Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017
Ran by Safire (administrator) on DESKTOP-UVHEV98 (21-02-2017 22:23:38)
Running from C:\Users\Safire\Desktop
Loaded Profiles: Safire (Available Profiles: defaultuser0 & Safire)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(HP) C:\Windows\System32\hpservice.exe
(Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
() C:\Windows\System32\fpCSEvtSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(IEC) C:\Program Files (x86)\BikaQRssReader\BikaQ.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
() E:\wallpaper_engine\wallpaper64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) E:\Steam\Steam.exe
(Valve Corporation) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9745312 2016-10-16] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5374880 2016-10-16] (Lenovo(beijing) Limited)
HKLM\...\Run: [RtsCM] => c:\windows\RTSCM64.EXE [227896 2016-06-23] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-07-03] (Synaptics Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [16293496 2016-09-29] (Logitech Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM-x32\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe [222160 2016-09-28] (Razer Inc.)
HKLM-x32\...\Run: [Manticore] => C:\Program Files (x86)\Genius\Manticore\MThid.exe [293376 2013-10-29] (KYE)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4557504 2016-10-06] (Disc Soft Ltd)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [Steam] => E:\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [f.lux] => C:\Users\Safire\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [Battle.net] => E:\Battle.net\Battle.net Launcher.exe [3122152 2016-10-15] (Blizzard Entertainment)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [GoogleChromeAutoLaunch_86536B082181848BA60E21454357D310] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1116504 2017-02-01] (Google Inc.)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [51fa5df9-73ee-4efa-96ac-853c6418a27f] => C:\Program Files\8VG3U2BWP7\8VG3U2BWP.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [b2956951-fab2-487d-ac0d-16138d77c2d2] => C:\Program Files\40SGV55LUE\SWICAKXEY.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [baad9cf4-d497-405b-8736-78c7780c3422] => C:\Program Files\L9H6Y29HWJ\L9H6Y29HW.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [18c294f5-8b2b-415f-a903-553cccbe3aad] => C:\Program Files\4IDBK0B7IX\732D05FC5.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [WallpaperEngine] => E:\wallpaper_engine\wallpaper64.exe [894464 2017-02-11] ()
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\RunOnce: [Uninstall C:\Users\Safire\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Safire\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\MountPoints2: {b4011332-93a8-11e6-a064-c5b9bf7a5324} - "H:\setup.exe"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\MountPoints2: {b60a08b8-9cff-11e6-a08a-a4db30d8d363} - "F:\LaunchU3.exe" -a
HKLM\...\Providers\jebnkuvk: C:\Program Files (x86)\Nimasy Engine\local64spl.dll [307200 2017-02-20] ()
IFEO\SppExtComObj.exe: [Debugger] SppExtComObjPatcher.exe
