Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:13-12-2015 Uruchomiony przez Michał (administrator) MOIKERC (14-12-2015 12:09:33) Uruchomiony z C:\Users\Michał\Desktop Załadowane profile: Michał (Dostępne profile: Michał) Platform: Windows 10 Home Wersja 1511 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: Chrome) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (tsvr.com) C:\Users\Michał\AppData\Roaming\TSv\TSvr.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (TFuns LIMITED) C:\ProgramData\tWdMt\WdMan.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Piriform Ltd) C:\Windows.old\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) D:\Programy\Office\Office14\WINWORD.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944648 2015-09-27] (Synaptics Incorporated) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-09-24] (Adobe Systems Incorporated) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-1890577046-1904970765-735041783-1001\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-1890577046-1904970765-735041783-1001\...\Run: [EA Core] => C:\Program Files (x86)\Electronic Arts\EADM\Core.exe [3325952 2009-03-28] (Electronic Arts) HKU\S-1-5-21-1890577046-1904970765-735041783-1001\...\Run: [CCleaner Monitoring] => C:\Windows.old\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd) HKU\S-1-5-21-1890577046-1904970765-735041783-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [232960 2015-10-30] (Microsoft Corporation) Startup: C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk [2015-02-03] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk -> D:\Programy\Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{3e8ecc4c-05a3-456f-a037-69d4c4ba02ec}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-1890577046-1904970765-735041783-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130945540971226823&GUID=4A770436-E1B6-4A5C-BDD9-8D9CF61A66EA HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130945540971236597&GUID=4A770436-E1B6-4A5C-BDD9-8D9CF61A66EA HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1447141879&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07163&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447141879&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07163&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS&q={searchTerms} HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1890577046-1904970765-735041783-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1447141646&z=b5842949f4f8f8e2756394dgaz5zbm0gcz7g3qbq3o&from=wpm07163&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS&q={searchTerms} HKU\S-1-5-21-1890577046-1904970765-735041783-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130945540971258425&GUID=4A770436-E1B6-4A5C-BDD9-8D9CF61A66EA HKU\S-1-5-21-1890577046-1904970765-735041783-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS HKU\S-1-5-21-1890577046-1904970765-735041783-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447141646&z=b5842949f4f8f8e2756394dgaz5zbm0gcz7g3qbq3o&from=wpm07163&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1890577046-1904970765-735041783-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-1890577046-1904970765-735041783-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-1890577046-1904970765-735041783-1001 -> {607D409B-3C06-4744-AA43-6650F770CB34} URL = BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Programy\Java\bin\ssv.dll [2014-12-15] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Programy\Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Programy\Java\bin\jp2ssv.dll [2014-12-15] (Oracle Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS Edge: ====== Edge HomeButtonPage: HKU\S-1-5-21-1890577046-1904970765-735041783-1001 -> hxxp://www.delta-homes.com/?type=hp&ts=1444459961&z=51a300e0dd52e700901a1edg3z5z8z2z4qce1eaecb&from=wpm07163&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> D:\Programy\Java\bin\dtplugin\npDeployJava1.dll [2014-12-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> D:\Programy\Java\bin\plugin2\npjp2.dll [2014-12-15] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> D:\Programy\Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> D:\Programy\Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-27] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Profile 1 -> hxxps://www.google.pl/ CHR StartupUrls: Profile 1 -> "hxxps://www.google.pl/" CHR Profile: C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Prezentacje Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-05] CHR Extension: (Dokumenty Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-05] CHR Extension: (Dysk Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-05] CHR