Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2017 Ran by [removed] (administrator) on PHO090161 (19-05-2017 18:56:25) Running from C:\Users\[removed]\Desktop [removed] Platform: Windows 10 Home Version 1607 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1") Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Tempo Semiconductor Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Windows\SysWOW64\SecUPDUtilSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe () C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Mozilla Corporation) C:\Program Files (x86)\Firefox\Firefox.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3946184 2015-08-13] (Synaptics Incorporated) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-09] (AVAST Software) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2867712 2017-01-09] (Dominik Reichl) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation) HKU\S-1-5-21-356737074-1852378437-2674757308-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27716568 2017-05-04] (Skype Technologies S.A.) HKU\S-1-5-18\...\Run: [] => [X] IFEO\GoogleUpdate.exe: [Debugger] 324095823984.exe IFEO\GoogleUpdaterService.exe: [Debugger] 8736459873644.exe ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\logo\AppData\Local\MEGAsync\ShellExtX64.dll [2017-02-04] () ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\logo\AppData\Local\MEGAsync\ShellExtX64.dll [2017-02-04] () ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\logo\AppData\Local\MEGAsync\ShellExtX64.dll [2017-02-04] () ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-09] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-09] (AVAST Software) ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\logo\AppData\Local\MEGAsync\ShellExtX32.dll [2017-02-04] () ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\logo\AppData\Local\MEGAsync\ShellExtX32.dll [2017-02-04] () ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\logo\AppData\Local\MEGAsync\ShellExtX32.dll [2017-02-04] () BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] [removed] [removed] Tcpip\Parameters: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{133768a4-2b8f-4750-b1d7-fe0bf03af4ac}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{133768a4-2b8f-4750-b1d7-fe0bf03af4ac}: [DhcpNameServer] 8.8.8.8 Tcpip\..\Interfaces\{3e5d82e6-69b6-4d3b-b06d-45eed403d6f4}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{3e5d82e6-69b6-4d3b-b06d-45eed403d6f4}: [DhcpNameServer] 8.8.8.8 Tcpip\..\Interfaces\{50b5c028-59a4-11e6-b82d-806e6f6e6963}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{56a9ce83-0519-4957-9c64-9c5f80d6c5ae}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{56a9ce83-0519-4957-9c64-9c5f80d6c5ae}: [DhcpNameServer] [removed] [removed] Tcpip\..\Interfaces\{6148d076-2bee-4e32-bd15-2c070674c0ae}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{6148d076-2bee-4e32-bd15-2c070674c0ae}: [DhcpNameServer] 8.8.8.8 Tcpip\..\Interfaces\{af165c26-6c76-4357-b53f-60c034637780}: [NameServer] 8.8.8.8 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-356737074-1852378437-2674757308-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-ie/?ocid=iehp BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-16] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-16] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-16] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-28] (Oracle Corporation) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-16] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-28] (Oracle Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-16] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-16] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-16] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-16] (Microsoft Corporation) Edge: ====== Edge HomeButtonPage: HKU\S-1-5-21-356737074-1852378437-2674757308-1001 -> hxxp://www.google.com FireFox: ======== FF DefaultProfile: 8q9j75nr.default-1495183176028 FF ProfilePath: C:\Users\logo\AppData\Roaming\Mozilla\Firefox\Profiles\8q9j75nr.default-1495183176028 [2017-05-19] FF Homepage: Mozilla\Firefox\Profiles\8q9j75nr.default-1495183176028 -> www.google.com FF Extension: (S3.Google Translator) - C:\Users\logo\AppData\Roaming\Mozilla\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\[removed] [2017-05-19] FF Extension: (Flashblock) - C:\Users\logo\AppData\Roaming\Mozilla\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2017-05-19] FF Extension: (Dr.Web Anti-Virus Link Checker) - C:\Users\logo\AppData\Roaming\Mozilla\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}.xpi [2017-05-19] FF Extension: (Adblock Plus) - C:\Users\logo\AppData\Roaming\Mozilla\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-05-19] FF ProfilePath: C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028 [2017-05-19] FF Extension: (SimilarWeb) - C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-05-19] [not signed] FF Extension: (FF Adr) - C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-05-19] [not signed] FF Extension: (Google Translator for Firefox) - C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\[removed] [2017-05-19] FF Extension: (Flashblock) - C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2017-05-19] FF Extension: (Dr.Web Anti-Virus Link Checker) - C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}.xpi [2017-05-19] FF Extension: (Adblock Plus) - C:\Users\logo\AppData\Roaming\Firefox\Firefox\Profiles\8q9j75nr.default-1495183176028\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-05-19] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF48 => not found FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 => not found FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF48 => not found FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 => not found FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-12] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-12] () FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-28] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-28] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-03-06] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-06] (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-09] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-09] (AVAST Software) R2 BIT; C:\ProgramData\BIT\BIT.dll [1857536 2017-05-15] (BIT) [File not signed] <==== ATTENTION R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3801280 2017-05-04] (Microsoft Corporation) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373752 2016-12-02] (Intel Corporation) R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes) R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [118576 2014-11-26] () R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [350224 2015-07-23] (Tempo Semiconductor Inc.) R2 swpsvr; C:\ProgramData\Microsoft\Windows\system\appidsvr.dll [103936 2017-05-18] (TODO: ) [File not signed] R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-08-13] (Synaptics Incorporated) R3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [120392 2015-11-17] (Toshiba Europe GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2017-03-28] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2017-03-28] (Microsoft Corporation) S2 CSHMDR; C:\Users\logo\AppData\Local\CSHMDR\Snare.dll [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [311808 2017-05-09] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [190256 2017-05-09] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334576 2017-05-09] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [49016 2017-05-09] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-05-09] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [128648 2017-05-09] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-05-09] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1007160 