ShellExecuteHooks: No Name - {5AD340E8-F445-11E6-B566-64006A5CFC23} - C:\Program Files (x86)\Divosh\Reuqutain.dll [146432 2017-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2016-11-27]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Safire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sapphire TRIXX.lnk [2016-10-16]
ShortcutTarget: Sapphire TRIXX.lnk -> C:\Program Files (x86)\Sapphire TRIXX\TRIXX.exe (Sapphire Technology Limited)
Startup: C:\Users\Safire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ThrottleStop - Shortcut.lnk [2016-10-16]
ShortcutTarget: ThrottleStop - Shortcut.lnk -> C:\Users\Safire\Desktop\ThrottleStop_600\ThrottleStop.exe (uWebb Software)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{52adbf23-2f58-4fe5-8893-08748841f73c}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{dc55f9e6-d6a5-4d11-afd3-37bb98a04aa6}: [DhcpNameServer] 88.212.8.8 88.212.8.88
Tcpip\..\Interfaces\{ebc0d160-1295-4994-86c8-614ca694f736}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Internet Explorer:
==================
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://
www.msn.com/?ocid=iehp
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-02-07] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-07] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-07] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-02-07] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-02-07] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData2
CHR HomePage: ChromeDefaultData2 -> hxxp://
www.youndoo.com/?z=46817d47ee5f418369f8 ... EX&type=hp
CHR StartupUrls: ChromeDefaultData2 -> "hxxp://
www.youndoo.com/?z=46817d47ee5f418369f8 ... EX&type=hp"
CHR Profile: C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2017-02-21] <==== ATTENTION
CHR Extension: (Prezentácie Google) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-15]
CHR Extension: (Dokumenty Google) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-15]
CHR Extension: (Disk Google) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-15]
CHR Extension: (YouTube) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-15]
CHR Extension: (Tabuľky Google) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-15]
CHR Extension: (Musixmatch Lyrics for YouTube) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\gfenjblodoldnbiddmggcbkcapiolbig [2016-12-20]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-15]
CHR Extension: (AdBlock) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-21]
CHR Extension: (Speed Dial 2) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2017-02-20]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-02-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19]
CHR Extension: (Gmail) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-15]
CHR Extension: (Chrome Media Router) - C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2016-12-14] ()
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3702472 2017-01-29] (Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1468608 2016-10-06] (Disc Soft Ltd)
R2 fpCsEvtSvc; C:\Windows\system32\fpCSEvtSvc.exe [22528 2015-06-10] ()
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