Extension: (YouTube) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-05] CHR Extension: (uBlock Origin) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2015-08-05] CHR Extension: (Google Search) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-05] CHR Extension: (Arkusze Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-05] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-05] CHR Extension: (Gmail) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-05] CHR Profile: C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Prezentacje Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-29] CHR Extension: (Dokumenty Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-29] CHR Extension: (Dysk Google) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22] CHR Extension: (YouTube) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29] CHR Extension: (Google Search) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28] CHR Extension: (uBlock) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\epcnnfbjfcgphgdmggkamkmgojdagdnn [2015-10-01] CHR Extension: (Dokumenty Google offline) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-29] CHR Extension: (Gmail) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-29] CHR HKLM\...\Chrome\Extension: [jdiejbegdjikmehflknhkbieocmnogcf] - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jdiejbegdjikmehflknhkbieocmnogcf.crx [2015-11-07] CHR HKLM-x32\...\Chrome\Extension: [jdiejbegdjikmehflknhkbieocmnogcf] - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jdiejbegdjikmehflknhkbieocmnogcf.crx [2015-11-07] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12] StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449648574&z=ba9f503fca513245a78a3fcg9z0z4t7q6z2b8w2bfw&from=ient07021&uid=TOSHIBAXMQ01ABD050_93P5S0FVSXX93P5S0FVS ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation) R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152 2014-01-29] (Samsung Electronics CO., LTD.) R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [Brak podpisu cyfrowego] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-10-09] (Intel Corporation) R2 IhPul; C:\Users\Michał\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3020120 2015-04-21] (Samsung Electronics CO., LTD.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-09-27] (Synaptics Incorporated) R2 WdMan; C:\ProgramData\tWdMt\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-01-07] (Atheros) [Brak podpisu cyfrowego] ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402960 2015-05-14] (Realsil Semiconductor Corporation) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-14 12:07 - 2015-12-14 12:09 - 00039958 _____ C:\Users\Michał\Desktop\Addition.txt 2015-12-14 12:05 - 2015-12-14 12:09 - 00023489 _____ C:\Users\Michał\Desktop\FRST.txt 2015-12-14 12:05 - 2015-12-14 12:09 - 00000000 ____D C:\FRST 2015-12-14 12:05 - 2015-12-14 12:05 - 02369536 _____ (Farbar) C:\Users\Michał\Desktop\FRST64.exe 2015-12-14 12:00 - 2015-12-14 12:00 - 00004148 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{59F5C6BF-5FF9-4337-BE88-3FB67D031A8E} 2015-12-13 23:58 - 2015-12-14 11:08 - 00000001 _____ C:\WINDOWS\SysWOW64\pl.html 2015-12-10 14:25 - 2015-12-10 14:25 - 00000279 _____ C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kosz.lnk 2015-12-10 10:31 - 2015-12-10 10:31 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2015-12-09 09:47 - 2015-11-03 01:12 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-12-09 09:47 - 2015-11-03 01:12 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-12-09 09:09 - 2015-12-09 09:11 - 00000000 ____D C:\ProgramData\tWdMt 2015-12-09 09:09 - 2015-12-09 09:09 - 00000000 ____D C:\ProgramData\pWdMp 2015-12-07 11:10 - 2015-12-07 11:10 - 00002880 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2015-12-06 17:39 - 2015-12-06 17:39 - 00000000 ____D C:\ProgramData\ATI 2015-12-06 17:37 - 2015-12-06 17:37 - 00000000 ____D C:\Users\Michał\AppData\Local\ActiveSync 2015-12-06 17:34 - 2015-12-06 17:34 - 00000020 ___SH C:\Users\Michał\ntuser.ini 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Ustawienia lokalne 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Szablony 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Moje dokumenty 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Menu Start 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Documents\Moje wideo 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Documents\Moje obrazy 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Documents\Moja muzyka 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\Dane aplikacji 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\AppData\Local\Historia 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dane