2017-05-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [569192 2017-05-09] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [158368 2017-05-09] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-05-09] (AVAST Software) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-05-09] () R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-03-17] (Malwarebytes) S3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [111544 2017-03-17] (Malwarebytes) S3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-03-17] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-05-19] (Malwarebytes) S3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [92088 2017-03-18] (Malwarebytes) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [42184 2015-08-13] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-08-13] (Synaptics Incorporated) R3 STHDA; C:\Windows\system32\DRIVERS\stwrt64.sys [561680 2015-07-23] (Tempo Semiconductor Inc.) R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [54424 2015-07-29] (Toshiba Corporation) S3 tosdbt; C:\Windows\System32\drivers\tosdbt.sys [57344 2007-01-15] (TOSHIBA Corporation) S3 toshidpt; C:\Windows\system32\drivers\Toshidpt.sys [10232 2012-08-01] (TOSHIBA Corporation.) S3 usbezdisplay64; C:\Windows\system32\drivers\usbezdisplay64.sys [31336 2009-09-26] (Windows (R) Codename Longhorn DDK provider) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-05-19 18:55 - 2017-05-19 18:56 - 00000000 ____D C:\FRST 2017-05-19 18:55 - 2017-05-19 18:55 - 02429952 _____ (Farbar) C:\Users\logo\Desktop\FRST64.exe 2017-05-19 13:34 - 2017-05-19 13:34 - 01091544 _____ C:\Users\logo\Desktop\Tim Crane-The Mechanical Mind_ A Philosophical Introduction to Minds, Machines and Mental Representation-Routledge (2016).pdf 2017-05-19 12:40 - 2017-05-19 12:40 - 00000000 ____D C:\Users\logo\AppData\Roaming\Firefox 2017-05-19 12:40 - 2017-05-19 12:40 - 00000000 ____D C:\Users\logo\AppData\Local\Firefox 2017-05-19 12:39 - 2017-05-19 18:13 - 00000000 ____D C:\Program Files (x86)\Firefox 2017-05-19 12:35 - 2017-05-19 17:31 - 00000000 _____ C:\Users\Public\Documents\report.dat 2017-05-19 12:35 - 2017-05-19 12:52 - 00000000 _____ C:\Users\Public\Documents\temp.dat 2017-05-19 11:57 - 2017-05-19 11:57 - 00042822 _____ C:\Users\logo\Desktop\WIVSY0QKZCB840EE339728ABDE706130CE8A8FEB1I1QIFN8OP.pdf 2017-05-19 11:57 - 2017-05-19 11:57 - 00042809 _____ C:\Users\logo\Desktop\GCNHZ4ALYC0226486F61A3374D218657AA7A4D7ECB5CEHCBA2.pdf 2017-05-19 10:39 - 2017-05-19 10:39 - 00000000 ____D C:\Users\logo\Desktop\Old Firefox Data 2017-05-19 10:31 - 2017-05-19 10:39 - 00000000 ____D C:\Users\logo\AppData\Roaming\Mozilla 2017-05-19 10:31 - 2017-05-19 10:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-05-19 10:31 - 2017-05-19 10:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-05-19 10:09 - 2017-05-19 10:09 - 00619291 _____ C:\Users\logo\Desktop\bookmarks.html 2017-05-18 16:37 - 2017-05-18 16:37 - 00003662 _____ C:\Windows\System32\Tasks\Milimili 2017-05-18 16:37 - 2017-05-18 16:37 - 00000000 ____D C:\Users\logo\AppData\Roaming\WinSAPSvc 2017-05-18 16:35 - 2017-05-18 16:35 - 00000000 ____D C:\Reimward 2017-05-18 08:31 - 2017-05-18 08:31 - 01327004 _____ C:\Users\logo\Desktop\David Schmidtz, Jason Brennan-A Brief History of Liberty (Brief Histories of Philosophy)-Wiley-Blackwell (2010).pdf 2017-05-18 08:29 - 2017-05-18 08:29 - 00619983 _____ C:\Users\logo\Desktop\Jason Brennan-The Ethics of Voting-Princeton University Press (2011).pdf 2017-05-18 08:23 - 2017-05-18 08:23 - 00771195 _____ C:\Users\logo\Desktop\Jason Brennan-Why Not Capitalism_-Routledge (2014).pdf 2017-05-18 08:21 - 2017-05-18 08:21 - 01542760 _____ C:\Users\logo\Desktop\Jason Brennan-Against Democracy-Princeton University Press (2016).pdf 2017-05-17 12:36 - 2017-05-17 12:36 - 00176819 _____ C:\Users\logo\Desktop\reclamo_mobilit--.pdf 2017-05-17 11:17 - 2017-05-17 