Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:07-05-2016 Uruchomiony przez p1 (administrator) HPPAVILONDV4 (07-05-2016 12:23:50) Uruchomiony z C:\Users\p1\Desktop Załadowane profile: p1 (Dostępne profile: p1) Platform: Windows 10 Pro Wersja 1511 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\syswow64\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe (Adobe Systems, Inc.) C:\Windows\syswow64\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.168_none_76587b40265ca57e\TiWorker.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Apoint] => X:\Program Files\Apoint2K\Apoint.exe HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2016-04-04] (IDT, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7391632 2016-05-03] (AVAST Software) HKU\S-1-5-21-1482506301-2984567061-4213870070-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-05-03] (AVAST Software) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{d6aef926-ef5c-402a-b031-8d36b20a56ee}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\p1\AppData\Roaming\Mozilla\Firefox\Profiles\ydzgkgem.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-28] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-28] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-02-26] (Adobe Systems Inc.) FF Extension: Przelewy24Ext2.2 - C:\Users\p1\AppData\Roaming\Mozilla\Firefox\Profiles\ydzgkgem.default\Extensions\jid1-AoXeeOB4j7kFdA@jetpack.xpi [2016-05-04] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-03] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AESTFilters; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [89600 2016-04-04] (Andrea Electronics Corporation) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-03] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [370656 2016-05-03] (AVAST Software) R3 fdPHost; C:\Windows\system32\fdPHost.dll [21504 2015-10-30] (Microsoft Corporation) [Brak podpisu cyfrowego] R2 STacSV; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe [247808 2016-04-04] (IDT, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-05-03] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-05-03] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-05-03] (AVAST Software) R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [536312 2016-05-03] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-05-03] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-05-03] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-05-03] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-05-03] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-05-03] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-05-03] (AVAST Software) R3 athr; C:\Windows\System32\drivers\athw10x.sys [4323976 2016-05-03] (Qualcomm Atheros Communications, Inc.) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-05-03] (REALiX(tm)) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R3 whfltr2k; C:\Windows\System32\drivers\whfltr2k.sys [10368 2009-09-16] () ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-05-07 12:14 - 2016-05-07 12:23 - 00008871 _____ C:\Users\p1\Desktop\FRST.txt 2016-05-07 11:34 - 2016-05-07 12:23 - 00000000 ____D C:\FRST 2016-05-07 11:33 - 2016-05-07 11:34 - 02379264 _____ (Farbar) C:\Users\p1\Desktop\FRST64.exe 2016-05-07 07:51 - 2016-05-07 07:51 - 00189228 _____ C:\WINDOWS\Minidump\050716-20406-01.dmp 2016-05-06 21:53 - 2016-05-06 21:54 - 00000000 ___HD C:\$WINDOWS.~BT 2016-05-06 21:53 - 2016-05-06 21:53 - 00001890 _____ C:\WINDOWS\diagwrn.xml 2016-05-06 21:53 - 2016-05-06 21:53 - 00001890 _____ C:\WINDOWS\diagerr.xml 2016-05-06 20:55 - 2016-05-06 20:56 - 00278980 _____ C:\WINDOWS\Minidump\050616-18187-01.dmp 2016-05-06 12:16 - 2016-05-06 12:17 - 00279180 _____ C:\WINDOWS\Minidump\050616-16687-01.dmp 2016-05-05 21:06 - 2016-05-06 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-05-05 19:31 - 2016-05-05 19:31 - 00278980 _____ C:\WINDOWS\Minidump\050516-19656-01.dmp 2016-05-04 19:34 - 2016-05-04 19:34 - 00163788 _____ C:\WINDOWS\Minidump\050416-19500-01.dmp 2016-05-03 17:00 - 2016-05-03 17:00 - 00000975 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk 2016-05-03 17:00 - 2016-05-03 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID 2016-05-03 17:00 - 2016-05-03 17:00 - 00000000 ____D C:\Program Files\CPUID 2016-05-03 16:59 - 2016-05-03 16:59 - 01199856 _____ ( ) C:\Users\p1\Downloads\hwmonitor_1.28.exe 2016-05-03 16:58 - 2016-05-03 16:59 - 00975504 _____ (Sacip ) C:\Users\p1\Downloads\HWMonitor-33495-dp.exe 2016-05-03 15:38 - 2016-05-03 15:38 - 04323976 _____ (Qualcomm Atheros Communications, Inc.) C:\WINDOWS\system32\Drivers\athw10x.sys 2016-05-03 15:35 - 2016-05-07 12:20 - 00003008 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (p1) 2016-05-03 15:35 - 2016-05-03 15:39 - 00002239 _____ C:\Users\Public\Desktop\Driver Booster 3.lnk 2016-05-03 15:35 - 2016-05-03 15:35 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS 2016-05-03 15:35 - 2016-05-03 15:35 - 00003370 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\WINDOWS\IObit 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\Users\p1\AppData\Roaming\IObit 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\Users\p1\AppData\LocalLow\IObit 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\ProgramData\ProductData 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\ProgramData\IObit 2016-05-03 15:35 - 2016-05-03 15:35 - 00000000 ____D C:\Program Files (x86)\IObit 2016-05-03 13:51 - 2016-05-03 13:51 - 00004082 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1462276303 2016-05-03 13:51 - 2016-05-03 13:51 - 00001082 _____ C:\Users\Public\Desktop\Avast SafeZone 1 Browser.lnk 2016-05-03 13:51 - 2016-05-03 13:51 - 00001082 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone 1 Browser.lnk 2016-05-03 13:38 - 2016-05-03 13:38 - 00004082 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1462275454 2016-05-03 13:38 - 2016-05-03 13:38 - 00001082 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2016-05-03 13:38 - 2016-05-03 13:38 - 00001082 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2016-05-03 13:36 - 2016-05-03 13:36 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2016-05-03 13:30 - 2016-05-07 12:18 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2016-05-03 13:30 - 2016-05-03 15:34 - 14982312 _____ (IObit ) C:\Users\p1\Downloads\driver_booster_setup.exe 2016-05-03 13:30 - 2016-05-03 13:30 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premier.lnk 2016-05-03 13:30 - 2016-05-03 13:30 - 00001967 _____ C:\Users\Public\Desktop\Avast Premier.lnk 2016-05-03 13:30 - 2016-05-03 13:30 - 00000000 ____D C:\Users\p1\AppData\Roaming\AVAST Software 2016-05-03 13:30 - 2016-05-03 13:29 