R2 hpsrv; C:\Windows\system32\Hpservice.exe [38728 2016-10-12] (HP)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [356336 2016-08-04] (Intel Corporation)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-09-29] (Logitech Inc.)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-24] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [133376 2016-09-28] (Razer Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [53248 2015-06-10] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Safire\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-21] (TODO: <Company name>) [File not signed]
R2 WinSnare; C:\Users\Safire\AppData\Roaming\WinSnare\WinSnare.dll [779264 2017-02-21] (InterSect Alliance Pty Ltd) [File not signed]
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Accelerometer; C:\Windows\system32\DRIVERS\Accelerometer.sys [56128 2016-10-12] (HP)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-09-25] (Windows (R) Win 7 DDK provider)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-10-16] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-10-16] (Disc Soft Ltd)
R0 hpdskflt; C:\Windows\System32\DRIVERS\hpdskflt.sys [42312 2016-10-12] (HP)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\Windows\system32\drivers\LGJoyXlCore.sys [67736 2016-09-29] (Logitech Inc.)
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2016-09-29] (Logitech Inc.)
S1 ljkhoawh; C:\Windows\system32\drivers\ljkhoawh.sys [55168 2017-02-21] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [772336 2015-08-27] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3126032 2016-06-23] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 TRIXX; C:\Users\Safire\AppData\Local\Temp\TRIXX.sys [27008 2017-01-31] () <==== ATTENTION
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WinRing0_1_2_0; C:\Users\Safire\Desktop\ThrottleStop_600\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
R3 WirelessButtonDriver64; C:\Windows\system32\DRIVERS\WirelessButtonDriver64.sys [31656 2016-04-14] (HP)
S3 GPU-Z; \??\C:\Users\Safire\AppData\Local\Temp\GPU-Z.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-21 22:23 - 2017-02-21 22:24 - 00020395 _____ C:\Users\Safire\Desktop\FRST.txt
2017-02-21 21:41 - 2017-02-21 21:41 - 00095044 _____ C:\Users\Safire\Desktop\sdsadasdasdasdasd.webp
2017-02-21 21:41 - 2017-02-21 21:41 - 00095044 _____ C:\Users\Safire\Desktop\dasdasdasdasd.webp
2017-02-21 21:36 - 2017-02-21 21:36 - 00234434 _____ C:\Users\Safire\Downloads\New Recording.m4a
2017-02-21 21:36 - 2017-02-21 21:36 - 00234434 _____ C:\Users\Safire\Desktop\New Recording.m4a
2017-02-21 10:13 - 2017-02-21 10:47 - 00000000 ____D C:\Users\Safire\Downloads\Before.the.Flood.2016.DOCU.1080p.WEBRip.x264.DD5.1-FGT
2017-02-21 09:54 - 2017-02-21 09:54 - 00003354 _____ C:\Windows\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-21 09:54 - 2017-02-21 09:54 - 00000000 ____D C:\Users\Safire\AppData\Roaming\WinSnare
2017-02-21 09:54 - 2017-02-21 09:54 - 00000000 ____D C:\Users\Safire\AppData\Roaming\WinSAPSvc
2017-02-21 09:54 - 2017-02-21 09:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-02-21 09:54 - 2017-02-21 09:54 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.3)
2017-02-21 09:54 - 2017-02-21 09:54 - 00000000 ____D C:\Program Files (x86)\BikaQRssReader
2017-02-21 09:53 - 2017-02-21 09:54 - 00003672 _____ C:\Windows\System32\Tasks\Milimili
2017-02-21 09:53 - 2017-02-21 09:54 - 00000000 ____D C:\Program Files (x86)\MIO
