Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-10-2015 Ran by SYSTEM on MININT-KT2PJH2 (03-11-2015 22:30:49) Running from D:\ Platform: Windows 7 Ultimate (X64) Language: English (United States) Internet Explorer Version 8 Boot Mode: Recovery Default: ControlSet001 [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14021336 2015-06-18] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-20] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-10-16] () HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-17] (AVAST Software) HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [8192 2013-04-29] () HKU\ZSpicher\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2901584 2015-10-14] (Valve Corporation) HKU\ZSpicher\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-19] (Piriform Ltd) HKU\ZSpicher\...\Run: [f.lux] => C:\Users\ZSpicher\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC) HKU\ZSpicher\...\Run: [AdobeBridge] => [X] HKU\ZSpicher\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-08-30] (AMD) ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 ASGT; C:\Windows\SysWOW64\ASGT.exe [48640 2015-05-28] () S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-17] (AVAST Software) S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4048280 2015-10-17] (Avast Software) S2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16896 2015-04-14] () S2 GCloud; C:\Program Files (x86)\GIGABYTE\CloudStation\HomeCloud\GCloud.exe [12800 2014-03-27] (Microsoft) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) S2 Realtek11nSU; C:\Program Files (x86)\RNX-N150UBE\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) S2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) S3 AppleChargerSrv; system32\AppleChargerSrv.exe [X] S2 igfxCUIService1.0.0.0; %SystemRoot%\system32\igfxCUIService.exe [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S0 aswRvrt; no ImagePath S0 aswVmm; no ImagePath S3 etocdrv; C:\Windows\etocdrv.sys [15584 2013-10-30] (Giga-Byte Technology CO., LTD.) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2015-10-19] () S0 ngvss; no ImagePath S2 secdrv; no ImagePath S2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [274336 2015-10-17] (Avast Software) S3 1394ohci; \SystemRoot\system32\DRIVERS\1394ohci.sys [X] S0 ACPI; system32\DRIVERS\ACPI.sys [X] S3 AcpiPmi; \SystemRoot\system32\DRIVERS\acpipmi.sys [X] S3 adp94xx; \SystemRoot\system32\DRIVERS\adp94xx.sys [X] S3 adpahci; \SystemRoot\system32\DRIVERS\adpahci.sys [X] S3 adpu320; \SystemRoot\system32\DRIVERS\adpu320.sys [X] S3 agp440; \SystemRoot\system32\DRIVERS\agp440.sys [X] S3 aliide; \SystemRoot\system32\DRIVERS\aliide.sys [X] S3 amdide; \SystemRoot\system32\DRIVERS\amdide.sys [X] S3 AmdK8; \SystemRoot\system32\DRIVERS\amdk8.sys [X] S3 amdkmdag; system32\DRIVERS\atikmdag.sys [X] S3 amdkmdap; system32\DRIVERS\atikmpag.sys [X] S3 AmdPPM; \SystemRoot\system32\DRIVERS\amdppm.sys [X] S3 amdsata; \SystemRoot\system32\DRIVERS\amdsata.sys [X] S3 amdsbs; \SystemRoot\system32\DRIVERS\amdsbs.sys [X] S0 amdxata; system32\DRIVERS\amdxata.sys [X] S1 AppleCharger; system32\DRIVERS\AppleCharger.sys [X] S3 arc; \SystemRoot\system32\DRIVERS\arc.sys [X] S3 arcsas; \SystemRoot\system32\DRIVERS\arcsas.sys [X] S2 aswHwid; \SystemRoot\system32\drivers\aswHwid.sys [X] S2 aswMonFlt; \SystemRoot\system32\drivers\aswMonFlt.sys [X] S1 