Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 Ran by [removed] (administrator) on MYRI-PC (24-03-2017 19:07:00) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe () C:\Windows\vsnpstd3.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (GOG.com) G:\Games\GalaxyClient\GalaxyClient.exe (GOG.com) G:\Games\GalaxyClient\GalaxyClient Helper.exe (GOG.com) G:\Games\GalaxyClient\GalaxyClient Helper.exe (GOG.com) G:\Games\GalaxyClient\GalaxyClient Helper.exe (GOG.com) G:\Games\GalaxyClient\GalaxyClient Helper.exe (CD Projekt Red) G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\witcher3.exe (GOG.com) G:\Games\GalaxyClient\GalaxyClientService.exe (WhatsApp) C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\WhatsApp.exe (WhatsApp) C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\WhatsApp.exe (WhatsApp) C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\WhatsApp.exe (WhatsApp) C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\WhatsApp.exe (Adobe Systems, Incorporated) C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2000-01-01] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [8900328 2016-08-12] (AVAST Software) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [Sony PC Companion] => "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [GalaxyClient] => G:\Games\GalaxyClient\GalaxyClient.exe [4027968 2017-03-20] (GOG.com) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [Dropbox Update] => C:\Users\anton_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-20] (Piriform Ltd) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\MountPoints2: {8add1da7-44ea-11e6-82ed-74d43585e708} - "J:\LG_PC_Programs.exe" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\MountPoints2: {a4d6a2f6-3134-11e6-82ed-74d43585e708} - "J:\LG_PC_Programs.exe" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\MountPoints2: {b950ca33-841f-11e4-8259-74d43585e708} - "F:\Startme.exe" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\MountPoints2: {f602d237-94f2-11e4-8260-74d43585e708} - "F:\AUTORUN.EXE" Software\The~Adventure~Company\Nibiru \nibiru.exe Run~Nibiru? Nibiru~autorun ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-07-11] (AVAST Software) ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-03-06] (Dropbox, Inc.) Startup: C:\Users\anton_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-06-21] ShortcutTarget: Dropbox.lnk -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) GroupPolicyScripts: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) AutoConfigURL: [S-1-5-21-1863226909-815411734-1163765807-1001] => hxxp://noblok.net/wpad.dat?23cf5679789acc05cd8832d2adcb3f3f26537041 Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{9C160283-6C54-4748-80AE-419952B884C2}: [DhcpNameServer] 192.168.1.254 ManualProxies: 0hxxp://noblok.net/wpad.dat?23cf5679789acc05cd8832d2adcb3f3f26537041 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1863226909-815411734-1163765807-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/el-gr/?ocid=iehp BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-20] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-07-11] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-20] (Oracle Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-20] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-07-11] (AVAST Software) BHO-x32: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll [2007-02-16] (IDM) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-20] (Oracle Corporation) FireFox: ======== FF DefaultProfile: f4tyqx01.default FF ProfilePath: C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default [2017-03-24] FF user.js: detected! => C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\user.js [2015-12-18] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\f4tyqx01.default -> sweet-page FF Extension: (Youtube Mp3 Downloader) - C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\Extensions\[removed] [2017-03-04] FF Extension: (Simple YouTube to MP3/MP4 Converter and Downloader) - C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\Extensions\[removed] [2017-03-04] FF Extension: (1-Click YouTube Video Downloader) - C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\Extensions\[removed] [2016-11-03] FF Extension: (ColorZilla) - C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-16] FF Extension: (MeasureIt) - C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2016-04-19] FF Extension: (Adblock Plus) - C:\Users\anton_000\AppData\Roaming\Mozilla\Firefox\Profiles\f4tyqx01.