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00536312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00465792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00287528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00166432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00103064 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00074544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2016-05-03 13:30 - 2016-05-03 13:29 - 00037656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2016-05-03 13:29 - 2016-05-03 13:29 - 00398152 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2016-05-03 13:29 - 2016-05-03 13:29 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2016-05-03 13:26 - 2016-05-03 13:36 - 00000000 ____D C:\Program Files\AVAST Software 2016-05-03 13:24 - 2016-05-03 13:36 - 00000000 ____D C:\ProgramData\AVAST Software 2016-05-03 13:23 - 2016-05-03 13:24 - 05139680 _____ (AVAST Software) C:\Users\p1\Downloads\avast_premier_antivirus_setup_online.exe 2016-05-03 12:49 - 2016-05-03 12:51 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-05-03 12:44 - 2016-05-03 12:44 - 00144884 _____ C:\WINDOWS\Minidump\050316-17671-01.dmp 2016-05-03 12:38 - 2016-05-07 12:17 - 505378632 _____ C:\WINDOWS\MEMORY.DMP 2016-05-03 12:35 - 2016-05-03 12:35 - 00001175 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-05-03 12:35 - 2016-05-03 12:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-05-03 12:34 - 2016-05-03 12:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-05-03 12:34 - 2016-05-03 12:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-05-03 12:34 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-05-03 12:34 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-05-03 12:34 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-05-03 12:31 - 2016-05-03 12:34 - 22851472 _____ (Malwarebytes ) C:\Users\p1\Downloads\mbam-setup-2.2.1.1043.exe 2016-05-03 12:30 - 2016-05-03 12:30 - 00002858 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2016-05-03 12:29 - 2016-05-03 12:29 - 06882192 _____ (Piriform Ltd) C:\Users\p1\Downloads\ccsetup517.exe 2016-05-03 12:29 - 2016-05-03 12:29 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-05-03 12:29 - 2016-05-03 12:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-05-03 12:29 - 2016-05-03 12:29 - 00000000 ____D C:\Program Files\CCleaner 2016-05-02 22:31 - 2016-05-02 22:31 - 00032256 _____ C:\Users\p1\Desktop\MLB.rozliczenie.szablon.xls 2016-05-02 22:14 - 2016-05-02 22:14 - 00032256 _____ C:\Users\p1\Desktop\NHL.rozliczenie.szablon.xls 2016-05-02 17:40 - 2016-05-02 17:40 - 00000000 ____D C:\Users\p1\AppData\Local\CEF 2016-05-02 13:16 - 2016-05-02 13:16 - 00033280 _____ C:\Users\p1\Downloads\Hokej.rozliczenie.szablon(1).xls 2016-05-02 13:15 - 2016-05-02 13:15 - 00033280 _____ C:\Users\p1\Downloads\Hokej.rozliczenie.szablon.xls 2016-05-02 13:09 - 2016-05-02 13:09 - 00033280 _____ C:\Users\p1\Desktop\Hokej.rozliczenie.szablon.xls 2016-05-02 12:41 - 2016-05-02 13:07 - 00033280 _____ C:\Users\p1\Downloads\rozliczenie.szablon.xls 2016-05-02 12:41 - 2016-05-02 12:41 - 00064000 _____ C:\Users\p1\Downloads\Tenis.rozliczenie.xls 2016-05-01 19:48 - 2016-05-01 19:48 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2016-04-30 11:51 - 2016-04-30 11:51 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-04-29 19:48 - 2016-04-29 19:48 - 00000000 ____D C:\Users\p1\AppData\Local\PeerDistRepub 2016-04-29 18:35 - 2016-04-29 18:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2016-04-29 18:35 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll 2016-04-29 18:35 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll 2016-04-29 18:35 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2016-04-29 18:35 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2016-04-29 18:35 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2016-04-29 18:33 - 2016-04-29 18:35 - 00000000 ____D C:\Users\p1\AppData\Roaming\Riot Games 2016-04-29 08:44 - 2016-04-29 08:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-04-29 08:44 - 2016-04-29 08:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-04-29 08:44 - 2016-04-29 08:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-04-29 08:41 - 2016-04-29 08:43 - 13163744 _____ (Microsoft Corporation) C:\Users\p1\Downloads\Silverlight_x64(1).exe 2016-04-28 22:54 - 2016-04-28 22:54 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2016-04-28 22:54 - 2016-04-28 22:54 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2016-04-28 21:41 - 2016-04-28 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint 2016-04-28 21:41 - 2016-04-28 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-04-28 21:39 - 2016-04-28 21:39 - 00000000 ____D C:\WINDOWS\PCHEALTH 2016-04-28 21:39 - 2016-04-28 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2016-04-28 21:39 - 2016-04-28 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Sync Framework 2016-04-28 21:39 - 2016-04-28 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2016-04-28 21:37 - 2016-04-28 21:37 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform 2016-04-28 21:36 - 2016-04-28 21:36 - 00000000 ____D C:\Program Files\Microsoft Office 2016-04-28 21:36 - 2016-04-28 21:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2016-04-28 21:35 - 2016-04-28 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2016-04-28 21:35 - 2016-04-28 21:35 - 00000000 ____D C:\Users\p1\AppData\Local\Microsoft Help 2016-04-28 21:35 - 2016-04-28 21:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2016-04-28 21:32 - 2016-04-28 21:32 - 00000000 ____D C:\Users\p1\AppData\Roaming\LolClient 2016-04-28 21:19 - 2016-04-28 21:19 - 00000438 __RSH C:\ProgramData\ntuser.pol 2016-04-28 21:04 - 2016-04-28 21:21 - 00000000 ____D C:\Users\p1\AppData\Roaming\vlc 2016-04-28 21:04 - 2016-04-28 21:04 - 00001143 _____ C:\Users\Public\Desktop\VLC media player.lnk 2016-04-28 21:04 - 2016-04-28 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2016-04-28 21:04 - 2016-04-28 21:04 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2016-04-28 21:02 - 2016-04-29 08:04 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2016-04-28 21:01 - 2016-04-29 08:03 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-04-28 21:00 - 2016-04-28 21:04 - 30510920 _____ C:\Users\p1\Downloads\vlc-2.2.2-win32.exe 2016-04-28 20:57 - 2016-04-29 07:35 - 00000000 ____D C:\ProgramData\Adobe 2016-04-28 20:57 - 2016-04-28 21:01 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-04-28 20:57 - 2016-04-28 20:57 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2016-04-28 20:57 - 2016-04-28 20:57 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2016-04-28 20:56 - 2016-04-28 20:57 - 18672512 _____ (Adobe Systems Inc.) C:\Users\p1\Downloads\AdobeAIRInstaller(2).exe 2016-04-28 20:54 - 2016-04-28 20:54 - 05776144 _____ (Adobe Systems Inc.) C:\Users\p1\Downloads\Shockwave_Installer_Slim(3).exe 2016-04-28 20:54 - 2016-04-28 20:54 