11:17 - 00000260 _____ C:\Windows\SysWOW64\Drivers\vwifikerneldrv.sys 2017-05-17 11:17 - 2017-05-17 11:17 - 00000260 _____ C:\Windows\SysWOW64\d3dx9_11.dll.tmp 2017-05-17 10:27 - 2017-05-17 10:30 - 04653244 _____ C:\Users\logo\Desktop\F. Jackson, M. Smith (eds.), The Oxford Handbook of Contemporary Philosophy- (2008).pdf 2017-05-17 10:21 - 2017-05-17 10:21 - 11955902 _____ C:\Users\logo\Desktop\D.B. Mitchell, F. Jackson,Philosophy of Mind and Cognition_ An Introduction(2006).pdf 2017-05-17 10:07 - 2017-05-17 10:07 - 02124681 _____ C:\Users\logo\Desktop\U. Renz, Self-knowledge _ a history(2017).pdf 2017-05-17 09:36 - 2017-05-17 11:11 - 00000000 ____D C:\KVRT_Data 2017-05-17 08:46 - 2017-05-17 08:47 - 00000000 ____D C:\Users\logo\Desktop\Junkista, 50 Shades of Grey (2017, EP) 2017-05-16 12:02 - 2017-05-16 12:02 - 00000000 ____D C:\Program Files (x86)\Google 2017-05-15 10:30 - 2017-05-15 10:30 - 00000218 _____ C:\Users\logo\.recently-used.xbel 2017-05-12 19:00 - 2017-05-12 19:00 - 00000512 _____ C:\lsfc.isk20170512170054851.isk 2017-05-12 19:00 - 2017-05-12 19:00 - 00000512 _____ C:\lsfc.isk20170512170000546.isk 2017-05-12 19:00 - 2017-05-12 19:00 - 00000435 _____ C:\lsmc.isk20170512170054757.isk 2017-05-12 18:59 - 2017-05-12 19:00 - 00000512 _____ C:\lsfc.isk 2017-05-12 18:59 - 2017-05-12 19:00 - 00000435 _____ C:\lsmc.isk 2017-05-12 18:59 - 2017-05-12 18:59 - 00000512 _____ C:\lsfc.isk20170512165943249.isk 2017-05-12 18:59 - 2017-05-12 18:59 - 00000512 _____ C:\lsfc.isk20170512165923945.isk 2017-05-12 18:59 - 2017-05-12 18:59 - 00000435 _____ C:\lsmc.isk20170512165943171.isk 2017-05-12 18:59 - 2017-05-02 09:49 - 96903168 _____ C:\Windows\system32\config\SOFTWARE.SAV 2017-05-12 18:59 - 2017-05-02 09:49 - 22528000 _____ C:\Windows\system32\config\SYSTEM.SAV 2017-05-12 18:59 - 2017-05-02 09:49 - 02142208 _____ C:\Windows\system32\config\DEFAULT.SAV 2017-05-12 18:59 - 2017-05-02 09:49 - 00061440 _____ C:\Windows\system32\config\SAM.SAV 2017-05-12 18:59 - 2017-05-02 09:49 - 00028672 _____ C:\Windows\system32\config\SECURITY.SAV 2017-05-12 16:10 - 2017-05-10 11:43 - 00017778 _____ C:\Windows\ntbtlog.txt 2017-05-12 13:32 - 2017-05-12 13:32 - 00000000 ____D C:\Program Files\Malwarebytes 2017-05-12 12:54 - 2017-05-12 12:54 - 00006144 _____ C:\Windows\system32\umstartup.etl 2017-05-10 14:37 - 2017-05-10 14:37 - 00000000 ____D C:\Windows\system32\%PROGRAMDATA% 2017-05-09 15:41 - 2017-05-12 12:54 - 00000355 _____ C:\Windows\ZAM_Guard.krnl.trace 2017-05-09 15:10 - 2017-05-09 15:10 - 00000000 ____D C:\Windows\system32\%ALLUSERSPROFILE% 2017-05-09 13:50 - 2017-05-09 14:58 - 00062275 _____ C:\Windows\ZAM.krnl.trace 2017-05-09 13:50 - 2017-05-09 13:50 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys 2017-05-09 13:47 - 2017-05-09 13:47 - 00400456 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-05-08 16:56 - 2017-05-08 16:57 - 00000000 ____D C:\Users\logo\Desktop\Deutschland 83 S01 - Hardcoded Eng Subs - Sno 2017-05-07 08:35 - 2017-05-09 08:25 - 26307144 _____ C:\Users\logo\Desktop\RogueKillerX64.exe 2017-05-06 11:31 - 2017-05-06 11:32 - 166211496 _____ (Sophos Limited) C:\Users\logo\Desktop\Sophos Virus Removal Tool.exe 2017-05-06 11:19 - 2017-05-06 11:19 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\1B4A505C.sys 2017-05-06 11:18 - 2017-05-06 11:23 - 01663672 _____ (Malwarebytes) C:\Users\logo\Desktop\JRT.exe 2017-05-06 08:42 - 2017-05-06 08:42 - 00000000 ____D C:\Users\logo\AppData\Local\Publishers 2017-05-06 08:29 - 2017-05-06 08:29 - 00000000 ____D C:\Windows\Panther 2017-05-05 23:46 - 2017-05-05 23:47 - 05637515 _____ C:\Users\logo\Desktop\D. Pritchard, Epistemology (2016).pdf 2017-05-05 23:45 - 2017-05-05 23:47 - 10570229 _____ C:\Users\logo\Desktop\H.A. Costa, V. F. Hendricks, J. van Benthem (eds.), Readings in Formal Epistemology_ Sourcebook(2016).pdf 2017-05-05 09:55 - 2017-05-16 09:01 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys 2017-05-05 