Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Tibor (administrator) on TIBOR-PC (08-04-2016 18:38:09)
Running from C:\Users\AMD\Downloads
Loaded Profiles: Tibor (Available Profiles: Tibor & noelq & DefaultAppPool)
Platform: Windows 10 Enterprise (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Riot Games\LolScreenSaver\service\service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
(Micro-Star INT'L CO., LTD.) C:\MSI\Smart Utilities\SuperRAIDSvc.exe
() C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Users\AMD\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\AMD\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv.exe
() C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.19761.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.14\deploy\LoLLauncher.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.54\deploy\LoLPatcher.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.195\deploy\LolClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8781568 2015-11-27] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] ()
HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [830416 2015-10-13] (MSI)
HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1027024 2015-09-09] (MSI)
HKU\S-1-5-21-453637166-761797416-1449380958-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd)
HKU\S-1-5-21-453637166-761797416-1449380958-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\AMD\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-453637166-761797416-1449380958-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\AMD\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-453637166-761797416-1449380958-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-03-01] (SUPERAntiSpyware)
HKU\S-1-5-21-453637166-761797416-1449380958-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-453637166-761797416-1449380958-1000\...\MountPoints2: {5c54f98b-4786-11e5-9bd8-1c6f655138f6} - "E:\LG_PC_Programs.exe"
HKU\S-1-5-21-453637166-761797416-1449380958-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\SysWOW64\lol.scr [3721216 2016-03-30] ()
HKU\S-1-5-18\...\Policies\system: [DisableLockWorkstation] 0
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{5d3d195a-ab78-487e-8009-a19a668ae0c0}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{6cf397c4-bbdd-4752-9b4b-6315aa5b10cf}: [DhcpNameServer] 10.0.0.138
ManualProxies:
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://
www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {2BE5B35C-65FD-42AB-80A4-CEAC64C89EBB} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {3A004F33-0CC1-4A20-AED9-75A1B5C5BAA5} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {3B481CEB-FFD6-4226-B6A3-8C47FF5B2D7A} URL = hxxp://
www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {6C137BDB-3CA1-4F1A-81FC-7B0B65074AC7} URL = hxxp://
www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {833E670A-6679-44B3-B8F6-113E8196B0DE} URL = hxxp://
www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {94DF93B0-EF46-495D-A111-284CD78ED61B} URL = hxxp://
www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {CC59AD07-97B0-4E48-90D4-477D46636C4D} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {DEEBBE74-688A-4E45-B14B-0BFB65FA2775} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-453637166-761797416-1449380958-1000 -> {EBEC7380-D52F-4AAF-AA1D-F519BACD69EE} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-01-26] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-01-26] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-01-26] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-01-26] (Google Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\AMD\AppData\Roaming\Mozilla\Firefox\Profiles\kfjahmt5.default
FF Homepage: hxxps://
www.google.cz/
FF NetworkProxy: "backup.ftp", "213.39.104.37"
FF NetworkProxy: "backup.ftp_port", 80
FF NetworkProxy: "backup.socks", "213.39.104.37"
FF NetworkProxy: "backup.socks_port", 80
FF NetworkProxy: "backup.ssl", "213.39.104.37"
FF NetworkProxy: "backup.ssl_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Extension: Cash Kitten - C:\Users\AMD\AppData\Roaming\Mozilla\Firefox\Profiles\kfjahmt5.default\Extensions\{bbcb55a0-2035-41f8-8eef-c2012f0e6f5b}.xpi [2016-04-05] [not signed]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
Chrome:
=======
CHR Profile: C:\Users\AMD\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\AMD\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-05]
CHR Extension: (YouTube) - C:\Users\AMD\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-05]
CHR Extension: (Google Search) - C:\Users\AMD\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\AMD\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Users\AMD\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-05]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-11-09] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2016-01-21] (Intel Corporation)
R2 LolScreenSaverService; C:\Riot Games\LolScreenSaver\service\service.exe [707072 2016-03-30] () [File not signed]
S3 MSIBIOSData_CC; C:\Program Files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe [2107344 2015-11-05] (MSI)
S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4164048 2015-12-08] (MSI)
S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2208208 2015-12-08] (MSI)
S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4171216 2015-12-08] (MSI)
R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2015184 2015-12-08] (MSI)
R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2285520 2015-11-05] (MSI)
S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2072528 2015-11-05] (MSI)
S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [599504 2015-11-23] (MSI)
R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [105296 2015-06-04] (MSI)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI)
R2 SuperRAIDSvc; C:\MSI\Smart Utilities\SuperRAIDSvc.exe [29648 2015-02-09] (Micro-Star INT'L CO., LTD.)
