REKLAMA

FRST.txt

Jak usunąć infekcję? Raporty FRST do analizy

Witam, mam ten sam problem i wysyłam raporty Frist z FRST. Wydzieliłem post do nowego tematu. Nie podczepiaj się pod wątki innych Autorów. 3.1.11. Nie wysyłaj wiadomości, które nic nie wnoszą do dyskusji. Wprowadzają w błąd, są niebezpieczne czy nie rozwiązują problemu użytkownika.


Pobierz plik - link do postu

Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:07-01-2015
Uruchomiony przez AJOHAF (administrator) AJOHAF-KOMPUTER (08-01-2016 15:47:36)
Uruchomiony z C:\Users\AJOHAF\Downloads
Załadowane profile: AJOHAF (Dostępne profile: AJOHAF)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 8 (Domyślna przeglądarka: Chrome)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe
(Intel® Corporation) C:\Program Files\Intel\CAM\bin\CAMService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TData.com) C:\Program Files (x86)\TDataDld\TData.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(BitTorrent Inc.) C:\Users\AJOHAF\AppData\Roaming\BitTorrent\BitTorrent.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(BitTorrent Inc.) C:\Users\AJOHAF\AppData\Roaming\BitTorrent\updates\7.9.5_41373\utorrentie.exe
(BitTorrent Inc.) C:\Users\AJOHAF\AppData\Roaming\BitTorrent\updates\7.9.5_41373\utorrentie.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [RTHDVCPL] = & gt; C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-09-17] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] = & gt; C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1409264 2015-09-17] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] = & gt; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3942568 2015-08-03] (Synaptics Incorporated)
HKLM-x32\...\Run: [NUSB3MON] = & gt; C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2013-08-12] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe ARM] = & gt; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4028727819-3347721802-3378051285-1000\...\Run: [EADM] = & gt; C:\Program Files (x86)\Origin\Origin.exe [3639280 2015-12-31] (Electronic Arts)
HKU\S-1-5-21-4028727819-3347721802-3378051285-1000\...\Run: [BitTorrent] = & gt; C:\Users\AJOHAF\AppData\Roaming\BitTorrent\BitTorrent.exe [1877792 2016-01-04] (BitTorrent Inc.)
HKU\S-1-5-21-4028727819-3347721802-3378051285-1000\...\Run: [Skype] = & gt; C:\Program Files (x86)\Skype\Phone\Skype.exe [50378880 2015-12-29] (Skype Technologies S.A.)

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{A75671A0-3D1B-414F-8BF0-6BCCD1BA8677}: [DhcpNameServer] 192.168.178.1

Internet Explorer:
==================
HKU\S-1-5-21-4028727819-3347721802-3378051285-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}
HKU\S-1-5-21-4028727819-3347721802-3378051285-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms}
HKU\S-1-5-21-4028727819-3347721802-3378051285-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - & gt; DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 - & gt; ielnksrch URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4028727819-3347721802-3378051285-1000 - & gt; DefaultScope {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-4028727819-3347721802-3378051285-1000 - & gt; {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms}
BHO: Lync Browser Helper - & gt; {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - & gt; C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler - & gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} - & gt; C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - & gt; {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - & gt; C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - & gt; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - & gt; C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper - & gt; {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - & gt; C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - & gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} - & gt; C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - & gt; {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - & gt; C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 - & gt; C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - & gt; C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - & gt; C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-31] (Google Inc.)
FF Plugin-x32: Adobe Reader - & gt; C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentacje Google) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-06]
CHR Extension: (Dokumenty Google) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-06]
CHR Extension: (Dysk Google) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-06]
CHR Extension: (YouTube) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-06]
CHR Extension: (Google Search) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-06]
CHR Extension: (Arkusze Google) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-06]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-06]
CHR Extension: (Gmail) - C:\Users\AJOHAF\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-06]

==================== Usługi (filtrowane) ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 CAMService; C:\Program Files\Intel\CAM\bin\CAMService.exe [1246112 2015-06-03] (Intel® Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-31] (Electronic Arts)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2015-08-03] (Synaptics Incorporated)
R2 TDataSvr; C:\Program Files (x86)\TDataDld\TData.exe [133360 2015-12-31] (TData.com)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel® Corporation)