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe 2016-04-28 20:44 - 2016-04-28 20:44 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2016-04-28 20:44 - 2016-04-28 20:44 - 00000000 ____D C:\Program Files\IDT 2016-04-28 20:44 - 2016-04-04 17:24 - 00564224 _____ (IDT, Inc.) C:\WINDOWS\system32\idt64mp1.exe 2016-04-28 20:44 - 2016-04-04 17:24 - 00487424 _____ (IDT, Inc.) C:\WINDOWS\sttray64.exe 2016-04-28 20:44 - 2010-03-23 14:53 - 12772352 _____ (IDT, Inc.) C:\WINDOWS\system32\idtcpl64.cpl 2016-04-28 20:44 - 2010-03-23 14:53 - 03348480 _____ (IDT, Inc.) C:\WINDOWS\system32\stlang64.dll 2016-04-28 20:44 - 2010-01-26 18:30 - 00162816 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAC64.dll 2016-04-28 20:44 - 2009-10-09 16:45 - 00442368 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTEC64.dll 2016-04-28 20:44 - 2009-03-02 17:58 - 00068608 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAR64.dll 2016-04-28 20:44 - 2009-03-02 17:47 - 00090624 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTCo64.dll 2016-04-28 20:30 - 2016-04-28 20:30 - 00022200 _____ (Phoenix Technologies) C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS 2016-04-28 20:30 - 2016-04-28 20:30 - 00000000 ____D C:\Users\p1\AppData\Local\eSupport.com 2016-04-28 20:30 - 2016-04-28 20:30 - 00000000 ____D C:\Program Files (x86)\eSupport.com 2016-04-28 20:29 - 2016-04-28 20:29 - 01225680 _____ (Copyright © 2015 eSupport.com, Inc • All Rights Reserved ) C:\Users\p1\Downloads\driveragent-setup-794.exe 2016-04-28 20:28 - 2016-04-28 20:30 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-04-28 20:28 - 2016-04-28 20:28 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-04-28 20:28 - 2016-04-22 09:57 - 00453288 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2016-04-28 20:27 - 2016-04-28 20:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire 2016-04-28 20:27 - 2016-04-28 20:27 - 00000000 ____D C:\Program Files (x86)\FinalWire 2016-04-28 20:21 - 2016-05-07 11:58 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-04-28 20:21 - 2016-04-28 20:21 - 00003906 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2016-04-28 20:21 - 2016-04-28 20:21 - 00000000 ____D C:\Users\p1\AppData\Local\Macromedia 2016-04-28 20:20 - 2016-04-28 20:27 - 16335712 _____ (FinalWire Ltd. ) C:\Users\p1\Downloads\aida64extreme570.exe 2016-04-28 20:19 - 2016-05-02 17:40 - 00000000 ____D C:\Users\p1\AppData\Local\Adobe 2016-04-28 20:16 - 2016-04-28 20:18 - 04952336 _____ (Advanced Micro Devices, Inc.) C:\Users\p1\Downloads\autodetectutility.exe 2016-04-28 20:05 - 2016-04-28 20:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-04-28 20:05 - 2016-04-28 20:05 - 00000000 ____D C:\Program Files (x86)\Realtek 2016-04-28 20:04 - 2016-04-28 20:08 - 00000000 ___HD C:\Program Files (x86)\Temp 2016-04-28 20:04 - 2015-05-27 17:38 - 02825944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll 2016-04-28 19:55 - 2016-04-28 19:55 - 228531151 _____ (Realtek Semiconductor Corp.) C:\Users\p1\Downloads\Win7_Win8_Win81_Win10_R279.exe 2016-04-28 19:43 - 2016-04-28 19:43 - 123815724 _____ (AMD Inc.) C:\Users\p1\Downloads\amd-catalyst-15.11.1beta-64bit-win10-win8.1-win7-nov14.exe.part 2016-04-28 19:42 - 2016-05-07 12:17 - 00000286 _____ C:\WINDOWS\Tasks\{164C6228-4EBD-C994-28B9-5553392DA31F}.job 2016-04-28 19:42 - 2016-04-28 19:42 - 00002826 _____ C:\WINDOWS\System32\Tasks\{164C6228-4EBD-C994-28B9-5553392DA31F} 2016-04-28 19:32 - 2016-05-07 12:17 - 00000000 ____D C:\WINDOWS\Minidump 2016-04-28 17:35 - 2016-05-03 17:08 - 00000000 ____D C:\Windows.old 2016-04-28 17:35 - 2016-05-03 12:37 - 00000000 ___DC C:\WINDOWS\Panther 2016-04-28 17:35 - 2016-04-28 17:35 - 00000000 ____D C:\WINDOWS\InfusedApps 2016-04-28 17:29 - 2016-04-28 17:29 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2016-04-28 17:29 - 2016-04-28 17:29 - 00000000 ____D C:\Users\p1\AppData\Roaming\Macromedia 2016-04-28 17:28 - 2016-04-28 17:28 - 00000000 ____D C:\Program Files\Apoint2K 2016-04-28 17:26 - 2016-04-28 17:26 - 00000000 ____D C:\WINDOWS\Setup 2016-04-28 17:21 - 2016-04-28 21:40 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-04-28 17:21 - 2016-04-28 17:21 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2016-04-28 17:21 - 2016-04-28 17:21 - 00000000 ____D C:\WINDOWS\OCR 2016-04-28 17:21 - 2016-04-28 17:21 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-04-28 17:21 - 2016-04-28 17:21 - 00000000 ____D C:\Program Files\MSBuild 2016-04-28 17:21 - 2016-04-28 17:21 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-04-28 17:20 - 2016-05-07 12:23 - 00818302 _____ C:\WINDOWS\system32\perfh015.dat 2016-04-28 17:20 - 2016-05-07 12:23 - 00157970 _____ C:\WINDOWS\system32\perfc015.dat 2016-04-28 17:20 - 2016-04-28 17:19 - 00342912 _____ C:\WINDOWS\system32\perfi015.dat 2016-04-28 17:20 - 2016-04-28 17:19 - 00041236 _____ C:\WINDOWS\system32\perfd015.dat 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\pl 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\0409 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\winrm 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\WCN 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\slmgr 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\pl 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\0409 2016-04-28 17:19 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\DigitalLocker 2016-04-28 17:16 - 2016-04-28 17:16 - 00000000 ____D C:\ProgramData\Riot Games 2016-04-28 17:14 - 2016-04-12 20:27 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-04-28 17:14 - 2016-04-12 20:27 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-04-28 17:12 - 2016-04-28 23:45 - 00000167 _____ C:\WINDOWS\win.ini 2016-04-28 17:12 - 2016-04-28 17:35 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2016-04-28 17:12 - 2016-04-28 17:12 - 00000000 ____D C:\Users\p1\AppData\Local\Comms 2016-04-28 17:12 - 2016-04-28 17:08 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2016-04-28 17:12 - 2016-04-28 17:08 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat 2016-04-28 17:12 - 2016-04-28 17:08 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat 2016-04-28 17:12 - 2016-04-28 17:08 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT 2016-04-28 17:12 - 2016-04-28 17:07 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2016-04-28 17:12 - 2016-04-28 17:07 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat 2016-04-28 17:12 - 2016-04-28 17:07 - 00215943 _____ C:\WINDOWS\system32\dssec.dat 2016-04-28 17:12 - 2016-04-28 17:07 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services 2016-04-28 17:12 - 2016-04-28 17:07 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2016-04-28 17:12 - 2016-04-28 17:07 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat 2016-04-28 17:12 - 2016-04-28 17:07 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam 2016-04-28 17:12 - 2016-04-28 17:07 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat 2016-04-28 17:12 - 2016-04-28 17:07 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol 2016-04-28 17:12 - 2016-04-28 17:07 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json 2016-04-28 17:12 - 2016-04-28 17:07 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT 2016-04-28 17:12 - 2016-04-28 17:07 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks 2016-04-28 17:12 - 2016-04-28 17:07 - 00000389 _____ C:\WINDOWS\system32\AutoWorkplace.exe.config 2016-04-28 17:12 - 2016-04-28 17:07 - 00000219 _____ C:\WINDOWS\system.ini 2016-04-28 17:11 - 2016-05-07 11:23 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-04-28 17:11 - 2016-05-07 07:48 - 00000000 ___HD C:\Program Files\WindowsApps 2016-04-28 17:11 - 2016-05-05 08:58 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-04-28 17:11 - 2016-05-02 19:52 - 00000000 ____D C:\WINDOWS\rescache 2016-04-28 17:11 - 2016-04-29 07:26 - 00000000 ____D C:\WINDOWS\appcompat 2016-04-28 17:11 - 2016-04-28 23:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-04-28 17:11 - 2016-04-28 21:40 - 00000000 ____D C:\WINDOWS\ShellNew 2016-04-28 17:11 - 2016-04-28 21:16 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2016-04-28 17:11 - 2016-04-28 20:38 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 __RSD C:\WINDOWS\Media 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\Program Files\Windows Journal 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-04-28 17:11 - 2016-04-28 20:37 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-04-28 17:11 - 2016-04-28 17:25 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-04-28 17:11 - 2016-04-28 17:25 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-04-28 17:11 - 2016-04-28 17:25 - 00000000 ____D C:\WINDOWS\Provisioning 2016-04-28 17:11 - 2016-04-28 17:21 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2016-04-28 17:11 - 2016-04-28 17:21 - 00000000 ____D C:\WINDOWS\SystemApps 2016-04-28 17:11 - 2016-04-28 17:21 - 00000000 ____D C:\WINDOWS\system32\MUI 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ___SD C:\WINDOWS\system32\dsc 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\setup 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\SysWOW64\Com 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\setup 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\migwiz 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\system32\Com 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\IME 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\Help 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\Program Files\Windows Defender 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\Program Files\Common Files\System 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2016-04-28 17:11 - 2016-04-28 17:19 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ___SD C:\WINDOWS\system32\Nui 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ___RD C:\WINDOWS\Offline Web Pages 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ___RD C:\WINDOWS\DesktopTileResources 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\WinMetadata 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\MsDtc 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\icsxml 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\ias 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\downlevel 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\Bthprops 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\Registration 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\L2Schemas 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\Cursors 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\WINDOWS\addins 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-04-28 17:11 - 2016-04-28 17:12 - 00000000 ____D C:\Program Files\Common Files\Services 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 __SHD C:\Program Files\Windows Sidebar 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ___SD C:\WINDOWS\system32\Configuration 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ___RD C:\WINDOWS\DevicesFlow 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\Web 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\Vss 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\tracing 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\TAPI 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\ras 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SystemResources 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\winevt 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\ras 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\ProximityToast 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\PointOfService 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\Ipmi 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\IME 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\config\Journal 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\AppLocker 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\System 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SKB 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\security 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\schemas 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\SchCache 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\Resources 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\PLA 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\Performance 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\ModemLogs 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\InputMethod 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\Globalization 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\Branding 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\ProgramData\Comms 2016-04-28 17:11 - 2016-04-28 17:11 - 00000000 ____D C:\Program Files (x86)\Windows NT 2016-04-28 17:11 - 2016-04-28 16:53 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-04-28 17:11 - 2016-04-28 16:53 - 00000000 ___RD C:\WINDOWS\MiracastView 2016-04-28 17:11 - 2016-04-28 16:53 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-04-28 17:11 - 2016-04-28 16:51 - 00000000 ____D C:\Program Files\Windows NT 2016-04-28 17:11 - 2016-04-28 16:50 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2016-04-28 17:11 - 2016-04-28 16:49 - 00000000 __RHD C:\Users\Public\Libraries 2016-04-28 17:11 - 2016-04-28 16:49 - 00000000 ____D C:\WINDOWS\system32\spool 2016-04-28 17:11 - 2016-04-28 16:49 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-04-28 17:11 - 2016-04-28 16:47 - 00000000 ____D C:\WINDOWS\CSC 2016-04-28 17:11 - 2016-04-28 16:45 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-04-28 17:11 - 2016-04-28 16:42 - 00000000 ____D