R2 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [118424 2016-03-09] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5429520 2015-01-30] (TeamViewer GmbH)
S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dc1-controller; C:\Windows\System32\drivers\dc1-controller.sys [50688 2015-07-10] (Microsoft Corp.)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2015-04-17] (Disc Soft Ltd)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-04-06] ()
S3 INETMON; C:\WINDOWS\System32\Drivers\INETMON.sys [23936 2014-02-03] ()
S3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-02-03] ()
S3 libwamf; C:\Windows\System32\DRIVERS\libwamf.sys [15664 2016-04-08] (Windows (R) Win 7 DDK provider)
S3 libwasys; C:\Windows\System32\DRIVERS\libwasys.sys [28464 2016-04-08] ()
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2016-01-20] (Intel Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
R3 NTIOLib_MSI_RAID; C:\MSI\Smart Utilities\NTIOLib_X64.sys [13808 2014-03-17] (MSI)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [889584 2015-09-23] (Realtek )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2016-03-09] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S0 b06bdrv; System32\drivers\bxvbda.sys [X]
U3 idsvc; no ImagePath
S0 ignis; \SystemRoot\system32\DRIVERS\ignis.sys [X]
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-08 18:38 - 2016-04-08 18:39 - 00021025 _____ C:\Users\AMD\Downloads\FRST.txt
2016-04-08 18:37 - 2016-04-08 18:38 - 00000000 ____D C:\FRST
2016-04-08 18:36 - 2016-04-08 18:36 - 02374144 _____ (Farbar) C:\Users\AMD\Downloads\FRST64.exe
2016-04-08 18:21 - 2016-04-08 18:21 - 00016148 _____ C:\WINDOWS\system32\TIBOR-PC_Tibor_HistoryPrediction.bin
2016-04-08 16:12 - 2016-04-08 16:12 - 00000000 ____D C:\Users\AMD\AppData\Local\PeerDistRepub
2016-04-08 11:41 - 2016-04-08 11:41 - 00000000 ____D C:\Users\AMD\Desktop\Rambo
2016-04-08 11:15 - 2016-04-08 11:41 - 00000000 ____D C:\Users\AMD\Downloads\Rambo
2016-04-08 11:14 - 2016-04-08 11:14 - 00014701 _____ C:\Users\AMD\Downloads\[CzT]Rambo_1_4.torrent
2016-04-08 10:44 - 2016-04-08 10:44 - 00000681 _____ C:\DelFix.txt
2016-04-08 10:37 - 2016-04-08 10:17 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2016-04-08 10:05 - 2016-04-08 10:05 - 01270466 _____ C:\Users\AMD\Downloads\ProcessExplorer.zip
2016-04-08 09:23 - 2016-04-08 09:23 - 00027754 _____ C:\ProgramData\1460100186.bdinstall.bin
2016-04-08 08:59 - 2016-04-08 08:59 - 02842784 _____ C:\Users\AMD\Downloads\The_New_Bitdefender_UninstallTool.exe
2016-04-08 08:57 - 2016-04-08 08:57 - 00019313 _____ C:\ProgramData\1460098635.bdinstall.bin
2016-04-08 08:51 - 2016-04-08 08:51 - 00019313 _____ C:\ProgramData\1460098317.bdinstall.bin
2016-04-08 08:31 - 2016-04-08 08:51 - 00028464 _____ C:\WINDOWS\system32\Drivers\libwasys.sys
2016-04-08 08:31 - 2016-04-08 08:31 - 07043632 _____ () C:\Users\AMD\Downloads\OESISEndpointAssessmentTool.exe
2016-04-08 08:31 - 2016-04-08 08:31 - 00015664 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\libwamf.sys
2016-04-08 08:30 - 2016-04-08 08:30 - 11516104 _____ (OPSWAT, Inc.) C:\Users\AMD\Downloads\appremover.exe
2016-04-08 08:16 - 2016-04-08 08:16 - 00019313 _____ C:\ProgramData\1460096173.bdinstall.bin
2016-04-08 08:09 - 2016-04-08 08:09 - 00001239 _____ C:\Users\Public\Desktop\Intel(R) Driver Update Utility 2.4.lnk
2016-04-08 08:09 - 2016-04-08 08:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
2016-04-08 08:08 - 2016-04-08 08:09 - 00002110 _____ C:\WINDOWS\System32\Tasks\USER_ESRV_SVC_WILLAMETTE
2016-04-08 08:08 - 2016-04-08 08:08 - 05940136 _____ (Intel) C:\Users\AMD\Downloads\Intel Driver Update Utility Installer (1).exe