===================== Sterowniki (filtrowane) ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-07-18] (Qualcomm Atheros Co., Ltd.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [179456 2015-08-31] (Intel Corporation)
R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [404184 2015-08-18] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-01-08 15:47 - 2016-01-08 15:47 - 00000000 ____D C:\FRST
2016-01-08 15:46 - 2016-01-08 15:46 - 02370560 _____ (Farbar) C:\Users\AJOHAF\Downloads\FRST64.exe
2016-01-08 15:44 - 2016-01-08 15:47 - 00012370 _____ C:\Users\AJOHAF\Downloads\FRST.txt
2016-01-07 11:08 - 2016-01-07 11:08 - 00000000 ____D C:\Users\AJOHAF\Documents\Niestandardowe szablony pakietu Office
2016-01-06 22:28 - 2016-01-08 13:50 - 00003076 _____ C:\Windows\System32\Tasks\Advanced System~Protector_startup
2016-01-06 22:28 - 2016-01-06 22:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System~Protector
2016-01-06 22:28 - 2016-01-06 22:28 - 00003694 _____ C:\Windows\System32\Tasks\Advanced System~Protector
2016-01-06 22:28 - 2016-01-06 22:28 - 00001045 _____ C:\Users\Public\Desktop\Advanced System~Protector.lnk
2016-01-06 22:28 - 2016-01-06 22:28 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\Systweak
2016-01-06 22:27 - 2016-01-07 13:21 - 00000000 ____D C:\Program Files (x86)\ASP
2016-01-06 22:27 - 2016-01-06 22:28 - 00000000 ____D C:\ProgramData\Systweak
2016-01-06 22:27 - 2015-11-03 17:45 - 00022992 _____ C:\Windows\system32\sasnative64.exe
2016-01-06 22:26 - 2016-01-08 13:49 - 00000000 ____D C:\Users\AJOHAF\AppData\LocalLow\BitTorrent
2016-01-05 18:19 - 2016-01-05 18:19 - 00000000 ____D C:\Users\AJOHAF\Tracing
2016-01-05 18:18 - 2016-01-08 15:36 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Skype
2016-01-05 18:18 - 2016-01-05 18:18 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2016-01-05 18:18 - 2016-01-05 18:18 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-05 18:18 - 2016-01-05 18:18 - 00000000 ____D C:\ProgramData\Skype
2016-01-05 18:18 - 2016-01-05 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-01-05 14:28 - 2016-01-07 09:34 - 00000000 ____D C:\Users\AJOHAF\Desktop\lego wrocław
2016-01-05 14:27 - 2016-01-05 14:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2016-01-04 21:07 - 2016-01-06 17:07 - 00000066 _____ C:\Users\AJOHAF\AppData\Roaming\WB.CFG
2016-01-04 19:10 - 2016-01-08 15:46 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\BitTorrent
2016-01-04 19:10 - 2016-01-04 19:10 - 00002691 _____ C:\Users\AJOHAF\Desktop\BitTorrent.lnk
2016-01-04 19:10 - 2016-01-04 19:10 - 00002691 _____ C:\Users\AJOHAF\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2016-01-04 19:10 - 2016-01-04 19:10 - 00000000 ____D C:\Program Files (x86)\TDataDld
2016-01-04 19:08 - 2016-01-04 19:08 - 00002377 _____ C:\Windows\SysWOW64\findit.xml
2016-01-04 19:08 - 2016-01-04 19:08 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Mozilla
2016-01-04 19:07 - 2016-01-06 22:07 - 00000296 _____ C:\Windows\Tasks\Price Fountain.job
2016-01-04 19:07 - 2016-01-04 19:09 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\SwarmerAntithetical
2016-01-04 19:07 - 2016-01-04 19:07 - 00003458 _____ C:\Windows\System32\Tasks\AJOHAFSwarmerAntitheticalV2
2016-01-04 19:07 - 2016-01-04 19:07 - 00003252 _____ C:\Windows\System32\Tasks\Price Fountain
2016-01-04 11:44 - 2016-01-04 11:44 - 00000000 ____D C:\Users\AJOHAF\Documents\efile-backup
2016-01-04 11:40 - 2016-01-04 11:40 - 00003998 _____ C:\Windows\System32\Tasks\e-pity2015_styczen
2016-01-04 11:40 - 2016-01-04 11:40 - 00003998 _____ C:\Windows\System32\Tasks\e-pity2015_kwiecien
2016-01-04 11:40 - 2016-01-04 11:40 - 00001185 _____ C:\Users\AJOHAF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\e-pity 2015 - program, pity roczne, e-deklaracje.lnk
2016-01-04 11:40 - 2016-01-04 11:40 - 00001155 _____ C:\Users\AJOHAF\Desktop\e-pity 2015 - program, pity roczne, e-deklaracje.lnk
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\Users\AJOHAF\Documents\efile
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Macromedia
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\fillUp
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\com.efile.epity2015
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Adobe
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-pity
2016-01-04 11:40 - 2016-01-04 11:40 - 00000000 ____D C:\Program Files (x86)\e-file
2016-01-01 14:20 - 2016-01-01 14:20 - 00002252 _____ C:\Users\Public\Desktop\The Sims™ 3 Nowoczesny apartament Akcesoria.lnk
2016-01-01 14:19 - 2016-01-01 14:19 - 00002324 _____ C:\Users\Public\Desktop\The Sims™ 3 Po zmroku.lnk
2016-01-01 14:12 - 2016-01-01 14:12 - 00002134 _____ C:\Users\Public\Desktop\The Sims™ 3 Zwierzaki.lnk
2015-12-31 19:02 - 2015-12-31 19:02 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-12-31 19:02 - 2015-12-31 19:02 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-12-31 19:02 - 2015-12-31 19:02 - 00000000 ____D C:\ProgramData\Adobe
2015-12-31 19:02 - 2015-12-31 19:02 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-12-31 19:00 - 2015-12-31 19:00 - 00000000 ____D C:\Users\AJOHAF\Desktop\MovieStarPlanet
