Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08.11.2018
Ran by Andrea (administrator) on ANDREA-PC (12-11-2018 09:48:05)
Running from C:\Users\Andrea\Desktop
Loaded Profiles: Andrea (Available Profiles: Andrea)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Safe Mode (minimal)
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\AtBroker.exe
(Farbar) C:\Users\Andrea\Desktop\ano.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6703648 2009-01-06] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2017-04-19] (Adobe Systems Incorporated)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1993408 2018-03-13] (COMODO)
HKLM\...\Run: [IseUI] => C:\Program Files\COMODO\Internet Security Essentials\vkise.exe [4072376 2018-01-17] (COMODO)
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll [2009-01-19] (Sony Corporation)
HKU\S-1-5-21-229735995-3260258197-3374296045-1000\...\Run: [WwwAccessConnectorUrlMonitor] => C:\Program Files\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe [274944 2016-06-29] (MEDIAN s.r.o.)
HKU\S-1-5-21-229735995-3260258197-3374296045-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2011-02-04] (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Url Monitor.lnk [2015-09-01]
ShortcutTarget: Url Monitor.lnk -> C:\Program Files\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnectorUrlMonitor.exe (MEDIAN s.r.o.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-21] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{5CDE5058-9E40-4DDC-828B-4E2609822D96}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{8C900FA7-380C-46AA-AF30-5FEC3355B95F}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-229735995-3260258197-3374296045-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-229735995-3260258197-3374296045-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.seznam.cz/
HKU\S-1-5-21-229735995-3260258197-3374296045-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://
www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-229735995-3260258197-3374296045-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-229735995-3260258197-3374296045-1000 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll [2009-03-09] (Sun Microsystems, Inc.)
BHO: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09] (Sun Microsystems, Inc.)
Toolbar: HKU\S-1-5-21-229735995-3260258197-3374296045-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll [2008-12-03] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2008-10-28] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll [2008-12-03] (Microsoft Corporation)
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-02-08] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2008-10-05] ()
FF Plugin: @mcafee.com/McAfeeMssPlugin -> C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
StartMenuInternet: firefox.exe - firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://
www.google.com
CHR StartupUrls: Default -> "hxxps://
www.seznam.cz/"
CHR Profile: C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default [2018-11-09]
CHR Extension: (Prezentace) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-04-02]
CHR Extension: (Dokumenty) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-04-02]
CHR Extension: (Disk Google) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-04-03]
CHR Extension: (YouTube) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Vyhledávání Google) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-04-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-08-01] (ArcSoft Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335872 2018-10-09] (Adobe Systems Incorporated) [File not signed]
S2 AudioHubWwwAccessConnector; C:\Program Files\Median\WwwAccessConnector\AudioHUB.Processing.WwwAccessConnector.exe [187392 2016-06-29] (MEDIAN s.r.o.) [File not signed]
S2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [8867672 2018-03-13] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2080448 2018-03-13] (COMODO)
S2 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [114688 2013-02-13] (Brio) [File not signed]
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2011-02-04] (Google)
S2 isesrv; C:\Program Files\COMODO\Internet Security Essentials\isesrv.exe [1199544 2018-01-17] (COMODO)
S2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [303104 2007-10-15] (Motive Communications, Inc.) [File not signed]
S3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation) [File not signed]
S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-01-20] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-01-20] (Sony Corporation)
S2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation) [File not signed]
S2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [203624 2009-01-19] (Sony Corporation)
S2 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [394536 2009-01-20] (Sony Corporation)
S3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
S2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S2 XAudioService; [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21272 2018-01-31] (COMODO)
S1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [648560 2018-01-31] (COMODO)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
S1 isedrv; C:\Windows\system32\drivers\isedrv.sys [40672 2018-01-17] (COMODO)
S3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtport.sys [12160 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbus.sys [10496 2009-09-29] (LG Electronics Inc.)
