Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-05-2016 01
Ran by Hanus (administrator) on HANUS-PC (05-05-2016 09:37:54)
Running from C:\Users\Hanus\Desktop
Loaded Profiles: Hanus (Available Profiles: Hanus)
Platform: Windows 8.1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13650648 2013-08-21] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7391632 2016-05-03] (AVAST Software)
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53737488 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-06-17] (Spotify Ltd)
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23484296 2016-04-25] (Google)
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [GSplay.exe] => C:\Users\Hanus\Desktop\Hry\GSplay.exe [4772747 2014-03-12] ()
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8686296 2016-03-11] (Piriform Ltd)
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4289728 2016-04-04] (Disc Soft Ltd)
HKU\S-1-5-21-3812361727-838257335-1277264128-1001\...\MountPoints2: {582e6474-feeb-11e5-8411-448a5b9b27f4} - "F:\autorun.exe"
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-05-03] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{45EBB24D-83FA-43A8-B741-2F2DCFC276C4}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4DDE0E17-7512-4773-AE02-D9007D1B58DA}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3812361727-838257335-1277264128-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-04-17] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-04-17] (AVAST Software)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-12] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-12] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-04-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-04-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-03]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-05-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Chrome:
=======
CHR Profile: C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentácie Google) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-04]
CHR Extension: (Dokumenty Google) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-04]
CHR Extension: (Disk Google) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-04]
CHR Extension: (YouTube) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-04]
CHR Extension: (Avast SafePrice) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-05-04]
CHR Extension: (Tabuľky Google) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-04]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-04]
CHR Extension: (Avast Online Security) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-05-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-04]
CHR Extension: (Gmail) - C:\Users\Hanus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-04]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-04-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-04-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-03] (AVAST Software)
S4 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1443520 2016-04-04] (Disc Soft Ltd)
S4 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [231480 2016-04-30] (GOG.com)
S4 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6133816 2016-04-13] (GOG.com)
S4 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S4 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
S4 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
S4 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
S4 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-25] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-05-03] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-05-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-05-03] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-05-03] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-05-03] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-05-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-05-03] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-05-03] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-05-03] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-04-20] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-04-20] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 NVVADARM; C:\Windows\system32\drivers\nvvadarm.sys [46016 2016-03-22] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R2 RtkIOAC60; C:\Windows\system32\DRIVERS\RtkIOAC60.sys [29912 2013-07-19] (Realtek semiconductor corp)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-05 09:37 - 2016-05-05 09:38 - 00014204 _____ C:\Users\Hanus\Desktop\FRST.txt
2016-05-05 09:37 - 2016-05-05 09:37 - 02378240 _____ (Farbar) C:\Users\Hanus\Desktop\FRST64.exe
2016-05-04 19:27 - 2016-05-04 19:05 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2016-05-04 19:04 - 2016-05-04 19:04 - 01309184 _____ C:\Users\Hanus\Desktop\zoek.exe
