FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
Ran by userr (administrator) on USER (31-01-2016 00:38:12)
Running from C:\Users\userr\Downloads
Loaded Profiles: userr (Available Profiles: userr & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MsDtsServer120 & MSSQLSERVER)
Platform: Windows 8.1 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-08-09] (IvoSoft)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [24952456 2015-12-08] (Dropbox, Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3874216 2016-01-08] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-952108444-1884632922-1627213431-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)
HKU\S-1-5-21-952108444-1884632922-1627213431-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-952108444-1884632922-1627213431-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd)
HKU\S-1-5-21-952108444-1884632922-1627213431-1001\...\RunOnce: [Report] => C:\AdwCleaner\AdwCleaner[C1].txt [999 2016-01-29] ()
HKU\S-1-5-21-952108444-1884632922-1627213431-1001\...\MountPoints2: {1e4983b1-5d1d-11e5-8255-240a6426f2fe} - "E:\vs_enterprise.exe"
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{1F576828-3532-4ACA-A28C-5DA5448BBB42}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{590217DF-6AAC-4211-A480-C24FD9DAF98B}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
Internet Explorer:
==================
HKU\S-1-5-21-952108444-1884632922-1627213431-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={C399D675-8C30-40AE-8358-6F7CCA44EA59}&mid=7df9e1ada56947cd9d247d6b4dead1d1-9656e9d677122fa80db35feb4f6b57029d96490a&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-25 09:15:43&v=4.1.0.411&pid=wtu&sg=&sap=hp
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-19] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-19] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-16] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 14.0 Helper -> {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} -> C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2015-07-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-16] (Oracle Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-19] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1220162.dll [2015-08-31] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-16] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
Chrome:
=======
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-17]
CHR Extension: (Google Docs) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-17]
CHR Extension: (Google Drive) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Sheets) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-17]
CHR Extension: (Google Docs Offline) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-19]
CHR Extension: (AdBlock) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-29]
CHR Extension: (NetBeans Connector) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafdlehgocfcodbgjnpecfajgkeejnaa [2015-11-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-17]
CHR Extension: (Gmail) - C:\Users\userr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-17]
CHR HKU\S-1-5-21-952108444-1884632922-1627213431-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [627544 2016-01-08] (AVG Technologies CZ, s.r.o.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3906568 2016-01-08] (AVG Technologies CZ, s.r.o.)
S2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1048488 2016-01-12] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [583936 2016-01-08] (AVG Technologies CZ, s.r.o.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-19] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-19] (Dropbox, Inc.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 MsDtsServer120; C:\Program Files\Microsoft SQL Server\120\DTS\Binn\MsDtsSrvr.exe [216768 2015-06-10] (Microsoft Corporation)
S3 MSSQLFDLauncher; C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [50880 2014-02-21] (Microsoft Corporation)
S2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [370368 2015-06-10] (Microsoft Corporation)
S2 MSSQLServerOLAPService; C:\Program Files\Microsoft SQL Server\MSAS12.MSSQLSERVER\OLAP\bin\msmdsrv.exe [51090624 2014-02-21] (Microsoft Corporation)
S2 ReportServer; C:\Program Files\Microsoft SQL Server\MSRS12.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2450112 2014-02-21] (Microsoft Corporation)
S3 SQL Server Distributed Replay Client; C:\Program Files (x86)\Microsoft SQL Server\120\Tools\DReplayClient\DReplayClient.exe [139968 2014-02-21] (Microsoft Corporation)
S3 SQL Server Distributed Replay Controller; C:\Program Files (x86)\Microsoft SQL Server\120\Tools\DReplayController\DReplayController.exe [345280 2014-02-21] (Microsoft Corporation)
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [613056 2015-06-10] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [56040 2015-11-19] (Microsoft Corporation)
S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 KMSEmulator; temp.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [23152 2015-09-09] (AVG Technologies CZ, s.r.o.)
