Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 30-10-2019 Uruchomiony przez Łukasz (administrator) ŁUKASZ-KOMPUTER (01-11-2019 09:49:13) Uruchomiony z C:\Users\Łukasz\Downloads Załadowane profile: Łukasz (Dostępne profile: Łukasz) Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ALCPU -> ALCPU) C:\Program Files\Core Temp\Core Temp.exe (Digital Wave Ltd -> Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (F.lux Software LLC -> f.lux Software LLC) C:\Users\Łukasz\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Nero AG -> ) C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (Nero AG -> Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7560296 2011-12-12] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-29] (Intel Corporation -> Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-1908724746-673112573-3840648487-1000\...\Run: [f.lux] => C:\Users\Łukasz\AppData\Local\FluxSoftware\Flux\flux.exe [1806344 2018-07-03] (F.lux Software LLC -> f.lux Software LLC) HKU\S-1-5-21-1908724746-673112573-3840648487-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19645800 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-1908724746-673112573-3840648487-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-21-1908724746-673112573-3840648487-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11012019094645375\...\Run: [f.lux] => C:\Users\Łukasz\AppData\Local\FluxSoftware\Flux\flux.exe [1806344 2018-07-03] (F.lux Software LLC -> f.lux Software LLC) HKU\S-1-5-21-1908724746-673112573-3840648487-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11012019094645375\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19645800 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-1908724746-673112573-3840648487-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11012019094645375\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Windows -> Microsoft Corporation) GroupPolicy: Ograniczenia ? <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {1972AD4F-AC6C-476F-B735-0C0137F86483} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_270_Plugin.exe [1457720 2019-10-09] (Adobe Inc. -> Adobe) Task: {3C36F11F-044A-40BE-BC12-2A616C982F94} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-10-09] (Adobe Inc. -> Adobe) Task: {84B44601-0CB7-4138-8271-04E0FC99E0CF} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-14] (Microsoft Corporation -> Microsoft Corporation) Task: {96F89D82-EEDF-4FDB-96AB-276E6BECA342} - System32\Tasks\{464C7196-C8CF-48B8-B0C3-44F55D9519B0} => C:\Windows\system32\pcalua.exe -a C:\Users\Łukasz\Desktop\setup.exe -d C:\Users\Łukasz\Desktop Task: {9ED56A22-95CE-4746-940F-94B0D906F143} - \AutoPico Daily Restart -> Brak pliku <==== UWAGA Task: {A3B95AAD-7B3C-4C7E-9EA9-2F6F1B8D450D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd) Task: {AA8CF5E1-C4F4-40C6-A162-97EF0012E480} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14679256 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd) Task: {C7A3AA8A-0104-4683-97F4-F748F79C1A6E} - System32\Tasks\Core Temp Autostart Łukasz => C:\Program Files\Core Temp\Core Temp.exe [998488 2018-05-20] (ALCPU -> ALCPU) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{60B932C8-0527-4AC3-B5F3-D6DC3A1D4422}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1908724746-673112573-3840648487-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1908724746-673112573-3840648487-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES007&pc=UE06 HKU\S-1-5-21-1908724746-673112573-3840648487-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11012019094645375\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1908724746-673112573-3840648487-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11012019094645375\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES007&pc=UE06 SearchScopes: HKLM-x32 -> DefaultScope - brak wartości BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2014-05-22] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2014-05-22] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF DefaultProfile: metegczb.default FF ProfilePath: C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\metegczb.default [2019-10-04] FF ProfilePath: C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release [2019-11-01] FF Homepage: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> www.google.pl FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: extension@tabliss.io FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: uBlock0@raymondhill.net FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: @contain-facebook FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: {506e023c-7f2b-40a3-8066-bc5deb40aebe} FF Extension: (Facebook Container) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\@contain-facebook.xpi [2019-10-04] FF Extension: (Tabliss) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\extension@tabliss.io.xpi [2019-10-09] FF Extension: (uBlock Origin) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\uBlock0@raymondhill.net.xpi [2019-10-24] FF Extension: (Worldwide Radio) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\worldwide@radio.xpi [2019-10-04] FF Extension: (Gesturefy) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2019-10-25] FF Extension: (YouTube Popout Player) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{85b42b8f-49cd-4935-aeca-a6b32dd6ac9f}.xpi [2019-10-23] FF Extension: (Dark Fox) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{e7fe4ffe-f256-4f85-906d-072fdd698585}.xpi [2019-10-04] FF Extension: (Nano Defender) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{fcf60470-b210-4c17-969e-9ae01491071e}.xpi [2019-10-04] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 => nie znaleziono FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_270.dll [2019-10-09] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_270.dll [2019-10-09] (Adobe Inc. -> ) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin HKU\S-1-5-21-1908724746-673112573-3840648487-1000: @acestream.net/acestreamplugin,version=3.1.32 -> C:\Users\Łukasz\AppData\Roaming\ACEStream\player\npace_plugin.dll [Brak pliku] FF Plugin HKU\S-1-5-21-1908724746-673112573-3840648487-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11012019094645375: @acestream.net/acestreamplugin,version=3.1.32 -> C:\Users\Łukasz\AppData\Roaming\ACEStream\player\npace_plugin.dll [Brak pliku] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.pl/ CHR StartupUrls: Default -> "hxxp://www.google.pl/" CHR DefaultSearchURL: Default -> hxxps://www.google.pl/search?source=hp&ei=FlOWXf71EojfkgW1s72QBw&q={searchTerms}&btnK=Szukaj+w+Google&oq=ublock&gs_l=psy-ab.3..0j0i131j0l8.22151.23446..23714...1.0..0.173.690.6j1......0....1..gws-wiz.....0.uWR9bk-V7no&ved=0ahUKEwj-2Lyq8IDlAhWIr6QKHbVZD3IQ4dUDCAY&uact=5 CHR Profile: C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default [2019-10-04] CHR Extension: (Video Downloader Plus) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\baejfnndpekpkaaancgpakjaengfpopk [2019-10-03] CHR Extension: (uBlock Origin) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-10-03] CHR Extension: (Nano Defender) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggolfgbegefeeoocgjbmkembbncoadlb [2019-10-03] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03] CHR Extension: (Worldwide Radio) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofncbjjbfchlegacifnndkkbdoaedcof [2019-10-03] CHR Extension: (Chrome Media Router) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-03] CHR Extension: (Eiffel Tower) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppbaibkigenhdcommebegmmmpoolmpip [2019-10-03] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [246784 2015-08-03] (Microsoft Windows Hardware Compatibility Publisher -> AMD) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-06-06] (Digital Wave Ltd -> Digital Wave Ltd.) S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3730024 2018-08-27] (AVB Disc Soft, SIA -> Disc Soft Ltd) R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2016-09-20] (Nero AG -> Nero AG) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [Brak podpisu cyfrowego] S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation) S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [Brak podpisu cyfrowego] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [Brak podpisu cyfrowego] S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [157480 2018-08-02] (Microsoft Corporation -> Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [X] S2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [X] S2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [X] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [21622784 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [665088 2015-08-03] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Windows -> Microsoft Corporation) <==== UWAGA (Brak