77d9aaaced2aec2da 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::kernel32 lz32.dll C:\WINDOWS\system32\lz32.dll 2560 60446a3f10ecba750127c8b21e30e9f1 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::lz32 ole32.dll C:\WINDOWS\system32\ole32.dll 1289216 8f4603f449469328c33e05a3574745f7 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::ole32 oleaut32.dll C:\WINDOWS\system32\oleaut32.dll 552448 907b485218c40606a141ff7c062da3b6 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::oleaut32 olecli32.dll C:\WINDOWS\system32\olecli32.dll 75264 3a5952ea643eb251a7b48dec33fbc25d 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::olecli32 olecnv32.dll C:\WINDOWS\system32\olecnv32.dll 37376 b6ed5d957434434bd7991a36f457e024 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::olecnv32 olesvr32.dll C:\WINDOWS\system32\olesvr32.dll 22016 634c41877848644bcba2b43571f0f02b 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::olesvr32 olethk32.dll C:\WINDOWS\system32\olethk32.dll 69120 259918dfde5cf53a5106793059e14a6b 15 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::olethk32 rpcrt4.dll C:\WINDOWS\system32\rpcrt4.dll 591360 85176ae46c6f2b3e980822ca6eab495d 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::rpcrt4 shell32.dll C:\WINDOWS\system32\shell32.dll 8491520 6a4cb36af9f060ed0d6046096429283c 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::shell32 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad::PostBootReminder -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad::CDBurn -> HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} url.dll C:\WINDOWS\system32\url.dll 105984 c82378276b67b4b171925131033f75ef 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::url urlmon.dll C:\WINDOWS\system32\urlmon.dll 1215488 71c14506c43470816c1547896fa1e8d4 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::urlmon user32.dll C:\WINDOWS\system32\user32.dll 580096 a435c5c069afd901751ac323ad238793 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::user32 version.dll C:\WINDOWS\system32\version.dll 18944 5b9fc235221dc3f48da7318cb0bd4888 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::version wininet.dll C:\WINDOWS\system32\wininet.dll 920064 aabefe8b5a794c1073c0694b16f62b9c 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::wininet wldap32.dll C:\WINDOWS\system32\wldap32.dll 172544 08ca57ca108d2cff23d9b7cf90ebfff4 3 -> HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls::wldap32 Explorer.exe C:\WINDOWS\Explorer.exe 1035264 c791ed9eac5e76d9525e157b1d7a599a 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon::Shell -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\::d userinit.exe C:\WINDOWS\system32\userinit.exe 26624 2a5b37d520508be6570a3ea79695f5b5 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon::Userinit sysdm.cpl C:\WINDOWS\system32\sysdm.cpl 303104 492c3297d7fc1f237b938772218ac01d 15 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon::VmApplet avgrsx.exe C:\Program Files\AVG\Av\avgrsx.exe 1010960 013816c6ac79adfc29eb557ec0dbb503 15 -> HKLM\System\CurrentControlSet\Control\Session Manager::BootExecute msapsspc.dll C:\WINDOWS\system32\msapsspc.dll 86016 d5331e4129df4c58f351ca46bfe46bdc 3 -> HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders::SecurityProviders mshta.exe C:\WINDOWS\system32\mshta.exe 45568 ad8f83f16a3ce2b093b38b279b419387 15 -> HKCR\htafile\shell\open\command::(Default) -> HKLM\SOFTWARE\Classes\htafile\shell\open\command::(Default) HYPERTRM.EXE C:\Program Files\Windows NT\HYPERTRM.EXE 28160 461543af34a8943f3fda1b5b81367411 15 -> HKCR\htfile\shell\open\command::(Default) -> HKLM\SOFTWARE\Classes\htfile\shell\open\command::(Default) iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe 638816 b60dddd2d63ce41cb8c487fcfbb6419e 15 -> HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command::(Default) firefox.exe C:\Program Files\Mozilla Firefox\firefox.exe 392136 4234e76a1b12c5f76b264c99540fd736 15 -> HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command::(Default) -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\::j -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe::d crypt32.dll C:\WINDOWS\system32\crypt32.dll 606720 a7e03a26bcf73ffd15c4989f09c4e369 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain cryptnet.dll C:\WINDOWS\system32\cryptnet.dll 64512 389e6205e0f2ac102b22918d65e969cf 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet cscdll.dll C:\WINDOWS\system32\cscdll.dll 102400 9dd90a28f72d623c064ee8cc8a889431 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll dimsntfy.dll C:\WINDOWS\System32\dimsntfy.dll 19456 80b008cf47c3d8affe350b310f4a98c1 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy igfxdev.dll C:\WINDOWS\system32\igfxdev.dll 205824 52befbd6988057e329e14cee7dc2ac4a 15 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui wlnotify.dll C:\WINDOWS\system32\wlnotify.dll 93184 f4d5baf5cbef44386aba2fa25642bc5a 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon sclgntfy.dll C:\WINDOWS\system32\sclgntfy.dll 22016 cb5c2a08280c6b149848ea1f8914b0cc 3 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy ieudinit.exe C:\WINDOWS\system32\ieudinit.exe 36864 06a0d051b6937cda3e38702494bbfc2a 15 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} unregmp2.exe C:\WINDOWS\inf\unregmp2.exe 318976 7db5820f096189b67dc9263ce64bd3b8 15 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95} ie4uinit.exe C:\WINDOWS\system32\ie4uinit.exe 174592 5520ab5cd41df70e749e51e92a77b8b9 15 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c} -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383} iedkcs32.dll C:\WINDOWS\system32\iedkcs32.dll 387584 2a56bf7330c40c442aa2a9c813311c30 3 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF} -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS shmgrate.exe C:\WINDOWS\system32\shmgrate.exe 45056 6d8aa2440c4562938bc830285bf16486 15 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a} advpack.dll C:\WINDOWS\system32\advpack.dll 128512 8fed1e0a491d4990853d23f21c59c730 15 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95} -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B} -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be} -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6} regsvr32.exe C:\WINDOWS\system32\regsvr32.exe 12288 394341a44deecce7680ac3f44d5378a3 3 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED} setup50.exe C:\Program Files\Outlook Express\setup50.exe 73728 319421d21ddf6f96efacf42bae60f3a6 15 -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C} -> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02} lxbxlmpm.DLL C:\WINDOWS\system32\lxbxlmpm.DLL 483328 752578101d5c95824a6404ecb07dc038 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\7100 Series Port cnbjmon.dll C:\WINDOWS\system32\cnbjmon.dll 49152 5a0f9dc34d4fa1c49b6bc6f4acfe2fb1 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\BJ Language Monitor localspl.dll C:\WINDOWS\system32\localspl.dll 347648 852d56ce8f4d718fccf39b1884c7d0ea 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Local Port mdimon.dll C:\WINDOWS\system32\mdimon.dll 28040 322fd75a97dba67fc8f97a9957f857f1 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Microsoft Document Imaging Writer Monitor OPDMN074.DLL C:\WINDOWS\system32\OPDMN074.DLL 146944 2d0b7fe002f5bf5ebe425669921c3db8 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\OKI HiperC Language Monitor7 2K OPPFLM32.DLL C:\WINDOWS\system32\OPPFLM32.DLL 22016 bc000168640f91ec8d8df7ee1a6f6a00 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Oki Language Monitor v2 x86 pjlmon.dll C:\WINDOWS\system32\pjlmon.dll 15360 609d8311b50b0b2e425f44f4b7f220b5 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\PJL Language Monitor tcpmon.dll C:\WINDOWS\system32\tcpmon.dll 46592 bcaacc9170b17cf908ba3a4c92ea0d53 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Standard TCP/IP Port usbmon.dll C:\WINDOWS\system32\usbmon.dll 16896 056a13265e1e20b49187113cbf13b129 3 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\USB