2017-02-21 09:52 - 2017-02-21 09:52 - 00055168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ljkhoawh.sys
2017-02-21 09:49 - 2017-02-21 09:49 - 00034328 _____ (Sysinternals -
www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP152.SYS
2017-02-21 09:49 - 2017-02-21 09:49 - 00000000 ____D C:\Program Files (x86)\jebnkuvk
2017-02-20 21:14 - 2017-02-20 21:55 - 2546251059 _____ C:\Users\Safire\Downloads\Wallpaper.Engine.Workshop.Pack.4.rar
2017-02-20 20:55 - 2017-02-20 21:04 - 906304620 _____ C:\Users\Safire\Downloads\Wallpaper.Engine.Workshop.Pack.2 (1).rar
2017-02-20 20:34 - 2017-02-20 20:45 - 906304620 _____ C:\Users\Safire\Downloads\Wallpaper.Engine.Workshop.Pack.2.rar
2017-02-20 20:24 - 2017-02-20 20:29 - 574809207 _____ C:\Users\Safire\Downloads\Wallpaper.Engine.gottx.Workshop.rar
2017-02-20 20:13 - 2017-02-20 20:17 - 00000000 ____D C:\AdwCleaner
2017-02-20 20:13 - 2017-02-20 20:12 - 04015056 _____ C:\Users\Safire\Desktop\adwcleaner_6.043.exe
2017-02-20 20:12 - 2017-02-20 20:12 - 04015056 _____ C:\Users\Safire\Downloads\adwcleaner_6.043.exe
2017-02-20 18:01 - 2017-02-21 22:23 - 00000000 ____D C:\FRST
2017-02-20 18:01 - 2017-02-20 18:01 - 02422784 _____ (Farbar) C:\Users\Safire\Downloads\FRST64.exe
2017-02-20 18:01 - 2017-02-20 18:01 - 02422784 _____ (Farbar) C:\Users\Safire\Desktop\FRST64.exe
2017-02-20 17:57 - 2017-02-20 17:57 - 00112640 _____ (forum.viry.cz) C:\Users\Safire\Downloads\FRSTLauncher (2).exe
2017-02-20 17:43 - 2017-02-20 17:43 - 00112640 _____ (forum.viry.cz) C:\Users\Safire\Downloads\Nepotvrdené 392475.crdownload
2017-02-20 17:42 - 2017-02-20 18:00 - 00029696 _____ C:\Users\Safire\AppData\Local\MSGBOX.EXE
2017-02-20 17:42 - 2017-02-20 17:42 - 00112640 _____ (forum.viry.cz) C:\Users\Safire\Downloads\FRSTLauncher (1).exe
2017-02-20 17:42 - 2017-02-20 17:42 - 00112640 _____ (forum.viry.cz) C:\Users\Safire\Desktop\FRSTLauncher.exe
2017-02-20 17:33 - 2017-02-21 09:52 - 00000000 ____D C:\Program Files\Y6T6BFBSH9
2017-02-20 17:31 - 2017-02-20 17:31 - 00000000 ____D C:\Program Files\4IDBK0B7IX
2017-02-20 17:30 - 2017-02-21 09:49 - 00000000 ____D C:\Program Files (x86)\Atepudomarlerward
2017-02-20 17:30 - 2017-02-20 17:30 - 00000000 ____D C:\Users\Safire\AppData\Roaming\Paceghvoqs
2017-02-20 17:29 - 2017-02-21 22:18 - 00001577 _____ C:\Users\Safire\Desktop\Google Chrome.lnk
2017-02-20 17:28 - 2017-02-20 17:31 - 00000000 ____D C:\Users\Safire\AppData\Local\Fomtion
2017-02-20 17:28 - 2017-02-20 17:28 - 00000258 __RSH C:\Users\Safire\ntuser.pol
2017-02-20 17:27 - 2017-02-20 17:28 - 00000000 ____D C:\Program Files\L9H6Y29HWJ
2017-02-20 17:23 - 2017-02-20 17:23 - 00000000 ____D C:\Program Files\B961C8CGOU
2017-02-20 17:22 - 2017-02-20 17:30 - 00000000 ____D C:\Program Files (x86)\PubHotspot
2017-02-20 17:22 - 2017-02-20 17:22 - 00000000 ____D C:\Program Files\40SGV55LUE
2017-02-20 17:21 - 2017-02-20 17:22 - 00000000 ____D C:\Users\Safire\AppData\Local\Grusert
2017-02-20 17:21 - 2017-02-20 17:22 - 00000000 ____D C:\Program Files\8VG3U2BWP7
2017-02-20 17:21 - 2017-02-20 17:22 - 00000000 ____D C:\Program Files (x86)\Divosh
2017-02-20 17:21 - 2017-02-20 17:21 - 00006028 _____ C:\Windows\System32\Tasks\Nimasy Engine
2017-02-20 17:21 - 2017-02-20 17:21 - 00005122 _____ C:\Windows\System32\Tasks\Kokock
2017-02-20 17:21 - 2017-02-20 17:21 - 00000000 ____D C:\Users\Public\Thunder Network