2016-04-08 08:08 - 2016-04-08 08:08 - 00000000 ____D C:\WINDOWS\System32\Tasks\Intel
2016-04-08 08:08 - 2016-04-08 08:08 - 00000000 ____D C:\Program Files (x86)\Intel Driver Update Utility
2016-04-08 08:08 - 2016-03-09 20:43 - 00021984 _____ C:\WINDOWS\system32\Drivers\semav6msr64.sys
2016-04-08 08:04 - 2016-04-08 08:04 - 62684415 _____ C:\Users\AMD\Downloads\bits-2073.zip
2016-04-07 20:07 - 2016-04-07 20:07 - 00000340 _____ C:\WINDOWS\system32\.crusader
2016-04-07 19:26 - 2016-04-07 19:40 - 00000000 ____D C:\ProgramData\HitmanPro
2016-04-07 19:25 - 2016-04-07 19:25 - 11441744 _____ (SurfRight B.V.) C:\Users\AMD\Downloads\hitmanpro_x64.exe
2016-04-07 19:24 - 2016-04-07 19:24 - 22851472 _____ (Malwarebytes ) C:\Users\AMD\Downloads\mbam-setup-2.2.1.1043 (1).exe
2016-04-07 18:39 - 2016-04-07 18:39 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-07 18:38 - 2016-04-07 18:38 - 22851472 _____ (Malwarebytes ) C:\Users\AMD\Downloads\mbam-setup-2.2.1.1043.exe
2016-04-07 18:26 - 2016-04-07 18:26 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\AMD\Downloads\sh-remover.exe
2016-04-07 18:15 - 2016-04-07 18:15 - 00000000 ____D C:\Users\AMD\Documents\BnS
2016-04-07 18:15 - 2016-04-07 18:15 - 00000000 ____D C:\Users\AMD\AppData\Roaming\Awesomium
2016-04-07 18:15 - 2005-01-03 08:43 - 00004682 _____ (INCA Internet Co., Ltd.) C:\WINDOWS\SysWOW64\npptNT2.sys
2016-04-07 18:15 - 2003-07-18 23:17 - 00005174 _____ C:\WINDOWS\SysWOW64\nppt9x.vxd
2016-04-07 18:14 - 2016-04-07 18:14 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2016-04-07 16:17 - 2016-04-07 16:17 - 00002303 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-04-07 16:17 - 2016-04-07 16:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest
2016-04-07 16:17 - 2016-04-07 16:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCSOFT
2016-04-07 16:17 - 2016-04-07 16:17 - 00000000 ____D C:\Program Files (x86)\NCWest
2016-04-07 16:17 - 2016-04-07 16:17 - 00000000 ____D C:\Program Files (x86)\NCSOFT
2016-04-07 16:12 - 2016-04-07 16:14 - 227195640 _____ (NC Interactive, LLC) C:\Users\AMD\Downloads\BnS_Lite_Installer.exe
2016-04-07 14:51 - 2016-04-07 17:32 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-04-07 14:51 - 2016-04-07 17:28 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-04-07 14:51 - 2016-04-07 14:51 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2016-04-07 14:19 - 2016-04-07 14:19 - 00000385 _____ C:\Users\AMD\AppData\Roaminguser_gensett.xml
2016-04-07 13:29 - 2016-04-07 13:29 - 00000000 ____D C:\SUPERDelete
2016-04-07 13:18 - 2016-04-08 10:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2016-04-07 13:18 - 2016-04-07 13:18 - 00001849 _____ C:\Users\AMD\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-04-07 13:18 - 2016-04-07 13:18 - 00000000 ____D C:\Users\AMD\AppData\Roaming\SUPERAntiSpyware.com
2016-04-07 13:18 - 2016-04-07 13:18 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-04-07 13:17 - 2016-04-07 13:17 - 25287704 _____ (SUPERAntiSpyware) C:\Users\AMD\Downloads\SUPERAntiSpyware (1).exe
2016-04-06 21:16 - 2016-04-07 17:27 - 00000000 ____D C:\Users\AMD\AppData\Roaming\Enigma Software Group
2016-04-06 21:16 - 2016-04-06 21:16 - 00000000 _____ C:\autoexec.bat
2016-04-06 21:15 - 2016-04-06 21:15 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-04-06 21:14 - 2016-04-06 21:14 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\AMD\Downloads\spyhunter-installer.exe
2016-04-06 20:06 - 2016-04-06 20:06 - 00002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-06 20:06 - 2016-04-06 20:06 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-06 20:05 - 2016-04-06 20:05 - 00987728 _____ (Google Inc.) C:\Users\AMD\Downloads\ChromeSetup (2).exe