Monitor FileOpenBroker32.exe C:\Program Files\FileOpen\Services\FileOpenBroker32.exe 840624 9febf194276370a1f74c10b56f613241 15 -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FileOpenBroker GoogleUpdate.exe C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe 144200 dd7423abbe2913e70d50e9318ad57ee4 15 -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Update -> C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-854245398-725345543-1003UA.job -> C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-854245398-725345543-1003Core.job Network Configuration.exe C:\Program Files\Okidata\ActKey\Network Configuration.exe 728640 3efec21af0f5957f357df39d22e63f41 3 -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Network Configuration webcheck.dll C:\WINDOWS\system32\webcheck.dll 236544 cc8915db4e33e8fb29ca0d2dbf75306e 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad::WebCheck stobject.dll C:\WINDOWS\system32\stobject.dll 122368 01fb72b0ce22c88f83acaa6f42fdf5ab 3 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad::SysTray WPDShServiceObj.dll C:\WINDOWS\system32\WPDShServiceObj.dll 133632 045e228f71c31901084b64be59093499 15 -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad::WPDShServiceObj ACPI.sys C:\WINDOWS\System32\drivers\ACPI.sys 188544 05118282f5d039595a2b92b4a4afe197 3 -> HKLM\SYSTEM\CurrentControlSet\Services\ACPI ACPIEC.sys C:\WINDOWS\System32\drivers\ACPIEC.sys 12032 66a42b7db194e24b973bbcce840a0f3f 3 -> HKLM\SYSTEM\CurrentControlSet\Services\ACPIEC ADIHdAud.sys C:\WINDOWS\System32\drivers\ADIHdAud.sys 334848 ec0c9249eb089b7c46c16c9fae7df789 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ADIHdAudAddService FlashPlayerUpdateService.exe C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 269504 04a7b373a727bd3acd824621cf65ae70 3 -> HKLM\SYSTEM\CurrentControlSet\Services\AdobeFlashPlayerUpdateSvc -> C:\WINDOWS\Tasks\Adobe Flash Player Updater.job AEAudio.sys C:\WINDOWS\System32\drivers\AEAudio.sys 94976 fff87a9b1ab36ee4b7bec98a4cb01b79 15 -> HKLM\SYSTEM\CurrentControlSet\Services\AEAudio aec.sys C:\WINDOWS\System32\drivers\aec.sys 142592 8bed39e3c35d6a489438b8141717a557 15 -> HKLM\SYSTEM\CurrentControlSet\Services\aec afd.sys C:\WINDOWS\System32\drivers\afd.sys 138496 1e44bc1e83d8fd2305f8d452db109cf9 15 -> HKLM\SYSTEM\CurrentControlSet\Services\AFD svchost.exe C:\WINDOWS\system32\svchost.exe 14336 8607d35d92528e2df386f19a960d23ce 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Alerter -> HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt -> HKLM\SYSTEM\CurrentControlSet\Services\AudioSrv -> HKLM\SYSTEM\CurrentControlSet\Services\BITS -> HKLM\SYSTEM\CurrentControlSet\Services\Browser -> HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc -> HKLM\SYSTEM\CurrentControlSet\Services\DcomLaunch -> HKLM\SYSTEM\CurrentControlSet\Services\Dhcp -> HKLM\SYSTEM\CurrentControlSet\Services\dmserver -> HKLM\SYSTEM\CurrentControlSet\Services\Dnscache -> HKLM\SYSTEM\CurrentControlSet\Services\Dot3svc -> HKLM\SYSTEM\CurrentControlSet\Services\EapHost -> HKLM\SYSTEM\CurrentControlSet\Services\ERSvc -> HKLM\SYSTEM\CurrentControlSet\Services\EventSystem -> HKLM\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility -> HKLM\SYSTEM\CurrentControlSet\Services\helpsvc -> HKLM\SYSTEM\CurrentControlSet\Services\HidServ -> HKLM\SYSTEM\CurrentControlSet\Services\hkmsvc -> HKLM\SYSTEM\CurrentControlSet\Services\HTTPFilter -> HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver -> HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation -> HKLM\SYSTEM\CurrentControlSet\Services\LmHosts -> HKLM\SYSTEM\CurrentControlSet\Services\Messenger -> HKLM\SYSTEM\CurrentControlSet\Services\napagent -> HKLM\SYSTEM\CurrentControlSet\Services\Netman -> HKLM\SYSTEM\CurrentControlSet\Services\Nla -> HKLM\SYSTEM\CurrentControlSet\Services\NtmsSvc -> HKLM\SYSTEM\CurrentControlSet\Services\RasAuto -> HKLM\SYSTEM\CurrentControlSet\Services\RasMan -> HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess -> HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry -> HKLM\SYSTEM\CurrentControlSet\Services\RpcSs -> HKLM\SYSTEM\CurrentControlSet\Services\Schedule -> HKLM\SYSTEM\CurrentControlSet\Services\seclogon -> HKLM\SYSTEM\CurrentControlSet\Services\SENS -> HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess -> HKLM\SYSTEM\CurrentControlSet\Services\ShellHWDetection -> HKLM\SYSTEM\CurrentControlSet\Services\srservice -> HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV -> HKLM\SYSTEM\CurrentControlSet\Services\stisvc -> HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv -> HKLM\SYSTEM\CurrentControlSet\Services\TermService -> HKLM\SYSTEM\CurrentControlSet\Services\Themes -> HKLM\SYSTEM\CurrentControlSet\Services\TrkWks -> HKLM\SYSTEM\CurrentControlSet\Services\upnphost -> HKLM\SYSTEM\CurrentControlSet\Services\W32Time -> HKLM\SYSTEM\CurrentControlSet\Services\WebClient -> HKLM\SYSTEM\CurrentControlSet\Services\winmgmt -> HKLM\SYSTEM\CurrentControlSet\Services\WmdmPmSN -> HKLM\SYSTEM\CurrentControlSet\Services\Wmi -> HKLM\SYSTEM\CurrentControlSet\Services\wscsvc -> HKLM\SYSTEM\CurrentControlSet\Services\wuauserv -> HKLM\SYSTEM\CurrentControlSet\Services\WudfSvc -> HKLM\SYSTEM\CurrentControlSet\Services\WZCSVC -> HKLM\SYSTEM\CurrentControlSet\Services\xmlprov alrsvc.dll C:\WINDOWS\system32\alrsvc.dll 17408 27af056d8c42f0ab3cf1dfdcbbeb3243 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Alerter\Parameters alg.exe C:\WINDOWS\System32\alg.exe 44544 d1738dddff196c5cee6d867c136af745 3 -> HKLM\SYSTEM\CurrentControlSet\Services\ALG Amfilter.sys C:\WINDOWS\System32\drivers\Amfilter.sys 8704 868ae6fa93c29c8a105539f3e6d5a77f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Amfilter Amusbprt.sys C:\WINDOWS\System32\drivers\Amusbprt.sys 14336 195fc77b558375151f8ee3f5cd047db3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Amusbprt appmgmts.dll C:\WINDOWS\System32\appmgmts.dll 172032 1561430da2f2ab81cc0ce71af95a778d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters aspnet_state.exe C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 35160 776acefa0ca9df0faa51a5fb2f435705 3 -> HKLM\SYSTEM\CurrentControlSet\Services\aspnet_state asyncmac.sys C:\WINDOWS\System32\drivers\asyncmac.sys 14336 b153affac761e7f5fcfa822b9c4e97bc 15 -> HKLM\SYSTEM\CurrentControlSet\Services\AsyncMac atapi.sys C:\WINDOWS\System32\drivers\atapi.sys 96512 9f3a2f5aa6875c72bf062c712cfa2674 15 -> HKLM\SYSTEM\CurrentControlSet\Services\atapi atmarpc.sys C:\WINDOWS\System32\drivers\atmarpc.sys 59904 9916c1225104ba14794209cfa8012159 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Atmarpc audiosrv.dll C:\WINDOWS\System32\audiosrv.dll 42496 3a28d3e7bad0eed3810cd918b2525b54 15 -> HKLM\SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters audstub.sys C:\WINDOWS\System32\drivers\audstub.sys 3072 d9f724aa26c010a217c97606b160ed68 15 -> HKLM\SYSTEM\CurrentControlSet\Services\audstub avgdiskx.sys C:\WINDOWS\System32\drivers\avgdiskx.sys 134944 5122f1aea7c3ed4f6e64178e7546a149 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avgdiskx avgidsagent.exe C:\Program Files\AVG\Av\avgidsagent.exe 3993088 56214db3f7bc6f897243dd5739a79571 15 -> HKLM\SYSTEM\CurrentControlSet\Services\AVGIDSAgent avgidsdriverlx.sys C:\WINDOWS\System32\drivers\avgidsdriverlx.sys 235808 7939f380e0d2e649b7287f39eb5da706 3 -> HKLM\SYSTEM\CurrentControlSet\Services\AVGIDSDriverl avgidshx.sys C:\WINDOWS\System32\drivers\avgidshx.sys 207792 a70c46182d78b5dd25dbb18ff1b4870c 3 -> HKLM\SYSTEM\CurrentControlSet\Services\AVGIDSHX avgidsshimx.sys C:\WINDOWS\System32\drivers\avgidsshimx.sys 31664 b6226f1d3146c8ce136366ceb5dbd256 3 -> HKLM\SYSTEM\CurrentControlSet\Services\AVGIDSShim avgldx86.sys C:\WINDOWS\System32\drivers\avgldx86.sys 229296 9458a6e6f281873f8f6d8cc4e39bf1a3 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avgldx86 avglogx.sys C:\WINDOWS\System32\drivers\avglogx.sys 287008 4bfce82c91f94ade7b806c13aa8304ab 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avglogx avgmfx86.sys