This is the Fresh FRST log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017
Ran by Alex (administrator) on ALEXSPC (08-03-2017 16:20:12)
Running from C:\Users\Alex\Desktop
Loaded Profiles: Alex (Available Profiles: Alex)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Electronic Arts) D:\Program Files\Origin\OriginWebHelperService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Verto Analytics Inc.) C:\Program Files (x86)\SmartApp\SmartAppMonitor.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Verto Analytics Inc.) C:\Program Files (x86)\SmartApp\SmartApp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Valve Corporation) D:\Program Files\Steam.exe
(Flux Software LLC) C:\Users\Alex\AppData\Local\FluxSoftware\Flux\flux.exe
(Rainmeter) C:\Program Files\Rainmeter\Rainmeter.exe
(Corsair Components, Inc.) D:\Program Files\Corsair\Corsair Utility Engine\CorsairHID.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Valve Corporation) D:\Program Files\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.693_none_42ff55c9655f38bf\TiWorker.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-26] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17305208 2016-12-08] (Logitech Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-06] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2016-09-28] (Raptr, Inc)
HKLM-x32\...\Run: [Corsair Utility Engine] => D:\Program Files\Corsair\Corsair Utility Engine\CorsairHID.exe [14885552 2016-03-23] (Corsair Components, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Steam] => D:\Program Files\steam.exe [2881824 2017-01-18] (Valve Corporation)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27427808 2017-02-08] (Skype Technologies S.A.)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Discord] => C:\Users\Alex\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [3970112 2016-11-28] (GOG.com)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [f.lux] => C:\Users\Alex\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Chromium] => "c:\users\alex\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2016-08-30] ()
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2017-01-19]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Rainmeter)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-482574108-2876646391-2450146034-1001] => Proxy is enabled.
ProxyServer: [S-1-5-21-482574108-2876646391-2450146034-1001] => http=127.0.0.1:64550;https=127.0.0.1:64550
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0efaab83-d67b-48ad-8f6c-a73e40ad1d2a}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{0efaab83-d67b-48ad-8f6c-a73e40ad1d2a}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7c160b3a-5445-4256-9fc0-e44e6feddd46}: [NameServer] 173.244.211.97,8.8.8.8
Tcpip\..\Interfaces\{80fe19d2-3f40-431f-ba78-c6175d1cfaad}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{999cdded-6345-4aba-ba99-46751f4637de}: [DhcpNameServer] 192.168.1.1
ManualProxies: 1http=127.0.0.1:64550;https=127.0.0.1:64550
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-19c53ff0
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-19c53ff0
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-19c53ff0
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21] (Oracle Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF DefaultProfile: xzezvwlb.default
FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xzezvwlb.default [2017-02-24]
FF Extension: (All Aboard) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xzezvwlb.default\Extensions\@all-aboard-v1 [2016-07-26]
FF Extension: (Notification Manager) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xzezvwlb.default\Extensions\{1ACA5BE8-BFF0-B122-637B-00976A61FF79} [2017-02-08] [not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-482574108-2876646391-2450146034-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Alex\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-07-14] (Unity Technologies ApS)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://mystart.incredibar.com/?a=6Oz8ZpUKl9&loc=skw
CHR StartupUrls: Default -> "","hxxp://mystart.incredibar.com/?a=6R9m9Z7cl4&i=26&loc=skw","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.0.5.292&pid=safeguard&sg=0&sap=hp","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.0.443&pid=safeguard&sg=0&sap=hp","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.5.512&pid=safeguard&sg=0&sap=hp","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.7.598&pid=safeguard&sg=0&sap=hp","hxxps://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.9.786&pid=safeguard&sg=0&sap=hp","hxxps://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.9.799&pid=safeguard&sg=0&sap=hp","hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=55&CUI=&UM=8&UP=SPDE37641D-D109-4BCC-9802-91C3E5978CAE&D=061215&SSPV="
CHR Plugin: (Widevine Content Decryption Module) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\WidevineCdm\_platform_specific\win_x64\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\pepflashplayer64_24_0_0_186.dll => No File
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2017-03-08]
CHR Extension: (BetterTTV) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2016-07-28]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-22]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-22]
CHR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-12-09]
CHR Extension: (uBlock Origin) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-02-10]
CHR Extension: (8 Ball Pool Chat) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmamjkbajpfchgmmmjcffiaoilhnckei [2017-02-09]
CHR Extension: (OP.GG Summoner Search) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfnoddgekoeiljeaekobnchnedoipgpc [2016-11-25]
CHR Extension: (Google Play Music) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-03-01]
CHR Extension: (AdBlock) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-25]
CHR Extension: (KingsRoad) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbcbablgmkkdnioiekpgjfacejkfomlg [2016-06-22]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-02-15]
CHR Extension: (TwitchAlerts Stream Labels) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg [2017-01-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-22]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-02-24]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-08]
CHR Extension: (Google Slides) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-08-22]
CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-22]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-22]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-22]
CHR Extension: (Google Sheets) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-08-22]
CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-29]
CHR Extension: (Gmail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-22]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\System Profile [2017-02-24]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2016-08-11] (Advanced Micro Devices) [File not signed]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1486344 2017-02-07] ()
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [409128 2017-02-23] (EasyAntiCheat Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [284224 2016-11-28] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2016-11-17] (GOG.com)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2015-11-20] (Logitech Inc.)