09:51 - 2017-05-05 09:51 - 00003642 _____ C:\Windows\System32\Tasks\CreateExplorerShellUnelevatedTask 2017-05-05 09:50 - 2017-05-05 09:51 - 00000958 _____ C:\DelFix.txt 2017-05-04 14:36 - 2017-05-04 18:15 - 00000000 ____D C:\Users\logo\AppData\Local\ESET 2017-05-03 20:16 - 2017-05-03 20:16 - 125185439 _____ C:\Users\logo\Desktop\P. Beste, True Norwegian Black Metal (2008).pdf 2017-05-03 20:01 - 2017-05-03 20:01 - 50578690 _____ C:\Users\logo\Desktop\M. Moynihan, D. Søderlind,Lords of chaos_ the bloody rise of the Satanic metal underground (1998).pdf 2017-05-03 19:40 - 2017-05-19 12:55 - 00000000 ____D C:\Users\logo\AppData\Local\CrashDumps 2017-05-03 19:30 - 2017-05-03 19:30 - 02389949 _____ C:\Users\logo\Desktop\C. Thompson, «Sons of Northern Darkness». Reflections of National Identity in Norway through Black Metal(2012).pdf 2017-05-03 19:27 - 2017-05-03 19:29 - 00569079 _____ C:\Users\logo\Desktop\B.H. Olson, I Am The Black Wizards_ Multiplicity, Mysticism and Identity in Black Metal Music and Culture(2008).pdf 2017-05-03 18:55 - 2017-05-03 18:58 - 848042910 _____ C:\Users\logo\Desktop\Until the Light Takes Us - Full Documentary (2009) 720p HD.avi 2017-05-03 14:56 - 2017-05-03 14:56 - 05613997 _____ C:\Users\logo\Desktop\B. Loewer, J. Schaffer, A Companion to David Lewis(2015).pdf 2017-05-03 12:17 - 2017-05-03 12:17 - 00548254 _____ C:\Users\logo\Desktop\Books.gcs 2017-05-03 11:30 - 2017-05-03 11:30 - 00242601 _____ C:\Users\logo\Desktop\gerusalemme.pdf 2017-05-03 08:42 - 2017-05-03 08:42 - 00000000 ____D C:\Users\logo\Desktop\.Books_pictures 2017-05-03 07:55 - 2017-05-19 12:35 - 00000000 ____D C:\Program Files\MK 2017-05-02 18:04 - 2014-03-09 13:24 - 00000000 ____D C:\Users\logo\Desktop\Venom, Black Metal (1982, 2002 reissue) 2017-05-02 11:55 - 2017-05-05 08:17 - 00000000 ____D C:\Users\logo\Desktop\Mobilita - 2017-18 2017-04-29 10:16 - 2017-05-09 13:40 - 00000000 ____D C:\Users\logo\AppData\LocalLow\Temp 2017-04-29 08:57 - 2017-04-15 13:01 - 00000000 ____D C:\Users\logo\Desktop\Chrome - Techromancy (2017) 2017-04-28 17:13 - 2017-05-09 13:48 - 00003994 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-04-28 15:51 - 2017-04-28 15:51 - 00000000 ____D C:\Users\logo\AppData\Local\Macromedia 2017-04-28 15:30 - 2017-04-28 15:29 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2017-04-28 15:29 - 2017-04-28 15:29 - 00000000 ____D C:\Program Files (x86)\Java 2017-04-28 15:26 - 2017-05-19 12:59 - 00000000 ____D C:\Users\logo\AppData\LocalLow\Mozilla 2017-04-28 15:25 - 2017-04-28 15:25 - 00000000 ____D C:\Users\logo\AppData\Roaming\Sun 2017-04-28 15:03 - 2017-04-28 15:03 - 00000000 ____D C:\Users\logo\AppData\Local\CEF 2017-04-28 14:51 - 2017-05-19 09:31 - 00000000 ____D C:\Windows\AppReadiness 2017-04-28 14:42 - 2017-04-28 14:42 - 00000000 ____D C:\Users\Public\Documents\Google 2017-04-28 10:28 - 2017-04-27 14:05 - 00000000 ____D C:\Users\logo\Desktop\Cashmere Cat - 9 (2017) 2017-04-28 08:32 - 2017-04-28 14:52 - 00000000 ____D C:\NPE 2017-04-28 08:30 - 2017-04-28 15:42 - 00000000 ____D C:\Users\logo\AppData\Local\NPE 2017-04-27 08:35 - 2017-04-27 08:37 - 00000000 ____D C:\Users\logo\Desktop\Nocow, Ledyanoy Album (2017) 2017-04-26 11:41 - 2017-05-17 11:11 - 00000000 ____D C:\Windows\psgo 2017-04-21 12:59 - 2017-04-21 12:59 - 00000000 _____ C:\Windows\SysWOW64\33 2017-04-20 11:38 - 2017-04-28 14:42 - 00000000 _____ C:\Windows\SysWOW64\11 ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-05-19 18:36 - 2016-08-03 19:02 - 00000000 ____D C:\Windows\system32\SleepStudy 2017-05-19 17:58 - 2017-03-08 12:42 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-05-19 15:53 - 2016-06-29 17:28 - 00000000 ____D C:\Users\logo\AppData\Roaming\KeePass 2017-05-19 13:23 - 2016-07-16 13:36 - 00000000 ____D C:\Windows\CbsTemp 2017-05-19 12:48 - 2016-08-03 19:09 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-05-19 12:48 - 2015-08-13 18:58 - 00000000 __SHD