C:\WINDOWS\System32\drivers\avgmfx86.sys 189216 a1ae2784f4f81add7f844d05be5ee85b 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avgmfx86 avgrkx86.sys C:\WINDOWS\System32\drivers\avgrkx86.sys 37296 f68a68b42184297bbdaa9aae7dbbbf16 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avgrkx86 avgsvcx.exe C:\Program Files\AVG\Framework\Common\avgsvcx.exe 886032 b1dacf1acd2f5e16843f541516b67fb3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\avgsvc avgtdix.sys C:\WINDOWS\System32\drivers\avgtdix.sys 231856 11e801b053479e93c319c51ed4831861 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avgtdix avgtpx86.sys C:\WINDOWS\system32\drivers\avgtpx86.sys 37664 15aca2ad17aceca4814f249783e63ad3 3 -> HKLM\SYSTEM\CurrentControlSet\Services\avgtp avgunivx.sys C:\WINDOWS\System32\drivers\avgunivx.sys 61216 edeb23a7e1886d5ab709633cc335398d 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Avgunivx avgwdsvcx.exe C:\Program Files\AVG\Av\avgwdsvcx.exe 593880 dc106e8c0138b667eb4e2b8c0de01f62 15 -> HKLM\SYSTEM\CurrentControlSet\Services\avgwd qmgr.dll C:\WINDOWS\system32\qmgr.dll 409088 78200faa6fd9c69394134c238c87fb7f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\BITS\Parameters browser.dll C:\WINDOWS\System32\browser.dll 78336 9d6788effb9972c28c38d9c5e67249d5 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Browser\Parameters btaudio.sys C:\WINDOWS\System32\drivers\btaudio.sys 533152 9e8cf88d340e32fcb3c53955b2df388f 3 -> HKLM\SYSTEM\CurrentControlSet\Services\btaudio btport.sys C:\WINDOWS\System32\drivers\btport.sys 37160 2f9f111d31aa3fbbe5781d829a4524e6 3 -> HKLM\SYSTEM\CurrentControlSet\Services\BTDriver btkrnl.sys C:\WINDOWS\System32\drivers\btkrnl.sys 993576 d26b5b9a40a2b2191b35c76d5cbf5d2a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\BTKRNL btwdins.exe C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe 349528 c261e704b5558ba04dd643a0d998327d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\btwdins btwdndis.sys C:\WINDOWS\System32\drivers\btwdndis.sys 156816 485020a1e1fc5c51a800ca69c618d881 3 -> HKLM\SYSTEM\CurrentControlSet\Services\BTWDNDIS btwmodem.sys C:\WINDOWS\System32\drivers\btwmodem.sys 37032 5922bae0cd84924b9cd7e6bb515ee070 3 -> HKLM\SYSTEM\CurrentControlSet\Services\btwmodem btwusb.sys C:\WINDOWS\System32\drivers\btwusb.sys 51752 7696f6f2e63086eeedb76b71bb7bb455 3 -> HKLM\SYSTEM\CurrentControlSet\Services\BTWUSB CCDECODE.sys C:\WINDOWS\System32\drivers\CCDECODE.sys 17024 0be5aef125be881c4f854c554f2b025c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\CCDECODE cdrom.sys C:\WINDOWS\System32\drivers\cdrom.sys 62976 1f4260cc5b42272d71f79e570a27a4fe 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Cdrom cisvc.exe C:\WINDOWS\system32\cisvc.exe 5632 45b63df2fb498d219fcbb4425cade676 3 -> HKLM\SYSTEM\CurrentControlSet\Services\CiSvc clipsrv.exe C:\WINDOWS\system32\clipsrv.exe 33280 c94f1b6f61858d6389c0fa06954fb9c4 3 -> HKLM\SYSTEM\CurrentControlSet\Services\ClipSrv mscorsvw.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 69632 d87acaed61e417bba546ced5e7e36d9c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32 mscorsvw.exe C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 130384 c5a75eb48e2344abdc162bda79e16841 15 -> HKLM\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32 CmBatt.sys C:\WINDOWS\System32\drivers\CmBatt.sys 13952 0f6c187d38d98f8df904589a5f94d411 15 -> HKLM\SYSTEM\CurrentControlSet\Services\CmBatt compbatt.sys C:\WINDOWS\System32\drivers\compbatt.sys 10240 6e4c9f21f0fae8940661144f41b13203 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Compbatt dllhost.exe C:\WINDOWS\system32\dllhost.exe 5120 edd19f93679c098429160c8866e8b1c2 3 -> HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp -> HKLM\SYSTEM\CurrentControlSet\Services\SwPrv cryptsvc.dll C:\WINDOWS\System32\cryptsvc.dll 62464 6b105fe95f2e9f0b6346044ba59d41c9 15 -> HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters rpcss.dll C:\WINDOWS\system32\rpcss.dll 401408 a37311d9d628c1042a2836731787f0f3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\DcomLaunch\Parameters -> HKLM\SYSTEM\CurrentControlSet\Services\RpcSs\Parameters dfmirage.sys C:\WINDOWS\System32\drivers\dfmirage.sys 31896 d8cd6a2a94f545858eec6117f0d5dff4 3 -> HKLM\SYSTEM\CurrentControlSet\Services\dfmirage dhcpcsvc.dll C:\WINDOWS\System32\dhcpcsvc.dll 126464 6b4afe7c676cff3eff2dc06a4ee945f7 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters disk.sys C:\WINDOWS\System32\drivers\disk.sys 36352 044452051f3e02e7963599fc8f4f3e25 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Disk dmadmin.exe C:\WINDOWS\System32\dmadmin.exe 225280 35eda0130a79ae2bfca97102d9e16ad1 3 -> HKLM\SYSTEM\CurrentControlSet\Services\dmadmin dmboot.sys C:\WINDOWS\System32\drivers\dmboot.sys 800000 bc9219abc5696942e6f9ac8a9b28670f 3 -> HKLM\SYSTEM\CurrentControlSet\Services\dmboot dmio.sys C:\WINDOWS\System32\drivers\dmio.sys 153856 5fa232e3ba6e1346f9f5a7e519320cb0 3 -> HKLM\SYSTEM\CurrentControlSet\Services\dmio dmload.sys C:\WINDOWS\System32\drivers\dmload.sys 5888 e9317282a63ca4d188c0df5e09c6ac5f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\dmload dmserver.dll C:\WINDOWS\System32\dmserver.dll 24064 d858920a05076914d34b0388e8d96cc0 15 -> HKLM\SYSTEM\CurrentControlSet\Services\dmserver\Parameters DMusic.sys C:\WINDOWS\System32\drivers\DMusic.sys 52864 8a208dfcf89792a484e76c40e5f50b45 15 -> HKLM\SYSTEM\CurrentControlSet\Services\DMusic dnsrslvr.dll C:\WINDOWS\System32\dnsrslvr.dll 45568 082be13166a3354f25f78e0b2601012b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters dot3svc.dll C:\WINDOWS\System32\dot3svc.dll 133632 e0b7d66cf29d9adccf873c77821cd4ca 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Dot3svc\Parameters DozeHDD.sys C:\WINDOWS\System32\drivers\DozeHDD.sys 24264 dfa9d633510697d69c8288c54f0adca0 3 -> HKLM\SYSTEM\CurrentControlSet\Services\DozeHDD DOZESVC.EXE C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE 280640 84311f6c7af747aef5fb7e33cd9ff155 15 -> HKLM\SYSTEM\CurrentControlSet\Services\DozeSvc drmkaud.sys C:\WINDOWS\System32\drivers\drmkaud.sys 2944 8f5fcff8e8848afac920905fbd9d33c8 15 -> HKLM\SYSTEM\CurrentControlSet\Services\drmkaud e1e5132.sys C:\WINDOWS\System32\drivers\e1e5132.sys 234496 06d94f4543671b497a5f4a0aedd5e36a 15 -> HKLM\SYSTEM\CurrentControlSet\Services\e1express eapsvc.dll C:\WINDOWS\System32\eapsvc.dll 33792 5f256c1ad50fefdc442cd5aab58c7dd8 15 -> HKLM\SYSTEM\CurrentControlSet\Services\EapHost\Parameters Agent.exe C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe 36904 2b9bdae7e1e20cf0b07dc0df7a2278ba 15 -> HKLM\SYSTEM\CurrentControlSet\Services\EaseUS Agent eboard_touch.sys C:\WINDOWS\System32\drivers\eboard_touch.sys 16128 b2b2b102aa5ec6293daca08b312dea8e 3 -> HKLM\SYSTEM\CurrentControlSet\Services\EboardTouch EMP_NSWLSV.exe C:\Program Files\EPSON Projector\EMP NS Connection V2\EMP_NSWLSV.exe 98304 c96475a5b4793e68fda226da1faad6c1 15 -> HKLM\SYSTEM\CurrentControlSet\Services\EMP_NSWLSV epmntdrv.sys C:\WINDOWS\system32\epmntdrv.sys 13896 d57f1811d8258d8d277cd9f53657eef9 15 -> HKLM\SYSTEM\CurrentControlSet\Services\epmntdrv ersvc.dll C:\WINDOWS\System32\ersvc.dll 23040 ed1b71382c31fd2cf3cdc4672efad6ea 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ERSvc\Parameters EsgScanner.sys C:\WINDOWS\System32\drivers\EsgScanner.sys 19984 01ce484ff6d70a39479bc6d619de7ed6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\EsgScanner eubakup.sys C:\WINDOWS\System32\drivers\eubakup.sys 52008 e77f5039063c2f74f012efed97bd1c7a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\EUBAKUP EUBKMON.sys C:\WINDOWS\System32\drivers\EUBKMON.sys 40744 2658f0fb1414a387518aa30848f00659 3 -> HKLM\SYSTEM\CurrentControlSet\Services\EUBKMON eudskacs.sys C:\WINDOWS\system32\drivers\eudskacs.sys 14888 9a66bb61d731136d2db81c5d4272d87e 3 -> HKLM\SYSTEM\CurrentControlSet\Services\EUDSKACS EuFdDisk.sys C:\WINDOWS\system32\drivers\EuFdDisk.sys 188840 b979e228c8132434d1a011c8a43f1a9d 3 -> HKLM\SYSTEM\CurrentControlSet\Services\EUFDDISK EuGdiDrv.sys C:\WINDOWS\system32\EuGdiDrv.sys 9160 