Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by barbara (administrator) on LENOVOBA (12-04-2018 23:17:21)
Running from C:\Users\barbara\Downloads
Loaded Profiles: barbara (Available Profiles: barbara & Administrator)
Platform: Windows 8.1 (Update) (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Avira Operations GmbH & Co. KG;) C:\Program Files (x86)\Avira\SoftwareUpdater\AviraSoftwareUpdaterToastNotificationsBridge.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2018-03-12] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2155449529-2713239103-2906735623-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [17074688 2018-03-06] (Piriform Ltd)
HKU\S-1-5-21-2155449529-2713239103-2906735623-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2155449529-2713239103-2906735623-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
BootExecute: autocheck autochk * SmartDefragBootTime.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 78.157.167.7 78.157.167.57 192.168.100.1
Tcpip\..\Interfaces\{4236D1C1-F566-4FBB-9344-085B2C594350}: [DhcpNameServer] 78.157.167.7 78.157.167.57 192.168.100.1
Tcpip\..\Interfaces\{4D046EE1-B35A-464F-B6B5-F4F84C6FD19B}: [DhcpNameServer] 192.168.100.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.msn.com/HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKU\S-1-5-21-2155449529-2713239103-2906735623-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhomeSearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_162\bin\ssv.dll [2018-03-19] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_162\bin\jp2ssv.dll [2018-03-19] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: m9j5zw78.default
FF ProfilePath: C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default [2018-04-12]
FF Homepage: Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default -> about:home
FF NewTab: Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default -> about:newtab
FF Extension: (Czech (CZ) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-cs@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-de@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (English (US) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-en-US@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Español (España) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-es-ES@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Finnish Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-fi@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Français Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-fr@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Galego (España) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-gl@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Hebrew (IL) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-he@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Magyar (HU) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-hu@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Italiano (IT) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-it@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Japanese Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-ja@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Korean (KR) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-ko@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Nederlands (NL) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-nl@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Polski Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-pl@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Russian (RU) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-ru@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Slovenski jezik Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-sl@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (српски (sr) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-sr@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Svenska (SE) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-sv-SE@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-zh-CN@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Users\barbara\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\m9j5zw78.default\Extensions\langpack-zh-TW@bluegriffon.org.xpi [2017-07-11] [Legacy] [not signed]
FF Plugin: @java.com/DTPlugin,version=11.162.2 -> C:\Program Files\Java\jre1.8.0_162\bin\dtplugin\npDeployJava1.dll [2018-03-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.162.2 -> C:\Program Files\Java\jre1.8.0_162\bin\plugin2\npjp2.dll [2018-03-19] (Oracle Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default [2018-04-12]
CHR Extension: (Prezentace) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-04-12]
CHR Extension: (Dokumenty) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-04-12]
CHR Extension: (Disk Google) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-04-12]
CHR Extension: (YouTube) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-04-12]
CHR Extension: (Tabulky) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-04-12]
CHR Extension: (Dokumenty Google offline) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-04-12]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-12]
CHR Extension: (Gmail) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-04-12]
CHR Extension: (Chrome Media Router) - C:\Users\barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-12]
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] -
hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] -
hxxps://clients2.google.com/service/update2/crx==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-09] (SUPERAntiSpyware.com)
S3 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-01-19] (Adobe Systems, Incorporated)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1136744 2018-03-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [492560 2018-03-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [492560 2018-03-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1533608 2018-03-07] (Avira Operations GmbH & Co. KG)
S3 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [443024 2018-03-12] (Avira Operations GmbH & Co. KG)
R2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2938504 2018-02-15] (Avira Operations GmbH & Co. KG)
R2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [103328 2018-04-11] (Avira Operations GmbH & Co. KG)
S3 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2013-10-15] (ELAN Microelectronics Corp.)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [183448 2017-08-24] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [296432 2014-04-16] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 KrosPlusFireBird; C:\Program Files (x86)\Cenkros\Firebird\FBbin\fbserver.exe [3784704 2013-03-19] (Firebird Project) [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
S3 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
S3 LenovoSetSvr; C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe [389680 2014-09-16] (Lenovo(beijing) Limited)
S3 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-09-16] (Lenovo(beijing) Limited)
S3 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-02-13] ()
S3 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [50600 2016-03-03] (Microsoft)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2158912 2018-03-28] (Electronic Arts)
S3 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3028808 2018-03-28] (Electronic Arts)
S3 PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2709176 2017-07-05] (pdfforge GmbH)
S3 PDF Architect 5 CrashHandler; C:\Program Files\PDF Architect 5\crash-handler-ws.exe [1051312 2017-07-05] (pdfforge GmbH)
S3 PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator-ws.exe [859312 2017-07-05] (pdfforge GmbH)
S3 PDF Architect 6 Manager; C:\Program Files (x86)\PDF Architect 6 Manager\PDF Architect 6\Architect Manager.exe [994080 2018-02-20] (© pdfforge GmbH.)