2016-04-06 12:17 - 2016-04-08 09:00 - 00014907 _____ C:\bdlog.txt
2016-04-06 12:14 - 2016-04-08 09:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2016
2016-04-06 12:14 - 2016-04-06 12:14 - 01438270 _____ C:\ProgramData\1459937261.bdinstall.bin
2016-04-06 12:14 - 2016-04-06 12:14 - 00003406 _____ C:\WINDOWS\System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C
2016-04-06 12:14 - 2016-04-06 12:14 - 00000684 ____H C:\bdr-cf01
2016-04-06 12:14 - 2016-04-06 12:14 - 00000000 ____D C:\ProgramData\BDLogging
2016-04-06 12:13 - 2016-04-06 12:14 - 00253404 ____H C:\bdr-ld01
2016-04-06 12:13 - 2016-04-06 12:14 - 00009216 ____H C:\bdr-ld01.mbr
2016-04-06 12:13 - 2015-12-15 21:35 - 49760229 ____H C:\bdr-im01.gz
2016-04-06 12:13 - 2013-08-13 13:38 - 03271472 ____H C:\bdr-bz01
2016-04-06 12:13 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\capicom.dll
2016-04-06 12:03 - 2016-04-06 12:03 - 10314896 _____ C:\Users\AMD\Downloads\bitdefender_isecurity.exe
2016-04-06 12:03 - 2016-04-06 12:03 - 00000000 ____D C:\ProgramData\Bitdefender Agent
2016-04-06 11:47 - 2016-04-06 11:51 - 00000000 ____D C:\Users\AMD\Downloads\Bitdefender Antivirus Plus,Internet Security,Total Security 2016 (x64,x86) ALL IN 1
2016-04-06 11:47 - 2016-04-06 11:47 - 00014887 _____ C:\Users\AMD\Downloads\[CzT]Bitdefender_2016_All_In_One_x64_x86_2015_.torrent
2016-04-06 11:39 - 2016-04-06 11:39 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-04-06 11:39 - 2016-04-06 11:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-04-06 11:38 - 2016-04-06 11:39 - 00000000 ____D C:\Program Files\iTunes
2016-04-06 11:38 - 2016-04-06 11:38 - 00000000 ____D C:\Program Files\iPod
2016-04-06 11:38 - 2016-04-06 11:38 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-04-06 11:36 - 2016-04-06 11:36 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2016-04-06 11:36 - 2016-04-06 11:36 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-04-06 07:11 - 2016-04-08 10:38 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-04-06 01:39 - 2016-04-06 01:39 - 00015151 _____ C:\Users\AMD\Downloads\[CzT]ESET_Smart_Security_NOD32_Antivirus_v9_0_318_22_x86_x64_CZ_.torrent
2016-04-06 01:39 - 2016-04-06 01:39 - 00000000 ____D C:\Users\AMD\Downloads\ESET Smart Security & NOD32 Antivirus 9.0.318.22 (x86,x64)(CZ)
2016-04-05 22:22 - 2016-04-05 22:22 - 00023258 _____ C:\WINDOWS\System32\Tasks\{04040847-0C0C-0A7D-0C11-7A7E0D7D110D}
2016-04-05 21:44 - 2016-04-05 21:44 - 00127040 _____ C:\Users\AMD\Downloads\binkw32.dll.zip
2016-04-05 21:06 - 2012-02-13 10:25 - 00174080 _____ (RAD Game Tools, Inc.) C:\WINDOWS\system32\binkw32.dll
2016-04-05 21:05 - 2016-04-05 21:05 - 00098195 _____ C:\Users\AMD\Downloads\binkw32.zip
2016-04-05 16:48 - 2016-04-05 20:26 - 00000000 ____D C:\Users\AMD\Downloads\Saints.Row.IV.Game.of.The.Century.Edition-PROPHET
2016-04-05 16:47 - 2016-04-05 16:47 - 00045326 _____ C:\Users\AMD\Downloads\[CzT]Saints_Row_IV_Game_of_the_Century_Edition_2014_.torrent
2016-04-05 12:01 - 2016-04-05 12:01 - 00059904 _____ C:\Users\AMD\Desktop\Nový Microsoft Publisher Document.pub
2016-04-04 20:52 - 2016-04-04 20:52 - 00143807 _____ C:\Users\AMD\Downloads\Životopis.pdf
2016-04-04 20:17 - 2016-04-04 20:17 - 00026578 _____ C:\Users\AMD\Downloads\[CzT]Iron_Man_1_3_2008_2013_CZ_ (2).torrent
2016-04-04 20:13 - 2016-04-08 11:42 - 00000000 ____D C:\Users\AMD\Desktop\Ironman
2016-04-04 20:13 - 2016-04-05 01:03 - 00000000 ____D C:\Users\AMD\Downloads\Iron-man
2016-04-04 20:12 - 2016-04-04 20:12 - 00026578 _____ C:\Users\AMD\Downloads\[CzT]Iron_Man_1_3_2008_2013_CZ_.torrent
2016-04-04 20:12 - 2016-04-04 20:12 - 00026578 _____ C:\Users\AMD\Downloads\[CzT]Iron_Man_1_3_2008_2013_CZ_ (1).torrent