f1de3eef501dda7ddf99f2edf0c5540e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\EuGdiDrv services.exe C:\WINDOWS\system32\services.exe 111104 02a467e27af55f7064c5b251e587315f 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Eventlog -> HKLM\SYSTEM\CurrentControlSet\Services\PlugPlay es.dll C:\WINDOWS\system32\es.dll 253952 6aff804839c85859e0247164fbe5f5bb 3 -> HKLM\SYSTEM\CurrentControlSet\Services\EventSystem\Parameters ew_hwusbdev.sys C:\WINDOWS\System32\drivers\ew_hwusbdev.sys 95232 a744d66bcd4cabdd4b111d9e220b4d57 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ew_hwusbdev ew_usbenumfilter.sys C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys 11904 6b4ac26c62f55af324e3809ee2ad9f0c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ew_usbenumfilter shsvcs.dll C:\WINDOWS\System32\shsvcs.dll 135680 55aae86c7c2cadf6972acd1d76c24a98 3 -> HKLM\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Parameters -> HKLM\SYSTEM\CurrentControlSet\Services\ShellHWDetection\Parameters -> HKLM\SYSTEM\CurrentControlSet\Services\Themes\Parameters FileOpenManagerService32.exe C:\Program Files\FileOpen\Services\FileOpenManagerService32.exe 213432 86746a35e764b5b925bca84d093495dd 15 -> HKLM\SYSTEM\CurrentControlSet\Services\FileOpenManagerService ewfiltertdidriver.sys C:\WINDOWS\System32\drivers\ewfiltertdidriver.sys 7552 f8946c6d013fc9e6db03fbcf32294799 15 -> HKLM\SYSTEM\CurrentControlSet\Services\filtertdidriver fltmgr.sys C:\WINDOWS\System32\drivers\fltmgr.sys 129792 b2cf4b0786f8212cb92ed2b50c6db6b0 15 -> HKLM\SYSTEM\CurrentControlSet\Services\FltMgr PresentationFontCache.exe c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 46104 8ba7c024070f2b7fdd98ed8a4ba41789 15 -> HKLM\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0 ftdisk.sys C:\WINDOWS\System32\drivers\ftdisk.sys 125568 ed6d921d8ab423138fb35beee6d6a6cb 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Ftdisk msgpc.sys C:\WINDOWS\System32\drivers\msgpc.sys 35072 0a02c63c8b144bd8c86b103dee7c86a2 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Gpc HDAudBus.sys C:\WINDOWS\System32\drivers\HDAudBus.sys 144384 573c7d0a32852b48f3058cfd8026f511 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HDAudBus pchsvc.dll C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 38400 af752014f7eb61542e3f35b9374d7e76 15 -> HKLM\SYSTEM\CurrentControlSet\Services\helpsvc\Parameters hidserv.dll C:\WINDOWS\System32\hidserv.dll 21504 1776c3b6069eeecc8042535296c1866a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\HidServ\Parameters hidusb.sys C:\WINDOWS\System32\drivers\hidusb.sys 10368 ccf82c5ec8a7326c3066de870c06daf1 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HidUsb kmsvc.dll C:\WINDOWS\System32\kmsvc.dll 61440 f0273916da6fb64cc88e0bd77619554f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\hkmsvc\Parameters HSFHWAZL.sys C:\WINDOWS\System32\drivers\HSFHWAZL.sys 217016 702a7e1b3c9263efbd6aede3b6919761 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HSFHWAZL HSF_DPV.sys C:\WINDOWS\System32\drivers\HSF_DPV.sys 993464 8d02cb68d53aa36189faf86fed438884 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HSF_DPV HTTP.sys C:\WINDOWS\System32\drivers\HTTP.sys 265728 f80a415ef82cd06ffaf0d971528ead38 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HTTP w3ssl.dll C:\WINDOWS\System32\w3ssl.dll 15872 aa268079ac119f3a596e5e27aee4bd17 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HTTPFilter\Parameters ew_jucdcacm.sys C:\WINDOWS\System32\drivers\ew_jucdcacm.sys 101248 616a53fce073763ddb010a6cec75fd56 3 -> HKLM\SYSTEM\CurrentControlSet\Services\huawei_cdcacm ew_jucdcecm.sys C:\WINDOWS\System32\drivers\ew_jucdcecm.sys 70528 2148d4f231408223dc33bd2f0b6a785c 3 -> HKLM\SYSTEM\CurrentControlSet\Services\huawei_cdcecm ew_jubusenum.sys C:\WINDOWS\System32\drivers\ew_jubusenum.sys 77824 dc63053744a3086be6e473a93d48ee39 3 -> HKLM\SYSTEM\CurrentControlSet\Services\huawei_enumerator ew_juextctrl.sys C:\WINDOWS\System32\drivers\ew_juextctrl.sys 27776 61be99e6d1ea098ca00144d624eef871 3 -> HKLM\SYSTEM\CurrentControlSet\Services\huawei_ext_ctrl HWDeviceService.exe C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe 276048 421069ee49968e06605464d050b65054 15 -> HKLM\SYSTEM\CurrentControlSet\Services\HWDeviceService.exe i8042prt.sys C:\WINDOWS\System32\drivers\i8042prt.sys 53248 177b372af55c4460d0968b5f1d02aa1c 3 -> HKLM\SYSTEM\CurrentControlSet\Services\i8042prt igxpmp32.sys C:\WINDOWS\System32\drivers\igxpmp32.sys 1730272 c5db546f9028cd00e64335091860d8f3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ialm ibmpmdrv.sys C:\WINDOWS\System32\drivers\ibmpmdrv.sys 35240 c693794f0ea5834870376c102eb1553d 3 -> HKLM\SYSTEM\CurrentControlSet\Services\IBMPMDRV ibmpmsvc.exe C:\WINDOWS\system32\ibmpmsvc.exe 39248 2895c7c082446ba833cad0adde06eaed 15 -> HKLM\SYSTEM\CurrentControlSet\Services\IBMPMSVC infocard.exe C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 881664 c01ac32dc5c03076cfb852cb5da5229c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\idsvc imapi.sys C:\WINDOWS\System32\drivers\imapi.sys 42112 083a052659f5310dd8b6a6cb05edcf8e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Imapi imapi.exe C:\WINDOWS\system32\imapi.exe 150528 9125af650608a921f98a789e5c5ba864 3 -> HKLM\SYSTEM\CurrentControlSet\Services\ImapiService intelppm.sys C:\WINDOWS\System32\drivers\intelppm.sys 40448 da153edc09de8c4f846c085caa39d1cc 3 -> HKLM\SYSTEM\CurrentControlSet\Services\intelppm ip6fw.sys C:\WINDOWS\System32\drivers\ip6fw.sys 36608 3bb22519a194418d5fec05d800a19ad0 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Ip6Fw ipfltdrv.sys C:\WINDOWS\System32\drivers\ipfltdrv.sys 32896 731f22ba402ee4b62748adaf6363c182 15 -> HKLM\SYSTEM\CurrentControlSet\Services\IpFilterDriver ipinip.sys C:\WINDOWS\System32\drivers\ipinip.sys 20864 b87ab476dcf76e72010632b5550955f5 15 -> HKLM\SYSTEM\CurrentControlSet\Services\IpInIp ipnat.sys C:\WINDOWS\System32\drivers\ipnat.sys 152832 cc748ea12c6effde940ee98098bf96bb 15 -> HKLM\SYSTEM\CurrentControlSet\Services\IpNat ipsec.sys C:\WINDOWS\System32\drivers\ipsec.sys 75264 23c74d75e36e7158768dd63d92789a91 15 -> HKLM\SYSTEM\CurrentControlSet\Services\IPSec irenum.sys C:\WINDOWS\System32\drivers\irenum.sys 11264 c93c9ff7b04d772627a3646d89f7bf89 15 -> HKLM\SYSTEM\CurrentControlSet\Services\IRENUM isapnp.sys C:\WINDOWS\System32\drivers\isapnp.sys 37632 c8eef2e93835b81bd335de2123121283 3 -> HKLM\SYSTEM\CurrentControlSet\Services\isapnp jqs.exe C:\Program Files\Java\jre7\bin\jqs.exe 182696 b9436a665a8621073a12338b16d7bfd4 15 -> HKLM\SYSTEM\CurrentControlSet\Services\JavaQuickStarterService k750bus.sys C:\WINDOWS\System32\drivers\k750bus.sys 55216 fe8300320281d658a7854d5cfc02a63f 3 -> HKLM\SYSTEM\CurrentControlSet\Services\k750bus k750mdfl.sys C:\WINDOWS\System32\drivers\k750mdfl.sys 6576 f44521f63c0c00364fa3d59db980de6a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\k750mdfl k750mdm.sys C:\WINDOWS\System32\drivers\k750mdm.sys 89872 e93323c3ed5e8923a177740a973c27b2 3 -> HKLM\SYSTEM\CurrentControlSet\Services\k750mdm k750mgmt.sys C:\WINDOWS\System32\drivers\k750mgmt.sys 81728 9d5f5a70ca0b7c428efcd73db50e6ac7 3 -> HKLM\SYSTEM\CurrentControlSet\Services\k750mgmt k750obex.sys C:\WINDOWS\System32\drivers\k750obex.sys 79488 81ca2d57b2c14f76f4ba80846784bb3d 3 -> HKLM\SYSTEM\CurrentControlSet\Services\k750obex kbdclass.sys C:\WINDOWS\System32\drivers\kbdclass.sys 24960 2aeca45d4aeaacbdcb77ad11184e4601 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Kbdclass kbdhid.sys C:\WINDOWS\System32\drivers\kbdhid.sys 14720 f718dcddac2544bc693f22977d06f78b 3 -> HKLM\SYSTEM\CurrentControlSet\Services\kbdhid kmixer.sys C:\WINDOWS\System32\drivers\kmixer.sys 172416 692bcf44383d056aed41b045a323d378 15 -> HKLM\SYSTEM\CurrentControlSet\Services\kmixer srvsvc.dll C:\WINDOWS\System32\srvsvc.dll 99840 061a4bb67c324ac8c176e0d77923b212 3 -> HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\Parameters wkssvc.dll C:\WINDOWS\System32\wkssvc.dll 132096 fa17019da45c5d6464776a639a5a9abb 15 -> HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\Parameters MICMUTE.exe