Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 20-04-2020 Uruchomiony przez El Jefe (administrator) DESKTOP-LV3H0QB (Gigabyte Technology Co., Ltd. B450M S2H) (21-04-2020 16:22:15) Uruchomiony z C:\Users\user\Desktop Załadowane profile: El Jefe (Dostępne profile: El Jefe) Platform: Windows 10 Pro Wersja 1909 18363.778 (X64) Język: Polski (Polska) Domyślna przeglądarka: Chrome Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0351300.inf_amd64_6d6cbd77ac26f221\B351053\atieclxx.exe (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0351300.inf_amd64_6d6cbd77ac26f221\B351053\atiesrxx.exe (Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <13> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1910.0.0_x64__8wekyb3d8bbwe\Calculator.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\schtasks.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2> ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG) HKU\S-1-5-21-1504688530-2681568869-95099009-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.113\Installer\chrmstp.exe [2020-04-16] (Google LLC -> Google LLC) AlternateShell: GroupPolicy: Ograniczenia ? <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {08EDB07C-3087-4DC8-953F-EBDF0CEF48B5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) Task: {284BBAD6-DB77-4345-BBC3-4F9C485671F0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems) Task: {3BAD4239-99AC-41EC-BC1E-982E06431D8B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {45459A42-C016-45B3-91FF-AD0B0835D85E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-12-12] (Google Inc -> Google LLC) Task: {4B8E1996-5478-4E20-B417-EBCB2373B4E1} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd) Task: {531E3292-4AE8-4B35-84F4-A74BE0A4396D} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-01-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {6D3BAB81-CBAC-4AAC-A8AF-92A09029B696} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628672 2020-01-17] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] Task: {84AE7CB7-8A3F-451C-AE3F-646F1C584C58} - System32\Tasks\microsoft\windows\windowsupdate\clean => cmd.exe /c attrib -h -s C:\Users\user\AppData\Roaming\*.exe & attrib -h -s C:\Users\user\AppData\Roaming\*.bat & del C:\Users\user\AppData\Roaming\*.bat & del C:\Users\user\AppData\Roaming\svchosts.exe Task: {8A3A4E96-1D46-42D2-8747-CDDDF65FADDA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {8F42DC21-EE86-4625-ADA2-A88BF9FE056B} - System32\Tasks\Microsoft\Windows\Maintenance\InstallWinSAT => C:\Windows\system32\Maintenance.vbs [12 2020-02-20] () [Brak podpisu cyfrowego] Task: {9B41A53E-8BF4-44EC-97EA-DB115A2226E2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-12-12] (Google Inc -> Google LLC) Task: {A131812E-848B-49F9-9F98-6D8C149605BD} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628672 2020-01-17] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] Task: {A9094CB9-9592-483E-8DDF-65A932D79D62} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628672 2020-01-17] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] Task: {EFE2E9F4-FBD8-4EC2-8F87-9858634320F4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F4274F06-18A4-44E3-91B4-A0E29D2CC2F5} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2020-01-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {F5F3A894-2799-4AA9-B6CD-74C61474CF93} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{c2eb92f3-ec52-4de1-8927-c9917a99b60c}: [DhcpNameServer] 192.168.43.65 Tcpip\..\Interfaces\{f69f53dd-4ba9-4d99-9003-c2f08f7428f4}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sTNLUi11.default [2019-12-12] FF Extension: (Avira Password Manager) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sTNLUi11.default\Extensions\passwordmanager@avira.com [2019-12-12] FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default [2020-04-21] CHR Notifications: Default -> hxxps://localbitcoins.com CHR HomePage: Default -> hxxps://www.youtube.com/ CHR StartupUrls: Default -> "hxxp://wolnemedia.net/" CHR Extension: (Prezentacje) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-12-12] CHR Extension: (Dokumenty) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-12-12] CHR Extension: (Dysk Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-12-12] CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-12-12] CHR Extension: (Tampermonkey) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2019-12-12] CHR Extension: (Arkusze) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-12-12] CHR Extension: (Bookmarks Menu) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffmdedmghpoipeldijkdlcckdpempkdi [2020-02-02] CHR Extension: (Dokumenty Google offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-20] CHR Extension: (AdBlock — best ad blocker) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-04-12] CHR Extension: (Auto Replay for YouTube™) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2019-12-12] CHR Extension: (Clickable Links) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgamelhnfokapndfdodnmfiningckjia [2019-12-12] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-12] CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-12-12] CHR Extension: (Chrome Media Router) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-10] CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AMD External Events Utility; C:\Windows\System32\DriverStore\FileRepository\u0351300.inf_amd64_6d6cbd77ac26f221\B351053\atiesrxx.exe [524088 2020-01-27] (Advanced Micro Devices, Inc. -> AMD) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2020-02-20] (Malwarebytes Inc -> Malwarebytes) R2 RtkAudioUniversalService; C:\Windows\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5930136 2020-04-17] (Microsoft Windows Publisher -> Microsoft Corporation) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WindscribeService; D:\Windscribe\WindscribeService.exe [493232 2019-01-19] (Windscribe Limited -> Windscribe Limited) S2 wut; cmd.exe /c C:\Users\user\AppData\Roaming\svchosts.exe [X] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 amdgpio2; C:\Windows\System32\drivers\amdgpio2.sys [46040 2019-10-30] (Advanced Micro Devices INC. -> Advanced Micro Devices, Inc) R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [24528 2019-04-18] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc) R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\u0351300.inf_amd64_6d6cbd77ac26f221\B351053\atikmdag.sys [65752888 2020-01-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R3 AMDKMDAP; C:\Windows\System32\DriverStore\FileRepository\u0351300.inf_amd64_6d6cbd77ac26f221\B351053\atikmpag.sys [591672 2020-01-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [111456 2019-12-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R3 AMDPCIDev; C:\Windows\System32\drivers\AMDPCIDev.sys [32520 2019-09-17] (Advanced Micro Devices INC. -> Advanced Micro Devices) R0 amdpsp; C:\Windows\System32\drivers\amdpsp.sys [138064 2019-06-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. ) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [108152 2019-11-18] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices) S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-02-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1167768 2019-11-20] (Realtek Semiconductor Corp. -> Realtek ) R3 tapwindscribe0901; C:\Windows\System32\drivers\tapwindscribe0901.sys [54896 2018-07-06] (Windscribe Limited -> The OpenVPN Project) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation) S3 athur; \SystemRoot\System32\drivers\athuw8x.sys [X] S3 cpuz148; \??\C:\Windows\temp\cpuz148\cpuz148_x64.