2016-03-31 13:50 - 2016-03-31 13:50 - 00000000 ____D C:\Users\AMD\AppData\Roaming\LolScreenSaver
2016-03-31 13:50 - 2016-03-31 13:50 - 00000000 ____D C:\Users\AMD\AppData\Local\CEF
2016-03-31 13:49 - 2016-03-31 13:49 - 38577688 _____ C:\Users\AMD\Downloads\League_Screensaver (1).exe
2016-03-31 13:46 - 2016-03-31 13:46 - 38577688 _____ C:\Users\AMD\Downloads\League_Screensaver.exe
2016-03-30 20:25 - 2016-03-30 20:25 - 03721216 _____ C:\WINDOWS\SysWOW64\lol.scr
2016-03-30 09:09 - 2016-03-30 09:09 - 00162886 _____ C:\Users\AMD\Downloads\CV-cz (6).pdf
2016-03-30 09:00 - 2016-03-30 09:00 - 00154773 _____ C:\Users\AMD\Downloads\CV-cz (5).pdf
2016-03-23 15:40 - 2016-03-31 13:50 - 00000000 ____D C:\Riot Games
2016-03-23 15:40 - 2016-03-23 15:40 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-23 15:40 - 2016-03-23 15:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-03-23 15:39 - 2016-03-23 15:39 - 30993712 _____ (Riot Games) C:\Users\AMD\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014 (1).exe
2016-03-13 11:04 - 2016-03-13 11:04 - 00016148 _____ C:\WINDOWS\system32\TIBOR-PC_noelq_HistoryPrediction.bin
2016-03-12 18:20 - 2016-03-12 18:20 - 00000000 ____D C:\Users\noelq\Documents\gegl-0.0
2016-03-12 18:20 - 2016-03-12 18:20 - 00000000 ____D C:\Users\noelq\.gimp-2.6
2016-03-09 19:18 - 2015-06-09 18:14 - 02267304 _____ (Micro-Star INT'L CO., LTD.) C:\WINDOWS\SysWOW64\Liveinst.exe
2016-03-09 15:31 - 2016-02-23 14:16 - 02237952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 15:31 - 2016-02-23 12:48 - 21859840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 15:31 - 2016-02-23 12:38 - 07524864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 15:30 - 2016-02-23 16:53 - 01314496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 15:30 - 2016-02-23 16:51 - 00633184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-03-09 15:30 - 2016-02-23 16:50 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 15:30 - 2016-02-23 16:48 - 08022368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 15:30 - 2016-02-23 16:48 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-09 15:30 - 2016-02-23 16:48 - 01123952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-09 15:30 - 2016-02-23 16:41 - 00299600 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMASF.DLL
2016-03-09 15:30 - 2016-02-23 16:41 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-03-09 15:30 - 2016-02-23 16:40 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-03-09 15:30 - 2016-02-23 16:38 - 00272752 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 15:30 - 2016-02-23 16:36 - 00080128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-03-09 15:30 - 2016-02-23 16:11 - 00781984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 15:30 - 2016-02-23 16:11 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-09 15:30 - 2016-02-23 16:11 - 00103776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-03-09 15:30 - 2016-02-23 16:08 - 03622272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-09 15:30 - 2016-02-23 16:07 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-09 15:30 - 2016-02-23 15:39 - 00607416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 15:30 - 2016-02-23 15:30 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 15:30 - 2016-02-23 15:25 - 01085632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-03-09 15:30 - 2016-02-23 15:23 - 00952968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 15:30 - 2016-02-23 15:21 - 00529456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 15:30 - 2016-02-23 15:11 - 00249976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMASF.DLL