ServiceDLL) R3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [130536 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc) R3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [395752 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [104976 2016-03-31] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2018-08-30] (Disc Soft Ltd -> Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2018-08-30] (Disc Soft Ltd -> Disc Soft Ltd) R1 epp; C:\EEK\bin64\epp.sys [176128 2019-10-02] (Emsisoft Ltd -> Emsisoft Ltd) S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (3am.com(Test) -> HTC, Corporation) S3 htcnprot; C:\Windows\System32\DRIVERS\htcnprot.sys [36928 2013-10-17] (HTC Corp. -> Windows (R) Win 7 DDK provider) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (Sqa.com(Test) -> QUALCOMM Incorporated) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-11-01] (Malwarebytes Corporation -> Malwarebytes) R2 mi2c; C:\Windows\system32\drivers\mi2c.sys [20784 2019-10-06] (AOC International (Europe) GmbH -> Nicomsoft Ltd.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [21504 2008-12-26] (AVnex Ltd. -> Avnex) R3 ALSysIO; \??\C:\Users\UKASZ~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== UWAGA S3 catchme; \??\C:\ComboFix\catchme.sys [X] U4 ekrn; Brak ImagePath S3 esihdrv; \??\C:\Users\UKASZ~1\AppData\Local\Temp\esihdrv.sys [X] <==== UWAGA ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-11-01 09:49 - 2019-11-01 09:50 - 000021782 _____ C:\Users\Łukasz\Downloads\FRST.txt 2019-11-01 09:48 - 2019-11-01 09:48 - 001619456 _____ (Farbar) C:\Users\Łukasz\Downloads\FRST64.exe 2019-11-01 09:45 - 2019-11-01 09:45 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2019-11-01 09:43 - 2019-11-01 09:43 - 000020104 _____ C:\Users\Łukasz\Documents\cc_20191101_094327.reg 2019-11-01 09:41 - 2019-11-01 09:41 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2019-11-01 09:41 - 2019-11-01 09:41 - 000001867 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2019-11-01 09:41 - 2019-11-01 09:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-11-01 09:41 - 2019-11-01 09:41 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-11-01 09:41 - 2019-11-01 09:41 - 000000000 ____D C:\Program Files\Malwarebytes 2019-11-01 09:41 - 2019-09-30 06:25 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2019-11-01 09:40 - 2019-11-01 09:41 - 067054848 _____ (Malwarebytes ) C:\Users\Łukasz\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.629-1.0.13127.exe 2019-11-01 09:22 - 2019-11-01 09:22 - 000000000 ____D C:\ProgramData\dbg 2019-11-01 09:09 - 2019-11-01 09:27 - 000000000 ____D C:\Program Files\Mozilla Firefox 2019-11-01 04:00 - 2019-08-09 11:30 - 000000001 _____ C:\Windows\y.txt 2019-11-01 03:59 - 2019-11-01 09:34 - 000000000 ____D C:\Program Files (x86)\HitmanPro.Alert 2019-11-01 03:59 - 2019-11-01 09:31 - 000000000 ____D C:\ProgramData\HitmanPro.Alert 2019-11-01 03:59 - 2019-11-01 03:59 - 000000000 ____D C:\Windows\Wget 2019-11-01 03:59 - 2019-11-01 03:59 - 000000000 ____D C:\Windows\curl 2019-10-31 16:29 - 2019-10-31 16:29 - 006312056 _____ (ESET) C:\Users\Łukasz\Downloads\sysinspector_nt64_plk.exe 2019-10-31 14:43 - 2019-10-31 14:43 - 002067103 _____ C:\Users\Łukasz\Downloads\Malwarebytes.Anti.Exploit.Premium.1.13.1.117_Startcrack.com.zip 2019-10-31 14:37 - 2019-10-31 14:37 - 000000000 ____D C:\Users\Łukasz\AppData\Local\mbam 2019-10-31 14:36 - 2019-10-31 14:36 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\Obsidium 2019-10-31 14:35 - 2019-10-31 14:42 - 000000000 ____D C:\Users\Łukasz\Downloads\Malwarebytes 2019 Full 2019-10-31 14:34 - 2019-10-31 14:34 - 064896307 _____ C:\Users\Łukasz\Downloads\Malwarebytes 2019 Full.rar 2019-10-27 05:11 - 2019-10-27 05:11 - 015450704 _____ C:\Users\Łukasz\Downloads\2c240c-2013 Audi S8 4.0TFSI quattro.rar 2019-10-27 05:04 - 2019-10-27 05:05 - 019757409 _____ C:\Users\Łukasz\Downloads\544abf-0c5585-Mercedes Benz CLS 63 AMG.zip 2019-10-26 12:22 - 2019-10-26 12:22 - 007622344 _____ (Malwarebytes) C:\Users\Łukasz\Desktop\adwcleaner_7.4.2.exe 2019-10-23 13:35 - 2019-10-23 13:35 - 000588412 _____ C:\Users\Łukasz\Downloads\OWU_i_OFERTA.pdf 2019-10-23 13:35 - 2019-10-23 13:35 - 000367623 _____ C:\Users\Łukasz\Downloads\REGULAMIN KLUBU_NOWY.pdf 2019-10-23 13:17 - 2019-10-23 13:17 - 000198538 _____ C:\Users\Łukasz\Downloads\always-on-top.rar 2019-10-23 13:12 - 2002-06-30 05:30 - 000024576 _____ () C:\Users\Łukasz\Desktop\AlwaysOnTopMaker.exe 2019-10-23 13:11 - 