2016-05-04 14:05 - 2016-05-04 14:07 - 24017992 _____ C:\Users\Hanus\Desktop\RogueKillerX64.exe
2016-05-04 13:58 - 2016-05-04 13:58 - 00000896 _____ C:\Users\Hanus\Desktop\JRT.txt
2016-05-04 13:56 - 2016-05-04 13:56 - 01610816 _____ (Malwarebytes) C:\Users\Hanus\Desktop\JRT.exe
2016-05-04 11:18 - 2016-05-04 11:18 - 03615296 _____ C:\Users\Hanus\Desktop\AdwCleaner (1).exe
2016-05-04 11:08 - 2016-05-04 11:08 - 00448512 _____ (OldTimer Tools) C:\Users\Hanus\Desktop\TFC.exe
2016-05-03 18:17 - 2016-05-03 18:17 - 00398152 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-05-03 18:17 - 2016-05-03 18:17 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-05-01 15:55 - 2016-05-01 15:55 - 01999192 _____ C:\Users\Hanus\Downloads\laigle141hotfix.rar
2016-05-01 15:54 - 2016-05-01 15:54 - 09145734 _____ C:\Users\Hanus\Downloads\laiglever1p4.rar
2016-05-01 13:35 - 2016-05-01 14:20 - 610727371 _____ C:\Users\Hanus\Downloads\laiglefull1point3.rar
2016-04-30 18:58 - 2016-04-30 18:58 - 00963232 _____ (Microsoft Corporation) C:\Program Files\msvcr120.dll
2016-04-30 18:58 - 2016-04-30 18:58 - 00660128 _____ (Microsoft Corporation) C:\Program Files\msvcp120.dll
2016-04-30 17:55 - 2016-04-30 17:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com]
2016-04-27 14:02 - 2016-04-27 14:32 - 418173385 _____ C:\Users\Hanus\Downloads\MaxPayne3_cesky_0_58_1_0.exe
2016-04-27 09:07 - 2016-04-27 09:07 - 00000000 ____D C:\ProgramData\Rockstar Games
2016-04-23 16:32 - 2016-04-23 16:33 - 06378189 _____ C:\Users\Hanus\Downloads\Extreme_Fortifications_3.0_PC.zip
2016-04-21 14:32 - 2016-04-21 14:32 - 00001342 _____ C:\Users\Hanus\Desktop\Napoleonic Era 2.lnk
2016-04-21 14:32 - 2016-04-21 14:32 - 00001116 _____ C:\Users\Hanus\Desktop\NE 2.1.7b Release Notes.lnk
2016-04-21 14:32 - 2016-04-21 14:32 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\Microsoft\Windows\Start Menu\Napoleonic Era 2
2016-04-21 13:37 - 2016-04-21 14:24 - 676386816 _____ C:\Users\Hanus\Downloads\Age-of-Empires-III.-The-Warchiefs-Expansion.iso
2016-04-20 19:58 - 2016-04-20 20:36 - 541633984 _____ (Macrovision Corporation ) C:\Users\Hanus\Downloads\setup.exe
2016-04-20 19:58 - 2016-04-20 19:58 - 00000000 ____D C:\Users\Hanus\Downloads\Age.of.Empires.III.The.WarChiefs - Razor1911
2016-04-20 19:57 - 2016-04-20 19:57 - 00018240 _____ C:\Users\Hanus\Downloads\Age.of.Empires.III.The.WarChiefs - Razor1911.torrent
2016-04-20 17:19 - 2016-04-20 17:25 - 00000000 ____D C:\Age of Empires III
2016-04-20 17:13 - 2016-04-20 17:18 - 79252124 _____ (Napoleonic Era Team ) C:\Users\Hanus\Desktop\ne217b_setup.exe
2016-04-20 17:05 - 2016-04-20 17:05 - 00000000 ____D C:\ProgramData\Age of Empires 3
2016-04-20 16:59 - 2016-04-20 16:59 - 00047672 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtliteusbbus.sys
2016-04-20 16:58 - 2016-04-20 16:59 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2016-04-20 16:58 - 2016-04-20 16:58 - 00030264 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtlitescsibus.sys
2016-04-20 16:58 - 2016-04-20 16:58 - 00001789 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-04-20 16:58 - 2016-04-20 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2016-04-20 16:58 - 2016-04-20 16:58 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-04-20 16:56 - 2016-04-20 16:56 - 00690448 _____ (Disc Soft Ltd.) C:\Users\Hanus\Desktop\DTLiteInstaller.exe
2016-04-20 15:40 - 2016-04-20 16:21 - 588793325 _____ C:\Users\Hanus\Downloads\Age_Of_Empire_3_Expansion-AsianDynasties_www.download.ir.rar
2016-04-20 15:35 - 2016-04-20 15:35 - 00002137 _____ C:\Users\Public\Desktop\Age of Empires III.lnk
2016-04-20 15:35 - 2016-04-20 15:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2016-04-17 12:25 - 2016-05-04 11:02 - 00003924 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1460888704
2016-04-17 12:25 - 2016-05-04 11:02 - 00001057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-04-17 12:25 - 2016-04-17 12:25 - 00001057 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-04-17 12:24 - 2016-05-03 18:17 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-04-17 12:17 - 2016-04-17 12:17 - 00001942 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-17 12:17 - 2016-04-17 12:17 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\AVAST Software
2016-04-17 12:17 - 2016-04-17 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-04-17 12:16 - 2016-05-05 09:32 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-04-17 12:16 - 2016-05-03 18:17 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00465792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00287528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00166432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00103064 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00074544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-04-17 12:16 - 2016-05-03 18:17 - 00037656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-04-17 12:11 - 2016-04-17 12:24 - 00000000 ____D C:\Program Files\AVAST Software