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-04-21 16:22 - 2020-04-21 16:22 - 000015800 _____ C:\Users\user\Desktop\FRST.txt 2020-04-21 16:21 - 2020-04-21 16:22 - 000000000 ____D C:\FRST 2020-04-21 16:21 - 2020-04-21 16:21 - 002281984 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe 2020-04-21 16:06 - 2020-04-21 16:07 - 000000000 ____D C:\AdwCleaner 2020-04-20 19:46 - 2020-04-20 19:46 - 000000000 ____D C:\Users\user\Desktop\Autoruns 2020-04-20 17:27 - 2020-03-13 16:30 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthA2dp.sys 2020-04-17 12:23 - 2020-04-17 12:23 - 025444352 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 019812864 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 004129624 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 002951832 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 002494744 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 001870408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 001151816 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 001013000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000983040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000420152 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000321536 _____ (Microsoft Corporation) C:\Windows\system32\wbadmin.exe 2020-04-17 12:23 - 2020-04-17 12:23 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.XamlHost.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.XamlHost.dll 2020-04-17 12:23 - 2020-04-17 12:23 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll 2020-04-17 12:22 - 2020-04-17 12:23 - 001659408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.AppAgent.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 022636544 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 019850240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 018027520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 017790464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 014818816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 009930552 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 008013824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 007849216 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 007756800 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 007017472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 006523048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 006168064 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 005910016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 005040640 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 004611584 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 004563200 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 004538880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003980800 _____ (Microsoft Corporation) C:\Windows\system32\tellib.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003802624 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003753472 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003742544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003729408 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 003708928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003587384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 003547648 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003512320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 003109376 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002986808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 002871608 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 002800640 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 002800128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 002767928 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002717184 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 002453504 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002369576 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.AppAgent.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002188600 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002180408 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002131456 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002126144 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002114560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 002086656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001999960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001960448 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001945600 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001942528 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001918976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001835008 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001783296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001764336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001762816 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001757096 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2020-04-17 12:22 - 2020-04-17 12:22 - 001729024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001726264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001719808 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001697792 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001665216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001656904 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001646048 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001612800 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001603584 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001587712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001545216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001512832 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001497600 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001495864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001484384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001480192 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001477112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001427456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001413840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001413704 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001397576 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001386296 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001378528 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001318912 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001300280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 001264640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001263856 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001261808 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001257472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001245184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001243648 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\windowsperformancerecordercontrol.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001136128 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001127424 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001083904 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001081856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001077064 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 001071616 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001055376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001011200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001009152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 001008128 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000993280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000982840 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000974336 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000924672 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000923136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000915192 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000912896 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000893952 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000892416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000879616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000874296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windowsperformancerecordercontrol.