2019-10-23 13:11 - 000006039 _____ C:\Users\Łukasz\Downloads\AlwaysOnTopMaker.zip 2019-10-20 06:35 - 2019-10-20 06:35 - 001892368 _____ (CPUID, Inc. ) C:\Users\Łukasz\Downloads\cpu-z_1.90-en.exe 2019-10-20 06:35 - 2019-10-20 06:35 - 000000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2019-10-20 06:35 - 2019-10-20 06:35 - 000000869 _____ C:\ProgramData\Desktop\CPUID CPU-Z.lnk 2019-10-20 06:35 - 2019-10-20 06:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2019-10-20 06:35 - 2019-10-20 06:35 - 000000000 ____D C:\Program Files\CPUID 2019-10-19 15:40 - 2019-10-19 15:40 - 000000000 ____D C:\Users\Łukasz\AppData\LocalLow\Oracle 2019-10-17 11:30 - 2019-10-17 11:34 - 000000000 ____D C:\AV_LOGS 2019-10-17 11:30 - 2019-10-17 11:30 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\Avnex 2019-10-17 11:28 - 2008-12-26 06:56 - 000021504 _____ (Avnex) C:\Windows\system32\Drivers\vcsvad.sys 2019-10-17 11:26 - 2019-10-17 11:27 - 018521788 _____ C:\Users\Łukasz\Downloads\AV Voice Changer Diamond 7.0.29 (FULL witch CRACK).rar 2019-10-13 04:57 - 2019-10-13 04:58 - 000118981 _____ C:\Users\Łukasz\Downloads\FLIX-Ticket-1058967673.pdf 2019-10-09 09:37 - 2019-10-07 02:49 - 000390752 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2019-10-09 09:37 - 2019-10-07 01:57 - 000341896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2019-10-09 09:37 - 2019-10-06 00:12 - 025753088 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2019-10-09 09:37 - 2019-10-06 00:00 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2019-10-09 09:37 - 2019-10-06 00:00 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2019-10-09 09:37 - 2019-10-05 23:49 - 002909184 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2019-10-09 09:37 - 2019-10-05 23:48 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2019-10-09 09:37 - 2019-10-05 23:47 - 000579584 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2019-10-09 09:37 - 2019-10-05 23:47 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2019-10-09 09:37 - 2019-10-05 23:47 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2019-10-09 09:37 - 2019-10-05 23:46 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2019-10-09 09:37 - 2019-10-05 23:41 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2019-10-09 09:37 - 2019-10-05 23:40 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2019-10-09 09:37 - 2019-10-05 23:38 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2019-10-09 09:37 - 2019-10-05 23:37 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2019-10-09 09:37 - 2019-10-05 23:37 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2019-10-09 09:37 - 2019-10-05 23:36 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2019-10-09 09:37 - 2019-10-05 23:36 - 000797696 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2019-10-09 09:37 - 2019-10-05 23:34 - 005500928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2019-10-09 09:37 - 2019-10-05 23:32 - 020290048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2019-10-09 09:37 - 2019-10-05 23:31 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2019-10-09 09:37 - 2019-10-05 23:28 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2019-10-09 09:37 - 2019-10-05 23:28 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2019-10-09 09:37 - 2019-10-05 23:23 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2019-10-09 09:37 - 2019-10-05 23:22 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2019-10-09 09:37 - 2019-10-05 23:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2019-10-09 09:37 - 2019-10-05 23:19 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2019-10-09 09:37 - 2019-10-05 23:19 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2019-10-09 09:37 - 2019-10-05 23:18 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2019-10-09 09:37 - 2019-10-05 23:18 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2019-10-09 09:37 - 2019-10-05 23:17 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2019-10-09 09:37 - 2019-10-05 23:17 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2019-10-09 09:37 - 2019-10-05 23:17 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2019-10-09 09:37 - 2019-10-05 23:16 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2019-10-09 09:37 - 2019-10-05 23:16 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2019-10-09 09:37 - 2019-10-05 23:15 - 002302464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2019-10-09 