2017-02-20 17:21 - 2017-02-20 17:21 - 00000000 ____D C:\ProgramData\Thunder Network
2017-02-20 17:21 - 2017-02-20 17:21 - 00000000 ____D C:\Program Files (x86)\Nimasy Engine
2017-02-20 17:20 - 2017-02-20 17:20 - 01703936 _____ C:\Users\Safire\Downloads\Wallpaper_Engine_Build_1_0_562.iso
2017-02-20 17:20 - 2017-02-20 17:20 - 01703936 _____ C:\Users\Safire\Downloads\Wallpaper_Engine_Build_1_0_562 (2).iso
2017-02-20 17:20 - 2017-02-20 17:20 - 01703936 _____ C:\Users\Safire\Downloads\Wallpaper_Engine_Build_1_0_562 (1).iso
2017-02-20 17:10 - 2017-02-20 17:10 - 00321484 _____ C:\Users\Safire\Downloads\1eb150662091390fa69ef9a7640fda6b.mp4
2017-02-20 14:31 - 2017-02-20 14:32 - 220727043 ____R C:\Users\Safire\Downloads\wallpaper_engine.rar
2017-02-20 11:28 - 2017-02-20 11:49 - 00000000 ____D C:\Users\Safire\Downloads\From [
WWW.TORRENTING.ME ] - The.Walking.Dead.S07E10.720p.HDTV.x264-AVS
2017-02-17 13:49 - 2017-02-17 13:49 - 06337024 _____ C:\Users\Safire\Downloads\CIT_final_nove (1).ppt
2017-02-17 13:29 - 2017-02-17 13:29 - 00000200 _____ C:\Users\Safire\Desktop\Sid Meier's Civilization V.url
2017-02-17 11:40 - 2017-02-17 11:40 - 02536455 _____ C:\Users\Safire\Downloads\levoca-februar-2014.pdf
2017-02-16 21:31 - 2017-02-16 21:32 - 01435813 _____ C:\Users\Safire\Downloads\4Q16_PT_ENG (1).pdf
2017-02-16 21:29 - 2017-02-16 21:29 - 01435813 _____ C:\Users\Safire\Downloads\4Q16_PT_ENG.pdf
2017-02-16 16:58 - 2017-02-17 12:08 - 00000000 ____D C:\Users\Safire\Downloads\Vikings.S04E20.The.Reckoning.1080p.WEB-DL.DD5.1.H.264-DRACULA[ettv]
2017-02-16 16:58 - 2017-02-17 10:05 - 00000000 ____D C:\Users\Safire\Downloads\From [
WWW.TORRENTING.ME ] - Vikings.S04E19.720p.HDTV.x264-SVA
2017-02-16 16:58 - 2017-02-16 21:48 - 00000000 ____D C:\Users\Safire\Downloads\Vikings.S04E18.720p.WEB-DL.DD5.1.H264-LiGaS
2017-02-16 16:57 - 2017-02-16 17:22 - 00000000 ____D C:\Users\Safire\Downloads\From [
WWW.TORRENTING.ME ] - Vikings.S04E17.720p.HDTV.x264-SVA
2017-02-16 13:05 - 2017-02-16 13:05 - 00000000 ____D C:\Users\Safire\Documents\Elder Scrolls Online
2017-02-16 13:05 - 2017-02-16 13:05 - 00000000 ____D C:\ProgramData\Elder Scrolls Online
2017-02-16 11:52 - 2017-02-16 11:52 - 00000000 ____D C:\Users\Safire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Elder Scrolls Online
2017-02-16 11:51 - 2017-02-16 11:52 - 00000000 ___HD C:\Program Files (x86)\Zero G Registry
2017-02-16 11:51 - 2017-02-16 11:52 - 00000000 ____D C:\Windows\jre
2017-02-16 11:51 - 2017-02-16 11:51 - 00000000 ___HD C:\Users\Safire\InstallAnywhere
2017-02-15 15:54 - 2017-02-15 15:54 - 06337024 _____ C:\Users\Safire\Downloads\CIT_final_nove.ppt
2017-02-15 15:31 - 2017-02-15 15:31 - 01449723 _____ C:\Users\Safire\Downloads\zaverecna_prace.pdf
2017-02-15 15:31 - 2017-02-15 15:31 - 00489040 _____ C:\Users\Safire\Downloads\226_Zateplovanie_budov.pdf
2017-02-13 19:41 - 2017-02-13 19:43 - 00000000 ____D C:\Users\Safire\Downloads\From [
WWW.TORRENTING.ME ] - The.Walking.Dead.S07E09.720p.HDTV.x264-AVS
2017-02-13 15:04 - 2017-02-13 15:04 - 01674807 _____ C:\Users\Safire\Downloads\BE2D31DF2BE5431DA8296E5EBB5F7E60.pdf
2017-02-13 15:04 - 2017-02-13 15:04 - 01674807 _____ C:\Users\Safire\Desktop\BE2D31DF2BE5431DA8296E5EBB5F7E60.pdf
