Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 05-04-2020 Uruchomiony przez Magda Wcisło (administrator) MAGDA (ASUSTeK COMPUTER INC. TP300LA) (09-04-2020 10:11:07) Uruchomiony z C:\Users\Magda Wcisło\Desktop\FILE Załadowane profile: Magda Wcisło (Dostępne profile: Magda Wcisło) Platform: Windows 10 Home Wersja 1909 18363.720 (X64) Język: Polski (Polska) Domyślna przeglądarka: Edge Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel® Trusted Connect Service -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GetHelp_10.2002.30711.0_x64__8wekyb3d8bbwe\GetHelp.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.18017.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20022.82.0_x64__8wekyb3d8bbwe\YourPhoneServer\YourPhoneServer.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20022.11011.0_x64__8wekyb3d8bbwe\Music.UI.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [ASUS HDD Protection Tray Application] => C:\Program Files (x86)\ST Microelectronics\ST_ACCEL\FFP_Manager.exe [54272 2014-02-12] (STMicroelectronics) [Brak podpisu cyfrowego] HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [606296 2014-10-02] (Waves Inc -> Waves Audio Ltd.) [Brak podpisu cyfrowego] HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (Shenzhen Jia Xing Investment Co., Ltd. -> AimerSoft) HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [63296 2014-08-20] (ASUS Cloud Corporation -> ) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5314096 2020-03-06] (Adobe Inc. -> Adobe Systems Inc.) HKLM-x32\...\Run: [] => [X] HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5557296 2020-03-06] (Adobe Inc. -> Adobe Systems Incorporated) HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\...\Run: [Napisy24Update] => C:\Program Files (x86)\Napisy24\Napisy24Update.exe [3990528 2018-02-02] (Napisy24.pl) [Brak podpisu cyfrowego] HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\...\Run: [Napisy24.pl] => C:\Program Files (x86)\Napisy24\Napisy24.exe [7487488 2019-06-19] (Napisy24.pl) [Brak podpisu cyfrowego] HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\...\MountPoints2: {5d93632e-104a-11e6-83d2-4851b7a63fdd} - "E:\AutoRun.exe" HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\...\MountPoints2: {fbd98fa1-a6d7-11e9-86c5-de2d86135529} - "E:\AutoRun.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.92\Installer\chrmstp.exe [2020-04-09] (Google LLC -> Google LLC) Startup: C:\Users\Magda Wcisło\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk [2016-02-03] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation) FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {189CA6DD-F93B-4DE2-AA87-9FE09D38A79C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA Task: {1A4107A9-3204-4E45-9B35-437D77F6A3CD} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16403712 2015-08-14] (Realtek Semiconductor Corp -> Realtek Semiconductor) Task: {2742AE3C-032A-4328-A088-50A950AE073C} - System32\Tasks\AdobeGCInvoker-1.0-Magda-Magda => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {28952983-1644-4200-B6FD-25D031F8F949} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19853392 2014-09-11] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe Task: {3621D158-E387-44EE-B386-9BF9120097A5} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA Task: {47D067E2-CDD5-4B65-A35E-10E431A95AF2} - System32\Tasks\{885A5A7A-88C5-45A0-BE68-B3FF0960BE8F} => C:\WINDOWS\system32\pcalua.exe -a "C:\Users\Magda Wcisło\AppData\Roaming\yoursearching\UninstallManager.exe" -c -ptid=cornl Task: {4AE332A3-CDA4-4767-8661-43C267B845D3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA Task: {4BE5F9FF-D877-4C44-A104-130B8B7795DD} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe Task: {538B9A25-9A2B-4CD2-A07C-2910336B0217} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {587A304E-DF6F-4981-8A3E-880B22B7F5CF} - System32\Tasks\klcp_update => CodecTweakTool.exe Task: {5A3FB241-0B11-4EA5-BC66-0D9F1B406040} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM => {C8367320-6F85-11E0-A1F0-0800200C9A66} C:\WINDOWS\System32\BthTelemetry.dll [32256 2019-03-19] (Microsoft Windows -> Microsoft Corporation) Task: {5BA8B2DA-3434-45AB-AB30-BBCCEF899158} - System32\Tasks\{E97C2FF8-D3F7-4E4C-920A-A1DA6BF31FBA} => C:\WINDOWS\system32\pcalua.exe -a "C:\Users\Magda Wcisło\AppData\Roaming\mysites123\UninstallManager.exe" -c -ptid=amt Task: {5CF6F65C-97B9-4D92-BEAB-AA99CBF4F8BF} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA Task: {5EB775AC-69FE-423D-A70C-F08C2CFFC839} - \WPD\SqmUpload_S-1-5-21-1759528249-1563250885-1912870111-1001 -> Brak pliku <==== UWAGA Task: {5EEF1506-E8E4-413A-B9E4-622296E711F4} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [120632 2014-06-11] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {6DA30928-130F-473E-8776-AD799C09F6DD} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1271424 2014-09-02] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) [Brak podpisu cyfrowego] Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Task: {6EBAFAC5-6527-4B6D-83BA-EF2230D65EC1} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [17920 2016-08-01] () [Brak podpisu cyfrowego] Task: {73EADED8-0EFF-4463-AB79-3269E424BD2D} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA Task: {7D487599-5889-45A2-A57B-5750A18366A7} - System32\Tasks\ASUS Patch for Touch Panel => C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe [158336 2013-01-09] (ASUSTeK Computer Inc. -> ASUSTek Computer INC.) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE} Task: {8F89DFC5-195B-467C-BEA5-9BC41FD91B3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA Task: {924D4E3A-D3B7-480D-9DED-CE97E3680AE4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\Adobe Acrobat Update Task" /ENABLE Task: {924D4E3A-D3B7-480D-9DED-CE97E3680AE4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\AdobeGCInvoker-1.0-Magda-Magda" /ENABLE Task: {924D4E3A-D3B7-480D-9DED-CE97E3680AE4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\Antivirus Emergency Update" /ENABLE Task: {924D4E3A-D3B7-480D-9DED-CE97E3680AE4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE Task: {924D4E3A-D3B7-480D-9DED-CE97E3680AE4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE Task: {924D4E3A-D3B7-480D-9DED-CE97E3680AE4} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE Task: {9291E1BA-0146-458A-9739-E9A3B00EC2FF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-11-26] (Google Inc -> Google Inc.) Task: {9688C59A-5854-4F70-B5BA-C877E05C3DF6} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [17920 2016-08-01] () [Brak podpisu cyfrowego] Task: {96E2784D-66C1-49D3-91A3-3077E46A13D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-11-26] (Google Inc -> Google Inc.) Task: {9B3E4D98-AE67-4912-A151-651E1CE046F1} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1403136 2015-08-14] (Realtek Semiconductor Corp -> Realtek Semiconductor) Task: {9FC2FA94-DB90-44F3-BE80-A58710EC9F6E} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [17920 2016-08-01] () [Brak podpisu cyfrowego] Task: {9FD3A0D3-6F76-4D60-963F-B57610165CB6} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [62536 2014-09-11] (ASUSTeK Computer Inc. -> ASUS) Task: {AF3319C3-F11F-41FC-8884-1D78448966B0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AFD47AF1-667E-4610-82AD-D3A98D77A483} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {BEA5CD2F-431F-4618-9740-4F5EC9CF202A} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA Task: {C33240EF-EB1F-4670-B198-6E5A1E4DC78F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA Task: {C6028D3D-1D34-41CE-BAD0-841EFB619A6D} - System32\Tasks\e-pity2019a_kwiecien => C:\Program Files (x86)\e-file\e-pity\Assets\signxml.exe [2256152 2020-01-23] (e-file sp. z o.o. -> e-file sp. z o.o. sp. k.) Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Task: {DA84F58C-D061-4EA2-AAE1-C1B1ED3A97E6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems) Task: {DD4D7E5D-EA62-4A80-9B60-AE79A6BD8A0C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA Task: {E27FAC20-DD03-458D-BDC9-B5DF3615ED3D} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA Task: {E5D06F33-5B86-41A7-BB86-DE17EFEC2C54} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA} Task: {E5FDF6BD-C5FE-4C75-9690-0B9D7174A63D} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe Task: {E776D782-A833-4210-8DC2-DA3593EAD9C7} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA Task: {E90FB6E6-2A2C-457D-87F7-5CEFF60FA1B3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA Task: {FA9D3DDC-40B9-48DD-ABEF-C744C993D66C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FEAA7C66-9D31-4843-89D8-6B9F0120305D} - System32\Tasks\e-pity2019_styczen => C:\Program Files (x86)\e-file\e-pity\Assets\signxml.exe [2256152 2020-01-23] (e-file sp. z o.o. -> e-file sp. z o.o. sp. k.) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 31.11.202.254 37.8.214.2 Tcpip\..\Interfaces\{19ff5d09-b7af-4e1a-956a-9b98d6d07f93}: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{5b102a18-5a0c-4ba4-906a-be5eb969d268}: [DhcpNameServer] 31.11.202.254 37.8.214.2 Tcpip\..\Interfaces\{904efe77-9a02-4bd6-a16e-7c06c319e230}: [DhcpNameServer] 192.168.42.129 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) FireFox: ======== FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-06-10] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-12-18] (Foxit Corporation -> ) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-12-18] (Foxit Corporation -> ) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-09-03] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-09-03] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default [2020-04-09] CHR DownloadDir: C:\Users\Magda Wcisło\Desktop\FILE CHR Notifications: Default -> hxxps://teach.classdojo.com; hxxps://www.facebook.com; hxxps://www.instagram.com CHR StartupUrls: Default -> "hxxp://www.google.pl/" CHR DefaultSearchURL: Default -> hxxps://boardgamearena.com/theme/img/favicon/android-icon-36x36.png CHR Extension: (Dysk Google) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-13] CHR Extension: (YouTube) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-13] CHR Extension: (uBlock Origin) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-02-06] CHR Extension: (Google Search) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-13] CHR Extension: (AdBlock — best ad blocker) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-04-05] CHR Extension: (VoiceNote II - Speech to text) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfknjgplnkgjihghcidajejfmldhibfm [2016-05-25] CHR Extension: (VoiceNote II - Speech to text) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\jimdfkeocobeeldobhpakapbhdeample [2016-05-28] CHR Extension: (Board Game Arena) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\njlcpjiladhhaadekdabogmglfkaphio [2019-08-09] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-05] CHR Extension: (Gmail) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15] CHR Extension: (Chrome Media Router) - C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-09] CHR Profile: C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-11-17] CHR Profile: C:\Users\Magda Wcisło\AppData\Local\Google\Chrome\User Data\System Profile [2019-03-11] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] CHR HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] CHR HKU\S-1-5-21-1759528249-1563250885-1912870111-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S4 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3117648 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2888272 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) S4 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [71168 2014-08-20] (ASUS Cloud Corporation) [Brak podpisu cyfrowego] R2 esifsvc; C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe [1714320 2017-11-30] (Intel Corporation -> Intel