S3 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-09-16] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-09-16] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S3 TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [104696 2014-09-16] (Lenovo)
R3 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2014-09-16] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-03-25] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-03-25] (Microsoft Corporation)
S3 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
S3 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3743648 2017-02-13] (Intel® Corporation)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [60920 2017-10-05] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [178840 2017-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [169864 2018-02-08] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-10-05] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-10-05] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [38048 2017-10-05] (Avira Operations GmbH & Co. KG)
S3 ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [32840 2017-07-14] (ELAN Microelectronic Corp.)
S1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [18576 2018-03-19] (Glarysoft Ltd)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-01-17] (REALiX(tm))
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [231400 2017-08-24] (Intel Corporation)
R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [3521032 2018-01-12] (Intel Corporation)
S3 NETwNe64; C:\WINDOWS\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
S3 NETwNs64; C:\WINDOWS\system32\DRIVERS\Netwsw02.sys [3427848 2017-10-22] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-08-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-08-18] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation)
R3 ROCKEYNT; C:\WINDOWS\system32\DRIVERS\Rockey4.sys [36904 2017-08-29] (Feitian Technologies Co., Ltd.)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [782816 2017-11-12] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3127552 2017-01-17] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit)
S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [33960 2017-01-17] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-03-25] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-03-25] (Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-03-25] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-11-13] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-11-13] (Zemana Ltd.)
S4 IUFileFilter; \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win7_amd64\IUFileFilter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-12 23:17 - 2018-04-12 23:17 - 000022644 _____ C:\Users\barbara\Downloads\FRST.txt
2018-04-12 23:17 - 2018-04-12 23:17 - 000000000 ____D C:\FRST
2018-04-12 23:14 - 2018-04-12 23:14 - 002403328 _____ (Farbar) C:\Users\barbara\Downloads\FRST64.exe
2018-04-12 22:36 - 2018-04-12 22:36 - 000028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2018-04-12 22:22 - 2018-04-12 23:17 - 000067870 _____ C:\WINDOWS\ZAM.krnl.trace
2018-04-12 22:22 - 2018-04-12 23:17 - 000038009 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-04-12 22:14 - 2018-04-12 22:14 - 000388608 _____ (Trend Micro Inc.) C:\Users\barbara\Downloads\HijackThis (1).exe
2018-04-12 19:45 - 2018-04-12 19:43 - 000024064 _____ C:\WINDOWS\zoek-delete.exe
2018-04-12 19:43 - 2018-04-12 19:43 - 000000000 ____D C:\zoek_backup
2018-04-12 19:41 - 2018-04-12 19:42 - 001168896 _____ C:\Users\barbara\Downloads\zoek.exe
2018-04-12 18:00 - 2018-04-12 18:00 - 008222496 _____ (Malwarebytes) C:\Users\barbara\Downloads\adwcleaner_7.0.8.0.exe
2018-04-12 16:46 - 2018-04-12 16:46 - 000000887 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-04-12 16:46 - 2018-04-12 16:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-04-12 16:46 - 2018-04-12 16:46 - 000000000 ____D C:\Program Files\RogueKiller
2018-04-12 16:44 - 2018-04-12 16:44 - 036606712 _____ (Adlice Software ) C:\Users\barbara\Downloads\setup.exe
2018-04-12 12:34 - 2018-04-12 12:38 - 195958672 _____ (Sophos Limited) C:\Users\barbara\Downloads\Sophos Virus Removal Tool.exe