S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [258480 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [315840 2015-12-16] (AVG Technologies CZ, s.r.o.)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-09-19] (Disc Soft Ltd)
R0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [36568 2013-09-30] (IObit)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [184608 2015-07-07] (Intel Corporation)
S4 RsFx0300; C:\Windows\System32\DRIVERS\RsFx0300.sys [247488 2014-02-21] (Microsoft Corporation)
S3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-01-29] ()
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146072 2015-09-08] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-31 00:38 - 2016-01-31 00:38 - 00019602 _____ C:\Users\userr\Downloads\FRST.txt
2016-01-31 00:38 - 2016-01-31 00:38 - 00000000 ____D C:\FRST
2016-01-31 00:37 - 2016-01-31 00:37 - 02370560 _____ (Farbar) C:\Users\userr\Downloads\FRST64.exe
2016-01-31 00:26 - 2016-01-31 00:26 - 02451912 _____ (IObit ) C:\Users\userr\Downloads\unlocker-setup (1).exe
2016-01-31 00:26 - 2016-01-31 00:26 - 00001196 _____ C:\Users\Public\Desktop\IObit Unlocker.lnk
2016-01-31 00:26 - 2016-01-31 00:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Unlocker
2016-01-31 00:26 - 2016-01-31 00:26 - 00000000 ____D C:\ProgramData\IObit
2016-01-31 00:26 - 2016-01-31 00:26 - 00000000 ____D C:\Program Files (x86)\IObit
2016-01-29 20:06 - 2016-01-29 20:06 - 01721856 _____ (Farbar) C:\Users\userr\Downloads\FRST.exe
2016-01-29 20:03 - 2016-01-29 20:03 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-01-29 20:03 - 2016-01-29 20:03 - 00000000 ____D C:\ProgramData\RogueKiller
2016-01-29 20:01 - 2016-01-29 20:01 - 20940872 _____ C:\Users\userr\Downloads\RogueKiller.exe
2016-01-29 19:55 - 2016-01-29 19:55 - 00380416 _____ C:\Users\userr\Downloads\c1c9dz1f.exe
2016-01-29 19:27 - 2016-01-29 19:27 - 02451912 _____ (IObit ) C:\Users\userr\Downloads\unlocker-setup.exe
2016-01-29 19:24 - 2016-01-29 19:45 - 00000000 ____D C:\AdwCleaner
2016-01-29 19:24 - 2016-01-29 19:24 - 01507840 _____ C:\Users\userr\Downloads\AdwCleaner.exe
2016-01-29 19:22 - 2016-01-31 00:26 - 00368104 _____ C:\Windows\ntbtlog.txt
2016-01-29 19:22 - 2016-01-29 19:22 - 00000000 _____ C:\Users\userr\Downloads\JRT (3).exe
2016-01-29 19:21 - 2016-01-29 19:21 - 00000000 _____ C:\Users\userr\Downloads\JRT (2).exe
2016-01-29 19:19 - 2016-01-29 19:19 - 00000000 ____D C:\Users\userr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2016-01-29 19:19 - 2016-01-29 19:19 - 00000000 ____D C:\Program Files\Unlocker
2016-01-29 19:18 - 2016-01-29 19:18 - 01078591 _____ C:\Users\userr\Downloads\Unlocker1.9.2.exe
2016-01-29 19:18 - 2016-01-29 19:18 - 00000000 _____ C:\Users\userr\Downloads\JRT (1).exe
2016-01-29 19:17 - 2016-01-29 19:17 - 00000000 _____ C:\Users\userr\Downloads\JRT.exe
2016-01-29 17:04 - 2016-01-29 17:05 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-01-29 16:16 - 2016-01-29 16:16 - 00001114 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-01-29 16:16 - 2016-01-29 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-01-29 16:16 - 2016-01-29 16:16 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-29 16:16 - 2016-01-29 16:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-01-29 16:16 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-01-29 16:16 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-01-29 16:16 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-01-29 16:15 - 2016-01-29 16:15 - 22908888 _____ (Malwarebytes ) C:\Users\userr\Downloads\mbam-setup-2.2.0.1024.exe
2016-01-29 15:53 - 2016-01-29 17:01 - 00015070 _____ C:\Users\userr\Desktop\avgrep.txt
2016-01-29 15:45 - 2016-01-29 15:45 - 00000000 ____D C:\Users\userr\AppData\Local\ElevatedDiagnostics
2016-01-29 15:16 - 2016-01-29 15:16 - 00307200 _____ (Secure By Design Inc.) C:\Users\userr\Desktop\Ninite Chrome Installer.exe
2016-01-29 12:03 - 2016-01-29 11:57 - 00927824 _____ (Google Inc.) C:\Users\userr\Desktop\ChromeSetup.exe