2016-04-17 12:09 - 2016-04-17 12:10 - 05168280 _____ (AVAST Software) C:\Users\Hanus\Downloads\avast_free_antivirus_setup_online.exe
2016-04-16 11:52 - 2016-03-31 02:54 - 25817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-16 11:52 - 2016-03-31 02:31 - 02892800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-04-16 11:52 - 2016-03-31 02:28 - 00571904 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-04-16 11:52 - 2016-03-31 02:25 - 06052352 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-04-16 11:52 - 2016-03-31 02:17 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-04-16 11:52 - 2016-03-31 02:03 - 20352512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-16 11:52 - 2016-03-31 01:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2016-04-16 11:52 - 2016-03-31 01:56 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-04-16 11:52 - 2016-03-31 01:55 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2016-04-16 11:52 - 2016-03-31 01:53 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-04-16 11:52 - 2016-03-31 01:51 - 02285056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-04-16 11:52 - 2016-03-31 01:50 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-04-16 11:52 - 2016-03-31 01:45 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-04-16 11:52 - 2016-03-31 01:45 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2016-04-16 11:52 - 2016-03-31 01:43 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-04-16 11:52 - 2016-03-31 01:43 - 00725504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-04-16 11:52 - 2016-03-31 01:43 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-04-16 11:52 - 2016-03-31 01:42 - 02131968 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-04-16 11:52 - 2016-03-31 01:39 - 15415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-16 11:52 - 2016-03-31 01:30 - 04611072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-04-16 11:52 - 2016-03-31 01:30 - 02596864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-16 11:52 - 2016-03-31 01:30 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2016-04-16 11:52 - 2016-03-31 01:30 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2016-04-16 11:52 - 2016-03-31 01:27 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-04-16 11:52 - 2016-03-31 01:24 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2016-04-16 11:52 - 2016-03-31 01:23 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-04-16 11:52 - 2016-03-31 01:23 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-04-16 11:52 - 2016-03-31 01:23 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-04-16 11:52 - 2016-03-31 01:21 - 13811712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-16 11:52 - 2016-03-31 01:18 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-16 11:52 - 2016-03-31 01:06 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-04-16 11:52 - 2016-03-31 01:05 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-16 11:52 - 2016-03-31 01:02 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-16 11:52 - 2016-03-31 01:00 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-04-16 11:51 - 2016-03-10 21:19 - 07452512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-16 11:51 - 2016-03-10 21:17 - 01663192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-16 11:51 - 2016-03-10 21:17 - 01523216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-16 11:51 - 2016-03-10 21:17 - 01490128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-16 11:51 - 2016-03-10 21:17 - 01358960 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-16 11:51 - 2016-03-10 21:17 - 01133752 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-04-16 11:51 - 2016-03-10 19:48 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-04-16 11:51 - 2016-03-10 19:43 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-16 11:51 - 2016-03-10 18:55 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-16 11:51 - 2016-03-10 18:42 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-16 11:51 - 2016-03-03 18:13 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-16 11:50 - 2016-04-04 08:35 - 00046768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-04-16 11:50 - 2016-04-02 15:26 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-04-16 11:50 - 2016-04-02 15:26 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-04-16 11:50 - 2016-03-28 15:21 - 00698368 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-04-16 11:50 - 2016-03-28 15:21 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-04-16 11:50 - 2016-03-28 15:21 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-04-16 