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-20] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-07-11] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-07-11] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-15] () FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-20] (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-15] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-06-24] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-06-24] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-20] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-20] (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1863226909-815411734-1163765807-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2017-03-21] () Chrome: ======= CHR DefaultProfile: Profile 1 CHR StartupUrls: Profile 1 -> "hxxp://google.com/" CHR DefaultSearchURL: Profile 1 -> hxxps://www.google.com/search?q={searchTerms}&pws=0&gl=us&gws_rd=cr CHR DefaultSearchKeyword: Profile 1 -> gint_ CHR Profile: C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default [2017-03-22] CHR Extension: (Google Slides) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-11] CHR Extension: (Google Docs) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-11] CHR Extension: (Google Drive) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22] CHR Extension: (YouTube) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-22] CHR Extension: (Google Search) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Adobe Acrobat) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-22] CHR Extension: (Avast SafePrice) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-03-22] CHR Extension: (Invite All (for Facebook)) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopekjehpibhfpjjcokfmhcaeiclddih [2016-06-06] CHR Extension: (Google Sheets) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-11] CHR Extension: (Google Docs Offline) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Avast Online Security) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-03-22] CHR Extension: (Video Control Extension) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\hicmdpdhcadcekoiogaeocejgcknkpob [2015-12-15] CHR Extension: (Skype) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-22] CHR Extension: (Ghostery) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-03-22] CHR Extension: (Chrome Web Store Payments) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-22] CHR Extension: (Amazon Assistant for Chrome) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-10-21] CHR Extension: (Gmail) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] CHR Extension: (Chrome Media Router) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-22] CHR Profile: C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Guest Profile [2016-10-25] CHR Profile: C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-24] CHR Extension: (Google Slides) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26] CHR Extension: (Google Docs) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26] CHR Extension: (Google Drive) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26] CHR Extension: (YouTube) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26] CHR Extension: (Adblock Plus) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-22] CHR Extension: (Adblock for Youtube™) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-05-26] CHR Extension: (Search by Image (by Google)) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2016-10-21] CHR Extension: (Yet another flags) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dmchcmgddbhmbkakammmklpoonoiiomk [2016-05-26] CHR Extension: (Multiple Account Checker for Gmail™) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dnimhgelcnggigekhdjlifjpndgmnglm [2016-05-26] CHR Extension: (Adobe Acrobat) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-03] CHR Extension: (Avast SafePrice) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-03-16] CHR Extension: (Google Sheets) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26] CHR Extension: (Google Docs Offline) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-26] CHR Extension: (Avast Online Security) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-02-28] CHR Extension: (space debris) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icefnbcfgejfmjnjgjcimkbhgkebdhab [2017-03-22] CHR Extension: (WhatFont) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm [2017-01-25] CHR Extension: (Tag Assistant (by Google)) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2017-02-28] CHR Extension: (Skype) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-09] CHR Extension: (Google Mail Checker) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2016-05-26] CHR Extension: (Dictionary.com Spanish!) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjeoplfnbghcdcjmegbolhgikciockpo [2016-05-26] CHR Extension: (Ghostery) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-02-14] CHR Extension: (Chrome Web Store Payments) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09] CHR Extension: (Amazon Assistant for Chrome) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-10-18] CHR Extension: (Gmail) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26] CHR Extension: (Chrome Media Router) - C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07] CHR Profile: C:\Users\anton_000\AppData\Local\Google\Chrome\User Data\System Profile [2016-11-08] CHR HKU\S-1-5-21-1863226909-815411734-1163765807-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-05-02] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-02] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-07-11] (AVAST Software) R3 GalaxyClientService; G:\Games\GalaxyClient\GalaxyClientService.exe [284736 2017-03-20] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2016-12-18] (GOG.com) R2 HPSLPSVC; C:\Users\anton_000\AppData\Local\Temp\7zS49F8\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed] <==== ATTENTION R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319080 2000-01-01] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-06-24] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) S3 mi-raysat_3dsmax2015_64; C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [86016 2011-09-15] () [File not signed] R2 NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [4948992 2009-07-17] (Native Instruments GmbH) [File not signed] S3 Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) [File not signed] S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) S3 AndnetBus; C:\Windows\System32\drivers\lgandnetbus64.sys [29184 2015-05-12] (LG Electronics Inc.) S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [30720 2015-05-12] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [37376 2015-05-12] (LG Electronics Inc.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-07-11] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-07-11] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108304 2016-07-11] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-07-11] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-07-11] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-07-11] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [473592 2016-07-13] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162904 2016-07-11] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-05] (AVAST Software) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [118848 2016-08-09] (Advanced Micro Devices) S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-10] (Disc Soft Ltd) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-22] (Malwarebytes) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [125952 2014-06-24] (Intel Corporation) S3 mvdM23; C:\Users\anton_000\AppData\Local\Temp\mvdM23.sys [100912 2016-10-24] () <==== ATTENTION S3 s1039bus; C:\Windows\System32\drivers\s1039bus.sys [127600 2010-03-15] (MCCI Corporation) S3 s1039mdfl; C:\Windows\system32\DRIVERS\s1039mdfl.sys [19568 2010-03-15] (MCCI Corporation) S3 s1039mdm; C:\Windows\system32\DRIVERS\s1039mdm.sys [161904 2010-03-15] (MCCI Corporation) S3 s1039mgmt; C:\Windows\system32\DRIVERS\s1039mgmt.sys [141424 2010-03-15] (MCCI Corporation) S3 s1039nd5; C:\Windows\system32\DRIVERS\s1039nd5.sys [34416 2010-03-15] (MCCI Corporation) S3 s1039obex; C:\Windows\system32\DRIVERS\s1039obex.sys [137328 2010-03-15] (MCCI Corporation) S3 s1039unic; C:\Windows\System32\drivers\s1039unic.sys [158320 2010-03-15] (MCCI Corporation) S2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [11973 2004-10-15] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed] S2 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11973 2015-09-11] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed] R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2000-01-01] (Synaptics Incorporated) S3 SNPSTD3; C:\Windows\system32\DRIVERS\snpstd3.sys [10550272 2007-03-27] (Sonix Co. Ltd.) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) S3 MSICDSetup; \??\E:\CDriver64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2061-12-07 16:51 - 2061-12-07 16:51 - 00000000 ____D C:\Users\anton_000\Documents\VST3 Presets 2061-12-07 16:51 - 2061-12-07 16:51 - 00000000 ____D C:\Users\anton_000\Documents\Steinberg 2061-12-07 16:49 - 2061-12-07 16:49 - 00002892 _____ () C:\Windows\SysWOW64\audcon.sys 2061-12-07 16:49 - 2061-12-07 16:49 - 00000000 ____D C:\ProgramData\Syncrosoft 2061-12-07 16:49 - 2061-12-07 16:49 - 00000000 ____D C:\ProgramData\eLicenser 2061-12-07 16:49 - 2061-12-07 16:49 - 00000000 ____D C:\Program Files\eLicenser 2061-12-07 16:49 - 2061-12-07 16:49 - 00000000 ____D C:\Program Files (x86)\eLicenser 2061-12-07 16:49 - 2060-12-28 17:19 - 00000049 _____ C:\Windows\SysWOW64\SYNSOPOS.exe.cfg 2061-12-07 16:49 - 2060-12-28 17:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eLicenser 2061-12-07 16:49 - 2014-12-28 20:39 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Steinberg 2061-12-07 16:49 - 2012-12-07 17:48 - 01714176 _____ (Steinberg Media Technologies GmbH) C:\Windows\system32\SYNSOACC.dll 2061-12-07 16:49 - 2012-12-07 17:48 - 01277952 _____ (Steinberg Media Technologies GmbH) C:\Windows\SysWOW64\SYNSOACC.dll 2061-12-07 16:49 - 2011-12-14 21:21 - 00086016 _____ C:\Windows\SysWOW64\SYNSOPOS.exe 2060-12-28 17:18 - 2060-12-28 17:18 - 00000000 ____D C:\ProgramData\Steinberg 2060-12-28 17:18 - 2060-12-28 17:18 - 00000000 ____D C:\Program Files\Common Files\Steinberg 2060-12-28 17:17 - 2060-12-28 17:17 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg Cubase LE AI Elements 7 64bit 2060-12-28 17:17 - 2060-12-28 17:17 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software 2060-12-28 17:17 - 2060-12-28 17:17 - 00000000 ____D C:\Program Files (x86)\Syncrosoft 2060-12-28 17:17 - 2015-01-02 16:02 - 00000000 ____D C:\Program Files\Steinberg 2017-03-24 19:07 - 2017-03-24 19:07 - 00033358 _____ C:\Users\anton_000\Downloads\FRST.txt 2017-03-24 19:06 - 2017-03-24 19:07 - 00000000 ____D C:\FRST 2017-03-24 19:06 - 2017-03-24 19:06 - 02424832 _____ (Farbar) C:\Users\anton_000\Downloads\FRST64.exe 2017-03-24 16:53 - 2017-03-24 17:41 - 42133184 _____ C:\Users\anton_000\Desktop\witcher.psd 2017-03-24 14:56 - 2017-03-24 15:01 - 00002034 _____ C:\RectorDecryptor.2.7.0.0_24.03.2017_14.56.15_log.txt 2017-03-24 14:53 - 2017-03-24 14:55 - 00002246 _____ C:\RectorDecryptor.2.7.0.0_24.03.2017_14.53.44_log.txt 2017-03-24 14:53 - 2017-03-24 14:53 - 00800338 _____ C:\Users\anton_000\Desktop\rectordecryptor.zip 2017-03-24 14:53 - 2015-12-05 00:28 - 00919432 _____ (Kaspersky Lab ZAO) C:\Users\anton_000\Desktop\hellokitty.com 2017-03-22 17:15 - 2017-03-22 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Planescape Torment [GOG.com] 2017-03-22 17:14 - 2017-03-22 17:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com] 2017-03-22 16:01 - 2017-03-22 16:32 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-03-22 16:01 - 2017-03-22 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-03-22 16:01 - 2017-03-22 16:01 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-22 16:01 - 2017-03-22 16:01 - 00000000 ____D C:\Program Files\Malwarebytes 2017-03-22 16:01 - 2017-02-24 06:23 - 00077408 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-03-22 15:59 - 2017-03-22 16:00 - 57131432 _____ (Malwarebytes ) C:\Users\anton_000\Downloads\mb3-setup-consumer-3.0.6.1469-1075.exe 2017-03-22 14:11 - 2017-03-22 14:16 - 00353988 _____ C:\Windows\ntbtlog.txt 2017-03-22 11:55 - 2017-03-22 12:22 - 00000000 ____D C:\Users\anton_000\Desktop\Filmora media 2017-03-21 16:01 - 2017-03-21 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2017-03-21 16:01 - 2017-03-21 16:01 - 00000000 ____D C:\Program Files\7-Zip 2017-03-21 12:14 - 2017-03-21 12:14 - 00018738 _____ C:\Users\anton_000\Downloads\sandbox.zip 2017-03-21 12:11 - 2017-03-21 12:11 - 01083722 _____ C:\Users\anton_000\Downloads\custom-javascript-editor.1.1.zip 2017-03-20 17:41 - 2017-03-20 17:41 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Fran_Bow 2017-03-20 17:40 - 2017-03-20 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fran Bow [GOG.com] 2017-03-20 17:04 - 2017-03-20 17:04 - 01101824 _____ C:\Users\anton_000\Downloads\setup_fran_bow_2.2.0.3.txt 2017-03-20 16:58 - 2017-03-20 16:58 - 00038706 _____ C:\Users\anton_000\Downloads\Fran.Bow.2.2.0.3-GOG.torrent 