aswRdr; \SystemRoot\system32\drivers\aswRdr2.sys [X] S1 aswSnx; \SystemRoot\system32\drivers\aswSnx.sys [X] S1 aswSP; \SystemRoot\system32\drivers\aswSP.sys [X] S2 aswStm; \SystemRoot\system32\drivers\aswStm.sys [X] S0 atapi; system32\DRIVERS\atapi.sys [X] S3 AtiHDAudioService; system32\drivers\AtihdW76.sys [X] S3 b06bdrv; \SystemRoot\system32\DRIVERS\bxvbda.sys [X] S3 b57nd60a; system32\DRIVERS\b57nd60a.sys [X] S1 blbdrive; system32\DRIVERS\blbdrive.sys [X] S3 BrFiltLo; \SystemRoot\system32\DRIVERS\BrFiltLo.sys [X] S3 BrFiltUp; \SystemRoot\system32\DRIVERS\BrFiltUp.sys [X] S3 Brserid; \SystemRoot\System32\Drivers\Brserid.sys [X] S3 BrSerWdm; \SystemRoot\System32\Drivers\BrSerWdm.sys [X] S3 BrUsbMdm; \SystemRoot\System32\Drivers\BrUsbMdm.sys [X] S3 BrUsbSer; \SystemRoot\System32\Drivers\BrUsbSer.sys [X] S3 BTHMODEM; \SystemRoot\system32\DRIVERS\bthmodem.sys [X] S1 cdrom; system32\DRIVERS\cdrom.sys [X] S3 circlass; \SystemRoot\system32\DRIVERS\circlass.sys [X] S3 CmBatt; \SystemRoot\system32\DRIVERS\CmBatt.sys [X] S3 cmdide; \SystemRoot\system32\DRIVERS\cmdide.sys [X] S3 Compbatt; \SystemRoot\system32\DRIVERS\compbatt.sys [X] S3 CompositeBus; system32\DRIVERS\CompositeBus.sys [X] S4 crcdisk; \SystemRoot\system32\DRIVERS\crcdisk.sys [X] S0 Disk; system32\DRIVERS\disk.sys [X] S3 drmkaud; system32\drivers\drmkaud.sys [X] S3 ebdrv; \SystemRoot\system32\DRIVERS\evbda.sys [X] S3 elxstor; \SystemRoot\system32\DRIVERS\elxstor.sys [X] S3 ErrDev; \SystemRoot\system32\DRIVERS\errdev.sys [X] S3 fdc; \SystemRoot\system32\DRIVERS\fdc.sys [X] S3 flpydisk; \SystemRoot\system32\DRIVERS\flpydisk.sys [X] S3 gagp30kx; \SystemRoot\system32\DRIVERS\gagp30kx.sys [X] S2 GhFlt; \??\C:\Windows\system32\drivers\ghflt.sys [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] S3 hcw85cir; \SystemRoot\system32\drivers\hcw85cir.sys [X] S3 HdAudAddService; system32\drivers\HdAudio.sys [X] S3 HDAudBus; system32\DRIVERS\HDAudBus.sys [X] S3 HidBatt; \SystemRoot\system32\DRIVERS\HidBatt.sys [X] S3 HidBth; \SystemRoot\system32\DRIVERS\hidbth.sys [X] S3 HidIr; \SystemRoot\system32\DRIVERS\hidir.sys [X] S3 HidUsb; system32\DRIVERS\hidusb.sys [X] S3 HpSAMD; \SystemRoot\system32\DRIVERS\HpSAMD.sys [X] S3 i8042prt; \SystemRoot\system32\DRIVERS\i8042prt.sys [X] S0 iaStorA; system32\DRIVERS\iaStorA.sys [X] S0 iaStorF; system32\DRIVERS\iaStorF.sys [X] S3 iaStorV; \SystemRoot\system32\DRIVERS\iaStorV.sys [X] S3 igfx; system32\DRIVERS\igdkmd64.sys [X] S3 iirsp; \SystemRoot\system32\DRIVERS\iirsp.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X] S3 IntcDAud; system32\DRIVERS\IntcDAud.sys [X] S3 intelide; \SystemRoot\system32\DRIVERS\intelide.sys [X] S3 intelppm; system32\DRIVERS\intelppm.sys [X] S4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X] S3 IPMIDRV; \SystemRoot\system32\DRIVERS\IPMIDrv.sys [X] S3 isapnp; \SystemRoot\system32\DRIVERS\isapnp.sys [X] S3 iScsiPrt; \SystemRoot\system32\DRIVERS\msiscsi.sys [X] S0 iusb3hcs; system32\DRIVERS\iusb3hcs.sys [X] S3 iusb3hub; system32\DRIVERS\iusb3hub.sys [X] S3 iusb3xhc; system32\DRIVERS\iusb3xhc.sys [X] S3 kbdclass; system32\DRIVERS\kbdclass.sys [X] S3 kbdhid; system32\DRIVERS\kbdhid.sys [X] S3 LGBusEnum; system32\drivers\LGBusEnum.sys [X] S3 LGSHidFilt; system32\DRIVERS\LGSHidFilt.Sys [X] S3 LGVirHid; system32\drivers\LGVirHid.sys [X] S3 LSI_FC; \SystemRoot\system32\DRIVERS\lsi_fc.sys [X] S3 LSI_SAS; \SystemRoot\system32\DRIVERS\lsi_sas.sys [X] S3 LSI_SAS2; \SystemRoot\system32\DRIVERS\lsi_sas2.sys [X] S3 LSI_SCSI; \SystemRoot\system32\DRIVERS\lsi_scsi.sys [X] S3 megasas; \SystemRoot\system32\DRIVERS\megasas.sys [X] S3 MegaSR; \SystemRoot\system32\DRIVERS\MegaSR.sys [X] S3 MEIx64; system32\DRIVERS\TeeDriverx64.sys [X] S3 monitor; system32\DRIVERS\monitor.sys [X] S3 mouclass; system32\DRIVERS\mouclass.sys [X] S3 mouhid; system32\DRIVERS\mouhid.sys [X] S3 mpio; \SystemRoot\system32\DRIVERS\mpio.sys [X] S0 msahci; system32\DRIVERS\msahci.sys [X] S3 msdsm; \SystemRoot\system32\DRIVERS\msdsm.sys [X] S0 msisadrv; system32\DRIVERS\msisadrv.sys [X] S1 mssmbios; system32\DRIVERS\mssmbios.sys [X] S3 MTConfig; \SystemRoot\system32\DRIVERS\MTConfig.sys [X] S3 nfrd960; \SystemRoot\system32\DRIVERS\nfrd960.sys [X] S3 nvraid; \SystemRoot\system32\DRIVERS\nvraid.sys [X] S3 nvstor; \SystemRoot\system32\DRIVERS\nvstor.sys [X] S3 nv_agp; \SystemRoot\system32\DRIVERS\nv_agp.sys [X] S3 ohci1394; \SystemRoot\system32\DRIVERS\ohci1394.sys [X] S3 Parport; system32\DRIVERS\parport.sys [X] S0 pci; system32\DRIVERS\pci.sys [X] S3 pciide; \SystemRoot\system32\DRIVERS\pciide.sys [X] S3 pcmcia; \SystemRoot\system32\DRIVERS\pcmcia.sys [X] S3 Processor; \SystemRoot\system32\DRIVERS\processr.sys [X] S3 ql2300; \SystemRoot\system32\DRIVERS\ql2300.sys [X] S3 ql40xx; \SystemRoot\system32\DRIVERS\ql40xx.sys [X] S3 rdpbus; system32\DRIVERS\rdpbus.sys [X] S3 RTL8167; system32\DRIVERS\Rt64win7.sys [X] S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X] S3 s3cap; \SystemRoot\system32\DRIVERS\vms3cap.sys [X] S3 sbp2port; \SystemRoot\system32\DRIVERS\sbp2port.sys [X] S3 Serenum; system32\DRIVERS\serenum.sys [X] S1 Serial; system32\DRIVERS\serial.sys [X] S3 sermouse; \SystemRoot\system32\DRIVERS\sermouse.sys [X] S3 sffdisk; \SystemRoot\system32\DRIVERS\sffdisk.sys [X] S3 sffp_mmc; \SystemRoot\system32\DRIVERS\sffp_mmc.sys [X] S3 sffp_sd; \SystemRoot\system32\DRIVERS\sffp_sd.sys [X] S3 sfloppy; \SystemRoot\system32\DRIVERS\sfloppy.sys [X] S3 SiSRaid2; \SystemRoot\system32\DRIVERS\SiSRaid2.sys [X] S3 SiSRaid4; \SystemRoot\system32\DRIVERS\sisraid4.sys [X] S3 stexstor; \SystemRoot\system32\DRIVERS\stexstor.sys [X] S0 storflt; system32\DRIVERS\vmstorfl.sys [X] S3 storvsc; \SystemRoot\system32\DRIVERS\storvsc.sys [X] S3 swenum; system32\DRIVERS\swenum.sys [X] S1 TermDD; system32\DRIVERS\termdd.sys [X] S3 uagp35; \SystemRoot\system32\DRIVERS\uagp35.sys [X] S3 uliagpkx; \SystemRoot\system32\DRIVERS\uliagpkx.sys [X] S3 umbus; system32\DRIVERS\umbus.sys [X] S3 UmPass; \SystemRoot\system32\DRIVERS\umpass.sys [X] S3 usbccgp; system32\DRIVERS\usbccgp.sys [X] S1 UsbCharger; system32\DRIVERS\UsbCharger.sys [X] S3 usbcir; \SystemRoot\system32\DRIVERS\usbcir.sys [X] S3 usbehci; system32\DRIVERS\usbehci.sys [X] S3 usbhub; system32\DRIVERS\usbhub.sys [X] S3 usbohci; \SystemRoot\system32\DRIVERS\usbohci.sys [X] S3 usbprint; \SystemRoot\system32\DRIVERS\usbprint.sys [X] S3 USBSTOR; system32\DRIVERS\USBSTOR.SYS [X] S3 usbuhci; \SystemRoot\system32\DRIVERS\usbuhci.sys [X] S0 vdrvroot; system32\DRIVERS\vdrvroot.sys [X] S3 vga; system32\DRIVERS\vgapnp.sys [X] S3 vhdmp; \SystemRoot\system32\DRIVERS\vhdmp.sys [X] S3 viaide; \SystemRoot\system32\DRIVERS\viaide.sys [X] S3 vmbus; \SystemRoot\system32\DRIVERS\vmbus.sys [X] S3 VMBusHID; \SystemRoot\system32\DRIVERS\VMBusHID.sys [X] S0 volmgr; system32\DRIVERS\volmgr.sys [X] S0 volsnap; system32\DRIVERS\volsnap.sys [X] S3 vsmraid; \SystemRoot\system32\DRIVERS\vsmraid.sys [X] S3 WacomPen; \SystemRoot\system32\DRIVERS\wacompen.sys [X] S3 Wd; \SystemRoot\system32\DRIVERS\wd.sys [X] S3 WmiAcpi; \SystemRoot\system32\DRIVERS\wmiacpi.sys [X] S3 WSDPrintDevice; system32\DRIVERS\WSDPrint.sys [X] S3 WSDScan; system32\DRIVERS\WSDScan.