11:50 - 2016-03-28 15:21 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-04-16 11:50 - 2016-03-28 15:21 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-04-16 11:50 - 2016-03-16 01:00 - 00561952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-16 11:50 - 2016-03-15 16:14 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-16 11:50 - 2016-03-11 16:48 - 00833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-16 11:50 - 2016-03-10 20:22 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-04-16 11:50 - 2016-03-10 20:21 - 00401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-04-16 11:50 - 2016-03-10 20:20 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-04-16 11:50 - 2016-03-10 19:44 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-04-16 11:50 - 2016-03-10 19:16 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-04-16 11:50 - 2016-03-10 19:03 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-16 11:50 - 2016-03-10 18:48 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-16 11:50 - 2016-03-03 18:47 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-16 11:50 - 2016-03-03 18:33 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-16 11:50 - 2016-03-03 03:39 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-04-16 11:50 - 2016-03-03 03:39 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-04-16 11:49 - 2016-03-29 16:05 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-04-14 16:16 - 2016-04-14 16:16 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2016-04-14 16:16 - 2016-04-14 16:16 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2016-04-14 16:04 - 2016-05-01 07:48 - 00000962 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0cd9ff5d8ba59.job
2016-04-14 16:04 - 2016-05-01 07:48 - 00000958 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-14 16:04 - 2016-04-30 11:16 - 00003936 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0cd9ff5d8ba59
2016-04-14 16:04 - 2016-04-30 11:16 - 00003700 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-04-14 13:52 - 2016-05-01 12:15 - 00002790 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-04-14 13:52 - 2016-04-14 13:52 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-04-14 13:52 - 2016-04-14 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-04-14 13:52 - 2016-04-14 13:52 - 00000000 ____D C:\Program Files\CCleaner
2016-04-14 13:51 - 2016-04-14 13:51 - 06868672 _____ (Piriform Ltd) C:\Users\Hanus\Downloads\ccsetup516.exe
2016-04-13 16:00 - 2016-03-22 04:10 - 00112184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-04-13 15:57 - 2016-03-22 06:12 - 42923576 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 37567424 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 31555008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 25321408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 21355248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 20897416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 17748712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 17342392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 17248408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 16446032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 12567608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-04-13 15:57 - 2016-03-22 06:12 - 10550736 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 08659472 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 03235896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 02809280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436472.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436472.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00959544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00889400 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00879000 _____ C:\WINDOWS\system32\nvmcumd.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00753208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00695864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00678520 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00501896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00473592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00425016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00423080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00391632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00153392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00129208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00126008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcaparm.dll
2016-04-13 15:57 - 2016-03-22 06:12 - 00046016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvadarm.sys