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000865280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000865280 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000840704 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Language.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000836608 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000835584 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000822208 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000811320 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000785920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000783480 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000775696 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000772096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000768528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000759272 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000747320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000744960 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.Office2013CustomActions.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000729600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FlightSettings.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000722072 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BTAGService.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000684560 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000673704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000673464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000668672 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000654912 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000647680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000638480 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000637240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000632832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000629760 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000628616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000618296 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000604984 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000589384 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000561464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000555008 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl 2020-04-17 12:22 - 2020-04-17 12:22 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000538160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000530432 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000529408 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000524264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000516096 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000515600 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000513576 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000510792 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000507152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000498688 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000491008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcext.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000487784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000477496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2020-04-17 12:22 - 2020-04-17 12:22 - 000469504 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000465208 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000459688 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000456504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000456192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl 2020-04-17 12:22 - 2020-04-17 12:22 - 000452096 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000441144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000437560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000416016 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000415760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000410112 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000408064 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000406480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\es.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000374784 _____ (Microsoft Corporation) C:\Windows\system32\ncbservice.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000355840 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicSvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\WpcApi.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\wpr.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000339304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\es.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000330240 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000324408 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000323584 _____ (Microsoft Corporation) C:\Windows\system32\sppcommdlg.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000297272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicCapsule.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000278016 _____ (Microsoft Corporation) C:\Windows\system32\WpcTok.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000277864 _____ (Microsoft Corporation) C:\Windows\system32\LsaIso.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000268288 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000268008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000259776 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000251704 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000251392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000241152 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\InstallServiceTasks.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000231912 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000214528 _____ (Microsoft Corporation) C:\Windows\system32\srumsvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000203264 _____ (Microsoft Corporation) C:\Windows\system32\LanguageComponentsInstaller.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000200192 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000193848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000190048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrad.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000185952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000178192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000178176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srumsvc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\SpatialAudioLicenseSrv.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000164368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000152408 _____ (Microsoft Corporation) C:\Windows\system32\KerbClientShared.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000151352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scmbus.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000147696 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000142544 _____ (Microsoft Corporation) C:\Windows\system32\LicensingUI.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\slc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000130560 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000129024 _____ (Microsoft Corporation) C:\Windows\system32\UtcDecoderHost.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000127280 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000123952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KerbClientShared.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000122368 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000115120 _____ (Microsoft Corporation) C:\Windows\system32\phoneactivate.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\WorkFolders.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000102216 _____ (Microsoft Corporation) C:\Windows\system32\changepk.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Custom.