09:37 - 2019-10-05 23:12 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2019-10-09 09:37 - 2019-10-05 23:12 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2019-10-09 09:37 - 2019-10-05 23:11 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2019-10-09 09:37 - 2019-10-05 23:10 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2019-10-09 09:37 - 2019-10-05 23:10 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2019-10-09 09:37 - 2019-10-05 23:10 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2019-10-09 09:37 - 2019-10-05 23:07 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2019-10-09 09:37 - 2019-10-05 23:05 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2019-10-09 09:37 - 2019-10-05 23:05 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2019-10-09 09:37 - 2019-10-05 23:03 - 002132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2019-10-09 09:37 - 2019-10-05 23:03 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2019-10-09 09:37 - 2019-10-05 23:03 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2019-10-09 09:37 - 2019-10-05 23:00 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2019-10-09 09:37 - 2019-10-05 23:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2019-10-09 09:37 - 2019-10-05 22:59 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2019-10-09 09:37 - 2019-10-05 22:58 - 015413760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2019-10-09 09:37 - 2019-10-05 22:57 - 004859904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2019-10-09 09:37 - 2019-10-05 22:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2019-10-09 09:37 - 2019-10-05 22:56 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2019-10-09 09:37 - 2019-10-05 22:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2019-10-09 09:37 - 2019-10-05 22:55 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2019-10-09 09:37 - 2019-10-05 22:53 - 004112384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2019-10-09 09:37 - 2019-10-05 22:50 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2019-10-09 09:37 - 2019-10-05 22:49 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2019-10-09 09:37 - 2019-10-05 22:48 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2019-10-09 09:37 - 2019-10-05 22:48 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2019-10-09 09:37 - 2019-10-05 22:45 - 013808640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2019-10-09 09:37 - 2019-10-05 22:45 - 001566208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2019-10-09 09:37 - 2019-10-05 22:35 - 004387840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2019-10-09 09:37 - 2019-10-05 22:34 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2019-10-09 09:37 - 2019-10-05 22:32 - 001331712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2019-10-09 09:37 - 2019-10-05 22:30 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2019-10-09 09:37 - 2019-09-19 00:27 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll 2019-10-09 09:37 - 2019-09-16 22:32 - 004060896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2019-10-09 09:37 - 2019-09-16 22:32 - 003966688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2019-10-09 09:37 - 2019-09-16 22:32 - 000709856 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2019-10-09 09:37 - 2019-09-16 22:32 - 000627424 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2019-10-09 09:37 - 2019-09-16 22:31 - 005552864 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2019-10-09 09:37 - 2019-09-16 22:31 - 001319496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2019-10-09 09:37 - 2019-09-16 22:31 - 000263904 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2019-10-09 09:37 - 2019-09-16 22:31 - 000155360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2019-10-09 09:37 - 2019-09-16 22:31 - 000096992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2019-10-09 09:37 - 2019-09-16 22:30 - 001670784 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000834048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000555520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:29 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 001211392 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 001010176 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000408576 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:28 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 22:04 