2015-12-31 19:00 - 2015-12-31 19:00 - 00000000 ____D C:\Users\AJOHAF\Desktop\Life is Strange
2015-12-31 19:00 - 2015-12-31 19:00 - 00000000 ____D C:\Users\AJOHAF\Desktop\Hania
2015-12-31 19:00 - 2015-12-31 19:00 - 00000000 ____D C:\Users\AJOHAF\Desktop\Facebook
2015-12-31 18:35 - 2015-12-31 18:35 - 00001398 _____ C:\Users\Public\Desktop\The Sims 3.lnk
2015-12-31 18:35 - 2015-12-31 18:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 3
2015-12-31 18:33 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2015-12-31 18:33 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2015-12-31 18:28 - 2016-01-06 22:35 - 00000000 ____D C:\Program Files\KMSpico
2015-12-31 18:21 - 2015-12-31 18:25 - 01637498 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-12-31 18:08 - 2015-12-31 18:08 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-12-31 18:07 - 2015-12-31 18:07 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-12-31 18:07 - 2015-12-31 18:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-12-31 18:07 - 2015-12-31 18:07 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2015-12-31 18:07 - 2015-12-31 18:07 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2015-12-31 18:06 - 2015-12-31 18:07 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2015-12-31 18:06 - 2015-12-31 18:06 - 00000000 ____D C:\Windows\PCHEALTH
2015-12-31 18:06 - 2015-12-31 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-31 18:04 - 2015-12-31 18:06 - 00000000 ____D C:\Program Files\Microsoft Office
2015-12-31 18:04 - 2015-12-31 18:04 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\Microsoft Help
2015-12-31 18:04 - 2015-12-31 18:04 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2015-12-31 18:04 - 2015-12-31 18:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-12-31 18:04 - 2015-12-31 18:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2015-12-31 18:03 - 2015-12-31 18:03 - 00000000 __RHD C:\MSOCache
2015-12-31 18:00 - 2015-12-31 18:41 - 00000000 ____D C:\Users\AJOHAF\Documents\Electronic Arts
2015-12-31 17:52 - 2015-12-31 17:52 - 00001342 _____ C:\Users\Public\Desktop\The Sims 4.lnk
2015-12-31 17:52 - 2015-12-31 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4
2015-12-31 17:51 - 2015-04-14 16:09 - 00447752 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll
2015-12-31 17:28 - 2016-01-01 14:19 - 00000000 ____D C:\Program Files (x86)\Origin Games
2015-12-31 17:28 - 2015-12-31 17:28 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ICCWDT_01009.Wdf
2015-12-31 17:27 - 2016-01-08 13:55 - 00000000 ____D C:\ProgramData\Origin
2015-12-31 17:27 - 2015-12-31 18:00 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-12-31 17:27 - 2015-12-31 17:35 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Origin
2015-12-31 17:27 - 2015-12-31 17:28 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\Origin
2015-12-31 17:27 - 2015-12-31 17:27 - 00000983 _____ C:\Users\Public\Desktop\Origin.lnk
2015-12-31 17:27 - 2015-12-31 17:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\SysWOW64\sda
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\2C0A
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0C0A
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0C04
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0816
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0804
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0424
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\041F
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\041E
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\041D
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\041B
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0419
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0416
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0415
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0414
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0413
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0412
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0411
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0410
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\040E
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\040D
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\040C
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\040B
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\040A
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0408
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0407
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0406
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0405
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0404
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\Windows\system32\0401
2015-12-31 17:26 - 2015-12-31 17:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
2015-12-31 17:25 - 2015-12-31 17:27 - 00000000 ____D C:\Program Files (x86)\Origin
2015-12-31 17:25 - 2015-12-31 17:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2015-12-31 17:25 - 2015-12-31 17:25 - 00000000 ____D C:\Program Files (x86)\Renesas Electronics