2018-04-12 12:32 - 2018-04-12 12:32 - 000001254 _____ C:\Users\barbara\Desktop\JRT.txt
2018-04-12 12:28 - 2018-04-12 12:28 - 001790024 _____ (Malwarebytes) C:\Users\barbara\Downloads\JRT.exe
2018-04-11 10:04 - 2018-04-11 10:04 - 000001902 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-04-11 10:04 - 2018-04-11 10:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-04-11 10:04 - 2018-03-19 12:57 - 000076192 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2018-04-11 10:01 - 2018-04-11 10:01 - 072943704 _____ (Malwarebytes ) C:\Users\barbara\Downloads\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.4678.exe
2018-04-11 09:53 - 2018-04-12 18:10 - 000000000 ____D C:\AdwCleaner
2018-04-11 09:52 - 2018-04-11 09:52 - 008222496 _____ (Malwarebytes) C:\Users\barbara\Downloads\AdwCleaner.exe
2018-04-11 09:40 - 2018-04-11 09:40 - 000448512 _____ (OldTimer Tools) C:\Users\barbara\Downloads\TFC.exe
2018-04-09 13:14 - 2018-04-09 13:14 - 000388608 _____ (Trend Micro Inc.) C:\Users\barbara\Downloads\HijackThis.exe
2018-04-09 13:01 - 2018-04-09 13:41 - 000000000 ____D C:\Users\barbara\AppData\Local\FSDART
2018-04-09 13:01 - 2018-04-09 13:02 - 000000000 ____D C:\ProgramData\F-Secure
2018-04-09 13:01 - 2018-04-09 13:01 - 000000000 ____D C:\Users\barbara\AppData\Local\F-Secure
2018-04-09 12:24 - 2018-04-09 12:24 - 000000808 _____ C:\DelFix.txt
2018-04-09 10:32 - 2018-04-09 10:32 - 000000000 ____D C:\Users\barbara\AppData\Local\ElevatedDiagnostics
2018-04-08 22:08 - 2018-04-08 22:08 - 000001073 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2018-04-08 01:34 - 2018-03-16 20:51 - 000144000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-04-08 01:34 - 2018-03-14 15:23 - 001993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-04-08 01:34 - 2018-03-14 15:23 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000739840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\centel.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-04-08 01:34 - 2018-03-14 15:23 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-04-08 01:34 - 2018-02-10 03:29 - 000531632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-04-08 01:34 - 2018-02-10 03:25 - 001137872 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-04-08 01:34 - 2018-02-09 19:44 - 000276304 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2018-04-08 01:34 - 2018-02-09 19:21 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-04-08 01:34 - 2018-02-08 20:53 - 000309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2018-04-08 01:34 - 2018-02-08 20:22 - 000477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2018-04-08 01:34 - 2018-02-08 20:18 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2018-04-08 01:34 - 2018-02-08 20:03 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-04-08 01:34 - 2018-02-08 19:49 - 000289280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2018-04-08 01:34 - 2018-02-08 19:42 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2018-04-08 01:34 - 2018-02-08 19:42 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2018-04-08 01:34 - 2018-02-08 19:40 - 001096192 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2018-04-08 01:34 - 2018-02-08 19:38 - 000866304 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2018-04-08 01:34 - 2018-02-08 19:27 - 000367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2018-04-08 01:34 - 2018-02-08 19:24 - 000199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2018-04-08 01:34 - 2018-02-08 19:03 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2018-04-08 01:34 - 2018-02-08 19:03 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2018-04-08 01:34 - 2018-01-25 16:19 - 000995272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-04-08 01:34 - 2018-01-25 16:14 - 000922944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-04-08 01:10 - 2018-04-08 01:13 - 000020326 _____ C:\WINDOWS\SysWOW64\Defrag.debuglog
2018-04-07 18:21 - 2018-04-11 10:25 - 000001701 _____ C:\Users\barbara\Desktop\malwarebytes.txt
2018-04-07 18:12 - 2018-04-11 10:04 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-04-02 01:38 - 2018-04-02 01:38 - 000000000 ____D C:\Users\barbara\AppData\Local\MajorSilence
2018-04-02 01:15 - 2018-04-02 01:15 - 000000000 ____D C:\Users\barbara\AppData\Local\fontconfig