C:\ProgramData\USOPrivate 2016-04-28 17:10 - 2016-05-06 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-04-28 17:10 - 2016-05-06 11:28 - 00000000 ____D C:\Users\p1\AppData\Roaming\Mozilla 2016-04-28 17:10 - 2016-04-28 17:24 - 00000000 ____D C:\Users\p1\AppData\Local\Mozilla 2016-04-28 17:10 - 2016-04-28 17:10 - 00001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-04-28 17:10 - 2016-04-28 17:10 - 00001220 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-04-28 17:09 - 2016-05-07 12:23 - 00000000 ____D C:\WINDOWS\INF 2016-04-28 17:07 - 2016-04-28 17:07 - 00242336 _____ C:\Users\p1\Downloads\Firefox Setup Stub 46.0.exe 2016-04-28 17:00 - 2016-04-28 17:01 - 00000000 ____D C:\Users\p1\AppData\Local\MicrosoftEdge 2016-04-28 17:00 - 2016-04-28 17:00 - 00000000 ____D C:\Users\p1\AppData\Local\ElevatedDiagnostics 2016-04-28 16:57 - 2016-04-28 16:58 - 00002402 _____ C:\Users\p1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-04-28 16:56 - 2016-04-28 16:56 - 00024398 _____ C:\Users\p1\Desktop\Usunięte aplikacje.html 2016-04-28 16:56 - 2016-04-28 16:56 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-04-28 16:55 - 2016-05-07 12:23 - 01845594 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-04-28 16:55 - 2016-04-28 20:31 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-04-28 16:54 - 2016-04-28 16:54 - 00000000 ____D C:\Users\p1\AppData\Local\ActiveSync 2016-04-28 16:53 - 2016-04-28 16:53 - 00000000 ____D C:\Users\p1\AppData\Local\Publishers 2016-04-28 16:52 - 2016-05-03 10:47 - 00000000 ____D C:\Users\p1\AppData\Local\Packages 2016-04-28 16:52 - 2016-05-02 17:40 - 00000000 ____D C:\Users\p1\AppData\Roaming\Adobe 2016-04-28 16:52 - 2016-04-28 16:52 - 00000000 ____D C:\Users\p1\AppData\Local\VirtualStore 2016-04-28 16:52 - 2016-04-28 16:52 - 00000000 ____D C:\Users\p1\AppData\Local\TileDataLayer 2016-04-28 16:51 - 2016-04-28 16:51 - 00000020 ___SH C:\Users\p1\ntuser.ini 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Ustawienia lokalne 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Szablony 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Moje dokumenty 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Menu Start 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Documents\Moje wideo 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Documents\Moje obrazy 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Documents\Moja muzyka 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\Dane aplikacji 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\AppData\Local\Historia 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dane aplikacji 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User\Documents\Moje wideo 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User\Documents\Moje obrazy 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User\Documents\Moja muzyka 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Historia 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dane aplikacji 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\Default User 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\Users\All Users 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Ulubione 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Szablony 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Pulpit 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Menu Start 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Dokumenty 2016-04-28 16:51 - 2016-04-28 16:51 - 00000000 _SHDL C:\ProgramData\Dane aplikacji 2016-04-28 16:48 - 2016-05-07 11:23 - 00000000 ____D C:\Users\p1 2016-04-28 16:48 - 2016-04-28 16:49 - 00000000 ____D C:\Users\DefaultAppPool 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Ustawienia lokalne 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Szablony 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Moje dokumenty 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Menu Start 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Documents\Moje wideo 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Documents\Moje obrazy 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Documents\Moja muzyka 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\Dane aplikacji 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\AppData\Local\Historia 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\p1\AppData\Local\Dane aplikacji 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Ustawienia lokalne 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Szablony 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Moje dokumenty 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Menu Start 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Moje wideo 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Moje obrazy 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Moja muzyka 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\Dane aplikacji 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Historia 2016-04-28 16:48 - 2016-04-28 16:48 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Dane aplikacji 2016-04-28 16:46 - 2016-05-05 10:18 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-04-28 16:46 - 2016-04-28 17:19 - 00000000 ____D C:\WINDOWS\servicing 2016-04-28 16:46 - 2016-04-28 17:11 - 00000000 ____D C:\WINDOWS\system32\SMI 2016-04-28 16:46 - 2016-04-28 16:42 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2016-04-28 16:46 - 2015-10-30 08:33 - 00000164 _____ C:\WINDOWS\system32\config\FP 2016-04-28 16:42 - 2016-04-28 16:42 - 00000000 ____D C:\ProgramData\USOShared 2016-04-28 16:42 - 2016-04-28 16:42 - 00000000 _____ C:\WINDOWS\ativpsrm.bin 2016-04-28 16:41 - 2016-04-28 16:41 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2016-04-28 16:41 - 2015-10-30 09:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-04-28 16:38 - 2016-05-07 12:17 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-04-28 16:37 - 2016-04-29 07:23 - 00357080 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-04-28 16:37 - 2016-04-28 16:38 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2016-04-28 15:43 - 2016-04-29 08:29 - 00000000 ___HD C:\$SysReset 2016-04-12 20:17 - 2016-04-12 20:17 - 22378496 ____N (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 19340800 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 18673664 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 12125184 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 02755584 ____N (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 02229760 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 01731584 ____N (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 01500672 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00970752 ____N (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00792064 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00630632 ____N (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-04-12 20:17 - 2016-04-12 20:17 - 00365568 ____N (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00069632 ____N (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00065536 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00052224 ____N (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2016-04-12 20:17 - 2016-04-12 20:17 - 00045568 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 24602112 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 16985600 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 13382656 ____N (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 13018624 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 11545600 ____N (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 09918976 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 07836160 ____N (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 07474016 ____N (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-04-12 20:16 - 2016-04-12 20:16 - 07199232 ____N (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 05662208 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 05202944 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 03994624 ____N (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 03592704 ____N (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-04-12 20:16 - 2016-04-12 20:16 - 03575296 ____N (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 03078144 ____N (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02722816 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02656952 ____N C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02635776 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02624512 ____N (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02275328 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02158592 ____N (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 02152280 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-04-12 20:16 - 2016-04-12 20:16 - 01946112 ____N (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01944576 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01862008 ____N C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01832448 ____N (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01714688 ____N (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01626624 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01444352 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01395712 ____N (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01390080 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01388544 ____N (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-04-12 20:16 - 2016-04-12 20:16 - 01388032 ____N (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01297752 ____N (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01213440 ____N (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01139712 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01098240 ____N (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 01054208 ____N (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00986976 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00965632 ____N (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00948736 ____N (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00938496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00859136 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00852480 ____N (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00799744 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00711680 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00649728 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00641536 ____N (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00630272 ____N (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00605440 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-04-12 20:16 - 2016-04-12 20:16 - 00345600 ____N (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00245760 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00118272 ____N (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-04-12 20:16 - 2016-04-12 20:16 - 00045568 ____N (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-04-12 20:15 - 2016-04-12 20:16 - 00958976 ____N (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 07979008 ____N (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 06297088 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 04774912 ____N (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 03671040 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 03428864 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 03351040 ____N (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 02798080 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 02403680 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 01902592 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01799680 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01588224 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01575936 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01410560 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01317640 ____N (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-04-12 20:15 - 2016-04-12 20:15 - 01239552 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01211904 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01152864 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 01141504 ____N (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 01117184 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01090048 ____N (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01089888 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 01072128 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01056256 ____N (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01052160 ____N (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 01030416 ____N (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-04-12 20:15 - 2016-04-12 20:15 - 00989536 ____N (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-04-12 20:15 - 2016-04-12 20:15 - 00988160 ____N (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00988160 ____N (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00957952 ____N (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2016-04-12 20:15 - 2016-04-12 20:15 - 00888320 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00881664 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00874968 ____N (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00854528 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00848896 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00848896 ____N (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00841216 ____N (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00821760 ____N (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00821248 ____N (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00800768 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00794112 ____N (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2016-04-12 20:15 - 2016-04-12 20:15 - 00787456 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00777728 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00770640 ____N (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00765952 ____N (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00764928 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00730344 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00712704 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00708608 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00705536 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00696664 ____N (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00694784 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00688640 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00686976 ____N (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00686592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00682496 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00676352 ____N (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00638464 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00638464 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00628736 ____N (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00617984 ____N (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00592384 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00587776 ____N (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00564224 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00556032 ____N (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00555520 ____N (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00550912 ____N (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00541304 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00535080 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00530432 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00521728 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00502104 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00498688 ____N (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00498176 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00496128 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00471552 ____N (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00460288 ____N (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00450560 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00440320 ____N (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00438784 ____N (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00418304 ____N (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00415232 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00411648 ____N (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00402432 ____N (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 2016-04-12 20:15 - 2016-04-12 20:15 - 00378208 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2016-04-12 20:15 - 2016-04-12 20:15 - 00374008 ____N (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00369912 ____N (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00361472 ____N (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00358752 ____N (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00358400 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00354304 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00350720 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00346624 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00339968 ____N (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00338432 ____N (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00334736 ____N (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00333824 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00330240 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00328192 ____N (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00324608 ____N (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00324608 ____N (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00323072 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00306176 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00303104 ____N (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00300104 ____N (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00296488 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00294752 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00288256 ____N (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00285696 ____N (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00284672 ____N (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00278528 ____N (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00277856 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00269824 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2016-04-12 20:15 - 2016-04-12 20:15 - 00269824 ____N (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00261376 ____N (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00258912 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00256000 ____N (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00253088 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00250880 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00239616 ____N (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00239104 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00230400 ____N (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00219648 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00209408 ____N (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00207360 ____N (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00193024 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00185184 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00176640 ____N (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00176128 ____N (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00175616 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00169472 ____N (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00167936 ____N (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00166400 ____N (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00162816 ____N (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00161792 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00151040 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00151040 ____N (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00148480 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00144896 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00141824 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00134656 ____N (Microsoft Corporation) C:\WINDOWS\system32\browser.