2017-02-13 14:29 - 2017-02-13 19:43 - 00000000 ____D C:\Users\Safire\Downloads\Vikings.S04E02.720p.HDTV.x264-KILLERS[ettv]
2017-02-13 14:29 - 2017-02-13 17:34 - 00000000 ____D C:\Users\Safire\Downloads\Vikings.S04E01.720p.HDTV.x264-KILLERS[ettv]
2017-02-13 11:50 - 2017-02-13 11:50 - 00115443 _____ C:\Users\Safire\Downloads\Hudák_Riadenie kvality v doprave.pptx
2017-02-13 09:13 - 2017-02-13 09:13 - 00261632 _____ C:\Users\Safire\Downloads\rozpocet__ocu_2016-2018_z.xls
2017-02-13 09:11 - 2017-02-13 09:11 - 00192000 _____ C:\Users\Safire\Downloads\navrh_rozpocet_2017-2019.xls
2017-02-12 22:27 - 2017-02-12 22:28 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-02-12 22:27 - 2017-02-12 22:27 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-02-12 22:27 - 2017-02-12 22:27 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2017-02-12 22:27 - 2017-02-12 22:27 - 00000000 ____D C:\Users\Safire\AppData\Roaming\TeamViewer
2017-02-12 22:25 - 2017-02-12 22:26 - 12973136 _____ (TeamViewer GmbH) C:\Users\Safire\Downloads\TeamViewer_Setup_sk.exe
2017-02-11 19:01 - 2017-02-11 19:01 - 00030225 _____ C:\Users\Safire\Downloads\Keanu (2016) [720p] [YTS.AG].torrent
2017-02-11 19:01 - 2017-02-11 19:01 - 00000000 ____D C:\Users\Safire\Downloads\The Escort (2015) [YTS.AG]
2017-02-11 19:01 - 2017-02-11 19:01 - 00000000 ____D C:\Users\Safire\Downloads\Keanu (2016) [YTS.AG]
2017-02-11 18:59 - 2017-02-11 18:59 - 00026115 _____ C:\Users\Safire\Downloads\The Escort (2015) [720p] [YTS.AG].torrent
2017-02-11 11:50 - 2017-02-11 11:50 - 00000162 ____H C:\Users\Safire\Desktop\~$ke_word_2013_sk.dotx
2017-02-10 20:30 - 2017-02-11 19:09 - 00000000 ____D C:\Users\Safire\Downloads\Hacksaw Ridge (2016) [1080p] [YTS.AG]
2017-02-10 20:30 - 2017-02-10 20:30 - 00022412 _____ C:\Users\Safire\Downloads\Hacksaw Ridge (2016) [1080p] [YTS.AG].torrent
2017-02-09 17:29 - 2017-02-09 17:29 - 00663521 _____ C:\Users\Safire\Downloads\LED Control Module 2.pdf
2017-02-09 17:29 - 2017-02-09 17:29 - 00542351 _____ C:\Users\Safire\Downloads\LED Control Module.pdf
2017-02-07 10:12 - 2017-02-07 10:12 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-02-06 22:06 - 2017-02-06 22:29 - 00000000 ____D C:\Users\Safire\Downloads\Police Squad! - 1982 TV Comedy (Basis for Naked Gun Movies)
2017-02-06 22:06 - 2017-02-06 22:06 - 00000000 ____D C:\Users\Safire\Downloads\Police Squad! - Original 1982 Naked Gun TV Series [Complete]
2017-02-06 18:26 - 2017-02-06 18:27 - 08197518 _____ C:\Users\Safire\Downloads\GBR_20161020.zip
2017-02-06 13:56 - 2017-02-07 15:02 - 00000000 ____D C:\Users\Safire\Downloads\Vikings Season 2 1080p
2017-02-04 20:35 - 2017-02-04 20:35 - 00000000 ____D C:\Users\Safire\Downloads\Jack Reacher Never Go Back (2016) [1080p] [YTS.AG]
2017-02-04 20:34 - 2017-02-04 20:34 - 00037578 _____ C:\Users\Safire\Downloads\Jack Reacher- Never Go Back (2016) [1080p] [YTS.AG].torrent
2017-02-04 18:18 - 2017-02-04 18:18 - 07934872 _____ C:\Users\Safire\Downloads\ŠO (1).rar
2017-02-04 18:13 - 2017-02-04 18:14 - 07934872 _____ C:\Users\Safire\Downloads\ŠO.rar
2017-02-04 14:41 - 2017-02-04 15:05 - 1399619684 _____ C:\Users\Safire\Downloads\SK_MIB1_411_MHIG_EU_SK_K1552_pwd (1).rar
2017-02-04 12:03 - 2017-02-04 12:03 - 05545384 _____ C:\Users\Safire\Downloads\Maintenance.pdf
2017-02-03 19:37 - 2017-02-21 10:13 - 00000000 ____D C:\Users\Safire\AppData\LocalLow\uTorrent