2017-03-20 15:47 - 2017-03-21 16:09 - 00011096 _____ C:\Users\anton_000\Desktop\Whishlist.odt 2017-03-20 11:59 - 2017-03-20 11:59 - 00000128 _____ C:\Users\anton_000\index.html 2017-03-20 11:36 - 2017-03-20 11:36 - 00952684 _____ C:\Users\anton_000\Downloads\twentyseventeen.1.1.zip 2017-03-16 14:35 - 2017-03-16 14:35 - 00006148 _____ C:\Users\anton_000\Downloads\DS_Store 2017-03-15 19:30 - 2017-03-15 19:30 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-15 19:30 - 2017-03-15 19:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-10 13:19 - 2017-03-10 13:19 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-03-07 22:27 - 2017-03-07 22:27 - 00002376 _____ C:\Users\anton_000\Documents\MumbleAutomaticCertificateBackup.p12 2017-03-07 22:22 - 2017-03-07 23:25 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Mumble 2017-03-07 22:21 - 2017-03-07 22:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble 2017-03-07 22:21 - 2017-03-07 22:21 - 00000000 ____D C:\Program Files (x86)\Mumble 2017-02-25 19:54 - 2017-02-25 19:54 - 00003160 _____ C:\Windows\System32\Tasks\StartCN 2017-02-25 19:54 - 2017-02-25 19:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings 2017-02-25 14:45 - 2017-03-24 18:03 - 00000000 ____D C:\Users\anton_000\AppData\Local\CrashDumps 2017-02-24 16:34 - 2017-03-20 12:00 - 00000000 ____D C:\Users\anton_000\AppData\Local\FileZilla 2017-02-23 12:02 - 2017-03-02 10:31 - 00000696 _____ C:\Users\anton_000\Desktop\Front-End - Shortcut.lnk 2017-02-23 12:01 - 2017-02-23 12:01 - 00000577 _____ C:\Users\anton_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Front-End.lnk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-24 18:15 - 2015-06-21 20:47 - 00000940 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1863226909-815411734-1163765807-1001UA.job 2017-03-24 18:04 - 2015-05-19 11:04 - 00000000 ____D C:\Users\anton_000\Documents\The Witcher 3 2017-03-24 15:11 - 2017-01-10 13:19 - 00000000 ____D C:\Users\anton_000\Desktop\Camera unload 2017-03-24 15:08 - 2016-10-25 14:39 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\WhatsApp 2017-03-24 15:02 - 2017-02-05 04:29 - 00000000 ____D C:\Users\anton_000\AppData\LocalLow\Mozilla 2017-03-24 14:53 - 2015-05-04 23:25 - 03783680 ___SH C:\Users\anton_000\Downloads\Thumbs.db 2017-03-24 14:53 - 2015-05-04 23:10 - 03699712 ___SH C:\Users\anton_000\Desktop\Thumbs.db 2017-03-23 15:42 - 2014-12-10 21:53 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1863226909-815411734-1163765807-1001 2017-03-23 15:38 - 2014-12-10 22:18 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Skype 2017-03-23 15:34 - 2014-12-11 00:35 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\vlc 2017-03-22 23:53 - 2015-09-24 13:41 - 00000000 ____D C:\Users\anton_000\AppData\Local\Battle.net 2017-03-22 20:15 - 2015-06-21 20:47 - 00000888 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1863226909-815411734-1163765807-1001Core.job 2017-03-22 19:55 - 2017-01-12 14:21 - 00000000 ____D C:\Program Files (x86)\Battle.net 2017-03-22 16:37 - 2014-12-10 21:47 - 00865408 _____ C:\Windows\system32\PerfStringBackup.INI 2017-03-22 16:37 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf 2017-03-22 16:32 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-22 16:10 - 2017-02-05 03:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-22 16:10 - 2016-11-04 22:00 - 00001204 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2017-03-22 16:10 - 2016-03-01 13:03 - 00001026 _____ C:\Users\anton_000\Desktop\Play Dragon Age Inquisition.lnk 2017-03-22 16:10 - 2014-12-13 15:43 - 00000000 ____D C:\ProgramData\APN 2017-03-22 16:10 - 2014-12-10 22:38 - 00002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-03-22 16:10 - 2014-12-10 21:57 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-03-21 16:26 - 2014-12-10 21:47 - 00000000 ____D C:\Users\anton_000 2017-03-21 16:03 - 2016-02-17 23:39 - 00000000 ____D C:\Program Files\WinRAR 2017-03-21 16:03 - 2014-12-10 21:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-21 16:01 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp 2017-03-21 16:00 - 2016-02-17 23:39 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-03-21 16:00 - 2016-02-17 23:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-03-21 15:51 - 2015-09-14 19:23 - 00000000 ____D C:\Users\anton_000\AppData\Local\Ubisoft Game Launcher 2017-03-21 11:22 - 2016-02-09 17:56 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\FileZilla 