aplikacji 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default User\Documents\Moje wideo 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default User\Documents\Moje obrazy 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default User\Documents\Moja muzyka 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Historia 2015-12-06 16:24 - 2015-12-06 16:24 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dane aplikacji 2015-12-06 16:15 - 2015-12-14 09:05 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-12-06 16:04 - 2015-12-06 16:04 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-12-06 16:04 - 2015-12-06 16:04 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI 2015-12-06 16:04 - 2015-12-06 16:04 - 00000000 ____D C:\Users\Default\AppData\Local\ATI 2015-12-06 16:04 - 2015-12-06 16:04 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI 2015-12-06 16:04 - 2015-12-06 16:04 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI 2015-12-06 15:58 - 2015-12-06 15:58 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2015-12-06 15:55 - 2015-12-09 09:23 - 00000000 ____D C:\Users\Michał 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Ustawienia lokalne 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Szablony 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Moje dokumenty 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Menu Start 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Documents\Moje wideo 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Documents\Moje obrazy 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Documents\Moja muzyka 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\Dane aplikacji 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\AppData\Local\Historia 2015-12-06 15:55 - 2015-12-06 15:55 - 00000000 _SHDL C:\Users\Michał\AppData\Local\Dane aplikacji 2015-12-06 15:51 - 2015-12-06 15:51 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2015-12-06 15:51 - 2015-12-06 15:51 - 00000000 ____D C:\WINDOWS\SysWOW64\sda 2015-12-06 15:51 - 2015-12-06 15:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2015-12-06 15:51 - 2015-12-06 15:51 - 00000000 ____D C:\Program Files\Synaptics 2015-12-06 15:51 - 2015-12-06 15:51 - 00000000 ____D C:\Program Files\Common Files\Atheros 2015-12-06 15:50 - 2015-12-06 15:59 - 00000000 ____D C:\Program Files\Intel 2015-12-06 15:50 - 2015-12-06 15:59 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2015-12-06 15:50 - 2015-12-06 15:50 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2015-12-06 15:50 - 2015-12-06 15:50 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2015-12-06 15:50 - 2015-12-06 15:50 - 00000000 ____D C:\Program Files\Realtek 2015-12-06 15:50 - 2015-12-06 15:50 - 00000000 ____D C:\Program Files\ATI Technologies 2015-12-06 15:50 - 2015-12-06 15:50 - 00000000 _____ C:\WINDOWS\ativpsrm.bin 2015-12-06 15:49 - 2015-12-06 15:50 - 00000000 ____D C:\ProgramData\Package Cache 2015-12-06 15:49 - 2015-12-06 15:49 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2015-12-06 15:49 - 2015-12-06 15:49 - 00000000 ____D C:\Program Files\AMD 2015-12-06 15:46 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2015-12-06 15:42 - 2015-12-09 09:45 - 00260744 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-12-06 15:41 - 2015-12-09 10:20 - 00000000 ___DC C:\WINDOWS\Panther 2015-12-06 15:37 - 2015-12-06 15:37 - 00000000 ____D C:\Windows.old 2015-12-06 15:36 - 2015-12-06 15:36 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 13380608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 12124672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2015-12-06 15:36 - 2015-12-06 15:36 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2015-12-06 15:36 - 2015-12-06 15:36 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-12-06 15:36 - 2015-12-06 15:36 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-12-06 15:36 - 2015-12-06 15:36 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2015-12-06 15:36 - 2015-12-06 15:36 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2015-12-06 15:36 - 2015-12-06 15:36 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-12-06 15:36 - 2015-12-06 15:36 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2015-12-06 15:36 - 2015-12-06 15:36 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-12-06 15:36 - 2015-12-06 15:36 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2015-12-06 15:36 - 2015-12-06 15:36 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll 2015-12-06 15:36 - 2015-12-06 15:36 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01284960 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00975200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2015-12-06 