2016-04-13 15:57 - 2016-03-22 06:12 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-04-13 15:57 - 2016-03-22 06:12 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-04-05 19:12 - 2016-04-05 19:12 - 00000000 ____D C:\Users\Hanus\AppData\LocalLow\Adobe
2016-04-05 19:12 - 2016-04-05 19:12 - 00000000 ____D C:\Users\Hanus\AppData\Local\Adobe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-05 09:37 - 2015-11-06 12:27 - 00000000 ____D C:\FRST
2016-05-05 09:35 - 2015-08-03 00:41 - 00003970 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1F85D8D3-BFBD-487A-96B3-E6C2E0978322}
2016-05-05 09:31 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-04 19:24 - 2015-11-05 15:03 - 00000000 ____D C:\zoek_backup
2016-05-04 19:21 - 2015-12-13 14:22 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-05-04 18:51 - 2015-09-09 14:21 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-05-04 16:21 - 2015-09-29 14:27 - 00000000 ___RD C:\Users\Hanus\Desktop\Hry
2016-05-04 15:55 - 2015-11-05 15:03 - 00008192 _____ C:\WINDOWS\system32\edb.chk
2016-05-04 11:48 - 2015-08-03 00:41 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3812361727-838257335-1277264128-1001
2016-05-04 11:24 - 2015-09-08 14:25 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-05-04 11:19 - 2015-11-04 21:55 - 00000000 ____D C:\AdwCleaner
2016-05-04 11:11 - 2014-06-17 15:17 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-04 11:01 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2016-05-03 18:20 - 2016-01-03 15:06 - 00007602 _____ C:\Users\Hanus\AppData\Local\resmon.resmoncfg
2016-05-03 18:11 - 2015-08-03 00:35 - 00000000 ____D C:\Users\Hanus
2016-05-03 08:53 - 2015-08-03 00:44 - 00002191 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-01 22:10 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-05-01 16:06 - 2016-01-24 20:39 - 00000000 ____D C:\Users\Hanus\Documents\Mount&Blade Warband Savegames
2016-05-01 13:09 - 2015-08-03 00:58 - 00000000 ____D C:\Users\Hanus\AppData\Local\ElevatedDiagnostics
2016-05-01 12:15 - 2015-08-02 20:29 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-30 19:38 - 2015-08-03 17:08 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\TS3Client
2016-04-30 18:58 - 2015-08-03 17:08 - 00000000 ____D C:\Program Files\translations
2016-04-30 18:58 - 2015-08-03 17:08 - 00000000 ____D C:\Program Files\plugins
2016-04-30 18:58 - 2015-08-03 17:08 - 00000000 ____D C:\Program Files\news
2016-04-30 18:58 - 2014-08-04 15:46 - 01532184 _____ (TeamSpeak Systems GmbH) C:\Program Files\update.exe
2016-04-30 18:58 - 2014-08-04 15:46 - 00474904 _____ (TeamSpeak Systems GmbH) C:\Program Files\package_inst.exe
2016-04-30 18:58 - 2014-08-04 15:46 - 00447256 _____ (TeamSpeak Systems GmbH) C:\Program Files\error_report.exe
2016-04-30 18:58 - 2014-08-04 15:46 - 00161399 _____ C:\Program Files\changelog.txt
2016-04-30 18:58 - 2014-08-04 15:45 - 11480344 _____ (TeamSpeak Systems GmbH) C:\Program Files\ts3client_win64.exe
2016-04-30 18:58 - 2014-08-04 10:29 - 00000313 _____ C:\Program Files\plugin_sdk.html
2016-04-30 18:58 - 2014-06-20 09:44 - 00579975 _____ C:\Program Files\usb.ids
2016-04-30 18:58 - 2014-06-05 15:48 - 02084352 _____ (The OpenSSL Project,
hxxp://www.openssl.org/) C:\Program Files\libeay32.dll
2016-04-30 18:58 - 2014-06-05 15:48 - 00349696 _____ (The OpenSSL Project,
hxxp://www.openssl.org/) C:\Program Files\ssleay32.dll
2016-04-30 18:58 - 2014-05-19 13:15 - 01704176 _____ (Overwolf) C:\Program Files\OverwolfTeamSpeakInstaller.exe
2016-04-30 18:58 - 2014-02-28 11:14 - 00174872 _____ C:\Program Files\quazip.dll
2016-04-30 18:58 - 2014-02-27 16:50 - 05426176 _____ (The Qt Company Ltd) C:\Program Files\Qt5Widgets.dll
2016-04-30 18:58 - 2014-02-27 16:48 - 03935744 _____ (The Qt Company Ltd) C:\Program Files\Qt5Gui.dll
2016-04-30 18:58 - 2014-02-27 16:47 - 05629952 _____ (The Qt Company Ltd) C:\Program Files\Qt5Core.dll
2016-04-30 18:58 - 2014-02-27 16:47 - 01094656 _____ (The Qt Company Ltd) C:\Program Files\Qt5Network.dll
2016-04-30 18:58 - 2014-02-27 16:47 - 00216576 _____ (The Qt Company Ltd) C:\Program Files\Qt5Sql.dll
2016-04-30 18:58 - 2013-11-13 14:36 - 00375336 _____ C:\Program Files\createfileassoc.exe
2016-04-30 18:04 - 2015-12-17 16:49 - 00000000 ____D C:\Users\Hanus\Documents\The Witcher 3
2016-04-30 17:54 - 2015-12-17 16:17 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
2016-04-30 11:16 - 2014-06-17 15:31 - 00002914 _____ C:\WINDOWS\System32\Tasks\Hotkey Utility
2016-04-29 12:38 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-29 12:38 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-28 15:16 - 2015-10-24 11:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-04-27 12:40 - 2015-09-12 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
2016-04-27 09:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-04-27 09:13 - 2015-09-13 18:25 - 00000000 ____D C:\Users\Hanus\Documents\Rockstar Games