2016-01-25 03:02 - 2016-01-25 03:02 - 01175040 _____ C:\Users\userr\Downloads\14_Web_turpinajums (5).ppt
2016-01-25 02:59 - 2016-01-25 02:59 - 01236480 _____ C:\Users\userr\Downloads\13_Web (2).ppt
2016-01-25 02:57 - 2016-01-25 02:57 - 01759232 _____ C:\Users\userr\Downloads\12_DataBinding_API_Install (3).ppt
2016-01-25 02:57 - 2016-01-25 02:57 - 01757184 _____ C:\Users\userr\Downloads\12_DataBinding_API_Install (2).ppt
2016-01-25 02:57 - 2016-01-25 02:57 - 01234432 _____ C:\Users\userr\Downloads\13_Web (1).ppt
2016-01-25 02:52 - 2016-01-25 02:52 - 02405888 _____ C:\Users\userr\Downloads\11_Task_API_Install (3).ppt
2016-01-25 02:51 - 2016-01-25 02:51 - 02405888 _____ C:\Users\userr\Downloads\11_Task_API_Install (2).ppt
2016-01-25 02:46 - 2016-01-25 02:46 - 01414656 _____ C:\Users\userr\Downloads\10_BuildingControls (1).ppt
2016-01-25 02:42 - 2016-01-25 02:42 - 01587712 _____ C:\Users\userr\Downloads\09_Reporti (1).ppt
2016-01-25 02:32 - 2016-01-25 02:32 - 04893696 _____ C:\Users\userr\Downloads\08_Datubazes_ADO (2).ppt
2016-01-25 02:25 - 2016-01-25 02:25 - 03410432 _____ C:\Users\userr\Downloads\07_Datubazes_EntityFramework (2).ppt
2016-01-25 02:19 - 2016-01-25 02:19 - 06079488 _____ C:\Users\userr\Downloads\06_LINQ (1).ppt
2016-01-25 02:19 - 2016-01-25 02:19 - 06076928 _____ C:\Users\userr\Downloads\06_LINQ (2).ppt
2016-01-25 02:12 - 2016-01-25 02:12 - 05125632 _____ C:\Users\userr\Downloads\05_kludas_interfeisi (1).ppt
2016-01-25 01:59 - 2016-01-25 02:05 - 20087808 _____ C:\Users\userr\Downloads\04_Kolekcijas_Files_Kludas (1).ppt
2016-01-24 23:13 - 2016-01-24 23:13 - 02152448 _____ C:\Users\userr\Downloads\03_NET_Strukturas_Klases (1).ppt
2016-01-24 19:44 - 2016-01-24 19:44 - 02523136 _____ C:\Users\userr\Downloads\02_NET_Pamati (1).ppt
2016-01-24 14:06 - 2016-01-24 14:06 - 04534784 _____ C:\Users\userr\Downloads\01_Ievadlekcija (1).ppt
2016-01-24 13:53 - 2016-01-24 13:53 - 00314880 _____ C:\Users\userr\Downloads\Sesijas_plans_atjauninats.ppt
2016-01-20 11:23 - 2016-01-20 11:23 - 00176635 _____ C:\Users\userr\Downloads\Tavegyl.pdf
2016-01-20 11:23 - 2016-01-20 11:23 - 00176635 _____ C:\Users\userr\Downloads\Tavegyl (1).pdf
2016-01-19 12:55 - 2016-01-19 12:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2016-01-19 10:26 - 2016-01-19 10:26 - 00016701 _____ C:\Users\userr\Downloads\Eksāmena grafiks-Exam schedule.xlsx
2016-01-18 10:45 - 2016-01-18 10:45 - 00258777 _____ C:\Users\userr\Downloads\07_CodeIgniter_MVC.pdf
2016-01-18 00:39 - 2016-01-29 18:39 - 00000000 ____D C:\Windows\Minidump
2016-01-14 15:59 - 2016-01-14 16:09 - 00000348 _____ C:\Users\userr\Desktop\Apraksts.txt
2016-01-14 15:58 - 2016-01-14 15:58 - 00000000 ____D C:\Users\userr\Desktop\2.md
2016-01-13 11:21 - 2015-12-11 06:38 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-01-13 11:21 - 2015-12-11 06:00 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-01-13 11:21 - 2015-12-11 05:55 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-01-13 11:21 - 2015-12-11 05:50 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-01-13 11:21 - 2015-12-11 05:45 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-01-13 11:21 - 2015-12-11 05:21 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-01-13 11:21 - 2015-12-11 05:18 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-01-13 11:21 - 2015-12-11 05:09 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-01-13 11:21 - 2015-12-11 05:09 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-01-13 11:21 - 2015-12-11 05:03 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-01-13 11:21 - 2015-12-11 04:59 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-01-13 11:21 - 2015-12-11 04:43 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-01-13 11:21 - 2015-12-11 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-01-13 11:21 - 2015-12-11 04:38 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-01-13 11:21 - 2015-12-11 04:37 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-01-13 11:21 - 2015-12-11 04:35 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-01-13 