2015-12-31 17:24 - 2015-12-31 17:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2015-12-31 17:24 - 2015-12-31 17:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2015-12-31 17:24 - 2015-12-31 17:24 - 00000000 ____D C:\Program Files\Synaptics
2015-12-31 17:23 - 2016-01-08 15:28 - 00001048 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-31 17:23 - 2016-01-08 13:49 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-31 17:23 - 2016-01-06 22:11 - 00002265 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-31 17:23 - 2015-12-31 19:33 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\Google
2015-12-31 17:23 - 2015-12-31 17:23 - 00004044 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-31 17:23 - 2015-12-31 17:23 - 00003792 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-31 17:23 - 2015-12-31 17:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-31 17:23 - 2015-12-31 17:23 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-31 17:22 - 2016-01-01 14:20 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-31 17:22 - 2015-12-31 18:28 - 00111520 _____ C:\Users\AJOHAF\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-31 17:22 - 2015-12-31 17:23 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\Deployment
2015-12-31 17:22 - 2015-12-31 17:22 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-12-31 17:22 - 2015-12-31 17:22 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e
2015-12-31 17:22 - 2015-12-31 17:22 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\Apps\2.0
2015-12-31 17:22 - 2013-07-18 13:54 - 00129224 _____ (Qualcomm Atheros Co., Ltd.) C:\Windows\system32\Drivers\L1C62x64.sys
2015-12-31 17:21 - 2015-12-31 17:21 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2015-12-31 17:21 - 2015-12-31 17:21 - 00000000 ____D C:\Windows\system32\DAX2
2015-12-31 17:21 - 2015-12-31 17:21 - 00000000 ____D C:\Program Files\Realtek
2015-12-31 17:19 - 2014-09-29 11:16 - 00454416 _____ (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcDAud.sys
2015-12-31 17:16 - 2015-12-31 17:16 - 00016236 _____ C:\Windows\system32\results.xml
2015-12-31 17:14 - 2015-12-31 17:14 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-12-31 17:14 - 2015-12-31 17:14 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-12-31 17:14 - 2015-12-31 17:14 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2015-12-31 17:14 - 2015-12-31 17:14 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-12-31 17:13 - 2015-12-31 17:13 - 00000000 ____D C:\ProgramData\Intel.sav
2015-12-31 17:13 - 2015-12-31 17:13 - 00000000 ____D C:\Program Files\Common Files\Intel
2015-12-31 17:13 - 2015-12-31 17:13 - 00000000 ____D C:\Program Files (x86)\Cisco
2015-12-31 17:12 - 2015-12-31 17:26 - 00000000 ____D C:\ProgramData\Package Cache
2015-12-31 17:10 - 2015-12-31 17:10 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-12-31 17:10 - 2012-05-15 07:13 - 00144896 _____ (Intel Corporation) C:\Windows\system32\IntelOpenCL64.dll
2015-12-31 17:10 - 2012-05-15 07:13 - 00020992 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-12-31 17:10 - 2012-05-15 06:20 - 00104448 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelOpenCL32.dll
2015-12-31 17:10 - 2012-05-15 06:20 - 00017920 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-12-31 17:09 - 2015-12-31 17:28 - 00000000 ____D C:\temp
2015-12-31 17:09 - 2015-12-31 17:09 - 00000000 ____D C:\Intel
2015-12-31 17:09 - 2015-06-04 22:21 - 05906536 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00513640 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00444008 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00401512 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00280680 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00256616 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00187496 _____ (Intel Corporation) C:\Windows\system32\difx64.exe
2015-12-31 17:09 - 2015-06-04 22:21 - 00173672 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe
2015-12-31 17:09 - 2015-06-04 22:20 - 00116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4229.dll
2015-12-31 17:09 - 2015-05-26 21:02 - 05375448 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
2015-12-31 17:09 - 2015-05-26 21:00 - 12937864 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 12694808 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 11245520 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 11117808 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 01049576 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00940360 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00530968 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00525800 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00220432 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00184352 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00031984 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
2015-12-31 17:09 - 2015-05-26 21:00 - 00017082 _____ C:\Windows\system32\iglhxs64.vp
2015-12-31 17:09 - 2015-05-26 20:53 - 00101376 _____ C:\Windows\system32\igdde64.dll