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll 2019-10-09 09:37 - 2019-09-16 22:03 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2019-10-09 09:37 - 2019-09-16 22:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2019-10-09 09:37 - 2019-09-16 22:00 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2019-10-09 09:37 - 2019-09-16 22:00 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2019-10-09 09:37 - 2019-09-16 21:59 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2019-10-09 09:37 - 2019-09-16 21:59 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2019-10-09 09:37 - 2019-09-16 21:59 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2019-10-09 09:37 - 2019-09-16 21:59 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2019-10-09 09:37 - 2019-09-16 21:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2019-10-09 09:37 - 2019-09-16 21:57 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2019-10-09 09:37 - 2019-09-16 21:57 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 21:57 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 21:57 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 21:57 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2019-10-09 09:37 - 2019-09-16 21:56 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2019-10-09 09:37 - 2019-09-16 21:56 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys 2019-10-09 09:37 - 2019-09-16 21:55 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2019-10-09 09:37 - 2019-09-16 21:53 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2019-10-09 09:37 - 2019-09-16 21:53 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2019-10-09 09:37 - 2019-09-16 21:52 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2019-10-09 09:37 - 2019-09-16 21:52 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2019-10-09 09:37 - 2019-09-16 21:52 - 000169984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2019-10-09 09:37 - 2019-09-16 21:52 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2019-10-09 09:37 - 2019-09-16 21:51 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2019-10-09 09:37 - 2019-09-16 21:51 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys 2019-10-09 09:37 - 2019-09-16 21:51 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys 2019-10-09 09:37 - 2019-09-16 21:51 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys 2019-10-09 09:37 - 2019-09-16 21:51 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys 2019-10-09 09:37 - 2019-09-16 21:51 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys 2019-10-09 09:37 - 2019-09-16 21:51 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2019-10-09 09:37 - 2019-09-16 20:13 - 000455392 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2019-10-09 09:37 - 2019-09-11 00:56 - 000353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2019-10-09 09:37 - 2019-09-11 00:56 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll 2019-10-09 09:37 - 2019-09-09 22:27 - 000383488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2019-10-09 09:37 - 2019-09-09 22:27 - 000320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll 2019-10-09 09:37 - 2019-09-09 22:27 - 000160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll 2019-10-09 09:37 - 2019-09-09 22:24 - 001281536 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll 2019-10-09 09:37 - 2019-09-09 22:24 - 000486912 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2019-10-09 09:37 - 2019-09-09 22:24 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll 2019-10-09 09:37 - 2019-09-09 22:24 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll 2019-10-09 09:37 - 2019-09-09 22:24 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll 2019-10-09 09:37 - 2019-09-09 22:24 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll 2019-10-09 09:37 - 2019-09-09 22:02 - 006135296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2019-10-09 09:37 - 2019-09-09 22:00 - 000361472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe 2019-10-09 09:37 - 2019-09-09 22:00 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE 2019-10-09 09:37 - 2019-09-09 22:00 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe 2019-10-09 09:37 - 2019-09-09 22:00 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe 2019-10-09 09:37 - 2019-09-09 22:00 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll 2019-10-09 09:37 - 2019-09-09 21:54 - 003231744 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2019-10-09 