2017-02-03 18:59 - 2017-02-03 19:00 - 00000000 ____D C:\Users\Safire\Downloads\Inferno (2016) [1080p] [YTS.AG]
2017-02-03 18:58 - 2017-02-03 18:58 - 00000000 ____D C:\Users\Safire\Downloads\Inferno 2016 1080p WEB-DL x264 AC3-JYK
2017-02-03 15:13 - 2017-02-03 15:14 - 00000000 ____D C:\Users\Safire\Desktop\New folder (3)
2017-02-02 20:17 - 2017-02-02 20:17 - 00000000 ____D C:\ProgramData\IsolatedStorage
2017-01-30 18:27 - 2017-01-30 18:33 - 00000000 ____D C:\Users\Safire\Desktop\New folder (2)
2017-01-30 18:25 - 2017-01-30 18:30 - 00000000 ____D C:\Users\Safire\Desktop\New folder
2017-01-28 16:35 - 2017-01-28 16:41 - 00000000 ____D C:\Users\Safire\Downloads\Gone Girl (2014)
2017-01-27 17:12 - 2017-01-27 17:15 - 43232825 _____ C:\Users\Safire\Downloads\Malindzak.rar
2017-01-26 15:20 - 2017-01-26 15:20 - 00000000 _____ C:\Windows\ativpsrm.bin
2017-01-26 14:39 - 2017-01-26 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2017-01-26 14:37 - 2017-01-26 15:20 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-01-26 14:25 - 2017-01-26 14:25 - 00004292 _____ C:\Windows\System32\Tasks\AMD Updater
2017-01-25 20:35 - 2017-01-25 20:35 - 00255488 _____ C:\Users\Safire\Downloads\sablona.dot
2017-01-25 19:30 - 2017-01-25 19:30 - 00990425 _____ C:\Users\Safire\Downloads\Bitcoin-Kryptografická-mena-Bitcoin---Bakalárska-práca.pdf
2017-01-25 15:22 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-01-25 15:22 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-01-23 18:05 - 2017-01-23 18:05 - 04145320 _____ C:\Users\Safire\Downloads\Jozef-Iskra--Bakalárska-práca.pdf
2017-01-22 13:03 - 2017-01-22 13:03 - 00000000 ____D C:\ProgramData\Steam
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-21 22:18 - 2016-10-15 16:16 - 00001589 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-21 21:30 - 2016-10-26 22:28 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-02-21 21:30 - 2016-10-16 15:09 - 00000000 __SHD C:\Users\Safire\IntelGraphicsProfiles
2017-02-21 17:42 - 2016-10-15 17:36 - 00000000 ____D C:\Users\Safire\AppData\Roaming\uTorrent
2017-02-21 17:04 - 2016-10-16 18:51 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-21 09:47 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-02-20 20:22 - 2016-10-15 15:27 - 01162554 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-20 20:18 - 2016-10-16 15:12 - 00000000 ____D C:\ProgramData\Validity
2017-02-20 20:18 - 2016-10-16 15:06 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2017-02-20 20:18 - 2016-10-15 15:07 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-20 20:18 - 2016-07-16 07:04 - 00262144 _____ C:\Windows\system32\config\BBI
2017-02-20 19:48 - 2016-10-15 15:07 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-02-20 17:47 - 2016-10-15 15:32 - 00000000 ____D C:\Users\Safire
2017-02-20 17:25 - 2016-10-15 15:06 - 00224936 _____ C:\Windows\system32\FNTCACHE.DAT
2017-02-20 17:21 - 2016-10-22 10:37 - 00002184 __RSH C:\ProgramData\ntuser.pol
2017-02-20 17:21 - 2016-07-16 12:47 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-02-20 17:20 - 2016-10-16 13:15 - 00000000 ____D C:\Users\Safire\AppData\Roaming\DAEMON Tools Lite
2017-02-19 19:03 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\AppReadiness