2017-03-20 17:36 - 2016-09-05 13:22 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\qBittorrent 2017-03-16 14:30 - 2014-12-10 22:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2017-03-16 14:30 - 2014-12-10 22:00 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client 2017-03-16 10:39 - 2017-01-27 21:19 - 00001774 _____ C:\Users\anton_000\Desktop\rick and morty.txt 2017-03-15 19:30 - 2015-05-18 20:58 - 00000000 ____D C:\ProgramData\Package Cache 2017-03-15 19:30 - 2014-12-10 22:08 - 00000000 ____D C:\ProgramData\Skype 2017-03-15 11:46 - 2014-12-11 18:31 - 00004288 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-03-15 11:46 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-03-15 11:46 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\Macromed 2017-03-15 11:39 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps 2017-03-15 11:39 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness 2017-03-13 12:58 - 2016-10-25 14:39 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2017-03-13 12:58 - 2016-10-25 14:39 - 00000000 ____D C:\Users\anton_000\AppData\Local\WhatsApp 2017-03-13 12:58 - 2016-10-25 14:39 - 00000000 ____D C:\Users\anton_000\AppData\Local\SquirrelTemp 2017-03-11 00:48 - 2016-02-17 14:16 - 00000000 ____D C:\Users\anton_000\AppData\Local\AMD 2017-03-10 13:19 - 2014-12-10 22:08 - 00000000 ____D C:\Users\anton_000\AppData\Roaming\Dropbox 2017-03-10 06:34 - 2013-08-22 17:38 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-03-10 06:34 - 2013-08-22 17:38 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-03-03 13:50 - 2016-01-29 21:23 - 00001456 _____ C:\Users\anton_000\AppData\Local\Adobe Save for Web 13.0 Prefs 2017-02-28 12:22 - 2015-02-13 18:23 - 00154088 _____ C:\Users\anton_000\AppData\Local\GDIPFONTCACHEV1.DAT 2017-02-25 19:53 - 2016-04-27 07:57 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-02-25 19:35 - 2015-05-20 18:08 - 00000000 ____D C:\AMD 2017-02-24 11:48 - 2016-12-20 14:52 - 00000000 ____D C:\Users\anton_000\AppData\Local\Sublime Text 3 2017-02-22 23:30 - 2016-03-18 15:55 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk ==================== Files in the root of some directories ======= 2016-02-16 12:45 - 2016-02-16 13:51 - 0000132 _____ () C:\Users\anton_000\AppData\Roaming\Adobe IllExport Filter CS6 Prefs 2015-09-10 17:17 - 2015-09-11 13:27 - 0000132 _____ () C:\Users\anton_000\AppData\Roaming\Adobe PNG Format CS5 Prefs 2017-01-05 13:59 - 2017-01-25 14:32 - 0000132 _____ () C:\Users\anton_000\AppData\Roaming\Adobe PNG Format CS6 Prefs 2014-12-19 01:45 - 2016-01-23 15:04 - 0001456 _____ () C:\Users\anton_000\AppData\Local\Adobe Save for Web 12.0 Prefs 2016-01-29 21:23 - 2017-03-03 13:50 - 0001456 _____ () C:\Users\anton_000\AppData\Local\Adobe Save for Web 13.0 Prefs 2014-12-15 21:34 - 2014-12-15 21:34 - 0000017 _____ () C:\Users\anton_000\AppData\Local\resmon.resmoncfg 2015-10-16 14:30 - 2015-10-16 14:30 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== 2016-12-23 21:23 - 2016-12-23 21:23 - 0737856 _____ (Oracle Corporation) C:\Users\anton_000\AppData\Local\Temp\jre-8u111-windows-au.exe 2017-01-20 10:30 - 2017-01-20 10:30 - 0739904 _____ (Oracle Corporation) C:\Users\anton_000\AppData\Local\Temp\jre-8u121-windows-au.exe 2016-03-18 15:13 - 2016-03-18 15:13 - 0736352 _____ (Oracle Corporation) C:\Users\anton_000\AppData\Local\Temp\jre-8u73-windows-au.exe 2016-06-03 13:47 - 2016-06-03 13:47 - 0739904 _____ (Oracle Corporation) C:\Users\anton_000\AppData\Local\Temp\jre-8u91-windows-au.exe 2016-03-15 14:39 - 2016-03-15 14:40 - 59756456 _____ () C:\Users\anton_000\AppData\Local\Temp\playstv_patch.exe 2016-10-24 10:13 - 2016-10-24 10:13 - 1397464 _____ (Clarus, Inc.) C:\Users\anton_000\AppData\Local\Temp\Portable SecretZone.exe 2016-02-17 14:01 - 2016-02-17 14:01 - 12910000 _____ (AMD Inc.) C:\Users\anton_000\AppData\Local\Temp\radeon-crimson-15.12-minimalsetup.exe 2016-02-17 14:04 - 2016-02-17 14:05 - 61022664 _____ () C:\Users\anton_000\AppData\Local\Temp\raptrpatch.exe 2016-02-17 14:04 - 2016-02-17 14:04 - 0221632 _____ () C:\Users\anton_000\AppData\Local\Temp\raptr_stub.exe 2017-03-22 12:53 - 2017-03-22 12:53 - 0008192 _____ () C:\Users\anton_000\AppData\Local\Temp\utpjb2xl.dll 2016-06-13 08:53 - 2016-06-13 08:53 - 30533688 _____ () C:\Users\anton_000\AppData\Local\Temp\vlc-2.2.4-win32.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-03-24 13:28 ==================== End of FRST.txt ============================