09:37 - 2019-09-09 21:53 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2019-10-09 09:37 - 2019-09-09 21:53 - 000152576 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE 2019-10-09 09:37 - 2019-09-09 21:53 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe 2019-10-09 09:37 - 2019-09-09 21:53 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe 2019-10-09 09:37 - 2019-09-09 21:52 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\monitor.sys 2019-10-09 09:37 - 2019-09-09 21:49 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2019-10-09 09:37 - 2019-09-09 20:09 - 007082496 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2019-10-09 09:37 - 2019-09-09 20:09 - 003187712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2019-10-04 09:21 - 2019-09-11 23:53 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2019-10-04 09:21 - 2019-09-11 23:52 - 000373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2019-10-04 09:21 - 2019-09-11 23:52 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2019-10-04 09:21 - 2019-09-11 23:44 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2019-10-04 09:21 - 2019-09-11 23:44 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2019-10-04 09:21 - 2019-09-11 23:44 - 000438784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2019-10-04 09:21 - 2019-09-11 23:44 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2019-10-04 09:21 - 2019-09-11 23:44 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2019-10-04 09:21 - 2019-09-11 23:24 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2019-10-04 05:00 - 2019-11-01 09:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-10-04 05:00 - 2019-10-04 05:00 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-10-04 05:00 - 2019-10-04 05:00 - 000000924 _____ C:\Users\Public\Desktop\Firefox.lnk 2019-10-04 05:00 - 2019-10-04 05:00 - 000000924 _____ C:\ProgramData\Desktop\Firefox.lnk 2019-10-04 05:00 - 2019-10-04 05:00 - 000000000 ____D C:\Users\Łukasz\AppData\Local\Mozilla 2019-10-04 04:54 - 2019-10-04 04:54 - 000021758 _____ C:\ComboFix.txt 2019-10-04 04:45 - 2011-06-26 02:45 - 000256000 _____ C:\Windows\PEV.exe 2019-10-04 04:45 - 2010-11-07 13:20 - 000208896 _____ C:\Windows\MBR.exe 2019-10-04 04:45 - 2009-04-20 00:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2019-10-04 04:45 - 2000-08-30 20:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2019-10-04 04:45 - 2000-08-30 20:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2019-10-04 04:45 - 2000-08-30 20:00 - 000098816 _____ C:\Windows\sed.exe 2019-10-04 04:45 - 2000-08-30 20:00 - 000080412 _____ C:\Windows\grep.exe 2019-10-04 04:45 - 2000-08-30 20:00 - 000068096 _____ C:\Windows\zip.exe 2019-10-04 04:43 - 2019-10-04 04:54 - 000000000 ____D C:\Qoobox 2019-10-04 04:43 - 2019-10-04 04:52 - 000000000 ____D C:\Windows\erdnt 2019-10-04 04:40 - 2019-11-01 09:50 - 000000000 ____D C:\FRST 2019-10-04 04:35 - 2019-10-04 04:35 - 000000000 ____D C:\Windows\system32\Drivers\etc\BACKUP 2019-10-04 04:24 - 2019-10-04 04:24 - 000000826 _____ C:\Users\Łukasz\Documents\hosts.txt 2019-10-03 18:30 - 2019-10-03 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange 2019-10-03 18:30 - 2019-10-03 18:30 - 000000000 ____D C:\Program Files\Tracker Software 2019-10-03 13:20 - 2019-10-04 04:14 - 000000000 ____D C:\Windows\Minidump 2019-10-03 12:00 - 2019-10-03 12:00 - 000000000 _____ C:\autoexec.bat 2019-10-03 11:59 - 2019-10-03 15:53 - 000000000 ____D C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP 2019-10-03 11:39 - 2019-10-03 12:02 - 000000000 ____D C:\Windows\CryptoGuard 2019-10-03 11:33 - 2019-10-03 11:59 - 000000000 ____D C:\ProgramData\Sophos 2019-10-03 11:22 - 2019-11-01 03:59 - 000000000 ____D C:\ProgramData\HitmanPro 2019-10-03 10:06 - 2019-10-03 10:06 - 000000000 ____D C:\ProgramData\Emsisoft 2019-10-03 10:05 - 2019-10-03 10:39 - 000000000 ____D C:\EEK 2019-10-03 08:51 - 2019-10-03 08:51 - 000000000 ____D C:\Users\Łukasz\AppData\Local\ESET 2019-10-03 07:43 - 2019-10-03 16:05 - 000000000 ____D C:\Program Files\Common Files\AV 2019-10-03 07:37 - 2019-10-03 13:34 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2019-10-03 06:52 - 2019-10-03 06:52 - 000005378 _____ C:\Users\Łukasz\Documents\cc_20191003_125246.reg 2019-10-03 05:33 - 2019-10-03 05:33 - 000000000 ____D C:\Users\Łukasz\AppData\Local\mbamtray ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-11-01 09:48 - 2018-08-30 