C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe 101736 340288b3b2edc8afd5ff127df85142a7 15 -> HKLM\SYSTEM\CurrentControlSet\Services\LENOVO.MICMUTE smiif32.sys C:\WINDOWS\System32\drivers\smiif32.sys 13680 9aac267a225f3caebb9e633f7eb16e4b 3 -> HKLM\SYSTEM\CurrentControlSet\Services\lenovo.smi lmhsvc.dll C:\WINDOWS\System32\lmhsvc.dll 13824 437aa83d68f9fac234ca68dbd40db705 15 -> HKLM\SYSTEM\CurrentControlSet\Services\LmHosts\Parameters lxbxcoms.exe C:\WINDOWS\system32\lxbxcoms.exe 462848 d8945549e769f38133096173b71bdd6e 3 -> HKLM\SYSTEM\CurrentControlSet\Services\lxbx_device mbam.sys C:\WINDOWS\system32\drivers\mbam.sys 23256 b4cd87e78a01562e3da67fe1c2779204 3 -> HKLM\SYSTEM\CurrentControlSet\Services\MBAMProtector mbamscheduler.exe C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe 1871160 301e3fdfcf33640bb8763ba444bc5093 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MBAMScheduler mbamservice.exe C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe 1133880 83c982a395d00baff6515fb38424ea76 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MBAMService MBAMSwissArmy.sys C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 98520 739164a8b8fb2f1b50a498f20af7b21e 3 -> HKLM\SYSTEM\CurrentControlSet\Services\MBAMSwissArmy MDM.EXE C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 322120 11f714f85530a2bd134074dc30e99fca 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MDM mdmxsdk.sys C:\WINDOWS\System32\drivers\mdmxsdk.sys 19384 a027de1e6c11bd2daf61f6f276b2299f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\mdmxsdk msgsvc.dll C:\WINDOWS\System32\msgsvc.dll 33792 36f3ab18b1be303da51de90a67de3942 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Messenger\Parameters mnmsrvc.exe C:\WINDOWS\system32\mnmsrvc.exe 32768 845814a8cb9d704d030f076e1bce83f3 3 -> HKLM\SYSTEM\CurrentControlSet\Services\mnmsrvc mouclass.sys C:\WINDOWS\System32\drivers\mouclass.sys 23296 fbed3df6b884f8cf00447b73507f2c48 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Mouclass mouhid.sys C:\WINDOWS\System32\drivers\mouhid.sys 12160 ecec1e6cd558ab80f944f31326e9d3b5 3 -> HKLM\SYSTEM\CurrentControlSet\Services\mouhid maintenanceservice.exe C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 146888 5961c5d8edd2e2a3b99f1782ae1ac21f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MozillaMaintenance mrxdav.sys C:\WINDOWS\System32\drivers\mrxdav.sys 180608 11d42bb6206f33fbb3ba0288d3ef81bd 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MRxDAV mrxsmb.sys C:\WINDOWS\System32\drivers\mrxsmb.sys 456320 7d304a5eb4344ebeeab53a2fe3ffb9f0 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb msdtc.exe C:\WINDOWS\system32\msdtc.exe 6144 a54c5eecc7d3424824410bae0aa6c371 3 -> HKLM\SYSTEM\CurrentControlSet\Services\MSDTC msiexec.exe C:\WINDOWS\system32\msiexec.exe 78848 294d062d834ed634ea46073a4ca7af39 3 -> HKLM\SYSTEM\CurrentControlSet\Services\MSIServer MSKSSRV.sys C:\WINDOWS\System32\drivers\MSKSSRV.sys 7552 d1575e71568f4d9e14ca56b7b0453bf1 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MSKSSRV MSPCLOCK.sys C:\WINDOWS\System32\drivers\MSPCLOCK.sys 5376 325bb26842fc7ccc1fcce2c457317f3e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MSPCLOCK MSPQM.sys C:\WINDOWS\System32\drivers\MSPQM.sys 4992 bad59648ba099da4a17680b39730cb3d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MSPQM mssmbios.sys C:\WINDOWS\System32\drivers\mssmbios.sys 15488 af5f4f3f14a8ea2c26de30f7a1e17136 15 -> HKLM\SYSTEM\CurrentControlSet\Services\mssmbios MSTEE.sys C:\WINDOWS\System32\drivers\MSTEE.sys 5504 e53736a9e30c45fa9e7b5eac55056d1d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\MSTEE NABTSFEC.sys C:\WINDOWS\System32\drivers\NABTSFEC.sys 85248 5b50f1b2a2ed47d560577b221da734db 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NABTSFEC qagentrt.dll C:\WINDOWS\System32\qagentrt.dll 293376 14cb8528e17d1221c50fc8ca88b1795f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\napagent\Parameters NdisIP.sys C:\WINDOWS\System32\drivers\NdisIP.sys 10880 7ff1f1fd8609c149aa432f95a8163d97 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NdisIP ndistapi.sys C:\WINDOWS\System32\drivers\ndistapi.sys 10496 0109c4f3850dfbab279542515386ae22 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NdisTapi ndisuio.sys C:\WINDOWS\System32\drivers\ndisuio.sys 14592 f927a4434c5028758a842943ef1a3849 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Ndisuio ndiswan.sys C:\WINDOWS\System32\drivers\ndiswan.sys 91520 edc1531a49c80614b2cfda43ca8659ab 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NdisWan netbios.sys C:\WINDOWS\System32\drivers\netbios.sys 34688 5d81cf9a2f1a3a756b66cf684911cdf0 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NetBIOS netbt.sys C:\WINDOWS\System32\drivers\netbt.sys 162816 74b2b2f5bea5e9a3dc021d685551bd3d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NetBT netdde.exe C:\WINDOWS\system32\netdde.exe 114688 cbb409b314309fcffce5e682e91338c6 3 -> HKLM\SYSTEM\CurrentControlSet\Services\NetDDE -> HKLM\SYSTEM\CurrentControlSet\Services\NetDDEdsdm lsass.exe C:\WINDOWS\system32\lsass.exe 13312 88296f7943f30a1ee3af735440b92268 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Netlogon -> HKLM\SYSTEM\CurrentControlSet\Services\NtLmSsp -> HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent -> HKLM\SYSTEM\CurrentControlSet\Services\ProtectedStorage -> HKLM\SYSTEM\CurrentControlSet\Services\SamSs netman.dll C:\WINDOWS\System32\netman.dll 198144 4fe97d0b1b182df2a9bdd4c02155ef5e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Netman\Parameters SMSvcHost.exe C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 124240 d22cd77d4f0d63d1169bb35911bff12d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing NETwLx32.sys C:\WINDOWS\System32\drivers\NETwLx32.sys 6609920 72062b53186e4a3f5fcbc41ebb62b905 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NETwLx32 mswsock.dll C:\WINDOWS\System32\mswsock.dll 246784 9d1f13706fb5f02d0e8795fb2d03971d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Nla\Parameters -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000022 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000023 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000025 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000026 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000027 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000028 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000029 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000030 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000031 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000032 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000033 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000034 npf.sys C:\WINDOWS\System32\drivers\npf.sys 36600 25401b0c9576c8456b3e0bbd74ff0771 3 -> HKLM\SYSTEM\CurrentControlSet\Services\NPF ntmssvc.dll C:\WINDOWS\system32\ntmssvc.dll 435712 3fb5399dbb7001a80d58edad64c98225 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NtmsSvc\Parameters nwlnkflt.sys C:\WINDOWS\System32\drivers\nwlnkflt.sys 12416 b305f3fad35083837ef46a0bbce2fc57 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NwlnkFlt nwlnkfwd.sys C:\WINDOWS\System32\drivers\nwlnkfwd.sys 32512 c99b3415198d1aab7227f2c88fd664b9 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NwlnkFwd nwlnkipx.sys C:\WINDOWS\System32\drivers\nwlnkipx.sys 88320 8b8b1be2dba4025da6786c645f77f123 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NwlnkIpx nwlnknb.sys C:\WINDOWS\System32\drivers\nwlnknb.sys 63232 56d34a67c05e94e16377c60609741ff8 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NwlnkNb nwlnkspx.sys C:\WINDOWS\System32\drivers\nwlnkspx.sys 55936 c0bb7d1615e1acbdc99757f6ceaf8cf0 15 -> HKLM\SYSTEM\CurrentControlSet\Services\NwlnkSpx OSE.EXE C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 149352 9d10f99a6712e28f8acd5641e3a7ea6b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ose OSPPSVC.EXE C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 4640000 358a9cca612c68eb2f07ddad4ce1d8d7 