C:\Users\logo\IntelGraphicsProfiles 2017-05-19 12:47 - 2016-08-03 19:29 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-05-19 12:46 - 2016-07-16 08:04 - 01048576 _____ C:\Windows\system32\config\BBI 2017-05-19 11:39 - 2015-06-01 08:23 - 00004686 _____ C:\Users\logo\Desktop\NewDatabase.kdbx 2017-05-18 19:11 - 2016-08-03 19:29 - 00003294 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{44A53015-FCF1-4056-A84F-85E077F0F837} 2017-05-18 08:58 - 2016-06-29 16:36 - 00000000 ____D C:\Users\logo\AppData\Local\Packages 2017-05-18 08:47 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-05-18 08:30 - 2015-01-08 19:48 - 00000000 ____D C:\Users\logo\Documents\My Digital Editions 2017-05-16 12:30 - 2016-07-01 11:23 - 00000000 ____D C:\Users\logo\AppData\Local\MicrosoftEdge 2017-05-16 08:19 - 2016-06-29 17:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-05-15 10:30 - 2016-08-03 19:14 - 00000000 ____D C:\Users\logo 2017-05-15 10:30 - 2016-07-15 09:13 - 00000000 ____D C:\Users\logo\AppData\Roaming\gtk-2.0 2017-05-12 18:47 - 2016-07-16 13:47 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2017-05-12 18:43 - 2016-07-16 08:04 - 84934656 _____ C:\Windows\system32\config\SOFTWARE.lsk 2017-05-12 18:43 - 2016-07-16 08:04 - 17039360 _____ C:\Windows\system32\config\SYSTEM.lsk 2017-05-12 15:38 - 2016-06-29 20:36 - 00000000 ____D C:\Windows\system32\MRT 2017-05-12 15:36 - 2016-06-29 20:36 - 156335152 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-05-12 14:06 - 2017-03-15 21:07 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-05-12 13:09 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-05-12 13:09 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\Macromed 2017-05-12 13:05 - 2016-07-16 13:45 - 00000000 ____D C:\Windows\INF 2017-05-12 13:03 - 2017-02-01 23:20 - 00000000 ____D C:\Windows\Minidump 2017-05-12 13:03 - 2016-08-03 19:02 - 00345128 _____ C:\Windows\system32\FNTCACHE.DAT 2017-05-12 13:03 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-51375-01.dmp 2017-05-12 12:54 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-25390-01.dmp 2017-05-12 12:53 - 2016-06-30 10:38 - 00267428 ____N C:\Windows\Minidump\051217-24750-01.dmp 2017-05-12 12:52 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-24984-01.dmp 2017-05-12 12:51 - 2016-06-30 10:38 - 00268176 ____N C:\Windows\Minidump\051217-25531-02.dmp 2017-05-12 12:50 - 2016-06-30 10:38 - 00269656 ____N C:\Windows\Minidump\051217-25109-01.dmp 2017-05-12 12:49 - 2016-06-30 10:38 - 00272216 ____N C:\Windows\Minidump\051217-25656-01.dmp 2017-05-12 12:48 - 2016-06-30 10:38 - 00268120 ____N C:\Windows\Minidump\051217-25062-01.dmp 2017-05-12 12:37 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051217-26015-01.dmp 2017-05-12 12:36 - 2016-06-30 10:38 - 00271080 ____N C:\Windows\Minidump\051217-24656-02.dmp 2017-05-12 10:40 - 2016-06-30 10:38 - 00271080 ____N C:\Windows\Minidump\051217-25468-01.dmp 2017-05-12 10:39 - 2016-06-30 10:38 - 00268632 ____N C:\Windows\Minidump\051217-24703-01.dmp 2017-05-12 10:34 - 2016-06-30 10:38 - 00271080 ____N C:\Windows\Minidump\051217-25515-01.dmp 2017-05-12 10:33 - 2016-06-30 10:38 - 00271704 ____N C:\Windows\Minidump\051217-24078-01.dmp 2017-05-12 08:52 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-25000-01.dmp 2017-05-12 08:51 - 2016-06-30 10:38 - 00268176 ____N C:\Windows\Minidump\051217-24000-01.dmp 2017-05-12 08:46 - 2016-06-30 10:38 - 00268120 ____N C:\Windows\Minidump\051217-26187-01.dmp 2017-05-12 08:45 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-23843-01.dmp 2017-05-12 08:43 - 2016-06-30 10:38 - 00265324 ____N C:\Windows\Minidump\051217-24640-01.dmp 2017-05-12 08:42 - 2016-06-30 10:38 - 00269712 ____N C:\Windows\Minidump\051217-22687-01.dmp 2017-05-12 08:40 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-24828-01.dmp 2017-05-12 08:39 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051217-24609-01.dmp 2017-05-11 18:05 - 