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-03 22:29 - 2015-11-03 22:30 - 00000000 ____D C:\FRST 2015-11-03 21:52 - 2015-11-03 21:53 - 00000000 ____D C:\Windows\System32\config\mybackup 2015-11-02 00:42 - 2015-11-02 00:42 - 00000222 _____ C:\Users\ZSpicher\Desktop\Unturned.url 2015-11-01 20:13 - 2015-11-01 20:13 - 00000000 ____D C:\Windows\System32\NgBase 2015-10-31 13:14 - 2015-10-31 13:14 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\Curve Digital 2015-10-30 19:53 - 2015-10-30 19:53 - 00000222 _____ C:\Users\ZSpicher\Desktop\Stealth Inc 2.url 2015-10-30 18:46 - 2015-11-01 16:25 - 00000168 _____ C:\Windows\setupact.log 2015-10-30 18:46 - 2015-10-30 18:46 - 00000000 _____ C:\Windows\setuperr.log 2015-10-25 19:34 - 2015-10-25 19:34 - 03076250 _____ C:\Users\ZSpicher\Downloads\AutoHotkey112207_Install.exe 2015-10-25 15:08 - 2015-10-25 15:10 - 00002273 _____ C:\Users\ZSpicher\Documents\CSGOlounge IRL Money Trade.txt 2015-10-25 03:41 - 2015-10-25 03:43 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\MEGAsync 2015-10-25 03:41 - 2015-10-25 03:41 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\Mega Limited 2015-10-24 23:26 - 2015-10-24 23:27 - 11455283 _____ C:\Users\ZSpicher\Downloads\workbench_materials.zip 2015-10-19 19:29 - 2015-10-19 19:29 - 00000000 ____D C:\ProgramData\WRData 2015-10-19 19:14 - 2015-10-19 19:26 - 00000000 ____D C:\ProgramData\HitmanPro 2015-10-18 17:46 - 2015-10-18 17:46 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\Honeyview 2015-10-17 18:01 - 2015-10-17 18:01 - 00000000 ____D C:\Windows\SysWOW64\vbox 2015-10-17 18:01 - 2015-10-17 18:01 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\AVAST Software 2015-10-17 18:00 - 2015-10-17 18:00 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-10-17 18:00 - 2015-10-17 18:00 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-10-17 17:58 - 2015-10-17 17:58 - 03459152 ____N (AVAST Software) C:\Users\Public\Documents\aswOfferTool.exe 2015-10-17 17:58 - 2015-10-17 17:58 - 00000000 ____D C:\Program Files\AVAST Software 2015-10-17 17:57 - 2015-10-17 17:57 - 00000000 ____D C:\ProgramData\AVAST Software 2015-10-17 07:29 - 2015-10-17 07:30 - 19730692 _____ C:\Users\ZSpicher\Desktop\fran.psd 2015-10-17 06:31 - 2015-10-17 15:36 - 00000000 ____D C:\Fraps 2015-10-17 04:51 - 2015-10-17 04:51 - 00000000 ____D C:\Users\ZSpicher\AppData\LocalLow\Hyper Hippo Productions Ltd_ 2015-10-17 04:50 - 2015-10-17 04:50 - 00000222 _____ C:\Users\ZSpicher\Desktop\AdVenture Capitalist.url 2015-10-15 03:25 - 2015-10-24 14:38 - 00000132 _____ C:\Users\ZSpicher\AppData\Roaming\Adobe PNG Format CS6 Prefs 2015-10-15 03:18 - 2015-10-15 03:18 - 00000000 ____D C:\Users\ZSpicher\AppData\LocalLow\Adobe 2015-10-14 23:06 - 2015-10-14 23:06 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2015-10-14 23:05 - 2015-10-14 23:06 - 00000000 ____D C:\Program Files\Adobe 2015-10-14 23:03 - 2015-10-14 23:05 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-10-14 23:01 - 2015-10-14 23:01 