2016-03-09 15:30 - 2016-02-23 15:11 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-03-09 15:30 - 2016-02-23 15:11 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-03-09 15:30 - 2016-02-23 15:09 - 00229352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 15:30 - 2016-02-23 15:06 - 00069232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-03-09 15:30 - 2016-02-23 14:50 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-09 15:30 - 2016-02-23 14:50 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-03-09 15:30 - 2016-02-23 14:42 - 00658536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 15:30 - 2016-02-23 14:42 - 00467296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-09 15:30 - 2016-02-23 14:42 - 00078176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-03-09 15:30 - 2016-02-23 14:39 - 02879024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-09 15:30 - 2016-02-23 14:38 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-09 15:30 - 2016-02-23 14:35 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 15:30 - 2016-02-23 14:20 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-03-09 15:30 - 2016-02-23 14:15 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 15:30 - 2016-02-23 13:59 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2016-03-09 15:30 - 2016-02-23 13:59 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-09 15:30 - 2016-02-23 13:57 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-09 15:30 - 2016-02-23 13:55 - 24592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 15:30 - 2016-02-23 13:45 - 12504576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-09 15:30 - 2016-02-23 13:45 - 06788608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 15:30 - 2016-02-23 13:42 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 15:30 - 2016-02-23 13:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 15:30 - 2016-02-23 13:38 - 02663424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-09 15:30 - 2016-02-23 13:37 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2016-03-09 15:30 - 2016-02-23 13:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-09 15:30 - 2016-02-23 13:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 15:30 - 2016-02-23 13:17 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-03-09 15:30 - 2016-02-23 13:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-03-09 15:30 - 2016-02-23 13:14 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-03-09 15:30 - 2016-02-23 13:04 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 15:30 - 2016-02-23 13:03 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 15:30 - 2016-02-23 13:02 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 15:30 - 2016-02-23 12:55 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 15:30 - 2016-02-23 12:55 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 15:30 - 2016-02-23 12:51 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 15:30 - 2016-02-23 12:51 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 15:30 - 2016-02-23 12:48 - 05157376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 15:30 - 2016-02-23 12:46 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 15:30 - 2016-02-23 12:45 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 15:30 - 2016-02-23 12:45 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-03-09 15:30 - 2016-02-23 12:45 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 15:30 - 2016-02-23 12:45 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 15:30 - 2016-02-23 12:44 - 01821696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-09 15:30 - 2016-02-23 