11:21 - 2015-12-11 04:26 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-01-13 11:21 - 2015-12-11 04:14 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-01-13 11:21 - 2015-12-11 04:12 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-01-13 11:21 - 2015-12-11 04:08 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-01-13 11:21 - 2015-12-11 04:07 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-01-13 11:20 - 2015-12-30 21:32 - 07453016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-01-13 11:20 - 2015-12-30 21:32 - 01735000 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-01-13 11:20 - 2015-12-30 21:32 - 01499912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-01-13 11:20 - 2015-12-07 12:56 - 01380600 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 02745184 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 02528784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 02450240 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 02447136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 02334104 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 02324744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 01877504 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 01798480 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 01484888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 01288128 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 01210200 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 01150232 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 01115640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 01037680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00914672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00850680 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00735496 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00700360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00629600 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00584656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00557856 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00498472 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00492736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00463776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00399776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00299080 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00275312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00274280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00250520 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00248432 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00246856 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00244296 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00229272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00203016 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00184912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00183856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00116720 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00110544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00099136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-01-13 11:20 - 2015-12-05 07:58 - 00090904 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00090392 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00081032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2016-01-13 11:20 - 2015-12-05 07:58 - 00076936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
2016-01-13 11:20 - 2015-12-04 17:00 - 01097216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-01-13 11:20 - 2015-12-03 20:07 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-01-13 11:20 - 2015-12-03 20:07 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-01-13 11:20 - 2015-12-03 20:05 - 00644608 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2016-01-13 11:20 - 2015-12-03 20:02 - 01664000 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-01-13 11:20 - 2015-12-03 20:00 - 00451072 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2016-01-13 11:20 - 2015-12-03 19:58 - 00378880 ____C (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2016-01-13 11:20 - 2015-12-03 19:36 - 01697792 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-01-13 11:20 - 2015-12-03 19:30 - 00468480 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2016-01-13 11:20 - 2015-12-03 19:28 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-01-13 11:20 - 2015-12-03 19:28 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-01-13 11:20 - 2015-12-03 19:27 - 00736256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2016-01-13 11:20 - 2015-12-03 19:24 - 01411584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-01-13 11:20 - 2015-12-03 19:23 - 00402432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2016-01-13 11:20 - 2015-12-03 19:06 - 01501184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-01-13 11:20 - 2015-12-03 19:01 - 00743936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
2016-01-13 11:20 - 2015-12-03 18:40 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-01-13 11:20 - 2015-12-03 18:29 - 00887296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-01-13 11:20 - 2015-12-02 17:04 - 00670208 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-01-13 11:20 - 2015-12-02 17:01 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-01-13 11:19 - 2015-12-10 02:40 - 00033456 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-01-13 11:19 - 2015-12-08 21:08 - 00685432 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-01-13 11:19 - 2015-12-08 21:07 - 00507176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-01-13 11:19 - 2015-12-03 21:42 - 00561952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-01-13 11:19 - 2015-12-03 21:42 - 00397224 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2016-01-13 11:19 - 2015-12-03 21:42 - 00137968 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-01-13 11:19 - 2015-12-03 21:42 - 00106960 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2016-01-13 11:19 - 2015-12-03 21:41 - 00177488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-01-13 11:19 - 2015-12-03 20:52 - 00340872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2016-01-13 11:19 - 2015-12-03 20:52 - 00120376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-01-13 11:19 - 2015-12-03 20:52 - 00091416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2016-01-13 11:19 - 2015-12-03 20:28 - 00401920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-01-13 11:19 - 2015-12-03 20:28 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-01-13 11:19 - 2015-12-03 19:51 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-01-13 11:19 - 2015-12-03 19:16 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-01-13 11:19 - 2015-12-03 19:13 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-01-13 11:19 - 2015-12-03 19:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-01-13 11:19 - 2015-12-03 18:45 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 01380864 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 00705024 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-01-13 11:19 - 2015-11-17 23:07 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-01-07 19:48 - 2016-01-07 19:48 - 00000000 ____D C:\Users\userr\AppData\Roaming\Glimpse
2016-01-07 12:01 - 2016-01-07 12:01 - 00126305 _____ C:\Users\userr\Downloads\trenina_mk3_grafa_reprezentacija (1).pdf
2016-01-07 00:48 - 2016-01-07 00:48 - 00002905 _____ C:\Users\userr\Desktop\Sorting.cpp
2016-01-06 02:42 - 2016-01-05 23:14 - 17690235 _____ C:\Users\userr\Desktop\Eksāmens.pdf
2016-01-06 00:35 - 2016-01-06 20:30 - 00959319 _____ C:\Users\userr\Desktop\Sorting.exe
2016-01-06 00:35 - 2016-01-06 20:30 - 00004062 _____ C:\Users\userr\Desktop\Sorting.o
2016-01-05 23:12 - 2016-01-05 23:14 - 17690235 _____ C:\Users\userr\Downloads\Eksāmens.pdf
2016-01-05 22:51 - 2016-01-05 22:51 - 01759232 _____ C:\Users\userr\Downloads\12_DataBinding_API_Install (1).ppt