S3 Origin Client Service; D:\Program Files\Origin\OriginClientService.exe [2121736 2017-01-24] (Electronic Arts)
R2 Origin Web Helper Service; D:\Program Files\Origin\OriginWebHelperService.exe [2183696 2017-01-24] (Electronic Arts)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-04] ()
S3 VSStandardCollectorService140; D:\Program Files\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-06-20] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 amdacpksd; C:\WINDOWS\system32\drivers\amdacpksd.sys [305392 2016-04-05] (Advanced Micro Devices)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0310791.inf_amd64_1a41492ddaa53f63\atikmdag.sys [28762648 2017-01-27] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0310791.inf_amd64_1a41492ddaa53f63\atikmpag.sys [530968 2017-01-27] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47840 2016-01-20] (Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21728 2016-01-20] (Corsair)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-12-08] (Logitech Inc.)
S3 mt7612US; C:\WINDOWS\System32\drivers\mt7612US.sys [377864 2015-12-09] (MediaTek Inc.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 netr28ux; C:\WINDOWS\System32\drivers\netr28ux.sys [2224128 2016-07-16] (MediaTek Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-22] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-08 16:17 - 2017-03-08 16:17 - 00004613 _____ C:\Users\Alex\Desktop\AdwCleaner[C0].txt
2017-03-08 16:08 - 2017-03-08 16:16 - 00000000 ____D C:\AdwCleaner
2017-03-08 16:08 - 2017-03-08 16:08 - 04031440 _____ C:\Users\Alex\Desktop\AdwCleaner.exe
2017-03-08 15:24 - 2017-03-08 15:24 - 00412660 _____ C:\WINDOWS\Minidump\030817-6031-01.dmp
2017-03-07 10:40 - 2017-03-07 10:40 - 00412692 _____ C:\WINDOWS\Minidump\030717-6000-01.dmp
2017-03-03 23:09 - 2017-03-03 23:09 - 00412484 _____ C:\WINDOWS\Minidump\030317-6015-01.dmp
2017-03-03 09:40 - 2017-03-08 16:17 - 00004414 _____ C:\WINDOWS\System32\Tasks\SmartAppLiveUpdater
2017-03-02 23:39 - 2017-03-08 16:16 - 00003360 _____ C:\WINDOWS\System32\Tasks\SmartAppMonitor
2017-03-02 01:27 - 2017-03-02 01:27 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Mastfire Studios
2017-03-01 20:11 - 2017-03-03 09:40 - 00000000 ____D C:\Users\Alex\AppData\Local\Verto Analytics
2017-02-25 02:51 - 2017-02-25 02:51 - 00000537 _____ C:\Users\Public\Desktop\Overwatch Test.lnk
2017-02-25 02:51 - 2017-02-25 02:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch Test
2017-02-24 10:42 - 2017-02-24 10:45 - 00000688 _____ C:\Users\Alex\Desktop\JRT.txt
2017-02-24 10:37 - 2017-03-08 16:19 - 00000000 ____D C:\Users\Alex\Desktop\FRST-OlderVersion
2017-02-24 10:37 - 2017-02-24 10:37 - 00005840 _____ C:\Users\Alex\Desktop\Fixlog.txt
2017-02-24 02:59 - 2017-03-08 16:20 - 00021125 _____ C:\Users\Alex\Desktop\FRST.txt
2017-02-23 23:05 - 2017-03-08 16:19 - 02423808 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe
2017-02-23 22:58 - 2017-02-23 22:58 - 00356516 _____ C:\WINDOWS\Minidump\022317-6390-01.dmp
2017-02-22 21:19 - 2017-02-22 21:19 - 00001100 _____ C:\Users\Alex\Desktop\WinDirStat.lnk