2017-02-18 11:29 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-17 13:50 - 2016-10-15 15:32 - 00000000 ____D C:\Users\Safire\AppData\Local\Packages
2017-02-16 22:20 - 2016-10-15 16:28 - 00000000 ____D C:\Users\Safire\AppData\Local\Battle.net
2017-02-07 11:14 - 2016-12-02 13:07 - 00000000 ____D C:\Users\Safire\Downloads\Subs
2017-02-07 10:12 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-02-07 10:12 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-07 10:11 - 2016-10-16 15:10 - 00000000 ____D C:\Program Files\Microsoft Office
2017-02-05 12:32 - 2016-12-28 12:18 - 00000000 ____D C:\Program Files\AMD
2017-02-02 20:20 - 2016-10-23 19:33 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2017-02-02 20:20 - 2016-07-16 12:45 - 00000000 ____D C:\Windows\INF
2017-01-31 21:28 - 2016-12-30 13:29 - 00000000 ____D C:\Program Files\Acrylic Wi-Fi Home
2017-01-31 21:28 - 2016-11-28 19:01 - 00000000 ____D C:\Users\Safire\AppData\Roaming\Acrylic Wi-Fi Home
2017-01-31 21:27 - 2016-10-26 23:47 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-31 21:27 - 2016-10-15 15:35 - 00000000 ___RD C:\Users\Safire\OneDrive
2017-01-27 17:14 - 2016-12-28 23:59 - 00000000 ____D C:\Users\Safire\Desktop\BAKALARKA
2017-01-27 11:26 - 2017-01-12 15:44 - 00000000 ____D C:\Users\Safire\Desktop\Skúška_DLP
2017-01-26 21:52 - 2016-10-25 18:56 - 00000000 ____D C:\Users\Safire\Desktop\Vyska
2017-01-26 14:39 - 2016-12-25 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
2017-01-26 14:38 - 2016-10-26 23:33 - 00000000 ____D C:\Program Files (x86)\AMD
2017-01-26 14:24 - 2016-12-28 12:20 - 00000000 ____D C:\Users\Safire\AppData\Local\AMD
2017-01-26 14:06 - 2016-11-06 16:05 - 00000000 ____D C:\AMD
2017-01-25 16:04 - 2016-07-16 12:36 - 00000000 ____D C:\Windows\CbsTemp
2017-01-25 00:13 - 2016-11-07 22:08 - 00000000 ____D C:\Program Files (x86)\SpeedFan
==================== Files in the root of some directories =======
2017-02-20 17:42 - 2017-02-20 18:00 - 0029696 _____ () C:\Users\Safire\AppData\Local\MSGBOX.EXE
2016-10-16 23:15 - 2016-11-29 18:08 - 0007597 _____ () C:\Users\Safire\AppData\Local\Resmon.ResmonCfg
2016-11-27 16:56 - 2016-12-17 15:37 - 0001498 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2017-02-20 17:22 - 2017-02-20 17:22 - 0501318 _____ (Leading2Apps ) C:\Users\Safire\AppData\Local\Temp\97IHV8D.exe
2017-02-20 17:21 - 2017-02-20 17:21 - 2315388 _____ ( ) C:\Users\Safire\AppData\Local\Temp\AutoTime51495.exe
2017-02-05 12:31 - 2017-02-05 12:31 - 0103384 _____ (AMD Inc.) C:\Users\Safire\AppData\Local\Temp\CIMManifest.exe
2017-02-20 17:21 - 2017-02-20 17:21 - 0528175 _____ ( ) C:\Users\Safire\AppData\Local\Temp\global_installer.exe
2017-02-20 17:30 - 2017-02-20 17:30 - 0257024 _____ (U) C:\Users\Safire\AppData\Local\Temp\GOKALMFCICCW.exe
2017-02-20 17:21 - 2017-02-20 17:21 - 0129024 _____ () C:\Users\Safire\AppData\Local\Temp\load.exe
2017-02-20 17:21 - 2017-02-20 17:21 - 0734208 _____ (TIto's) C:\Users\Safire\AppData\Local\Temp\Setup.exe
2017-02-20 17:21 - 2017-02-20 17:21 - 2984392 _____ () C:\Users\Safire\AppData\Local\Temp\sys32.exe
2017-02-20 17:21 - 2017-02-20 17:21 - 1755887 _____ () C:\Users\Safire\AppData\Local\Temp\yt.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-02-19 19:14
==================== End of FRST.txt ============================