04:57 - 000000000 ____D C:\Program Files\CCleaner 2019-11-01 09:47 - 2019-08-27 08:00 - 000000000 ____D C:\Users\Łukasz\AppData\LocalLow\Mozilla 2019-11-01 09:45 - 2019-06-08 13:21 - 000000000 ____D C:\Users\Łukasz\AppData\Local\HTC MediaHub 2019-11-01 09:45 - 2018-08-30 03:04 - 000000000 ____D C:\Program Files\Core Temp 2019-11-01 09:45 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-11-01 09:43 - 2009-07-14 00:45 - 000021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2019-11-01 09:43 - 2009-07-14 00:45 - 000021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2019-11-01 09:41 - 2011-04-12 09:21 - 000740098 _____ C:\Windows\system32\perfh015.dat 2019-11-01 09:41 - 2011-04-12 09:21 - 000155672 _____ C:\Windows\system32\perfc015.dat 2019-11-01 09:41 - 2009-07-14 01:13 - 001669190 _____ C:\Windows\system32\PerfStringBackup.INI 2019-11-01 09:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf 2019-11-01 09:07 - 2018-08-29 18:33 - 000109976 _____ C:\Users\Łukasz\AppData\Local\GDIPFONTCACHEV1.DAT 2019-10-31 15:56 - 2018-08-30 03:11 - 000000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit 2019-10-23 02:32 - 2019-06-24 16:19 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\audacity 2019-10-22 02:48 - 2009-07-14 01:08 - 000032604 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2019-10-17 11:34 - 2018-08-29 18:07 - 000000000 ____D C:\Users\Łukasz 2019-10-16 14:09 - 2018-08-30 04:57 - 000004128 _____ C:\Windows\system32\Tasks\CCleaner Update 2019-10-10 05:19 - 2009-07-14 00:45 - 000418752 _____ C:\Windows\system32\FNTCACHE.DAT 2019-10-10 05:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\PolicyDefinitions 2019-10-09 18:50 - 2018-08-29 18:29 - 001640860 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2019-10-09 18:49 - 2018-08-29 19:02 - 000000000 ____D C:\Windows\system32\MRT 2019-10-09 18:47 - 2018-08-29 19:02 - 127230528 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2019-10-09 17:57 - 2019-09-20 16:31 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe 2019-10-09 17:57 - 2019-09-20 16:31 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2019-10-09 17:57 - 2019-09-20 16:31 - 000004536 _____ C:\Windows\system32\Tasks\Adobe Flash Player NPAPI Notifier 2019-10-09 17:57 - 2019-09-20 16:31 - 000004382 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater 2019-10-09 17:57 - 2019-09-20 16:31 - 000000000 ____D C:\Windows\system32\Macromed 2019-10-09 17:57 - 2019-02-01 18:37 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2019-10-06 16:51 - 2018-08-30 06:43 - 000000000 ____D C:\Users\Łukasz\Documents\Pliki programu Outlook 2019-10-06 16:25 - 2019-08-22 12:32 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\PhotoScape 2019-10-06 16:15 - 2019-08-22 12:32 - 000003072 ____H C:\Users\Łukasz\Desktop\photothumb.db 2019-10-06 16:11 - 2018-08-30 03:44 - 000000000 ____D C:\Users\Public\Documents\Catch! 2019-10-06 16:11 - 2018-08-30 03:44 - 000000000 ____D C:\ProgramData\Documents\Catch! 2019-10-06 13:50 - 2019-02-28 15:14 - 000020784 _____ (Nicomsoft Ltd.) C:\Windows\system32\Drivers\mi2c.sys 2019-10-06 13:50 - 2019-02-28 15:14 - 000000000 ____D C:\Program Files (x86)\SmartControl-4.3.12 2019-10-04 05:08 - 2018-08-29 18:10 - 000000000 ____D C:\Program Files (x86)\Google 2019-10-04 05:00 - 2019-08-27 08:00 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\Mozilla 2019-10-04 04:52 - 2009-07-13 22:34 - 000000215 _____ C:\Windows\system.ini 2019-10-03 18:31 - 2019-01-18 18:02 - 000000000 ____D C:\Program Files (x86)\Adobe 2019-10-03 15:59 - 2018-08-29 18:10 - 000000000 ____D C:\Users\Łukasz\AppData\Local\Google 2019-10-03 12:53 - 2019-02-16 12:37 - 000000623 _____ C:\Users\Public\Desktop\Spintires - MudRunner.lnk 2019-10-03 12:53 - 2019-02-16 12:37 - 000000623 _____ C:\ProgramData\Desktop\Spintires - MudRunner.lnk 2019-10-03 09:53 - 2018-08-30 04:55 - 000000000 ____D C:\Program Files\KMSpico 2019-10-03 07:14 - 2019-08-30 06:54 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 2019-10-03 07:14 - 2019-08-30 06:54 - 000000000 ____D C:\Users\Łukasz\AppData\Local\Discord ==================== Pliki w katalogu głównym wybranych folderów ======== 2019-04-05 15:16 - 2019-04-05 15:16 - 000000017 _____ () C:\Users\Łukasz\AppData\Local\resmon.resmoncfg 2018-11-11 06:45 - 2018-11-11 06:45 - 000000000 _____ () C:\Users\Łukasz\AppData\Local\{D42C1416-EC80-41BF-952F-E43A65B7A715} ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================