2016-07-16 08:04 - 00114688 _____ C:\Windows\system32\config\SAM.lsk 2017-05-11 18:05 - 2016-07-16 08:04 - 00028672 _____ C:\Windows\system32\config\SECURITY.lsk 2017-05-11 17:34 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051117-26265-01.dmp 2017-05-11 17:33 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051117-25812-01.dmp 2017-05-11 16:39 - 2016-06-30 10:38 - 00265324 ____N C:\Windows\Minidump\051117-26765-02.dmp 2017-05-11 16:38 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051117-24500-01.dmp 2017-05-11 16:36 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051117-26156-01.dmp 2017-05-11 16:36 - 2016-06-30 10:38 - 00271080 ____N C:\Windows\Minidump\051117-25312-01.dmp 2017-05-11 16:33 - 2016-06-30 10:38 - 00271080 ____N C:\Windows\Minidump\051117-26828-01.dmp 2017-05-11 16:32 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051117-26765-01.dmp 2017-05-11 12:10 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051117-26171-01.dmp 2017-05-11 12:09 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051117-25328-01.dmp 2017-05-11 08:04 - 2016-06-30 10:38 - 00271704 ____N C:\Windows\Minidump\051117-28046-01.dmp 2017-05-10 22:08 - 2016-06-30 10:38 - 00268176 ____N C:\Windows\Minidump\051017-24375-01.dmp 2017-05-10 19:08 - 2016-06-30 10:38 - 00269656 ____N C:\Windows\Minidump\051017-35234-01.dmp 2017-05-10 15:03 - 2016-06-30 10:38 - 00266984 ____N C:\Windows\Minidump\051017-23687-01.dmp 2017-05-10 14:38 - 2016-06-30 10:38 - 00272216 ____N C:\Windows\Minidump\051017-25921-01.dmp 2017-05-10 14:37 - 2016-06-30 10:38 - 00272216 ____N C:\Windows\Minidump\051017-23546-01.dmp 2017-05-10 13:33 - 2016-06-30 10:38 - 00268632 ____N C:\Windows\Minidump\051017-24734-01.dmp 2017-05-10 13:32 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051017-23625-01.dmp 2017-05-10 12:00 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051017-24656-01.dmp 2017-05-10 12:00 - 2016-06-30 10:38 - 00270736 ____N C:\Windows\Minidump\051017-23140-01.dmp 2017-05-10 11:54 - 2016-06-30 10:38 - 00265324 ____N C:\Windows\Minidump\051017-24906-02.dmp 2017-05-10 11:53 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051017-21750-01.dmp 2017-05-10 11:44 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051017-25140-01.dmp 2017-05-10 11:43 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051017-23968-01.dmp 2017-05-10 11:34 - 2016-06-30 10:38 - 00272272 ____N C:\Windows\Minidump\051017-24781-01.dmp 2017-05-10 11:33 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051017-23156-01.dmp 2017-05-10 11:27 - 2016-06-30 10:38 - 00271136 ____N C:\Windows\Minidump\051017-21718-01.dmp 2017-05-10 11:27 - 2016-06-30 10:38 - 00266916 ____N C:\Windows\Minidump\051017-24890-01.dmp 2017-05-09 16:37 - 2017-03-08 12:42 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-05-09 15:16 - 2016-07-16 08:04 - 02359296 _____ C:\Windows\system32\config\DEFAULT.lsk 2017-05-09 13:48 - 2016-08-03 19:29 - 00004010 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1467378093 2017-05-09 13:47 - 2016-07-01 14:55 - 00569192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2017-05-09 13:47 - 2016-07-01 14:55 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2017-05-09 13:47 - 2016-07-01 14:55 - 00158368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-05-09 13:47 - 2016-07-01 14:55 - 00128648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-05-09 13:47 - 2016-07-01 14:55 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-05-09 13:47 - 2016-07-01 14:55 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-05-09 13:47 - 2016-07-01 14:55 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-05-09 13:46 - 2017-03-03 12:00 - 00334576 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-05-09 13:46 - 2017-03-03 12:00 - 00311808 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-05-09 13:46 - 2017-03-03 12:00 - 00190256 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-05-09 