2018-04-02 01:14 - 2018-04-02 01:14 - 000000024 _____ C:\Users\barbara\AppData\Roaming\splitterdirectorys.txt
2018-04-02 01:13 - 2018-04-02 01:13 - 000001295 _____ C:\Users\Public\Desktop\Free Video Splitter.lnk
2018-04-02 01:13 - 2018-04-02 01:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Splitter
2018-04-02 01:00 - 2005-06-15 03:00 - 000102400 _____ (TechSmith Corporation) C:\WINDOWS\SysWOW64\tsccvid.dll
2018-04-02 00:52 - 2018-04-02 00:52 - 000001347 _____ C:\Users\barbara\Desktop\AVIToolbox.lnk
2018-04-02 00:52 - 2018-04-02 00:52 - 000000000 ____D C:\Users\barbara\AppData\Roaming\KC Softwares
2018-04-02 00:52 - 2018-04-02 00:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KC Softwares
2018-04-02 00:52 - 2018-04-02 00:52 - 000000000 ____D C:\Program Files (x86)\KC Softwares
2018-03-22 12:41 - 2018-03-22 12:41 - 000001147 _____ C:\Users\Public\Desktop\Avira.lnk
2018-03-19 04:20 - 2018-03-02 20:55 - 000834552 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-03-19 04:20 - 2018-03-02 20:55 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-03-19 04:13 - 2018-03-03 09:24 - 007407960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-03-19 04:13 - 2018-03-03 09:24 - 000419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-03-19 04:13 - 2018-03-03 09:11 - 001737600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-03-19 04:13 - 2018-03-03 09:11 - 001676064 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-03-19 04:13 - 2018-03-03 09:11 - 001536120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-03-19 04:13 - 2018-03-03 09:11 - 001500432 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-03-19 04:13 - 2018-03-03 09:11 - 001371352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-03-19 04:13 - 2018-03-03 07:23 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2018-03-19 04:13 - 2018-03-03 07:22 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2018-03-19 04:13 - 2018-02-18 22:53 - 004168704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2018-03-19 04:13 - 2018-02-16 17:51 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-03-19 04:13 - 2018-02-16 17:51 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-03-19 04:13 - 2018-02-16 17:45 - 025742848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-03-19 04:13 - 2018-02-16 17:44 - 013678080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-03-19 04:13 - 2018-02-16 17:28 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-03-19 04:13 - 2018-02-16 17:24 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-03-19 04:13 - 2018-02-16 17:24 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2018-03-19 04:13 - 2018-02-16 17:19 - 020286976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-03-19 04:13 - 2018-02-16 16:37 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2018-03-19 04:13 - 2018-02-16 16:37 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2018-03-19 04:13 - 2018-02-15 17:15 - 003241472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-03-19 04:13 - 2018-02-15 16:57 - 002767872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-03-19 04:13 - 2018-02-10 22:24 - 000178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-03-19 04:13 - 2018-02-10 21:29 - 000274272 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-03-19 04:13 - 2018-02-10 21:29 - 000124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NV_AGP.SYS
2018-03-19 04:13 - 2018-02-10 21:29 - 000065888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ULIAGPKX.SYS
2018-03-19 04:13 - 2018-02-10 21:29 - 000062304 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AGP440.sys
2018-03-19 04:13 - 2018-02-10 21:29 - 000021856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\isapnp.sys
2018-03-19 04:13 - 2018-02-10 21:29 - 000017240 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msisadrv.sys