12:29 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-03-09 15:30 - 2016-02-23 12:17 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 15:30 - 2016-02-23 12:11 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 15:30 - 2016-02-23 12:03 - 01495040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 15:30 - 2016-02-23 12:00 - 11263488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-09 15:30 - 2016-02-23 12:00 - 05457408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 15:30 - 2016-02-23 11:58 - 18800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-09 15:29 - 2016-02-23 16:52 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-09 15:29 - 2016-02-23 16:51 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 15:29 - 2016-02-23 16:41 - 01150816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 15:29 - 2016-02-23 15:21 - 00141152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 15:29 - 2016-02-23 14:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-03-09 15:29 - 2016-02-23 14:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-03-09 15:29 - 2016-02-23 14:15 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-03-09 15:29 - 2016-02-23 13:25 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 15:29 - 2016-02-23 13:08 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 15:29 - 2016-02-23 13:03 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 15:29 - 2016-02-23 12:17 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-08 18:34 - 2015-08-06 21:42 - 00004186 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DB555E0B-51DE-44AF-9D34-AF58781AF424}
2016-04-08 18:34 - 2015-05-03 15:31 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-08 18:29 - 2015-12-05 19:19 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-08 16:15 - 2016-01-22 19:47 - 00005220 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for TIBOR-PC-Tibor TIBOR-PC
2016-04-08 15:49 - 2015-08-07 11:08 - 00000000 ____D C:\Users\AMD\AppData\Roaming\Seznam.cz
2016-04-08 15:44 - 2015-12-05 19:19 - 00000974 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-08 15:43 - 2016-01-20 17:47 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-08 15:42 - 2015-07-10 14:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-08 15:42 - 2015-07-10 11:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-04-08 15:42 - 2015-05-03 15:31 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-04-08 15:42 - 2015-04-14 13:37 - 00000000 ____D C:\Users\AMD\AppData\Roaming\uTorrent
2016-04-08 15:34 - 2015-05-03 15:31 - 00003956 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-04-08 10:44 - 2015-06-19 18:53 - 00000000 ____D C:\AdwCleaner
2016-04-08 10:39 - 2015-07-10 13:02 - 00000000 ____D C:\WINDOWS\INF
2016-04-08 10:36 - 2016-01-27 17:36 - 00000000 ____D C:\Users\email\AppData\Local\Google
2016-04-08 10:29 - 2009-07-14 05:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-04-08 08:11 - 2016-01-20 21:13 - 00000000 ____D C:\Users\AMD\Downloads\Intel Components
2016-04-08 08:08 - 2016-01-20 17:47 - 00000000 ____D C:\Program Files (x86)\Intel
2016-04-08 08:08 - 2016-01-20 17:46 - 00000000 ____D C:\Program Files\Intel
2016-04-08 07:48 - 2015-07-10 13:04 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-08 07:48 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-07 19:39 - 2015-12-14 01:32 - 00000000 ____D C:\Users\noelq\Desktop\OpenMu No Sound
2016-04-07 19:39 - 2015-12-13 22:20 - 00000000 ____D C:\Users\AMD\Desktop\OpenMu No Sound
2016-04-07 16:17 - 2015-04-02 12:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-04-07 15:13 - 2015-03-24 19:27 - 00000000 ____D C:\Users\AMD\AppData\Local\VirtualStore