13:46 - 2017-03-03 12:00 - 00049016 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-05-09 13:46 - 2016-07-01 14:58 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2017-05-09 13:46 - 2016-07-01 14:55 - 01007160 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-05-08 23:07 - 2016-06-29 18:26 - 00000000 ____D C:\Users\logo\AppData\Roaming\vlc 2017-05-07 11:24 - 2016-08-03 19:29 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-05-06 08:35 - 2016-07-27 21:10 - 00000000 ____D C:\Users\logo\Downloads\PopcornTime 2017-05-05 16:02 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\LiveKernelReports 2017-05-05 07:37 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\appraiser 2017-05-04 15:23 - 2015-02-21 12:04 - 00000000 ____D C:\Users\logo\Documents\Office 2013 Activator 2017-05-03 12:17 - 2017-04-05 09:07 - 00000000 ____D C:\Users\logo\Desktop\To Read 2017-05-03 12:17 - 2014-06-06 17:00 - 00000000 ____D C:\Users\logo\Documents\Books 2017-05-03 09:51 - 2014-08-06 11:18 - 00000000 ____D C:\Users\logo\Documents\Syllabi, Course Slides, Notes, etc 2017-05-03 08:42 - 2016-07-01 15:14 - 00000000 ____D C:\Users\logo\AppData\Roaming\gcstar 2017-04-29 10:48 - 2016-06-29 17:21 - 00000000 ____D C:\Users\logo\AppData\Local\Mozilla 2017-04-29 02:59 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-04-29 02:59 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-04-28 15:45 - 2016-07-01 08:45 - 00532136 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2017-04-28 15:43 - 2016-06-29 16:37 - 00000000 ____D C:\Users\logo\AppData\Roaming\Adobe 2017-04-28 14:52 - 2014-04-25 09:01 - 00000000 ____D C:\Intel 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 __RSD C:\Windows\Media 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ___SD C:\Windows\SysWOW64\DiagSvcs 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ___SD C:\Windows\SysWOW64\Configuration 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\SysWOW64\setup 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\SysWOW64\MUI 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\SysWOW64\Com 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\security 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\Registration 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\InputMethod 2017-04-21 06:31 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\Help 2017-04-21 06:31 - 2015-12-16 17:18 - 00000000 ___RD C:\Users\logo\Documents\Scanned Documents 2017-04-21 06:31 - 2014-11-22 21:50 - 00000000 ____D C:\Users\logo\Documents\Native Instruments 2017-04-21 06:30 - 2017-03-27 17:24 - 00000000 ____D C:\Users\logo\AppData\Roaming\MAGIX 2017-04-21 06:30 - 2017-01-02 13:01 - 00000000 ____D C:\Program Files (x86)\KeePass Password Safe 2 2017-04-21 06:30 - 2016-07-01 15:34 - 00000000 ____D C:\Users\logo\AppData\Roaming\Skype 2017-04-21 06:30 - 2016-07-01 10:58 - 00000000 ____D C:\Users\logo\AppData\Local\Comms 2017-04-21 06:29 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared ==================== Files in the root of some directories ======= 2017-03-07 10:00 - 2017-05-17 11:20 - 0000035 _____ () C:\Users\logo\AppData\Roaming\gcstar.log 2017-03-03 14:52 - 2017-03-03 14:52 - 0047128 _____ () C:\ProgramData\agent.1488545554.bdinstall.bin 2017-03-03 15:12 - 2017-03-03 15:12 - 0029034 _____ () C:\ProgramData\agent.1488546738.bdinstall.bin 2017-03-03 15:48 - 2017-03-03 15:48 - 0029136 _____ () C:\ProgramData\agent.1488548887.bdinstall.bin 2017-05-17 11:17 - 2017-05-17 11:17 - 0000260 _____ () C:\ProgramData\fontcacheev1.dat Some files in TEMP: ==================== 2017-05-12 15:12 - 2016-11-11 12:13 - 1886344 _____ (Microsoft Corporation) C:\Users\logo\AppData\Local\Temp\dllnt_dump.dll ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed ATTENTION: ==> Could not access BCD. LastRegBack: 2017-05-12 16:24 ==================== End of FRST.txt ============================