2015-12-31 17:09 - 2015-05-26 20:53 - 00081408 _____ C:\Windows\SysWOW64\igdde32.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 10811392 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 09007616 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00442880 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00410112 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00384512 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc
2015-12-31 17:09 - 2015-05-26 20:52 - 00223664 _____ C:\Windows\system32\Gfxres.th-TH.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00210106 _____ C:\Windows\system32\Gfxres.el-GR.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00194245 _____ C:\Windows\system32\Gfxres.ru-RU.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00166170 _____ C:\Windows\system32\Gfxres.ar-SA.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00163421 _____ C:\Windows\system32\Gfxres.ja-JP.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00159008 _____ C:\Windows\system32\Gfxres.he-IL.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00149682 _____ C:\Windows\system32\Gfxres.it-IT.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00148042 _____ C:\Windows\system32\Gfxres.ko-KR.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00147393 _____ C:\Windows\system32\Gfxres.de-DE.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00147288 _____ C:\Windows\system32\Gfxres.es-ES.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00146004 _____ C:\Windows\system32\Gfxres.ro-RO.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00145491 _____ C:\Windows\system32\Gfxres.fr-FR.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00144645 _____ C:\Windows\system32\Gfxres.tr-TR.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00144260 _____ C:\Windows\system32\Gfxres.pt-BR.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00144020 _____ C:\Windows\system32\Gfxres.nl-NL.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00143932 _____ C:\Windows\system32\Gfxres.hu-HU.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00142882 _____ C:\Windows\system32\Gfxres.sv-SE.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00142877 _____ C:\Windows\system32\Gfxres.pt-PT.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00142717 _____ C:\Windows\system32\Gfxres.pl-PL.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00142289 _____ C:\Windows\system32\Gfxres.cs-CZ.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00142008 _____ C:\Windows\system32\Gfxres.fi-FI.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00141838 _____ C:\Windows\system32\Gfxres.sk-SK.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00141049 _____ C:\Windows\system32\Gfxres.hr-HR.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00137889 _____ C:\Windows\system32\Gfxres.sl-SI.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00137784 _____ C:\Windows\system32\Gfxres.nb-NO.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00137141 _____ C:\Windows\system32\Gfxres.da-DK.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00132623 _____ C:\Windows\system32\Gfxres.en-US.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl
2015-12-31 17:09 - 2015-05-26 20:52 - 00126300 _____ C:\Windows\system32\Gfxres.zh-TW.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00124650 _____ C:\Windows\system32\Gfxres.zh-CN.resources
2015-12-31 17:09 - 2015-05-26 20:52 - 00110592 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00064000 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll
2015-12-31 17:09 - 2015-05-26 20:52 - 00000268 _____ C:\Windows\system32\GfxUI.exe.config
2015-12-31 17:09 - 2015-05-26 20:51 - 13028864 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll
2015-12-31 17:09 - 2015-05-26 20:50 - 03511296 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
2015-12-31 17:09 - 2015-05-26 20:50 - 03121152 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
2015-12-31 17:09 - 2015-05-26 20:50 - 01981696 _____ C:\Windows\system32\iglhxa64.cpa
2015-12-31 17:09 - 2015-05-26 20:50 - 00963452 _____ C:\Windows\SysWOW64\igcodeckrng600.bin
2015-12-31 17:09 - 2015-05-26 20:50 - 00963452 _____ C:\Windows\system32\igcodeckrng600.bin
2015-12-31 17:09 - 2015-05-26 20:50 - 00575488 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
2015-12-31 17:09 - 2015-05-26 20:50 - 00542720 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
2015-12-31 17:09 - 2015-05-26 20:50 - 00272928 _____ C:\Windows\SysWOW64\igvpkrng600.bin
2015-12-31 17:09 - 2015-05-26 20:50 - 00272928 _____ C:\Windows\system32\igvpkrng600.bin
2015-12-31 17:09 - 2015-05-26 20:50 - 00094208 _____ C:\Windows\system32\IccLibDll_x64.dll
2015-12-31 17:09 - 2015-05-26 20:50 - 00059425 _____ C:\Windows\system32\iglhxo64.vp
2015-12-31 17:09 - 2015-05-26 20:50 - 00059398 _____ C:\Windows\system32\iglhxg64.vp
2015-12-31 17:09 - 2015-05-26 20:50 - 00059230 _____ C:\Windows\system32\iglhxc64.vp
2015-12-31 17:09 - 2015-05-26 20:50 - 00059104 _____ C:\Windows\system32\iglhxc64_dev.vp