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00133632 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00129024 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00128512 ____N (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00127488 ____N (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00119808 ____N (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00116224 ____N (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00115040 ____N (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00110584 ____N (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00108544 ____N (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00103936 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00100232 ____N (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00095744 ____N (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00092160 ____N (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00092160 ____N (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00091136 ____N (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00088576 ____N (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00087040 ____N (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00084832 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00083968 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00083968 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys 2016-04-12 20:15 - 2016-04-12 20:15 - 00081144 ____N (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00078040 ____N (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00076800 ____N (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00074752 ____N (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00074424 ____N (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00073872 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00069744 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00069632 ____N (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00066560 ____N (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00066048 ____N (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00065536 ____N (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00059904 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00058400 ____N (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00058368 ____N (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00056320 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00051128 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00048128 ____N (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00043520 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00036352 ____N (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00034816 ____N (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00033280 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00031232 ____N (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00030208 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00028672 ____N (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00027648 ____N (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00026112 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll 2016-04-12 20:15 - 2016-04-12 20:15 - 00026112 ____N (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2016-04-12 20:15 - 2016-04-12 20:15 - 00022528 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2016-04-12 20:14 - 2016-04-12 20:15 - 00120320 ____N (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-04-12 20:14 - 2016-04-12 20:15 - 00089088 ____N (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 02193408 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00784896 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00764928 ____N (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00414720 ____N (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-04-12 20:14 - 2016-04-12 20:14 - 00235008 ____N C:\WINDOWS\system32\MTF.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00223232 ____N (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00199168 ____N (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-04-12 20:14 - 2016-04-12 20:14 - 00162816 ____N C:\WINDOWS\SysWOW64\MTF.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00161280 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-04-12 20:14 - 2016-04-12 20:14 - 00147456 ____N (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00118272 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00107520 ____N (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00093696 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00087040 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00086528 ____N (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00083456 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00080384 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00061440 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00052736 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00037376 ____N (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00026112 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-04-12 20:14 - 2016-04-12 20:14 - 00012800 ____N (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll 2016-04-12 20:14 - 2016-04-12 20:14 - 00010240 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll 2016-04-12 15:54 - 2016-04-12 15:54 - 00000000 ___RD C:\Users\p1\3D Objects 2016-04-08 19:28 - 2016-04-08 19:28 - 05776144 _____ (Adobe Systems Inc.) C:\Users\p1\Downloads\Shockwave_Installer_Slim(2).exe ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-05-06 15:55 - 2014-06-26 17:23 - 00013116 _____ C:\Users\p1\Desktop\15.xlsx 2016-04-29 18:35 - 2016-02-16 18:26 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk 2016-04-29 18:33 - 2016-02-16 18:21 - 30993712 _____ (Riot Games) C:\Users\p1\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe 2016-04-28 20:42 - 2016-02-13 19:51 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-04-28 17:03 - 2016-02-13 19:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2016-04-28 17:03 - 2016-02-13 19:32 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2016-04-28 16:58 - 2016-04-06 20:02 - 00000000 ___RD C:\Users\p1\OneDrive 2016-04-28 16:49 - 2011-04-12 15:32 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-04-22 20:42 - 2014-06-01 11:58 - 00000000 ____D C:\Users\p1\Desktop\paweł Pliki do przeniesienia lub usunięcia: ==================== C:\Windows\Tasks\{164C6228-4EBD-C994-28B9-5553392DA31F}.job ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\wininit.exe => Plik podpisany cyfrowo C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2016-04-28 16:37 ==================== Koniec FRST.txt ============================