2018-03-19 04:13 - 2018-02-10 21:25 - 000533856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-03-19 04:13 - 2018-02-10 21:08 - 001307328 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-03-19 04:13 - 2018-02-10 21:06 - 000356184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-03-19 04:13 - 2018-02-10 19:50 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-03-19 04:13 - 2018-02-10 19:40 - 002901504 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-03-19 04:13 - 2018-02-10 19:40 - 000577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-03-19 04:13 - 2018-02-10 19:37 - 005779968 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-03-19 04:13 - 2018-02-10 19:27 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-03-19 04:13 - 2018-02-10 19:26 - 000440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-03-19 04:13 - 2018-02-10 19:20 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2018-03-19 04:13 - 2018-02-10 19:10 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-03-19 04:13 - 2018-02-10 19:09 - 003757056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2018-03-19 04:13 - 2018-02-10 19:06 - 002295296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-03-19 04:13 - 2018-02-10 19:03 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-03-19 04:13 - 2018-02-10 19:01 - 000617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2018-03-19 04:13 - 2018-02-10 19:00 - 000661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-03-19 04:13 - 2018-02-10 18:59 - 000404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-03-19 04:13 - 2018-02-10 18:58 - 001033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-03-19 04:13 - 2018-02-10 18:57 - 015281664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-03-19 04:13 - 2018-02-10 18:54 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2018-03-19 04:13 - 2018-02-10 18:52 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-03-19 04:13 - 2018-02-10 18:50 - 000807936 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-03-19 04:13 - 2018-02-10 18:50 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-03-19 04:13 - 2018-02-10 18:48 - 001436672 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-03-19 04:13 - 2018-02-10 18:47 - 002134016 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-03-19 04:13 - 2018-02-10 18:46 - 002412544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2018-03-19 04:13 - 2018-02-10 18:44 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-03-19 04:13 - 2018-02-10 18:43 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-03-19 04:13 - 2018-02-10 18:40 - 004496384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-03-19 04:13 - 2018-02-10 18:39 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-03-19 04:13 - 2018-02-10 18:35 - 000230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-03-19 04:13 - 2018-02-10 18:34 - 000694784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-03-19 04:13 - 2018-02-10 18:34 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-03-19 04:13 - 2018-02-10 18:33 - 002058240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-03-19 04:13 - 2018-02-10 18:33 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-03-19 04:13 - 2018-02-10 18:30 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-03-19 04:13 - 2018-02-10 18:29 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-03-19 04:13 - 2018-02-10 18:23 - 001545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-03-19 04:13 - 2018-02-10 18:12 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-03-19 04:13 - 2018-02-10 18:11 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-03-19 04:13 - 2018-02-10 18:09 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-03-19 04:13 - 2018-02-08 19:37 - 002779648 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2018-03-19 04:13 - 2018-02-08 18:57 - 002464256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2018-03-19 04:13 - 2018-02-02 22:42 - 003320832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-03-19 04:13 - 2018-02-02 21:24 - 003610112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2018-03-19 03:02 - 2018-03-19 03:02 - 000001235 _____ C:\Users\barbara\Desktop\CrystalDiskInfo.lnk
2018-03-19 03:00 - 2018-03-19 03:00 - 000000000 ____D C:\Users\barbara\AppData\Local\AviraSpeedup
2018-03-19 02:58 - 2018-03-19 02:58 - 000110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2018-03-19 02:58 - 2018-03-19 02:58 - 000000000 ____D C:\Users\barbara\AppData\Roaming\Sun