Corporation) R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [190208 2016-11-11] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-11-30] (Intel(R) pGFX -> Intel Corporation) R2 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel® Trusted Connect Service -> Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-09-03] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) S4 TransformService; C:\Program Files\ASUS\ASUS FlipLock\TransformService.exe [64512 2014-10-01] (ASUS) [Brak podpisu cyfrowego] R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe [492768 2017-06-21] (Wondershare Technology Co.,Ltd -> Wondershare) R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-07-09] (Wondershare Technology Co.,Ltd -> Wondershare) S3 AvgWscReporter; "C:\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe" /runassvc [X] S2 WsDrvInst; C:\Program Files (x86)\Wondershare\drfone\Library\DriverInstaller\DriverInstall.exe [X] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 ATP; C:\WINDOWS\System32\drivers\AsusTP.sys [101368 2015-12-14] (ASUSTeK Computer Inc. -> ASUS Corporation) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [231936 2019-09-13] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 esif_lf; C:\WINDOWS\System32\drivers\esif_lf.sys [392160 2017-11-30] (Intel Corporation -> Intel Corporation) R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32680 2019-08-07] (ASUSTek Computer Inc. -> ASUS) S3 huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [83456 2010-05-22] (Huawei Technologies Co., Ltd.) [Brak podpisu cyfrowego] S3 hwdatacard; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [120704 2010-03-25] (Huawei Technologies Co., Ltd.) [Brak podpisu cyfrowego] R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230144 2016-11-11] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) S0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [77992 2014-08-04] (Intel(R) Software -> Intel Corporation) R3 INVN_MotionApps; C:\WINDOWS\System32\drivers\WUDFRd.sys [297984 2019-03-19] (Microsoft Windows -> Microsoft Corporation) R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-06] (ASUSTeK Computer Inc. -> ) S3 kxspb; C:\WINDOWS\System32\drivers\kxspb.sys [40976 2014-10-21] (Kionix Inc -> Kionix, Inc.) S3 massfilter; C:\WINDOWS\System32\drivers\massfilter.sys [11776 2010-08-10] (Microsoft Windows Hardware Compatibility Publisher -> ZTE Incorporated) R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85048 2016-11-18] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, Inc.) R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [3525896 2016-11-09] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) R3 SensorsAlsDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [297984 2019-03-19] (Microsoft Windows -> Microsoft Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R0 stdcfltn; C:\WINDOWS\System32\DRIVERS\stdcfltn.sys [23216 2014-08-19] (STMicroelectronics -> ST Microelectronics) R3 ST_Accel; C:\WINDOWS\system32\DRIVERS\ST_Accel.sys [125104 2014-06-06] (STMicroelectronics -> STMicroelectronics) S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [35784 2017-02-10] (Avira Operations GmbH & Co. KG -> The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation) S3 ZTEusbnet; C:\WINDOWS\System32\drivers\ZTEusbnet.sys [137728 2010-08-10] (Microsoft Windows Hardware Compatibility Publisher -> ZTE Corporation) S3 ZTEusbnmea; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys [123520 2010-08-10] (Microsoft Windows Hardware Compatibility Publisher -> ZTE Incorporated) S3 ZTEusbser6k; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys [123520 2010-08-10] (Microsoft Windows Hardware Compatibility Publisher -> ZTE Incorporated) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-04-09 10:09 - 2020-04-09 10:11 - 000000000 ____D C:\FRST 2020-04-09 09:37 - 2020-04-09 09:37 - 000138104 _____ C:\Users\Magda Wcisło\Desktop\Wielkanocna wyliczanka - treść.pdf 2020-04-08 17:31 - 2020-04-08 18:07 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\4. czwartek - wierszyk 2020-04-06 11:37 - 2020-04-08 13:15 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\wiedza, pomysły 2020-03-30 09:59 - 2020-04-06 10:51 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\matematyka online 2020-03-19 11:52 - 2020-04-09 10:11 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\FILE 2020-03-19 11:00 - 2020-04-08 20:11 - 000000000 ___RD C:\Users\Magda Wcisło\Desktop\online 2020-03-15 10:19 - 2020-03-15 10:19 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2020-03-15 10:19 - 2020-03-15 10:19 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2020-03-15 10:19 - 2020-03-15 10:19 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2020-03-15 10:19 - 2020-03-15 10:19 - 006520776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-03-15 10:19 - 2020-03-15 10:19 - 004563416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2020-03-15 10:19 - 2020-03-15 10:19 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2020-03-15 10:19 - 2020-03-15 10:19 - 001398584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2020-03-15 10:19 - 2020-03-15 10:19 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2020-03-15 10:19 - 2020-03-15 10:19 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2020-03-15 10:19 - 2020-03-15 10:19 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2020-03-15 10:19 - 2020-03-15 10:19 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 019812352 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 018027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 011607552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 009711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 007755776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 006285312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 006084344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 005911040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 