2016-01-05 22:47 - 2016-01-05 22:47 - 02405888 _____ C:\Users\userr\Downloads\11_Task_API_Install (1).ppt
2016-01-05 22:44 - 2016-01-05 22:44 - 01414656 _____ C:\Users\userr\Downloads\10_BuildingControls.ppt
2016-01-05 22:40 - 2016-01-05 22:40 - 01587712 _____ C:\Users\userr\Downloads\09_Reporti.ppt
2016-01-05 22:34 - 2016-01-05 22:34 - 04893696 _____ C:\Users\userr\Downloads\08_Datubazes_ADO (1).ppt
2016-01-05 22:23 - 2016-01-05 22:23 - 06079488 _____ C:\Users\userr\Downloads\06_LINQ.ppt
2016-01-05 22:23 - 2016-01-05 22:23 - 03410432 _____ C:\Users\userr\Downloads\07_Datubazes_EntityFramework (1).ppt
2016-01-05 22:16 - 2016-01-05 22:16 - 05125632 _____ C:\Users\userr\Downloads\05_kludas_interfeisi.ppt
2016-01-05 22:00 - 2016-01-05 22:00 - 04521937 _____ C:\Users\userr\Downloads\04_Kolekcijas_Files_Kludas.pdf
2016-01-05 21:10 - 2016-01-05 21:10 - 20087808 _____ C:\Users\userr\Downloads\04_Kolekcijas_Files_Kludas.ppt
2016-01-05 21:08 - 2016-01-05 21:08 - 02152448 _____ C:\Users\userr\Downloads\03_NET_Strukturas_Klases.ppt
2016-01-05 20:59 - 2016-01-05 21:08 - 02446848 _____ C:\Users\userr\Downloads\02_NET_Pamati.ppt
2016-01-05 20:54 - 2016-01-05 20:54 - 04534784 _____ C:\Users\userr\Downloads\01_Ievadlekcija.ppt
2016-01-05 16:44 - 2016-01-05 16:44 - 00122268 _____ C:\Users\userr\Downloads\trenina_mk7_binaras_meklesanas_koks (1).pdf
2016-01-05 01:20 - 2016-01-05 01:20 - 00357727 _____ C:\Users\userr\Downloads\13_tt_app_droshiiba (4).pdf
2016-01-05 01:20 - 2016-01-05 01:20 - 00357727 _____ C:\Users\userr\Downloads\13_tt_app_droshiiba (3).pdf
2016-01-04 22:09 - 2016-01-04 22:10 - 01718408 _____ C:\Users\userr\Downloads\secnet.exe
2016-01-04 21:06 - 2016-01-04 21:06 - 00357727 _____ C:\Users\userr\Downloads\13_tt_app_droshiiba (2).pdf
2016-01-04 21:06 - 2016-01-04 21:06 - 00357727 _____ C:\Users\userr\Downloads\13_tt_app_droshiiba (1).pdf
2016-01-04 16:46 - 2016-01-04 16:46 - 00357727 _____ C:\Users\userr\Downloads\13_tt_app_droshiiba.pdf
2016-01-04 10:14 - 2016-01-04 10:14 - 00000144 _____ C:\Users\userr\.gitconfig
2016-01-03 23:45 - 2016-01-03 23:45 - 00000000 ____D C:\Program Files (x86)\ESET
2016-01-03 23:44 - 2016-01-03 23:44 - 02870984 _____ (ESET) C:\Users\userr\Downloads\esetsmartinstaller_enu.exe
2016-01-03 23:24 - 2016-01-03 23:24 - 00000000 ____D C:\Windows\pss
2016-01-03 13:55 - 2016-01-03 13:55 - 01175040 _____ C:\Users\userr\Downloads\14_Web_turpinajums (4).ppt
2016-01-03 13:54 - 2016-01-03 13:54 - 00317440 _____ C:\Users\userr\Downloads\Sesijas_plans (2).ppt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-31 00:37 - 2015-09-16 15:56 - 00000000 ____D C:\Users\userr\AppData\Local\ClassicShell
2016-01-31 00:04 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-31 00:03 - 2015-09-19 11:20 - 00000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-01-31 00:03 - 2015-09-16 15:55 - 00000210 _____ C:\Windows\Tasks\AutoKMS.job
2016-01-31 00:03 - 2015-09-16 14:35 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-30 00:12 - 2015-09-19 20:32 - 00000000 ____D C:\Users\ReportServer
2016-01-30 00:12 - 2015-09-19 20:32 - 00000000 ____D C:\Users\MSSQLServerOLAPService
2016-01-30 00:12 - 2015-09-19 20:32 - 00000000 ____D C:\Users\MsDtsServer120
2016-01-30 00:12 - 2015-09-19 20:31 - 00000000 ____D C:\Users\MSSQLSERVER
2016-01-30 00:12 - 2015-09-16 23:49 - 00000000 ____D C:\Users\userr
2016-01-30 00:12 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf
2016-01-29 17:48 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-01-29 17:36 - 2015-09-16 13:55 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-952108444-1884632922-1627213431-1001
2016-01-29 17:33 - 2015-09-17 18:51 - 00000000 __RDO C:\Users\userr\OneDrive
2016-01-29 17:03 - 2015-09-19 11:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2016-01-29 16:07 - 2015-09-29 19:58 - 00000000 ____D C:\Users\userr\.VirtualBox
2016-01-29 16:06 - 2015-10-03 12:16 - 00000000 ____D C:\Program Files\NetBeans 8.0.2