15 -> HKLM\SYSTEM\CurrentControlSet\Services\osppsvc pci.sys C:\WINDOWS\System32\drivers\pci.sys 68608 6862c69168d787b85a7d95ccd33c694e 3 -> HKLM\SYSTEM\CurrentControlSet\Services\PCI pciide.sys C:\WINDOWS\System32\drivers\pciide.sys 3456 548cf2d6369eae441a4c6baa75bc4f0a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\PCIIde pcmcia.sys C:\WINDOWS\System32\drivers\pcmcia.sys 120320 8db27f1ae9593c94095485305a583862 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Pcmcia pmemnt.sys C:\WINDOWS\System32\drivers\pmemnt.sys 7012 dedef40e1d05842639491365cb2c069e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\pmem PWMDBSVC.EXE C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE 1645568 f33167e633c483ea6c902600e4270b3f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Power Manager DBC Service raspptp.sys C:\WINDOWS\System32\drivers\raspptp.sys 48384 efeec01b1d3cf84f16ddd24d9d9d8f99 15 -> HKLM\SYSTEM\CurrentControlSet\Services\PptpMiniport psadd.sys C:\WINDOWS\System32\drivers\psadd.sys 30144 f8a25f1dd8b2c332cbc663e3579566e7 3 -> HKLM\SYSTEM\CurrentControlSet\Services\psadd psched.sys C:\WINDOWS\System32\drivers\psched.sys 69120 09298ec810b07e5d582cb3a3f9255424 15 -> HKLM\SYSTEM\CurrentControlSet\Services\PSched pssnap.sys C:\WINDOWS\System32\drivers\pssnap.sys 16016 b10bc6bcf6cbfa1d1879488caa3ec026 3 -> HKLM\SYSTEM\CurrentControlSet\Services\pssnap ptilink.sys C:\WINDOWS\System32\drivers\ptilink.sys 17792 80d317bd1c3dbc5d4fe7b1678c60cadd 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Ptilink PWMEWSVC.EXE C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE 1664064 a36c71196370d23d27bc93b050840cc3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\PwmEWSvc PxHelp20.sys C:\WINDOWS\System32\drivers\PxHelp20.sys 43528 d86b4a68565e444d76457f14172c875a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\PxHelp20 rasacd.sys C:\WINDOWS\System32\drivers\rasacd.sys 8832 fe0d99d6f31e4fad8159f690d68ded9c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RasAcd rasauto.dll C:\WINDOWS\System32\rasauto.dll 88576 bc22c5e1238d4d36d65679e249c483c3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RasAuto\Parameters rasl2tp.sys C:\WINDOWS\System32\drivers\rasl2tp.sys 51328 11b4a627bc9614b885c4969bfa5ff8a6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Rasl2tp rasmans.dll C:\WINDOWS\System32\rasmans.dll 186368 0c392e397b8d34aaaf19ec6119cbb788 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RasMan\Parameters raspppoe.sys C:\WINDOWS\System32\drivers\raspppoe.sys 41472 5bc962f2654137c9909c3d4603587dee 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RasPppoe raspti.sys C:\WINDOWS\System32\drivers\raspti.sys 16512 fdbb1d60066fcfbb7452fd8f9829b242 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Raspti rdbss.sys C:\WINDOWS\System32\drivers\rdbss.sys 175744 7ad224ad1a1437fe28d89cf22b17780a 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Rdbss RDPCDD.sys C:\WINDOWS\System32\drivers\RDPCDD.sys 4224 4912d5b403614ce99c28420f75353332 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RDPCDD rdpdr.sys C:\WINDOWS\System32\drivers\rdpdr.sys 196224 15cabd0f7c00c47c70124907916af3f1 15 -> HKLM\SYSTEM\CurrentControlSet\Services\rdpdr sessmgr.exe C:\WINDOWS\system32\sessmgr.exe 142336 f83907a9a038db2e35329b039628d293 3 -> HKLM\SYSTEM\CurrentControlSet\Services\RDSessMgr redbook.sys C:\WINDOWS\System32\drivers\redbook.sys 58880 e0c7bbd18040b58651bac700c804861d 3 -> HKLM\SYSTEM\CurrentControlSet\Services\redbook ReflectService.exe C:\Program Files\Macrium\Reflect\ReflectService.exe 2613200 387354031dc053ca8beaf6d81ec8b0c4 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ReflectService.exe mprdim.dll C:\WINDOWS\System32\mprdim.dll 53248 b3f57e6115bcd4dbade9874f300655e3 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\Parameters regsvc.dll C:\WINDOWS\system32\regsvc.dll 59904 b472b59ef98469c91651b751d3442cb8 15 -> HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters rpcapd.exe C:\Program Files\WinPcap\rpcapd.exe 118520 83a6c2cafe236652d1559640594a0ea8 3 -> HKLM\SYSTEM\CurrentControlSet\Services\rpcapd locator.exe C:\WINDOWS\system32\locator.exe 75264 6bc4d5a70f46ea27ddc14e5414c862a5 3 -> HKLM\SYSTEM\CurrentControlSet\Services\RpcLocator rsvp.exe C:\WINDOWS\system32\rsvp.exe 132608 9acee3313020a01235336c2a483afd1a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\RSVP SCardSvr.exe C:\WINDOWS\System32\SCardSvr.exe 98304 c6f479218e94896738c06af5ba6ab3d3 3 -> HKLM\SYSTEM\CurrentControlSet\Services\SCardSvr schedsvc.dll C:\WINDOWS\system32\schedsvc.dll 193536 dd73c11a5c4d14945846384b90a61a4b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Schedule\Parameters scsiport.sys C:\WINDOWS\system32\drivers\scsiport.sys 96384 76c465f570e90c28942d52ccb2580a10 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ScsiPort secdrv.sys C:\WINDOWS\System32\drivers\secdrv.sys 20480 90a3935d05b494a5a39d37e71f09a677 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Secdrv seclogon.dll C:\WINDOWS\System32\seclogon.dll 18944 2aad9026648120fffe2a8d871bb2bbc7 15 -> HKLM\SYSTEM\CurrentControlSet\Services\seclogon\Parameters sens.dll C:\WINDOWS\system32\sens.dll 39424 9d01e29d59723eb73b72107b208dafe6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\SENS\Parameters sfdrv01a.sys C:\WINDOWS\System32\drivers\sfdrv01a.sys 63352 4d0ce0fadca29e7da68ce597ac9010bd 3 -> HKLM\SYSTEM\CurrentControlSet\Services\sfdrv01a sfhlp02.sys C:\WINDOWS\System32\drivers\sfhlp02.sys 13680 daad4c099ebf5094d32c373ac1ac0f3c 3 -> HKLM\SYSTEM\CurrentControlSet\Services\sfhlp02 sfsync04.sys C:\WINDOWS\System32\drivers\sfsync04.sys 59776 c526ad307ff1900bc4c864f74553f762 3 -> HKLM\SYSTEM\CurrentControlSet\Services\sfsync04 ipnathlp.dll C:\WINDOWS\System32\ipnathlp.dll 330752 da5c015911f68f22ed821e9ee49ab233 15 -> HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters Apsx86.sys C:\WINDOWS\System32\drivers\Apsx86.sys 129384 da9e304518531de07e56507df91baabc 3 -> HKLM\SYSTEM\CurrentControlSet\Services\Shockprf SLIP.sys C:\WINDOWS\System32\drivers\SLIP.sys 11136 866d538ebe33709a5c9f5c62b73b7d14 15 -> HKLM\SYSTEM\CurrentControlSet\Services\SLIP splitter.sys C:\WINDOWS\System32\drivers\splitter.sys 6272 ab8b92451ecb048a4d1de7c3ffcb4a9f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\splitter spoolsv.exe C:\WINDOWS\system32\spoolsv.exe 58880 60784f891563fb1b767f70117fc2428f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Spooler sptd.sys C:\WINDOWS\System32\drivers\sptd.sys 466008 68103a2b441bbf3908ebb587f0704d6c 3 -> HKLM\SYSTEM\CurrentControlSet\Services\sptd SH4Service.exe C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe 784256 859c0992e57ec15eeee3d724424299c7 15 -> HKLM\SYSTEM\CurrentControlSet\Services\SpyHunter 4 Service sr.sys C:\WINDOWS\System32\drivers\sr.sys 73472 eb032822be406ef220d546ddffcf0002 3 -> HKLM\SYSTEM\CurrentControlSet\Services\sr srsvc.dll C:\WINDOWS\system32\srsvc.dll 171520 316d0e66074ae4cde641c50d3a1c5148 15 -> HKLM\SYSTEM\CurrentControlSet\Services\srservice\Parameters srv.sys C:\WINDOWS\System32\drivers\srv.sys 357888 47ddfc2f003f7f9f0592c6874962a2e7 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Srv ssdpsrv.dll C:\WINDOWS\System32\ssdpsrv.dll 71680 2c0b1224aa36b4ca1753302baa855882 15 -> HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV\Parameters wiaservc.dll C:\WINDOWS\system32\wiaservc.dll 334336 41508ea375c97dc2b56e5f1afc067187 15 -> HKLM\SYSTEM\CurrentControlSet\Services\stisvc\Parameters StreamIP.sys C:\WINDOWS\System32\drivers\StreamIP.sys 15232 77813007ba6265c4b6098187e6ed79d2 15 -> HKLM\SYSTEM\CurrentControlSet\Services\streamip swenum.sys C:\WINDOWS\System32\drivers\swenum.sys 4352 3941d127aef12e93addf6fe6ee027e0f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\swenum swmidi.sys C:\WINDOWS\System32\drivers\swmidi.sys 56576 8ce882bcc6cf8a62f2b2323d95cb3d01 15 -> HKLM\SYSTEM\CurrentControlSet\Services\swmidi SynTP.sys C:\WINDOWS\System32\drivers\SynTP.sys 344376 a593c7fd405316a44bc21e825db6d079 3 -> HKLM\SYSTEM\CurrentControlSet\Services\SynTP sysaudio.sys