2016-04-21 15:18 - 2015-12-30 14:20 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\uTorrent
2016-04-21 14:30 - 2014-06-17 15:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-04-21 13:39 - 2016-03-21 17:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2016-04-21 13:31 - 2013-08-22 16:44 - 00337792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-20 17:26 - 2015-08-03 05:58 - 00000000 ____D C:\Users\Hanus\Documents\My Games
2016-04-18 18:52 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2016-04-17 12:24 - 2015-08-11 10:48 - 00000000 ____D C:\ProgramData\AVAST Software
2016-04-16 12:11 - 2015-08-03 15:18 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-16 11:59 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-16 11:58 - 2015-08-03 13:04 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-16 11:55 - 2015-08-03 13:04 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-16 11:50 - 2016-01-20 17:22 - 00177488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-04-16 11:49 - 2016-03-10 15:17 - 01737080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-04-16 11:49 - 2016-03-10 15:17 - 01501488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-04-16 11:49 - 2016-03-10 15:17 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-04-15 17:09 - 2015-09-05 18:21 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\Spotify
2016-04-14 01:45 - 2015-08-04 16:52 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 16:01 - 2016-02-04 15:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-04-13 16:01 - 2014-06-17 15:17 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-04-13 15:59 - 2014-06-17 15:16 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-04-10 17:49 - 2014-03-06 08:43 - 00765714 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-08 15:09 - 2015-11-04 22:00 - 00001078 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-08 15:09 - 2015-09-08 14:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-08 15:09 - 2015-09-08 14:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-04-07 19:22 - 2015-09-06 13:01 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-05 23:53 - 2016-03-30 13:50 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-05 23:53 - 2016-03-30 13:50 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-05 19:12 - 2015-08-03 00:35 - 00000000 ____D C:\Users\Hanus\AppData\Roaming\Adobe
==================== Files in the root of some directories =======
2014-08-04 15:46 - 2016-04-30 18:58 - 0161399 _____ () C:\Program Files\changelog.txt
2013-11-13 14:36 - 2016-04-30 18:58 - 0375336 _____ () C:\Program Files\createfileassoc.exe
2014-08-04 15:46 - 2016-04-30 18:58 - 0447256 _____ (TeamSpeak Systems GmbH) C:\Program Files\error_report.exe
2014-06-05 15:48 - 2016-04-30 18:58 - 2084352 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\Program Files\libeay32.dll
2016-04-30 18:58 - 2016-04-30 18:58 - 0660128 _____ (Microsoft Corporation) C:\Program Files\msvcp120.dll
2016-04-30 18:58 - 2016-04-30 18:58 - 0963232 _____ (Microsoft Corporation) C:\Program Files\msvcr120.dll
2014-05-19 13:15 - 2016-04-30 18:58 - 1704176 _____ (Overwolf) C:\Program Files\OverwolfTeamSpeakInstaller.exe
2014-08-04 15:46 - 2016-04-30 18:58 - 0474904 _____ (TeamSpeak Systems GmbH) C:\Program Files\package_inst.exe
2014-08-04 10:29 - 2016-04-30 18:58 - 0000313 _____ () C:\Program Files\plugin_sdk.html
2014-02-27 16:47 - 2016-04-30 18:58 - 5629952 _____ (The Qt Company Ltd) C:\Program Files\Qt5Core.dll
2014-02-27 16:48 - 2016-04-30 18:58 - 3935744 _____ (The Qt Company Ltd) C:\Program Files\Qt5Gui.dll
2014-02-27 16:47 - 2016-04-30 18:58 - 1094656 _____ (The Qt Company Ltd) C:\Program Files\Qt5Network.dll
2014-02-27 16:47 - 2016-04-30 18:58 - 0216576 _____ (The Qt Company Ltd) C:\Program Files\Qt5Sql.dll
2014-02-27 16:50 - 2016-04-30 18:58 - 5426176 _____ (The Qt Company Ltd) C:\Program Files\Qt5Widgets.dll
2014-02-28 11:14 - 2016-04-30 18:58 - 0174872 _____ () C:\Program Files\quazip.dll
2014-06-05 15:48 - 2016-04-30 18:58 - 0349696 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\Program Files\ssleay32.dll
2014-08-04 15:45 - 2016-04-30 18:58 - 11480344 _____ (TeamSpeak Systems GmbH) C:\Program Files\ts3client_win64.exe
2015-08-03 17:08 - 2015-08-03 17:08 - 0126290 _____ (TeamSpeak Systems GmbH) C:\Program Files\Uninstall.exe
2014-08-04 15:46 - 2016-04-30 18:58 - 1532184 _____ (TeamSpeak Systems GmbH) C:\Program Files\update.exe
2014-06-20 09:44 - 2016-04-30 18:58 - 0579975 _____ () C:\Program Files\usb.ids
2015-08-05 12:33 - 2015-08-05 12:34 - 1065984 _____ () C:\Users\Hanus\AppData\Local\file__0.localstorage
2016-01-03 15:06 - 2016-05-03 18:20 - 0007602 _____ () C:\Users\Hanus\AppData\Local\resmon.resmoncfg
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-05-04 11:48
==================== End of FRST.txt ============================