S3 lgmdbus; C:\Windows\System32\DRIVERS\lgmdbus.sys [89600 2008-07-08] (MCCI Corporation)
S3 lgmdmdfl; C:\Windows\System32\DRIVERS\lgmdmdfl.sys [14976 2008-07-08] (MCCI Corporation)
S3 lgmdmdm; C:\Windows\System32\DRIVERS\lgmdmdm.sys [121344 2008-07-08] (MCCI Corporation)
S3 lgmdmgmt; C:\Windows\System32\DRIVERS\lgmdmgmt.sys [114944 2008-07-08] (MCCI Corporation)
S3 lgmdobex; C:\Windows\System32\DRIVERS\lgmdobex.sys [111232 2008-07-08] (MCCI Corporation)
S3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmodem.sys [12928 2009-09-29] (LG Electronics Inc.)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Andrea\AppData\Local\Temp\catchme.sys [X] <==== ATTENTION
S3 DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-11 13:58 - 2018-11-11 13:31 - 007592144 _____ (Malwarebytes) C:\Users\Andrea\Desktop\AdwCleaner.exe
2018-11-09 14:18 - 2018-11-09 14:20 - 000042396 _____ C:\Users\Andrea\Desktop\Addition.txt
2018-11-09 14:17 - 2018-11-12 09:48 - 000014024 _____ C:\Users\Andrea\Desktop\FRST.txt
2018-11-09 14:17 - 2018-11-12 09:48 - 000000000 ____D C:\FRST
2018-11-09 13:44 - 2018-11-11 14:06 - 000000000 ____D C:\Users\Andrea\Desktop\Nová složka
2018-11-09 13:30 - 2018-11-09 13:05 - 001775616 _____ (Farbar) C:\Users\Andrea\Desktop\ano.exe
2018-11-03 10:11 - 2018-11-03 10:11 - 000000022 _____ C:\Users\Andrea\Documents\Nový WinRAR ZIP archiv.zip
2018-11-03 09:35 - 2018-11-03 09:35 - 000000000 ____D C:\Users\Andrea\AppData\Roaming\Roxio
2018-11-03 09:35 - 2018-11-03 09:35 - 000000000 ____D C:\ProgramData\Roxio
2018-11-01 16:12 - 2018-11-01 16:12 - 000000000 ____D C:\Users\Andrea\Desktop\HD Tune Pro 5.70 - Portable
2018-11-01 13:41 - 2018-11-12 09:48 - 000870044 _____ C:\Windows\ntbtlog.txt
2018-10-23 11:57 - 2018-10-23 11:57 - 000000000 ____D C:\Users\Andrea\Documents\WebCam Albums
2018-10-17 09:40 - 2018-10-17 09:40 - 000077064 _____ C:\Users\Andrea\Downloads\sedUM_pozvanka_A5_screen_dejvice.jpeg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-12 09:45 - 2016-09-13 12:06 - 000007512 _____ C:\Users\Andrea\AppData\Local\d3d9caps.dat
2018-11-12 09:45 - 2006-11-02 14:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-11-12 09:45 - 2006-11-02 13:47 - 000003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2018-11-12 09:45 - 2006-11-02 13:47 - 000003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2018-11-12 09:44 - 2017-04-24 11:45 - 000152334 _____ C:\Windows\system32\Drivers\fvstore.dat
2018-11-12 09:44 - 2017-04-13 12:37 - 001412337 _____ C:\Windows\system32\Drivers\sfi.dat
2018-11-12 09:44 - 2006-11-02 14:01 - 000032560 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-11-12 09:35 - 2015-09-01 11:33 - 002396160 _____ C:\Windows\system32\tempResults.db
2018-11-11 13:59 - 2013-12-11 09:19 - 000000000 ____D C:\AdwCleaner
2018-11-06 08:55 - 2016-06-11 08:28 - 1467942912 _____ C:\Users\Andrea\Desktop\James-Bond---Casino-Royale-cz-avi.avi
2018-11-03 09:49 - 2006-11-02 13:37 - 000000000 ___RD C:\Users\Public\Recorded TV
2018-11-03 09:34 - 2009-03-09 19:09 - 000098586 _____ C:\Windows\system32\perfh005.dat
2018-11-03 09:34 - 2009-03-09 19:09 - 000030350 _____ C:\Windows\system32\perfc005.dat
2018-11-03 09:34 - 2006-11-02 12:18 - 000000000 ____D C:\Windows\inf
2018-11-03 09:34 - 2006-11-02 11:33 - 000119704 _____ C:\Windows\system32\PerfStringBackup.INI
2018-11-02 14:34 - 2011-02-04 15:41 - 000000000 ____D C:\Users\Andrea
2018-11-02 14:34 - 2006-11-02 12:18 - 000000000 ____D C:\Windows\system32\spool
2018-11-02 14:34 - 2006-11-02 12:18 - 000000000 ____D C:\Windows\system32\Msdtc
2018-11-02 14:34 - 2006-11-02 12:18 - 000000000 ____D C:\Windows\registration