2018-03-19 02:58 - 2018-03-19 02:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-03-19 02:55 - 2018-04-10 04:11 - 000000000 ____D C:\Users\barbara\AppData\Local\PDFCreator
2018-03-19 02:55 - 2018-03-19 02:55 - 000000000 ____D C:\Program Files (x86)\PDF Architect 6 Manager
2018-03-19 02:54 - 2018-03-19 02:54 - 000000000 ____D C:\ProgramData\PDF Architect 6
2018-03-19 02:53 - 2018-03-19 02:53 - 000000861 _____ C:\Users\Public\Desktop\PDFCreator.lnk
2018-03-19 02:53 - 2018-03-19 02:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2018-03-19 02:51 - 2018-03-19 02:51 - 000002340 _____ C:\Users\barbara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk
2018-03-19 02:51 - 2018-03-19 02:51 - 000002067 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk
2018-03-19 02:50 - 2018-03-19 02:50 - 000002976 _____ C:\WINDOWS\System32\Tasks\GU5SkipUAC
2018-03-19 02:48 - 2018-03-19 02:50 - 000001121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2018-03-19 02:48 - 2018-03-19 02:50 - 000001109 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk
2018-03-19 02:33 - 2018-03-19 02:33 - 000003870 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-03-19 00:40 - 2018-03-19 00:40 - 000003176 _____ C:\WINDOWS\System32\Tasks\SmartDefrag_AutoAnalyze
2018-03-19 00:40 - 2018-03-19 00:40 - 000003022 _____ C:\WINDOWS\System32\Tasks\SmartDefrag_Update
2018-03-19 00:40 - 2017-03-09 14:53 - 000030744 _____ (IObit) C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys
2018-03-19 00:40 - 2016-03-25 15:33 - 000128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll
2018-03-13 13:44 - 2018-03-13 13:44 - 001469952 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iaStorA.sys
2018-03-13 13:44 - 2018-03-13 13:44 - 000999760 _____ (Realtek ) C:\WINDOWS\system32\Drivers\Rt630x64.sys
2018-03-13 13:44 - 2018-03-13 13:44 - 000122824 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-12 23:10 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\Inf
2018-04-12 22:34 - 2016-12-23 09:14 - 000003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2155449529-2713239103-2906735623-1001
2018-04-12 22:30 - 2014-09-16 04:25 - 000734494 _____ C:\WINDOWS\system32\perfh005.dat
2018-04-12 22:30 - 2014-09-16 04:25 - 000148824 _____ C:\WINDOWS\system32\perfc005.dat
2018-04-12 22:30 - 2014-03-18 11:53 - 001739092 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-04-12 22:26 - 2014-09-16 04:17 - 000000000 ____D C:\ProgramData\NVIDIA
2018-04-12 22:24 - 2017-01-12 17:38 - 000000000 ___RD C:\Users\barbara\OneDrive
2018-04-12 22:23 - 2013-08-22 16:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-04-12 22:21 - 2014-09-16 05:10 - 000006656 _____ C:\WINDOWS\system32\VfService.trf
2018-04-12 20:18 - 2017-11-14 13:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2018-04-12 19:56 - 2016-12-22 14:36 - 000000000 ____D C:\Users\barbara
2018-04-12 18:03 - 2017-01-12 19:53 - 000000000 ____D C:\Users\barbara\AppData\Roaming\IObit
2018-04-12 18:03 - 2014-12-31 20:35 - 000000000 ____D C:\Users\barbara\AppData\LocalLow\IObit
2018-04-12 16:47 - 2017-01-05 21:06 - 000000000 ____D C:\Users\barbara\AppData\Roaming\eM Client
2018-04-12 12:24 - 2017-12-24 21:47 - 000000000 ____D C:\ProgramData\Origin
2018-04-12 10:47 - 2017-12-24 21:54 - 000000000 ____D C:\Users\barbara\AppData\Roaming\Origin
2018-04-10 03:42 - 2017-01-25 00:39 - 000000000 ____D C:\Users\barbara\AppData\Local\CrashDumps
2018-04-09 13:38 - 2017-11-13 17:04 - 000000000 ____D C:\Users\barbara\Downloads\backups
2018-04-09 09:58 - 2013-08-22 15:25 - 000262144 ___SH C:\WINDOWS\system32\config\BBI
2018-04-08 22:21 - 2017-01-12 14:56 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2018-04-08 22:21 - 2017-01-08 17:26 - 000000000 ____D C:\Program Files (x86)\Star Stable Online
2018-04-08 22:21 - 2017-01-06 00:09 - 000000000 ____D C:\ProgramData\Skype
2018-04-08 22:08 - 2017-11-13 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-04-08 19:05 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-04-08 14:58 - 2017-08-30 09:45 - 000000000 ____D C:\Users\barbara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2018-04-08 01:39 - 2017-01-13 05:02 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-04-08 01:39 - 2013-08-22 17:36 - 000000000 ___RD C:\WINDOWS\ToastData