2016-04-07 14:16 - 2015-07-10 11:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-07 14:14 - 2016-02-19 17:41 - 00000000 ____D C:\Program Files (x86)\InsaniaMU
2016-04-06 20:06 - 2015-04-12 14:59 - 00000000 ____D C:\Program Files (x86)\Google
2016-04-06 19:59 - 2016-01-20 19:21 - 00000000 ____D C:\Program Files\KMSpico
2016-04-06 12:57 - 2015-06-02 15:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-04-06 11:38 - 2015-05-09 20:15 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-04-06 11:36 - 2015-05-09 20:16 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-04-06 01:47 - 2015-07-08 17:34 - 00000000 ____D C:\Users\AMD\AppData\Local\ESET
2016-04-05 21:37 - 2015-07-31 00:32 - 02030544 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-05 21:37 - 2015-07-10 18:02 - 00839102 _____ C:\WINDOWS\system32\perfh005.dat
2016-04-05 21:37 - 2015-07-10 18:02 - 00191430 _____ C:\WINDOWS\system32\perfc005.dat
2016-04-05 21:27 - 2015-07-10 18:02 - 00000000 ____D C:\WINDOWS\SysWOW64\cs
2016-04-05 21:12 - 2015-07-31 00:33 - 00000000 ____D C:\Users\AMD
2016-04-05 21:11 - 2015-07-06 20:22 - 00000000 ____D C:\Users\AMD\Desktop\KOMEDIE BIATCH
2016-04-05 20:45 - 2015-07-18 17:10 - 00000000 ____D C:\Users\AMD\Desktop\Kmotr
2016-04-05 20:38 - 2015-05-26 23:59 - 00000000 ____D C:\Users\AMD\Desktop\Filmiky
2016-04-04 15:29 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\ELAMBKUP
2016-03-23 15:40 - 2016-01-31 19:58 - 00000000 ____D C:\Users\AMD\AppData\Roaming\Riot Games
2016-03-16 19:19 - 2015-09-18 00:14 - 00000000 ____D C:\Users\AMD\.gimp-2.6
2016-03-12 21:17 - 2015-12-14 01:26 - 00000000 ____D C:\Users\noelq\AppData\Roaming\Seznam.cz
2016-03-12 21:12 - 2016-01-27 17:13 - 00000000 __SHD C:\Users\noelq\IntelGraphicsProfiles
2016-03-12 21:11 - 2015-12-14 01:22 - 00000000 ____D C:\Users\noelq
2016-03-12 18:32 - 2015-04-25 20:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-12 18:29 - 2015-04-25 20:46 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-12 17:57 - 2015-12-14 01:26 - 00002387 _____ C:\Users\noelq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-12 17:57 - 2015-12-14 01:26 - 00000000 ___RD C:\Users\noelq\OneDrive
2016-03-12 17:55 - 2015-07-31 00:49 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-12 17:52 - 2015-07-10 14:20 - 00424128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-11 20:28 - 2015-07-10 12:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-11 20:03 - 2015-10-22 16:40 - 00000000 ____D C:\Users\AMD\Desktop\HESLA
2016-03-10 13:31 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 13:31 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 13:31 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 13:31 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-09 19:18 - 2016-01-21 18:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2016-03-09 19:18 - 2016-01-21 18:26 - 00000000 ____D C:\Program Files (x86)\MSI
2016-03-09 19:18 - 2016-01-21 18:26 - 00000000 ____D C:\MSI
==================== Files in the root of some directories =======
2016-04-06 12:14 - 2016-04-06 12:14 - 1438270 _____ () C:\ProgramData\1459937261.bdinstall.bin
2016-04-08 08:16 - 2016-04-08 08:16 - 0019313 _____ () C:\ProgramData\1460096173.bdinstall.bin
2016-04-08 08:51 - 2016-04-08 08:51 - 0019313 _____ () C:\ProgramData\1460098317.bdinstall.bin
2016-04-08 08:57 - 2016-04-08 08:57 - 0019313 _____ () C:\ProgramData\1460098635.bdinstall.bin
2016-04-08 09:23 - 2016-04-08 09:23 - 0027754 _____ () C:\ProgramData\1460100186.bdinstall.bin
2016-01-20 17:24 - 2016-01-20 17:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 09:27
==================== End of FRST.txt ============================