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000093712 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\dot3api.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000089912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000089336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicAgent.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000088352 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3api.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3msm.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000084280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000071480 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000066624 _____ (Microsoft Corporation) C:\Windows\system32\iumcrypt.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasacct.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\srumapi.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\CloudNotifications.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000059192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000058880 _____ C:\Windows\system32\runexehelper.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\audioresourceregistrar.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srumapi.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000050544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudNotifications.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000047000 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.Office2010CustomActions.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.Common.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\WiredNetworkCSP.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\UpgradeResultsUI.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iaspolcy.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\WpcProxyStubs.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000036152 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\sxssrv.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000033080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\ias.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\KNetPwrDepBroker.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicPS.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\flpydisk.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ias.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Custom.ps.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\slcext.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\sbservicetrigger.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000021520 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slcext.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sfloppy.sys 2020-04-17 12:22 - 2020-04-17 12:22 - 000017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\icsunattend.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.ps.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\pacjsworker.exe 2020-04-17 12:22 - 2020-04-17 12:22 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\DMAlertListener.ProxyStub.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DMAlertListener.ProxyStub.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin 2020-04-17 12:22 - 2020-04-17 12:22 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin 2020-04-17 12:17 - 2020-03-17 05:57 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2020-04-17 12:17 - 2020-03-17 05:56 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2020-04-12 18:12 - 2020-04-12 18:12 - 000000000 ____D C:\Users\user\Documents\Call of Duty Modern Warfare 2020-04-12 18:07 - 2020-04-12 18:07 - 000000549 _____ C:\Users\Public\Desktop\Call of Duty Modern Warfare.lnk 2020-04-12 18:07 - 2020-04-12 18:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Modern Warfare 2020-04-12 13:50 - 2020-04-19 19:40 - 000000000 ____D C:\Users\user\AppData\Local\Battle.net 2020-04-12 13:50 - 2020-04-12 13:50 - 000000000 ____D C:\Users\user\AppData\Roaming\Battle.net 2020-04-12 13:49 - 2020-04-12 13:49 - 000000489 _____ C:\Users\Public\Desktop\Battle.net.lnk 2020-04-12 13:49 - 2020-04-12 13:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2020-04-05 12:43 - 2020-04-05 12:43 - 000000000 ____D C:\Users\user\AppData\Local\TP-Link 2020-03-26 13:21 - 2020-03-26 13:21 - 006316979 _____ ( ) C:\Users\user\AppData\Roaming\setup.exe ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-04-21 16:21 - 2019-03-19 06:50 - 000000000 ____D C:\Windows\INF 2020-04-21 16:20 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-04-21 16:04 - 2019-12-12 13:42 - 001769484 _____ C:\Windows\system32\PerfStringBackup.INI 2020-04-21 16:04 - 2019-03-19 14:24 - 000784752 _____ C:\Windows\system32\perfh015.dat 2020-04-21 16:04 - 2019-03-19 14:24 - 000152550 _____ C:\Windows\system32\perfc015.dat 2020-04-21 16:00 - 2020-02-16 12:42 - 000003116 _____ C:\Windows\system32\Tasks\AMDLinkUpdate 2020-04-21 16:00 - 2020-02-08 15:37 - 000003130 _____ C:\Windows\system32\Tasks\AMDInstallLauncher 2020-04-21 16:00 - 2019-12-12 13:34 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-04-20 21:09 - 2019-12-12 13:43 - 000065536 _____ C:\Windows\system32\spu_storage.bin 2020-04-20 21:09 - 2019-03-19 06:37 - 000524288 _____ C:\Windows\system32\config\BBI 2020-04-20 19:09 - 2020-02-08 15:37 - 000002202 _____ C:\Windows\system32\Tasks\StartCN 2020-04-20 19:09 - 2020-02-08 15:37 - 000002122 _____ C:\Windows\system32\Tasks\StartDVR 2020-04-20 18:03 - 2019-03-19 06:37 - 000000000 ____D C:\Windows\CbsTemp 2020-04-20 17:12 - 2019-12-12 13:34 - 000000000 ____D C:\Windows\system32\SleepStudy 2020-04-19 14:36 - 2019-12-12 20:51 - 000000000 ____D C:\Users\user\AppData\LocalLow\Mozilla 2020-04-19 12:45 - 2019-12-12 13:43 - 000000000 ____D C:\Users\user\AppData\Local\D3DSCache 2020-04-18 12:19 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\AppReadiness 2020-04-18 12:05 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-04-18 12:04 - 2019-12-12 13:34 - 000447488 _____ C:\Windows\system32\FNTCACHE.DAT 2020-04-18 00:22 - 2019-03-19 14:26 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\SystemResources 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\PerceptionSimulation 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\migwiz 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\ShellExperiences 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\Provisioning 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\PolicyDefinitions 2020-04-18 00:22 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\bcastdvr 2020-04-16 12:21 - 2019-12-12 13:41 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-04-16 12:21 - 2019-12-12 13:41 - 000002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-04-15 22:43 - 2019-12-15 20:53 - 000000000 ____D C:\Users\user\AppData\Roaming\vlc 2020-04-15 21:08 - 2019-12-12 20:57 - 000000000 ____D C:\Users\user\AppData\Roaming\qBittorrent 2020-04-15 20:20 - 2019-12-12 13:39 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1504688530-2681568869-95099009-1001 2020-04-15 20:20 - 2019-12-12 13:39 - 000000000 ___RD C:\Users\user\OneDrive 2020-04-15 20:20 - 2019-12-12 13:37 - 000002404 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-04-05 14:34 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\NDF 2020-04-05 12:34 - 2020-01-22 14:06 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update 2020-04-02 16:28 - 2020-01-21 15:27 - 000000000 ____D C:\Users\user\AppData\Roaming\gnupg 2020-04-02 16:17 - 2019-12-12 13:44 - 000744808 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2020-03-25 19:41 - 2019-12-12 13:34 - 000000000 ____D C:\Windows\system32\Drivers\wd ==================== Pliki w katalogu głównym wybranych folderów ======== 2020-02-10 00:02 - 2020-02-10 00:02 - 000000447 ___SH () C:\Users\user\AppData\Roaming\d.vbs 2019-04-08 20:40 - 2019-04-08 20:40 - 000000338 ___SH () C:\Users\user\AppData\Roaming\h.vbs 2020-03-26 13:21 - 2020-03-26 13:21 - 006316979 _____ ( ) C:\Users\user\AppData\Roaming\setup.exe 2020-02-21 23:26 - 2020-02-21 23:26 - 000007611 _____ () C:\Users\user\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================