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2015-10-14 23:00 - 2015-10-14 23:06 - 00000000 ____D C:\Program Files\Common Files\Adobe 2015-10-14 22:58 - 2015-10-17 07:09 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\Adobe 2015-10-14 22:58 - 2015-10-16 18:10 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\Adobe 2015-10-14 22:58 - 2015-10-14 23:06 - 00000000 ____D C:\ProgramData\Adobe 2015-10-14 22:58 - 2015-10-14 22:58 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\Macromedia 2015-10-14 03:47 - 2015-10-19 19:29 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\tixati 2015-10-12 00:23 - 2015-10-12 00:23 - 00000793 _____ C:\Users\ZSpicher\Desktop\Start Tor Browser.lnk 2015-10-12 00:23 - 2015-10-12 00:23 - 00000000 ____D C:\Users\ZSpicher\Desktop\Tor Browser 2015-10-08 22:07 - 2015-10-08 22:07 - 00000967 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2015-10-08 22:07 - 2015-10-08 22:07 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2015-10-08 22:06 - 2015-10-08 22:06 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\Overwolf 2015-10-07 18:47 - 2015-10-28 02:31 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\OBS 2015-10-07 17:19 - 2015-10-07 17:19 - 00000000 ____D C:\Users\ZSpicher\Documents\Lightshot 2015-10-06 13:49 - 2015-10-06 13:49 - 00003584 _____ C:\Users\ZSpicher\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-10-06 13:47 - 2015-10-06 13:47 - 00000896 _____ C:\Users\Public\Desktop\Honeyview.lnk 2015-10-06 13:47 - 2015-10-06 13:47 - 00000000 ____D C:\Program Files\Honeyview 2015-10-06 13:46 - 2015-11-03 06:42 - 00000394 _____ C:\Windows\Tasks\update-sys.job 2015-10-06 13:46 - 2015-11-03 05:46 - 00000394 _____ C:\Windows\Tasks\update-S-1-5-21-1458460487-2957040447-3217016352-1000.job 2015-10-06 13:46 - 2015-10-19 19:37 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-10-06 13:46 - 2015-10-19 19:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-10-06 13:46 - 2015-10-06 13:53 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\MPC-HC 2015-10-06 13:46 - 2015-10-06 13:46 - 00001702 _____ C:\Users\ZSpicher\Desktop\MPC-HC x64.lnk 2015-10-06 13:46 - 2015-10-06 13:46 - 00000424 _____ C:\Users\ZSpicher\AppData\Local\UserProducts.xml 2015-10-06 13:46 - 2015-10-06 13:46 - 00000003 _____ C:\Users\ZSpicher\AppData\Local\updater.log 2015-10-06 13:46 - 2015-10-06 13:46 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-10-06 13:46 - 2015-10-06 13:46 - 00000000 ____D C:\Program Files\MPC-HC 2015-10-06 13:46 - 2015-10-06 13:46 - 00000000 ____D C:\Program Files (x86)\Skillbrains 2015-10-06 13:45 - 2015-10-20 18:09 - 00000000 ____D C:\Program Files\OBS 2015-10-06 13:45 - 2015-10-19 19:37 - 00000000 ____D C:\Program Files\Defraggler 2015-10-06 13:45 - 2015-10-06 13:45 - 00001724 _____ C:\Users\Public\Desktop\Defraggler.lnk 2015-10-06 13:45 - 2015-10-06 13:45 - 00000939 _____ C:\Users\ZSpicher\Desktop\Open Broadcaster Software.lnk 2015-10-06 13:45 - 2015-10-06 13:45 - 00000784 _____ C:\Users\ZSpicher\Desktop\Tixati.lnk 2015-10-06 13:45 - 2015-10-06 13:45 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\FluxSoftware 2015-10-06 13:45 - 2015-10-06 13:45 - 00000000 ____D C:\Program Files (x86)\OBS 2015-10-06 13:45 - 2015-10-06 13:45 - 00000000 ____D C:\Program Files (x86)\Combined Community Codec Pack 2015-10-06 13:44 - 2015-10-06 13:45 - 00000000 ____D C:\Program Files\tixati 2015-10-06 13:42 - 