005112832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 004855808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 004580352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 004129648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 003971808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 003819520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 003799552 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 003488768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 003243296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 002956688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002875904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 002773568 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002768440 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2020-03-12 19:35 - 2020-03-12 19:35 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2020-03-12 19:35 - 2020-03-12 19:35 - 002740736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002698040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 002584008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002315680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002307584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002259872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002224952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002087376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002072664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002031104 _____ C:\WINDOWS\system32\rdpnano.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 002021888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001999952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001985104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001867816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001835128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001770552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001684992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001665416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001490640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001484600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001417976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001284096 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001283600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2020-03-12 19:35 - 2020-03-12 19:35 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001273856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001264128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001218632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001190912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001108040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001098720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001088000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001054376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001031680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001007672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000935040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000929144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000877232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000776488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000769552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000757632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000734720 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000668296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000627216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000613888 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000605896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000551824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxs.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000526848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000478792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2020-03-12 19:35 - 2020-03-12 19:35 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2020-03-12 19:35 - 2020-03-12 19:35 - 000403456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000320312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcomapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000260920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000248064 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacEncoder.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000221200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000213984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeHelper.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000165504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000164776 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpclean.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000136328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NdisImPlatform.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000133944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000130112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000120560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000107832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000102760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000098104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000089568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000068408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceReactivation.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmRes.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmapi.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000042336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbs.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afunix.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmtask.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxstrace.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Drivers\afunix.sys 2020-03-12 19:35 - 2020-03-12 19:35 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000019768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MUILanguageCleanup.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\LangCleanupSysprepAction.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe 2020-03-12 19:35 - 2020-03-12 19:35 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetupproxyserv.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2020-03-12 19:35 - 2020-03-12 19:35 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2020-03-12 19:34 - 2020-03-12 19:35 - 000796904 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 007905784 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 006436352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 004622280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 004471296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 004048896 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 003728896 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 003587896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 003552768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 003371720 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 003260928 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 003143168 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002870272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002808832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002715648 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 002522112 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002474496 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002289152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 002157056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001972536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001823232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001762304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2020-03-12 19:34 - 2020-03-12 19:34 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001657120 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001581056 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001513040 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 001481216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 001428992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 001396152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2020-03-12 19:34 - 2020-03-12 19:34 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001260480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 001180160 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001071184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000983896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000945384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000908504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000833616 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000802304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000741392 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000642216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000636848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxs.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000540672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2020-03-12 19:34 - 2020-03-12 19:34 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000531768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2020-03-12 19:34 - 2020-03-12 19:34 - 000522384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000429880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Acx01000.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000306696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000250896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000234984 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000224056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000222520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ataport.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000208696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000201744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000201528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000199992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000183608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000180232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000174392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000146712 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000141840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000128312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000120048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Taskbar.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2020-03-12 19:34 - 2020-03-12 19:34 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000089616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000066336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlrmdr.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmRes.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000056632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pciidex.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000048256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbs.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS 2020-03-12 19:34 - 2020-03-12 19:34 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxstrace.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000030008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\atapi.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000029712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tbs.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000019984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelide.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000016912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pciide.sys 2020-03-12 19:34 - 2020-03-12 19:34 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe 2020-03-12 19:34 - 2020-03-12 19:34 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll 2020-03-12 19:34 - 2020-03-12 19:34 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUserRes.dll 2020-03-12 19:27 - 2020-02-11 06:48 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2020-03-12 19:27 - 2020-02-11 06:37 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-04-09 09:59 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2020-04-09 09:55 - 2019-07-09 10:53 - 001768484 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2020-04-09 09:55 - 2019-03-19 14:23 - 000787240 _____ C:\WINDOWS\system32\perfh015.dat 2020-04-09 09:55 - 2019-03-19 14:23 - 000152986 _____ C:\WINDOWS\system32\perfc015.dat 2020-04-09 09:55 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF 2020-04-09 09:52 - 2015-11-26 21:05 - 000002309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-04-09 09:52 - 2015-11-26 21:05 - 000002268 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-04-09 09:51 - 2019-07-09 10:57 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-04-09 09:51 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-04-09 09:51 - 2017-06-01 17:42 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2020-04-09 09:51 - 2015-11-26 18:41 - 000000000 __SHD C:\Users\Magda Wcisło\IntelGraphicsProfiles 2020-04-09 09:50 - 2019-03-19 06:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2020-04-09 09:49 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2020-04-09 00:43 - 2019-07-09 09:58 - 000000000 ____D C:\Users\Magda Wcisło 2020-04-08 20:59 - 2019-09-15 00:53 - 000000000 ____D C:\WINDOWS\Minidump 2020-04-08 20:59 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2020-04-08 19:53 - 2019-07-09 10:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2020-04-08 17:52 - 2018-07-04 20:49 - 000000000 ____D C:\Users\Magda Wcisło\AppData\Local\CrashDumps 2020-04-08 12:59 - 2019-09-17 19:23 - 000009216 _____ C:\Users\Magda Wcisło\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2020-04-07 08:26 - 2017-06-01 18:16 - 000000000 ____D C:\Users\Magda Wcisło\AppData\Local\ConnectedDevicesPlatform 2020-04-06 15:49 - 2015-11-27 20:57 - 000000000 ____D C:\Users\Magda Wcisło\AppData\Roaming\BESTplayer 2020-04-06 13:02 - 2019-08-12 21:41 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\Bratki 2019 2020-04-06 00:00 - 2016-02-02 00:34 - 000000000 ____D C:\ProgramData\Napisy24 2020-04-04 09:26 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-04-03 13:59 - 2019-07-09 11:21 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\Kaczuszki 2018 2020-04-02 14:28 - 2015-12-02 22:48 - 000000000 ____D C:\Users\Magda Wcisło\AppData\Roaming\Audacity 2020-04-02 12:13 - 2019-07-09 10:57 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2020-04-02 12:13 - 2018-05-25 19:41 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 2020-04-02 12:13 - 2018-05-25 19:41 - 000002116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk 2020-04-02 12:12 - 2019-09-23 12:52 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\matematyka 2019 2020-04-02 11:21 - 2016-05-14 19:45 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2020-04-02 08:47 - 2015-11-26 23:25 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2020-04-02 08:36 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\NDF 2020-04-01 13:26 - 2019-06-03 09:26 - 000000000 ____D C:\Praca 2020-03-29 13:55 - 2018-04-27 20:26 - 000000000 ____D C:\Users\Magda Wcisło\AppData\Roaming\PhotoScape 2020-03-26 15:55 - 2018-12-10 21:23 - 000000000 ___RD C:\Users\Magda Wcisło\Documents\Scanned Documents 2020-03-25 01:20 - 2018-05-16 11:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2020-03-23 12:57 - 2020-01-24 14:00 - 000000000 ____D C:\Users\Magda Wcisło\Desktop\staż Małgosi Kowalczyk 2020-03-21 08:40 - 2019-07-09 10:57 - 000003570 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2020-03-21 08:40 - 2019-07-09 10:57 - 000003446 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2020-03-16 01:18 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2020-03-16 01:18 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2020-03-12 23:44 - 2017-10-28 21:23 - 000000000 ___RD C:\Users\Magda Wcisło\3D Objects 2020-03-12 23:44 - 2015-11-27 01:40 - 000000000 __RHD C:\Users\Public\AccountPictures 2020-03-12 23:43 - 2019-07-09 10:41 - 000714368 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\setup 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\oobe 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Dism 2020-03-12 23:33 - 2019-03-19 06:52 - 000000000 ____D C:\Program Files\Windows Defender 2020-03-12 23:33 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\servicing 2020-03-12 19:45 - 2015-11-26 21:51 - 000000000 ____D C:\WINDOWS\system32\MRT 2020-03-12 19:38 - 2015-11-26 21:51 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe ==================== Pliki w katalogu głównym wybranych folderów ======== 2015-03-02 01:58 - 2014-03-26 03:11 - 000000137 _____ () C:\ProgramData\RefreshReg.vbs 2018-04-27 20:24 - 2018-04-27 20:24 - 000198868 _____ () C:\Users\Magda Wcisło\AppData\Roaming\DMGR_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt 2017-10-08 11:30 - 2017-10-09 10:19 - 000000125 _____ () C:\Users\Magda Wcisło\AppData\Roaming\sp_data.sys 2019-11-12 15:31 - 2017-09-09 16:12 - 000000701 _____ () C:\Users\Magda Wcisło\AppData\Roaming\vsound.dll 2016-07-18 11:28 - 2016-09-02 13:28 - 000000125 _____ () C:\Users\Magda Wcisło\AppData\Roaming\WB.CFG 2019-09-17 19:23 - 2020-04-08 12:59 - 000009216 _____ () C:\Users\Magda Wcisło\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2019-05-07 16:57 - 2019-05-07 16:57 - 000000218 _____ () C:\Users\Magda Wcisło\AppData\Local\recently-used.xbel ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================