2015-12-31 17:09 - 2015-05-26 20:50 - 00058796 _____ C:\Windows\system32\iglhxg64_dev.vp
2015-12-31 17:09 - 2015-05-26 20:50 - 00058109 _____ C:\Windows\system32\iglhxo64_dev.vp
2015-12-31 17:09 - 2015-05-26 20:50 - 00001074 _____ C:\Windows\system32\iglhxa64.vp
2015-12-31 17:09 - 2012-10-02 09:34 - 00016896 _____ (Intel(R) Corporation) C:\Windows\system32\IntcDAuC.dll
2015-12-31 16:54 - 2015-12-31 16:54 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_AMPPAL_01009.Wdf
2015-12-31 16:53 - 2015-12-31 16:53 - 00000000 ___HD C:\Windows\system32\WLANProfiles
2015-12-31 16:53 - 2015-12-31 16:53 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Intel
2015-12-31 16:52 - 2016-01-06 22:28 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Systweak
2015-12-31 16:52 - 2016-01-06 16:52 - 00000292 _____ C:\Windows\Tasks\AdvancedDriverUpdater_UPDATES.job
2015-12-31 16:52 - 2015-12-31 17:28 - 00000000 ____D C:\Program Files (x86)\Intel
2015-12-31 16:52 - 2015-12-31 17:17 - 00000000 ____D C:\ProgramData\Intel
2015-12-31 16:52 - 2015-12-31 17:14 - 00000000 ____D C:\Program Files\Intel
2015-12-31 16:52 - 2015-12-31 16:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater
2015-12-31 16:52 - 2015-12-31 16:52 - 00003050 _____ C:\Windows\System32\Tasks\AdvancedDriverUpdater_UPDATES
2015-12-31 16:52 - 2015-12-31 16:52 - 00001085 _____ C:\Users\Public\Desktop\Advanced Driver Updater.lnk
2015-12-31 16:52 - 2015-12-31 16:52 - 00000000 ____D C:\Program Files (x86)\Advanced Driver Updater
2015-12-31 16:49 - 2015-12-31 16:49 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-12-31 16:49 - 2015-12-31 16:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-12-31 16:49 - 2015-12-31 16:49 - 00000000 ____D C:\Program Files (x86)\WinRAR
2015-12-31 16:48 - 2016-01-06 22:11 - 00001455 _____ C:\Users\AJOHAF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-12-31 16:48 - 2016-01-06 22:11 - 00001433 _____ C:\Users\AJOHAF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-12-31 16:48 - 2015-12-31 16:48 - 00000000 ____D C:\Users\AJOHAF\AppData\Local\VirtualStore
2015-12-31 16:47 - 2016-01-05 18:19 - 00000000 ____D C:\Users\AJOHAF
2015-12-31 16:47 - 2015-12-31 16:47 - 00000020 ___SH C:\Users\AJOHAF\ntuser.ini
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Public\Documents\Moje wideo
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Public\Documents\Moje obrazy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Public\Documents\Moja muzyka
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Ustawienia lokalne
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Szablony
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Moje dokumenty
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Menu Start
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Documents\Moje wideo
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Documents\Moje obrazy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Documents\Moja muzyka
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\Dane aplikacji
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\AppData\Local\Historia
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dane aplikacji
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default User\Documents\Moje wideo
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default User\Documents\Moje obrazy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default User\Documents\Moja muzyka
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Historia
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dane aplikacji
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Ustawienia lokalne
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Szablony
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Moje dokumenty
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Menu Start
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Documents\Moje wideo
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Documents\Moje obrazy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Documents\Moja muzyka
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\Dane aplikacji
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\AppData\Local\Historia
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\Users\AJOHAF\AppData\Local\Dane aplikacji
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Ulubione
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Szablony
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Pulpit
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Menu Start
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Dokumenty
2015-12-31 16:47 - 2015-12-31 16:47 - 00000000 _SHDL C:\ProgramData\Dane aplikacji
2015-12-31 16:47 - 2010-11-21 14:03 - 00000000 ____D C:\Users\AJOHAF\AppData\Roaming\Media Center Programs
2015-12-31 16:45 - 2015-12-31 16:45 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-12-31 16:45 - 2015-12-31 16:45 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-12-31 16:44 - 2015-12-31 16:44 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2015-12-31 16:40 - 2015-12-31 16:47 - 00000000 ____D C:\Windows\Panther