15:35 - 2015-12-06 15:35 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys 2015-12-06 15:35 - 2015-12-06 15:35 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe 2015-12-06 15:35 - 2015-12-06 15:35 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll 2015-12-06 15:35 - 2015-12-06 15:35 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2015-12-06 15:32 - 2015-10-29 19:43 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll 2015-12-06 15:32 - 2015-10-29 19:43 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll 2015-12-06 15:32 - 2015-10-29 19:41 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll 2015-12-06 15:32 - 2015-10-29 19:25 - 06359040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll 2015-12-06 15:32 - 2015-10-29 19:24 - 04847616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll 2015-12-06 15:21 - 2015-12-06 15:21 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2015-12-06 15:17 - 2015-12-06 15:17 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2015-12-06 15:17 - 2015-12-06 15:17 - 00000000 ____D C:\Program Files\Reference Assemblies 2015-12-06 15:17 - 2015-12-06 15:17 - 00000000 ____D C:\Program Files\MSBuild 2015-12-06 15:17 - 2015-12-06 15:17 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2015-12-06 15:17 - 2015-12-06 15:17 - 00000000 ____D C:\Program Files (x86)\MSBuild 2015-12-06 15:16 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2015-12-06 15:16 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-12-06 15:16 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2015-12-06 15:16 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2015-12-06 15:16 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2015-12-06 15:16 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2015-12-05 15:37 - 2015-12-06 16:15 - 00002206 _____ C:\WINDOWS\System32\Tasks\{2A1F61DD-61AD-466F-BC19-4797CE369D96} 2015-12-03 18:51 - 2015-12-03 19:15 - 00009529 ____H C:\Users\Michał\Desktop\~WRL0003.tmp 2015-12-03 18:51 - 2015-12-03 18:54 - 00008000 ____H C:\Users\Michał\Desktop\~WRL3500.tmp 2015-12-03 18:51 - 2015-12-03 18:51 - 00000162 ____H C:\Users\Michał\Desktop\~$p -kolos.odt 2015-11-29 16:36 - 2015-11-29 16:38 - 00143584 _____ C:\Users\Michał\Desktop\Środki przymusu.pptx 2015-11-24 12:54 - 2015-11-24 12:54 - 00000000 ____D C:\Users\Michał\AppData\Roaming\eCyber 2015-11-24 12:49 - 2015-12-09 09:09 - 00000000 ____D C:\ProgramData\QWMiniProQ 2015-11-16 19:33 - 2015-12-06 16:15 - 00002184 _____ C:\WINDOWS\System32\Tasks\{CE9B6BF6-B523-4F4A-8CBB-20D770D544F9} ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-14 12:09 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF 2015-12-14 12:08 - 2015-10-30 07:28 - 00000000 ____D C:\Windows 2015-12-14 12:06 - 2014-12-11 18:47 - 00001072 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-14 09:11 - 2012-08-31 01:00 - 00000000 ____D C:\ProgramData\WinClon 2015-12-14 09:08 - 2015-08-04 19:40 - 00000000 __SHD C:\Users\Michał\IntelGraphicsProfiles 2015-12-14 09:08 - 2014-12-11 18:47 - 00001068 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-14 09:04 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-12-13 23:07 - 2014-12-11 19:37 - 00000000 ____D C:\Users\Michał\AppData\Roaming\Skype 2015-12-13 16:24 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-12-10 09:44 - 2015-10-13 11:50 - 00000000 ____D C:\Users\Michał\Desktop\coś 2015-12-09 10:05 - 2015-10-30 20:19 - 00819340 _____ C:\WINDOWS\system32\perfh015.dat 2015-12-09 10:05 - 2015-10-30 20:19 - 00158506 _____ C:\WINDOWS\system32\perfc015.dat 2015-12-09 10:05 - 2015-09-27 16:25 - 01849016 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-12-09 10:05 - 2015-01-10 18:47 - 00000000 ___RD C:\Users\Michał\Desktop\Programy 2015-12-09 09:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe 2015-12-09 09:09 - 2015-10-10 07:53 - 00000000 ____D C:\Users\Michał\AppData\Roaming\TSv 2015-12-09 09:09 - 2015-09-29 14:30 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat 2015-12-08 21:11 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps 2015-12-08 21:11 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-12-08 17:33 - 2015-10-13 11:49 - 00000000 ___RD C:\Users\Michał\Desktop\Prawo III 2015-12-07 11:28 - 2014-12-11 18:36 - 00000000 ____D C:\Users\Michał\AppData\Local\Packages 2015-12-07 08:55 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\appcompat 2015-12-06 17:54 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow 2015-12-06 17:41 - 2015-09-27 16:49 - 00002418 _____ C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2015-12-06 17:41 - 2015-08-04 22:14 - 00000000 ___RD C:\Users\Michał\OneDrive 2015-12-06 17:36 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog 2015-12-06 17:36 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\MiracastView 2015-12-06 17:35 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2015-12-06 17:35 - 2015-09-10 06:55 - 00000000 __RHD C:\Users\Public\AccountPictures 2015-12-06 17:34 - 2015-08-04 19:40 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2015-12-06 16:28 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache 2015-12-06 16:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows NT 2015-12-06 16:23 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2015-12-06 16:23 - 2015-08-04 18:23 - 00019053 _____ C:\WINDOWS\diagwrn.xml 2015-12-06 16:23 - 2015-08-04 18:23 - 00019053 _____ C:\WINDOWS\diagerr.xml 2015-12-06 16:21 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2015-12-06 16:21 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration 2015-12-06 16:15 - 2015-08-04 20:07 - 00002266 _____ C:\WINDOWS\System32\Tasks\SUPatchForW10Up 2015-12-06 16:15 - 2015-08-04 18:54 - 00023140 _____ C:\WINDOWS\system32\emptyregdb.dat 2015-12-06 16:15 - 2015-06-11 13:31 - 00002776 _____ C:\WINDOWS\System32\Tasks\Settings 2015-12-06 16:15 - 2015-06-11 13:27 - 00002514 _____ C:\WINDOWS\System32\Tasks\advRecovery 2015-12-06 16:15 - 2015-05-23 08:20 - 00002954 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-12-06 16:15 - 2015-01-10 19:03 - 00002304 _____ C:\WINDOWS\System32\Tasks\{C5C490B4-9C9F-464F-BCC5-D10E4A7F0061} 2015-12-06 16:15 - 2015-01-10 18:44 - 00002666 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Deskjet 3520 series 2015-12-06 16:15 - 2014-12-12 10:04 - 00003046 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2015-12-06 16:15 - 2014-12-11 20:14 - 00002680 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2015-12-06 16:15 - 2014-12-11 18:47 - 00003584 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-12-06 16:15 - 2014-12-11 18:47 - 00003360 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-12-06 16:15 - 2014-12-11 18:45 - 00002938 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1890577046-1904970765-735041783-1001 2015-12-06 16:15 - 2012-08-31 00:12 - 00002380 _____ C:\WINDOWS\System32\Tasks\SAgent 2015-12-06 16:14 - 2015-10-30 08:24 - 00000000 __RHD C:\Users\Public\Libraries 2015-12-06 16:11 - 2012-08-31 01:20 - 01873484 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2015-12-06 16:07 - 2015-03-10 14:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-12-06 16:07 - 2015-02-16 08:38 - 00000000 ____D C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer 2015-12-06 16:07 - 2015-01-10 18:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2015-12-06 16:07 - 2014-12-12 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2015-12-06 16:07 - 2012-08-31 00:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-12-06 16:04 - 2015-07-10 10:47 - 00000000 ____D C:\Users\Default.migrated 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE 2015-12-06 16:02 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MUI 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lv-LV 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lt-LT 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\IME 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\et-EE 2015-12-06 16:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\en-GB 2015-12-06 16:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared 2015-12-06 16:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared 2015-12-06 16:00 - 2015-10-30 20:23 - 00000000 ____D C:\WINDOWS\ShellNew 2015-12-06 16:00 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\DigitalLocker 2015-12-06 16:00 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2015-12-06 16:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2015-12-06 16:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2015-12-06 16:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod 2015-12-06 16:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\IME 2015-12-06 16:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\ADFS 2015-12-06 16:00 - 2012-08-31 01:10 - 00000000 ____D C:\WINDOWS\en 2015-12-06 16:00 - 2012-08-31 01:09 - 00000000 ____D C:\WINDOWS\pl 2015-12-06 16:00 - 2012-08-31 01:09 - 00000000 ____D C:\WINDOWS\fr 2015-12-06 16:00 - 2012-08-31 01:08 - 00000000 ____D C:\WINDOWS\nl 2015-12-06 15:59 - 2015-11-04 09:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-12-06 15:59 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\USOPrivate 2015-12-06 15:59 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\System 2015-12-06 15:59 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-12-06 15:59 - 2015-10-01 13:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-12-06 15:59 - 2015-01-30 17:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts 2015-12-06 15:59 - 2014-12-17 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt 2015-12-06 15:59 - 2014-12-15 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-12-06 15:59 - 2014-12-15 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-12-06 15:59 - 2014-12-11 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-12-06 15:59 - 2014-11-21 10:03 - 00000000 ____D C:\Program Files\Embedded Lockdown Manager 2015-12-06 15:59 - 2012-08-31 01:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel AppUp(SM) center 2015-12-06 15:59 - 2012-08-31 01:07 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go 8 2015-12-06 15:59 - 2012-08-31 01:06 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 10 2015-12-06 15:59 - 2012-08-31 00:48 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2015-12-06 15:58 - 2014-12-15 18:00 - 00000000 ____D C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-12-06 15:54 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2015-12-06 15:49 - 2015-08-04 18:11 - 00000000 ____D C:\AMD 2015-12-06 15:42 - 2015-10-30 20:30 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2015-12-06 15:41 - 2015-10-30 08:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2015-12-06 15:36 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2015-12-06 15:36 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-12-06 15:36 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning 2015-12-06 15:36 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2015-12-06 15:36 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Dism 2015-12-06 15:32 - 2015-10-30 20:20 - 00000000 ____D C:\WINDOWS\OCR 2015-12-06 15:31 - 2015-10-30 20:23 - 00000000 ____D C:\Program Files\Windows Journal 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\system32\winrm 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\system32\WCN 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\system32\slmgr 2015-12-06 15:31 - 2015-10-30 20:19 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\migwiz 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Defender 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2015-12-06 15:31 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2015-12-06 15:31 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\servicing 2015-12-06 15:17 - 2015-10-30 08:17 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe 2015-12-06 15:17 - 2015-10-30 08:17 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe 2015-12-06 15:17 - 2015-10-30 08:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe 2015-12-06 15:17 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll 2015-12-06 15:17 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll 2015-12-06 14:54 - 2015-10-30 20:56 - 00000000 ___HD C:\$WINDOWS.~BT 2015-12-06 09:38 - 2014-12-21 00:12 - 03203584 ___SH C:\Users\Michał\Desktop\Thumbs.db 2015-12-05 15:38 - 2015-03-27 14:10 - 00000000 ___RD C:\Program Files (x86)\Skype 2015-12-05 15:38 - 2014-12-11 19:37 - 00000000 ____D C:\ProgramData\Skype 2015-12-05 14:14 - 2015-10-16 20:05 - 00593262 _____ C:\WINDOWS\ProcessedPackets.KTL 2015-12-05 14:14 - 2015-10-16 20:05 - 00576089 _____ C:\WINDOWS\Packet.KTL 2015-12-05 14:14 - 2015-10-16 20:05 - 00288103 _____ C:\WINDOWS\SentOSPackets.KTL 2015-12-05 14:14 - 2015-10-16 20:05 - 00124556 _____ C:\WINDOWS\Control.KTL 2015-12-05 14:14 - 2015-10-16 20:05 - 00000415 _____ C:\WINDOWS\NGIControl.KTL 2015-11-14 22:30 - 2015-08-04 12:16 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-11-14 22:18 - 2015-08-04 12:15 - 145617392 ____N (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe ==================== Pliki w katalogu głównym wybranych folderów ======= 2015-11-10 08:46 - 2015-11-10 08:46 - 0000000 _____ () C:\Users\Michał\AppData\Local\{DFA18189-11A3-49EF-A214-FE610F856B45} 2015-05-01 13:11 - 2015-05-01 13:11 - 0000000 _____ () C:\Users\Michał\AppData\Local\{F8A828F5-D9FF-4496-A1CF-D8805236973D} 2015-01-10 18:44 - 2015-01-10 18:44 - 0000057 _____ () C:\ProgramData\Ament.ini 2012-08-31 01:10 - 2013-02-21 15:59 - 2063240 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe 2012-08-31 01:10 - 2013-01-12 22:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml 2015-09-29 14:30 - 2015-12-09 09:09 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Pliki do przeniesienia lub usunięcia: ==================== C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Niektóre pliki w TEMP: ==================== C:\Users\Michał\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\wininit.exe => Plik podpisany cyfrowo C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2015-12-06 15:42 ==================== Koniec FRST.txt ============================