2015-10-06 13:49 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\IrfanView ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-03 08:40 - 2015-09-17 00:56 - 00000000 ____D C:\Program Files (x86)\Steam 2015-11-03 08:40 - 2015-09-17 00:16 - 01201959 _____ C:\Windows\WindowsUpdate.log 2015-11-03 08:29 - 2015-09-17 00:19 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-11-03 01:05 - 2015-09-17 18:13 - 00000000 ____D C:\Users\ZSpicher\AppData\Roaming\Mumble 2015-11-03 00:29 - 2015-09-17 00:19 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\winevt 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\sysprep 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\spool 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\SMI 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\Setup 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\oobe 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\MUI 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\Msdtc 2015-11-01 19:14 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\com 2015-10-30 23:59 - 2015-09-17 01:00 - 00000219 _____ C:\Users\ZSpicher\Desktop\Counter-Strike Global Offensive.url 2015-10-30 18:47 - 2015-09-17 22:08 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2015-10-30 18:46 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-10-25 19:37 - 2009-07-13 23:46 - 00000000 ____D C:\Windows\ShellNew 2015-10-23 04:31 - 2015-09-17 00:19 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-10-19 16:33 - 2015-09-17 17:39 - 00030528 _____ C:\Windows\GVTDrv64.sys 2015-10-19 16:33 - 2015-09-17 17:39 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2015-10-19 16:33 - 2015-09-17 17:39 - 00000004 _____ C:\Windows\SysWOW64\GVTunner.ref 2015-10-16 22:07 - 2015-09-17 09:08 - 00000000 ____D C:\Windows\Minidump 2015-10-15 02:30 - 2015-09-17 00:55 - 00057560 _____ C:\Users\ZSpicher\AppData\Local\GDIPFONTCACHEV1.DAT 2015-10-12 16:35 - 2009-07-13 23:45 - 00000000 ___RD C:\Users\Public\Recorded TV 2015-10-08 13:11 - 2015-09-17 00:57 - 00000000 ____D C:\Users\ZSpicher\AppData\Local\Steam 2015-10-06 13:49 - 2015-09-17 00:47 - 00000000 ____D C:\Program Files (x86)\Raptr ==================== Known DLLs (Whitelisted) ========================= ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\dnsapi.dll => MD5 is legit C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys IS MISSING <==== ATTENTION C:\Windows\System32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION ==================== EXE Association (Whitelisted) ============= ==================== Restore Points ========================= Restore point date: 2015-10-19 19:23 Restore point date: 2015-10-31 17:09 Restore point date: 2015-11-01 19:10 Restore point date: 2015-11-02 23:18 ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 8091.94 MB Available physical RAM: 7362.15 MB Total Virtual: 8090.09 MB Available Virtual: 7346.91 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:831.21 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (R9K) (Removable) (Total:3.8 GB) (Free:3.57 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F5153338) Partition 1: (Active) - (Size=931.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 3.8 GB) (Disk ID: 33456F38) Partition 1: (Active) - (Size=3.8 GB) - (Type=06) LastRegBack: 2015-10-31 15:20 ==================== End of FRST.txt ============================