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-01-08 15:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2016-01-08 13:56 - 2009-07-14 05:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-08 13:56 - 2009-07-14 05:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-08 13:49 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-04 20:11 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-01-03 15:08 - 2010-11-21 13:53 - 00737480 _____ C:\Windows\system32\perfh015.dat
2016-01-03 15:08 - 2010-11-21 13:53 - 00154136 _____ C:\Windows\system32\perfc015.dat
2016-01-03 15:08 - 2009-07-14 06:13 - 01661232 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-03 15:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-01-01 21:14 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-01-01 14:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-12-31 20:12 - 2009-07-14 05:45 - 00442048 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-31 18:07 - 2010-11-21 14:03 - 00000000 ____D C:\Windows\ShellNew
2015-12-31 18:07 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-12-31 18:05 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-12-31 18:05 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini
2015-12-31 17:26 - 2010-11-21 13:53 - 00000000 ____D C:\Windows\system32\0409
2015-12-31 16:55 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-12-31 16:47 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT
2015-12-31 16:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sysprep
2015-12-31 16:42 - 2010-11-21 14:03 - 00000000 ____D C:\Windows\CSC
2015-12-31 16:40 - 2009-07-14 06:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template

==================== Pliki w katalogu głównym wybranych folderów =======

2016-01-04 21:07 - 2016-01-06 17:07 - 0000066 _____ () C:\Users\AJOHAF\AppData\Roaming\WB.CFG
2015-12-31 17:22 - 2015-12-31 17:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Niektóre pliki w TEMP:
====================
C:\Users\AJOHAF\AppData\Local\Temp\FilibusterHangnail.dll
C:\Users\AJOHAF\AppData\Local\Temp\KonDomtom.exe


==================== Bamital & volsnap =================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\explorer.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\services.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\User32.dll = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys = & gt; Plik podpisany cyfrowo


LastRegBack: 2016-01-01 21:01

==================== Koniec FRST.txt ============================