2018-11-02 14:34 - 2006-11-02 11:22 - 060030976 _____ C:\Windows\system32\config\software_previous
2018-11-02 14:34 - 2006-11-02 11:22 - 036962304 _____ C:\Windows\system32\config\system_previous
2018-11-02 14:28 - 2006-11-02 11:22 - 000262144 _____ C:\Windows\system32\config\security_previous
2018-11-02 14:28 - 2006-11-02 11:22 - 000262144 _____ C:\Windows\system32\config\sam_previous
2018-11-02 13:25 - 2006-11-02 13:47 - 000021504 _____ C:\Windows\system32\umstartup.etl
2018-11-02 13:21 - 2006-11-02 11:22 - 000524288 _____ C:\Windows\system32\config\default_previous
2018-11-02 13:17 - 2006-11-02 11:22 - 084410368 _____ C:\Windows\system32\config\components_previous
2018-10-23 11:57 - 2016-09-11 15:54 - 000000000 ____D C:\Users\Andrea\AppData\Roaming\ArcSoft
==================== Files in the root of some directories =======
2011-11-21 12:45 - 2011-11-21 12:45 - 000000600 _____ () C:\Users\Andrea\AppData\Roaming\winscp.rnd
2011-02-24 11:47 - 2014-12-02 08:18 - 000001218 _____ () C:\Users\Andrea\AppData\Roaming\wklnhst.dat
2016-09-13 12:06 - 2018-11-12 09:45 - 000007512 _____ () C:\Users\Andrea\AppData\Local\d3d9caps.dat
2017-04-13 08:13 - 2017-04-13 08:13 - 000003584 _____ () C:\Users\Andrea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-02-04 17:44 - 2011-02-04 17:47 - 000000184 _____ () C:\Users\Andrea\AppData\Local\setup.log
2017-06-25 09:14 - 2017-06-25 09:16 - 000000000 _____ () C:\Users\Andrea\AppData\Local\{33EF4A28-66D6-4BF4-85F2-3C0BA52CF8FF}
2017-05-16 11:15 - 2017-05-16 11:15 - 000000000 _____ () C:\Users\Andrea\AppData\Local\{650DDA52-F610-40AB-A85D-7A1B736F0CC4}
2017-04-27 08:42 - 2017-04-27 08:43 - 000000000 _____ () C:\Users\Andrea\AppData\Local\{A2419EC2-EB83-4E1D-A205-73A1E96C0320}
Some files in TEMP:
====================
2017-05-14 08:26 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU1209.tmp.exe
2018-04-06 21:16 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU15FF.tmp.exe
2017-05-30 11:40 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU163E.tmp.exe
2017-06-02 08:38 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU17C4.tmp.exe
2017-07-06 09:17 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU1E2A.tmp.exe
2017-10-10 09:08 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU1EA6.tmp.exe
2017-11-23 11:04 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU24DE.tmp.exe
2017-12-03 19:39 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU2FD6.tmp.exe
2017-04-24 12:00 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU38EA.tmp.exe
2018-07-25 13:09 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU3E85.tmp.exe
2018-11-12 09:35 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU95D8.tmp.exe
2018-07-19 12:55 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHU97DB.tmp.exe
2018-11-11 14:01 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHUA015.tmp.exe
2018-06-26 09:06 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHUA1D.tmp.exe
2018-11-01 13:52 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHUB634.tmp.exe
2018-10-04 09:19 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHUBEEB.tmp.exe
2018-11-01 14:01 - 2007-11-29 10:13 - 000540672 _____ (Motive Communications, Inc.) C:\Users\Andrea\AppData\Local\temp\IHUC4A5.tmp.exe
2017-06-13 09:15 - 2017-07-17 08:54 - 004113960 _____ (COMODO) C:\Users\Andrea\AppData\Local\temp\ise_installer.exe
2016-03-03 10:50 - 2015-07-29 21:08 - 000681097 _____ (SQLite Development Team) C:\Users\Andrea\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-11-12 09:42
==================== End of FRST.txt ============================