2016-01-29 15:28 - 2015-09-16 14:35 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-29 15:26 - 2015-09-19 11:20 - 00000916 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-01-29 14:51 - 2015-09-19 11:45 - 00000000 ____D C:\ProgramData\MFAData
2016-01-29 14:16 - 2015-09-19 11:23 - 00000000 ___RD C:\Users\userr\Dropbox
2016-01-29 13:19 - 2015-09-19 11:26 - 00000000 ___RD C:\Users\userr\Google Drive
2016-01-29 12:40 - 2015-09-19 11:20 - 00000000 ____D C:\Users\userr\AppData\Local\Dropbox
2016-01-29 12:05 - 2015-09-16 14:35 - 00000000 ____D C:\Users\userr\AppData\Local\Google
2016-01-29 09:33 - 2015-12-06 23:35 - 00000600 _____ C:\Users\userr\AppData\Roaming\winscp.rnd
2016-01-29 09:33 - 2015-12-06 19:07 - 00000600 _____ C:\Users\userr\AppData\Local\PUTTY.RND
2016-01-29 03:01 - 2015-09-16 14:35 - 00002232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-29 03:01 - 2015-09-16 14:35 - 00002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-28 22:57 - 2015-10-03 13:15 - 00000000 ____D C:\Users\userr\Documents\NetBeansProjects
2016-01-27 16:54 - 2015-09-19 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-01-27 16:42 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2016-01-26 18:01 - 2015-09-16 23:49 - 00000000 ____D C:\ProgramData\KMSAutoS
2016-01-25 13:17 - 2015-09-19 20:31 - 00000000 ____D C:\Users\userr\Documents\SQL Server Management Studio
2016-01-25 03:52 - 2015-09-19 21:36 - 00000000 ____D C:\Users\userr\Documents\Visual Studio 2015
2016-01-25 03:23 - 2015-09-19 11:38 - 00000000 ____D C:\Users\userr\AppData\Roaming\CodeBlocks
2016-01-18 00:40 - 2015-09-19 20:31 - 00000000 ____D C:\Users\MSSQLFDLauncher
2016-01-16 22:55 - 2015-09-16 14:57 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-01-16 22:55 - 2015-09-16 14:57 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-01-14 22:13 - 2015-09-16 14:55 - 00000000 ____D C:\Windows\system32\MRT
2016-01-14 22:06 - 2015-09-16 14:55 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-01-14 18:00 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2016-01-13 13:14 - 2014-03-18 12:17 - 01129840 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-13 13:06 - 2015-09-16 15:46 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-01-13 13:06 - 2015-09-16 15:46 - 00000000 ____D C:\Windows\system32\appraiser
2016-01-13 12:18 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2016-01-13 11:56 - 2013-08-22 15:25 - 00000167 _____ C:\Windows\win.ini
2016-01-08 00:53 - 2015-12-21 23:50 - 00000000 ____D C:\Users\userr\Downloads\IngaPire-NMD3
2016-01-07 20:43 - 2015-12-19 21:18 - 00000000 ____D C:\Users\userr\Desktop\packages
2016-01-07 20:43 - 2015-12-19 21:13 - 00000000 ____D C:\Users\userr\Desktop\WebApplication6
2016-01-06 11:18 - 2015-09-19 11:45 - 00000882 _____ C:\Users\Public\Desktop\AVG.lnk
2016-01-05 22:04 - 2015-09-17 10:46 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-05 22:04 - 2015-09-17 10:45 - 00826872 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-04 10:23 - 2015-11-25 16:26 - 00000000 ____D C:\Users\userr\AppData\Roaming\GitHub
2016-01-04 10:23 - 2015-11-25 16:26 - 00000000 ____D C:\Users\userr\AppData\Local\GitHub
2016-01-04 10:16 - 2015-11-25 16:26 - 00000000 ____D C:\Users\userr\Documents\GitHub
2016-01-04 10:15 - 2015-11-25 16:22 - 00000000 ____D C:\Users\userr\AppData\Local\Deployment
==================== Files in the root of some directories =======
2015-12-06 23:35 - 2016-01-29 09:33 - 0000600 _____ () C:\Users\userr\AppData\Roaming\winscp.rnd
2015-12-06 19:07 - 2016-01-29 09:33 - 0000600 _____ () C:\Users\userr\AppData\Local\PUTTY.RND
Some files in TEMP:
====================
C:\Users\userr\AppData\Local\Temp\1jewzpyq.dll
C:\Users\userr\AppData\Local\Temp\DeltaTB.exe
C:\Users\userr\AppData\Local\Temp\dllnt_dump.dll
C:\Users\userr\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwwhypi.dll
C:\Users\userr\AppData\Local\Temp\jpene2np.dll
C:\Users\userr\AppData\Local\Temp\unsetcpk.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-28 11:12
==================== End of FRST.txt ============================