C:\WINDOWS\System32\drivers\sysaudio.sys 60800 8b83f3ed0f1688b4958f77cd6d2bf290 15 -> HKLM\SYSTEM\CurrentControlSet\Services\sysaudio smlogsvc.exe C:\WINDOWS\system32\smlogsvc.exe 91136 e42048198518f9162027a9984cbb7b5c 3 -> HKLM\SYSTEM\CurrentControlSet\Services\SysmonLog tap0901.sys C:\WINDOWS\System32\drivers\tap0901.sys 35288 432d9d823c4c26b6070c41bad4404ce4 3 -> HKLM\SYSTEM\CurrentControlSet\Services\tap0901 tapisrv.dll C:\WINDOWS\System32\tapisrv.dll 249856 2340e6977548038c88e39a9ecbb3fadc 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv\Parameters tcpip.sys C:\WINDOWS\System32\drivers\tcpip.sys 361600 9aefa14bd6b182d61e3119fa5f436d3d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Tcpip tcpipBM.sys C:\WINDOWS\system32\drivers\tcpipBM.sys 24192 74905ebcbb8cbdb1f3c0b1778bbcb4bc 15 -> HKLM\SYSTEM\CurrentControlSet\Services\tcpipBM termdd.sys C:\WINDOWS\System32\drivers\termdd.sys 40840 88155247177638048422893737429d9e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TermDD termsrv.dll C:\WINDOWS\System32\termsrv.dll 296448 52e0505408edd4ab5ccc7f83b67b4299 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters tvt_reg_monitor_svc.exe C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe 1029432 5e001a6d6263a6c7c25b50e2cbe614e7 15 -> HKLM\SYSTEM\CurrentControlSet\Services\ThinkVantage Registry Monitor Service tlntsvr.exe C:\WINDOWS\system32\tlntsvr.exe 75264 b17551ab6eaa71dca530632c15fa3d9a 3 -> HKLM\SYSTEM\CurrentControlSet\Services\TlntSvr ApsHM86.sys C:\WINDOWS\System32\drivers\ApsHM86.sys 20328 4a6e82c67fc4c48ed3f977d8fec0a2fa 3 -> HKLM\SYSTEM\CurrentControlSet\Services\TPDIGIMN TPHDEXLG.exe C:\WINDOWS\system32\TPHDEXLG.exe 39304 72fd0751ce836cafa444bbbd366645dd 3 -> HKLM\SYSTEM\CurrentControlSet\Services\TPHDEXLGSVC TPHKDRV.sys C:\WINDOWS\System32\drivers\TPHKDRV.sys 17844 8aef2188630f5ecd79ad9abba630630b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TPHKDRV TPHKLOAD.exe C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe 131432 9cd364ecb3a10b24c7cac8ff89993a67 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TPHKLOAD TPHKSVC.exe C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe 142696 c04bb65441913ab621c58a8bd3169b23 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TPHKSVC Tppwrif.sys C:\WINDOWS\System32\drivers\Tppwrif.sys 13936 9e70c240868ed6a55b3b86d4a3a59fd6 3 -> HKLM\SYSTEM\CurrentControlSet\Services\TPPWRIF trkwks.dll C:\WINDOWS\system32\trkwks.dll 90112 9e70eb419d7785c286dc458a019bab9b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TrkWks\Parameters rrpservice.exe C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe 1118208 c874a8e5619daa27d60bca80c6e5e5e6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TVT Backup Protection Service rrservice.exe C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe 1425408 2e2dddd129c1151f95640cfc4fe47660 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TVT Backup Service tvtsched.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe 1171456 c6670a6610b24e18115f00d9e1cf4644 15 -> HKLM\SYSTEM\CurrentControlSet\Services\TVT Scheduler tvtfilter.sys C:\WINDOWS\System32\drivers\tvtfilter.sys 33536 49258a02a1e8d304ed88b0f1c56b1738 15 -> HKLM\SYSTEM\CurrentControlSet\Services\tvtfilter Tvti2c.sys C:\WINDOWS\System32\drivers\Tvti2c.sys 37312 7e66dda1ef146bfc3a6e36e08e036602 3 -> HKLM\SYSTEM\CurrentControlSet\Services\TVTI2C UnlockerDriver5.sys C:\Program Files\Unlocker\UnlockerDriver5.sys 4096 bb879dcfd22926efbeb3298129898cbb 15 -> HKLM\SYSTEM\CurrentControlSet\Services\UnlockerDriver5 update.sys C:\WINDOWS\System32\drivers\update.sys 384768 402ddc88356b1bac0ee3dd1580c76a31 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Update upnphost.dll C:\WINDOWS\System32\upnphost.dll 186880 e96a6baee0b2a14a38b45830d6e30697 15 -> HKLM\SYSTEM\CurrentControlSet\Services\upnphost\Parameters ups.exe C:\WINDOWS\System32\ups.exe 18432 eb90e28b28541ec845e5345609355ca7 3 -> HKLM\SYSTEM\CurrentControlSet\Services\UPS usbccgp.sys C:\WINDOWS\System32\drivers\usbccgp.sys 32384 1b611611c28d2df25bc057d79c6f13fc 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbccgp usbehci.sys C:\WINDOWS\System32\drivers\usbehci.sys 30336 4bac8df07f1d8434fc640e677a62204e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbehci usbhub.sys C:\WINDOWS\System32\drivers\usbhub.sys 59520 1ab3cdde553b6e064d2e754efe20285c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbhub usbprint.sys C:\WINDOWS\System32\drivers\usbprint.sys 25856 a717c8721046828520c9edf31288fc00 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbprint usbscan.sys C:\WINDOWS\System32\drivers\usbscan.sys 14976 f8ede2b6928970dce3d5614c27d9e7f6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbscan USBSTOR.SYS C:\WINDOWS\System32\drivers\USBSTOR.SYS 26368 a32426d9b14a089eaa1d922e0c5801a9 15 -> HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR usbuhci.sys C:\WINDOWS\System32\drivers\usbuhci.sys 20608 26496f9dee2d787fc3e61ad54821ffe6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbuhci usbvideo.sys C:\WINDOWS\System32\drivers\usbvideo.sys 123008 813236b1183cfcf289e367bd5de6e29e 15 -> HKLM\SYSTEM\CurrentControlSet\Services\usbvideo EMP_Vd1.sys C:\WINDOWS\System32\drivers\EMP_Vd1.sys 7680 1493b3bd6faa314a8c6fae199f962105 3 -> HKLM\SYSTEM\CurrentControlSet\Services\vdisp vga.sys C:\WINDOWS\System32\drivers\vga.sys 20992 0d3a8fafceacd8b7625cd549757a7df1 15 -> HKLM\SYSTEM\CurrentControlSet\Services\VgaSave VNUSB.sys C:\WINDOWS\System32\drivers\VNUSB.sys 38496 ae01e1ed5a81e0d268b91b4a6de5a872 15 -> HKLM\SYSTEM\CurrentControlSet\Services\VNUSB vssvc.exe C:\WINDOWS\System32\vssvc.exe 291840 7f2d7bffc4554e1c742dd3629fd1fb1b 3 -> HKLM\SYSTEM\CurrentControlSet\Services\VSS w32time.dll C:\WINDOWS\system32\w32time.dll 176128 a672ca3981352f8e9c30fea056e80a62 3 -> HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Parameters httpd.exe c:\wamp\bin\apache\apache2.4.4\bin\httpd.exe 22016 a650671af9a670f678f29ff212b4950c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\wampapache mysqld.exe c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe 10923520 8b9b777a82745dddbd80d7492b1aeac1 15 -> HKLM\SYSTEM\CurrentControlSet\Services\wampmysqld wanarp.sys C:\WINDOWS\System32\drivers\wanarp.sys 34560 e20b95baedb550f32dd489265c1da1f6 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Wanarp wdf01000.sys C:\WINDOWS\System32\drivers\wdf01000.sys 444136 d918617b46457b9ac28027722e30f647 15 -> HKLM\SYSTEM\CurrentControlSet\Services\Wdf01000 wdmaud.sys C:\WINDOWS\System32\drivers\wdmaud.sys 83072 6768acf64b18196494413695f0c3a00f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\wdmaud webclnt.dll C:\WINDOWS\System32\webclnt.dll 68096 81fb88b975e25d76e00b69879d8a434c 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WebClient\Parameters HSF_CNXT.sys C:\WINDOWS\System32\drivers\HSF_CNXT.sys 738360 115946a53b62a6b171fd0ed197c71d52 15 -> HKLM\SYSTEM\CurrentControlSet\Services\winachsf WMIsvc.dll C:\WINDOWS\system32\wbem\WMIsvc.dll 145408 70c22297534a88b0ad0568900ab5a6d9 15 -> HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Parameters MsPMSNSv.dll C:\WINDOWS\system32\MsPMSNSv.dll 27136 c51b4a5c05a5475708e3c81c7765b71d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WmdmPmSN\Parameters wmiacpi.sys C:\WINDOWS\System32\drivers\wmiacpi.sys 8832 c42584fd66ce9e17403aebca199f7bdb 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WmiAcpi wmiapsrv.