2018-04-08 01:37 - 2017-12-01 20:38 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-04-08 01:24 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2018-04-07 23:03 - 2013-08-22 17:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2018-04-07 18:12 - 2017-11-12 00:18 - 000000000 ____D C:\Program Files\Malwarebytes
2018-04-07 16:20 - 2017-01-12 15:32 - 000000000 ____D C:\Program Files (x86)\Glary Utilities 5
2018-04-07 16:17 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-04-04 19:43 - 2017-12-24 21:54 - 000000000 ____D C:\Program Files (x86)\Origin
2018-03-26 03:01 - 2017-12-25 21:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2018-03-22 12:41 - 2014-09-16 04:28 - 000000000 ____D C:\ProgramData\Package Cache
2018-03-22 11:38 - 2014-09-16 05:23 - 000000000 ____D C:\ProgramData\Energy Manager
2018-03-21 02:58 - 2017-01-12 16:50 - 000002255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-21 02:58 - 2017-01-12 16:50 - 000002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-03-19 04:19 - 2013-08-22 16:44 - 000454656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-03-19 04:04 - 2018-03-10 12:15 - 000000000 ____D C:\Users\Public\Speedup Sessions
2018-03-19 04:02 - 2017-01-12 13:11 - 000000000 ____D C:\Program Files\PDFCreator
2018-03-19 03:58 - 2017-01-12 21:51 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-03-19 03:58 - 2017-01-06 00:09 - 000000000 ____D C:\Users\barbara\AppData\Roaming\Skype
2018-03-19 03:55 - 2017-10-22 09:12 - 130364688 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-19 03:55 - 2017-01-12 21:51 - 130364688 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-03-19 03:02 - 2017-11-12 00:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2018-03-19 03:02 - 2017-11-12 00:52 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2018-03-19 03:01 - 2017-12-25 21:13 - 000001157 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2018-03-19 03:01 - 2017-12-25 21:13 - 000001145 _____ C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2018-03-19 02:58 - 2017-07-16 00:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2018-03-19 02:58 - 2017-07-16 00:51 - 000000000 ____D C:\Program Files\Java
2018-03-19 02:51 - 2017-12-25 21:13 - 000001181 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk
2018-03-19 02:51 - 2017-12-25 21:13 - 000001169 _____ C:\Users\Public\Desktop\VideoPad Video Editor.lnk
2018-03-19 02:51 - 2017-12-25 21:13 - 000001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
2018-03-19 02:51 - 2017-12-25 21:13 - 000001153 _____ C:\Users\Public\Desktop\WavePad Sound Editor.lnk
2018-03-19 02:50 - 2017-01-12 15:32 - 000018576 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\GUBootStartup.sys
2018-03-19 02:48 - 2017-01-12 15:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2018-03-19 02:39 - 2017-12-25 21:12 - 000000000 ____D C:\ProgramData\NCH Software
2018-03-19 02:39 - 2017-12-25 21:12 - 000000000 ____D C:\Program Files (x86)\NCH Software
2018-03-19 02:33 - 2017-01-05 19:09 - 000000845 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-03-19 00:39 - 2017-03-25 14:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2018-03-13 13:41 - 2017-09-28 02:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 5
==================== Files in the root of some directories =======
2016-12-28 14:48 - 2016-12-28 14:52 - 000000082 _____ () C:\Program Files\smaple.txt
2018-04-02 01:14 - 2018-04-02 01:14 - 000000024 _____ () C:\Users\barbara\AppData\Roaming\splitterdirectorys.txt
2017-11-12 17:08 - 2017-11-12 17:08 - 000003584 _____ () C:\Users\barbara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-12-28 14:54 - 2016-12-28 14:54 - 001065984 _____ () C:\Users\barbara\AppData\Local\file__0.localstorage
2017-11-15 13:03 - 2017-11-15 13:03 - 000000017 _____ () C:\Users\barbara\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
2018-04-12 22:36 - 2018-03-03 09:11 - 001737600 _____ (Microsoft Corporation) C:\Users\barbara\AppData\Local\Temp\dllnt_dump.dll
Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\mfevtps.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-04-06 02:34
==================== End of FRST.txt ============================