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe 126464 a2b12d80a1670511b047a7d8bb647598 3 -> HKLM\SYSTEM\CurrentControlSet\Services\WmiApSrv WMPNetwk.exe C:\Program Files\Windows Media Player\WMPNetwk.exe 918016 cdfa647aa82fdba6c9c7a06155afcb40 3 -> HKLM\SYSTEM\CurrentControlSet\Services\WMPNetworkSvc wpdusb.sys C:\WINDOWS\System32\drivers\wpdusb.sys 38528 cf4def1bf66f06964dc0d91844239104 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WpdUsb WPFFontCache_v0400.exe C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 754856 15673bd0b86150cb8e27766059c72a9b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WPFFontCache_v0400 ws2ifsl.sys C:\WINDOWS\System32\drivers\ws2ifsl.sys 12032 6abe6e225adb5a751622a9cc3bc19ce8 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WS2IFSL wscsvc.dll C:\WINDOWS\system32\wscsvc.dll 80896 b6669f49d42e09bc0f9889faa0f3336d 15 -> HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Parameters WSTCODEC.SYS C:\WINDOWS\System32\drivers\WSTCODEC.SYS 19200 c98b39829c2bbd34e454150633c62c78 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WSTCODEC wuauserv.dll C:\WINDOWS\system32\wuauserv.dll 6656 04550d5eb7ee82c115db547c01df09fd 15 -> HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters WudfPf.sys C:\WINDOWS\System32\drivers\WudfPf.sys 77568 f15feafffbb3644ccc80c5da584e6311 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WudfPf wudfrd.sys C:\WINDOWS\System32\drivers\wudfrd.sys 82944 28b524262bce6de1f7ef9f510ba3985b 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WudfRd WUDFSvc.dll C:\WINDOWS\System32\WUDFSvc.dll 55808 05231c04253c5bc30b26cbaae680ed89 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WudfSvc\Parameters wzcsvc.dll C:\WINDOWS\System32\wzcsvc.dll 483840 c2842273aaa77ac031edb87fa19a2147 15 -> HKLM\SYSTEM\CurrentControlSet\Services\WZCSVC\Parameters xmlprov.dll C:\WINDOWS\System32\xmlprov.dll 129024 24ed6935771359a5aef1fe8bf0c56f39 15 -> HKLM\SYSTEM\CurrentControlSet\Services\xmlprov\Parameters AcroIEHelperShim.dll C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll 60568 f9616d202b0124d373d2d82a4aa66b1d 3 -> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} ssv.dll C:\Program Files\Java\jre7\bin\ssv.dll 462760 14f5ed2452ee5ef1a711f60c07dd463c 3 -> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} URLREDIR.DLL C:\Program Files\Microsoft Office 2010\Office14\URLREDIR.DLL 562904 e04a1418b6caa33ef61f7b4ae826fc94 15 -> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF} jp2ssv.dll C:\Program Files\Java\jre7\bin\jp2ssv.dll 171944 23cf598c517104d3b0a55863875be534 3 -> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} shdocvw.dll C:\WINDOWS\system32\shdocvw.dll 1499136 9254251f76937a96877dcbe68f5290a7 3 -> HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376} -> HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E} mscoree.dll C:\WINDOWS\system32\mscoree.dll 297808 b04db1f0b2652fcbccc5fd0c46579f0f 15 -> HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{c585d593-e7f4-4852-a200-561686ee02e4} ieframe.dll C:\WINDOWS\system32\ieframe.dll 11112960 42b5fabdc78084e1d085e5ad05020944 3 -> HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks::{CFBFAE00-17A6-11D0-99CB-00C04FD64497} browseui.dll C:\WINDOWS\system32\browseui.dll 1025024 d535a311733f3d70adba7d7ac8ac4d5f 15 -> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler::{438755C2-A8BA-11D1-B96B-00A0C90312E1} -> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler::{8C7461EF-2B13-11d2-BE35-3078302C2030} xpnetdiag.exe C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 558080 aac1d4ee39df138c5d30ac5883e3b59f 15 -> HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} msmsgs.exe C:\Program Files\Messenger\msmsgs.exe 1695232 cfefdc4f940bbdeaaee76c17647becb8 3 -> HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683} IEXPRESS.EXE C:\WINDOWS\system32\IEXPRESS.EXE 114688 160dbd64aab666a31ebb8c3809edb05f 3 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\::h tftp.exe C:\WINDOWS\system32\tftp.exe 16896 a033dc9adbff91d733046a1e245c1f09 3 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\::e mspaint.exe C:\WINDOWS\system32\mspaint.exe 345088 86c35c52ad183d0d7feed70f77c40435 3 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\::n SpyHunter-Installer.exe C:\Documents and Settings\admin\Pulpit\SpyHunter-Installer.exe 3286400 29ac556acebded818f9aa954b85f92a2 15 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*::f -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe::i crashreporter.exe C:\Program Files\Mozilla Firefox\crashreporter.exe 282568 4c0be1a1d3e2be05c7bebd540f46f608 3 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe::b wer.dll E:\Dysk AdminDokumenty\Admin dokumenty\Pobieranie\wer.dll 534048 59a343c3bd792af308400b2ee5e1a924 15 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dll::d AccessibleMarshal.dll C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll 19912 97f8ee3b48a20a23884bdc5d8d74114b 3 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dll::f icuin55.dll C:\Program Files\Mozilla Firefox\icuin55.dll 1287112 542bf9151c6e6ffe7cf99b16fe855e8a 3 -> HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dll::g winrnr.dll C:\WINDOWS\System32\winrnr.dll 16896 b39ae93e06f87c364acf12b4d5df907d 3 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 nwprovau.dll C:\WINDOWS\System32\nwprovau.dll 143360 6fbfce6fb69db2cff4bfb6cd6e1f074b 3 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004 rsvpsp.dll C:\WINDOWS\system32\rsvpsp.dll 92672 fe67c92afc70994de0c60874d02170b6 3 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 -> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 logon.scr C:\WINDOWS\system32\logon.scr 220672 32c40430092ef950ac27299d45dd358b 15 -> HKU\.DEFAULT\Control Panel\Desktop::Scrnsave.exe logonui.exe C:\WINDOWS\system32\logonui.exe 515072 7a18eae605733d9dc572f6f501d30ac1 15 -> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon::UIHost FlashUtil32_21_0_0_213_pepper.exe C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_21_0_0_213_pepper.exe 1173184 35fc4d62c2210c0a389552358fe43fca 3 -> C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job PWMIDTSK.EXE C:\Program Files\ThinkPad\Utilities\PWMIDTSK.EXE 3004416 fa4744408ce97dd8097272d3c7f3100e 15 -> C:\WINDOWS\Tasks\PMTask.job launcher.exe C:\Program Files\Opera\launcher.exe 695848 b6111cceaae49b68ccea8167c1a443be 15 -> C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1446499447.job LXBXPMON.DLL C:\WINDOWS\system32\LXBXPMON.DLL 32768 e4f0d15fa5ad9056095023e6133fae97 2 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Fax Lexmark 7100 Series Port KMPJLMN.DLL C:\WINDOWS\system32\KMPJLMN.DLL 70144 73c5145f2ea80eeb6413f68f2f8baa30 2 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\KM Language Monitor PDFillWriterMon.dll C:\Program Files\PlotSoft\PDFill\PDFWriter\Driver\PDFillWriterMon.dll 28168 326bf5cbd8780233c4ffb1acb624bb99 2 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\PDFill Writer Monitor bthcrp.dll C:\WINDOWS\system32\bthcrp.dll 111904 896fb8bd35364f977b5d85b13d154932 2 -> HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Port drukarki interfejsu Bluetooth ezprint.exe C:\Program Files\Lexmark 7100 Series\ezprint.exe 61440 d2c11e7c5258b188b976ae3bf4b2d347 2 -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EzPrint fm3032.exe C:\Program Files\Lexmark 7100 Series\fm3032.exe 286720 34839abc458ca79b3f5c462cf09d0ddc 2 -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FaxCenterServer4_in_1 lxbxmon.exe C:\Program Files\Lexmark 7100 Series\lxbxmon.exe 196608 15be40d572214f017714aac459a34393 2 -> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lxbxmon.exe EMP_Map.sys C:\WINDOWS\System32\drivers\EMP_Map.sys 6400 677194565c990a89cb7dff609e98495e 2 -> HKLM\SYSTEM\CurrentControlSet\Services\EMP_MAP fbguard.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe 65536 eafa072d9bf7e2a230a3cc7107481afc 2 -> HKLM\SYSTEM\CurrentControlSet\Services\FirebirdGuardianDefaultInstance fbserver.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe 1527893 01fe3287c438d28eb6753169b1f43381 2 -> HKLM\SYSTEM\CurrentControlSet\Services\FirebirdServerDefaultInstance EP_NSWD.sys C:\WINDOWS\System32\drivers\EP_NSWD.sys 19584 d853a3d4464a736bd882c0061bda490b 2 -> HKLM\SYSTEM\CurrentControlSet\Services\Ndisprot IQWebFTPServerEngine.exe C:\Program Files\Fastream IQ Web FTP Server Engine\IQWebFTPServerEngine.exe 3221504 c9c54c185d5728028a559319f137d44e 2 -> HKLM\SYSTEM\CurrentControlSet\Services\NFService esgiguard.sys C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys 15920 881419b3d7bf48e53249ff16b00f976f 15 -> HKLM\SYSTEM\CurrentControlSet\Services\esgiguard