2017-02-22 21:19 - 2017-02-22 21:19 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinDirStat
2017-02-22 21:19 - 2017-02-22 21:19 - 00000000 ____D C:\Program Files (x86)\WinDirStat
2017-02-22 20:39 - 2017-02-22 20:39 - 00000044 _____ C:\Users\Alex\Documents\TS recovery key.txt
2017-02-22 20:38 - 2017-02-22 21:18 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TS3Client
2017-02-22 20:38 - 2017-02-22 20:38 - 00000970 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2017-02-22 20:38 - 2017-02-22 20:38 - 00000000 ____D C:\Users\Alex\AppData\Local\TeamSpeak 3
2017-02-22 20:38 - 2017-02-22 20:38 - 00000000 ____D C:\Users\Alex\.TeamSpeak 3
2017-02-22 20:38 - 2017-02-22 20:38 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2017-02-17 23:56 - 2017-03-08 16:20 - 00000000 ____D C:\FRST
2017-02-17 23:54 - 2017-02-17 23:54 - 00543684 _____ C:\WINDOWS\Minidump\021717-6140-01.dmp
2017-02-15 17:07 - 2017-02-15 17:07 - 00543652 _____ C:\WINDOWS\Minidump\021517-8078-01.dmp
2017-02-15 01:38 - 2017-02-23 13:10 - 00000000 ____D C:\Users\Alex\AppData\Roaming\EasyAntiCheat
2017-02-15 01:38 - 2017-02-15 01:38 - 00000000 ____D C:\ProgramData\For Honor Data
2017-02-14 12:39 - 2017-02-14 12:40 - 00412612 _____ C:\WINDOWS\Minidump\021417-5984-01.dmp
2017-02-08 21:23 - 2017-02-08 21:23 - 00000000 ____D C:\Users\Alex\.Plays.tv
2017-02-08 00:26 - 2017-02-08 17:03 - 00000000 ____D C:\Users\Alex\AppData\Local\Oqdlics
2017-02-07 16:34 - 2017-02-07 16:34 - 00003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2017-02-07 16:34 - 2017-02-07 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2017-02-07 16:32 - 2017-02-07 16:32 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\AMD
2017-02-07 16:25 - 2017-02-07 16:28 - 34390000 _____ (AMD Inc.) C:\Users\Alex\Downloads\radeon-crimson-relive-17.1.2-minimalsetup-170130_64bit.exe
2017-02-07 16:19 - 2017-02-07 16:19 - 00412660 _____ C:\WINDOWS\Minidump\020717-5671-01.dmp
2017-02-07 00:25 - 2017-02-08 00:25 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Metal.Gear.Solid.V.The.Phantom.Pain-ALI213
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-08 16:18 - 2016-12-16 23:00 - 00000000 ____D C:\Users\Alex\AppData\Local\Personify
2017-03-08 16:16 - 2016-08-16 10:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-08 16:16 - 2016-08-16 10:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-03-08 16:16 - 2016-07-16 01:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-03-08 16:15 - 2016-08-16 10:21 - 00000000 ____D C:\Users\Alex
2017-03-08 15:30 - 2016-08-16 10:21 - 02545600 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-08 15:24 - 2016-08-24 22:38 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-08 15:24 - 2016-08-16 10:20 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-08 15:24 - 2016-06-22 22:57 - 1350516210 _____ C:\WINDOWS\MEMORY.DMP
2017-03-05 01:52 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\rescache
2017-03-03 09:38 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-03 00:17 - 2016-07-27 13:02 - 00000000 ____D C:\Users\Alex\AppData\Local\Battle.net
2017-03-03 00:17 - 2016-06-22 21:27 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-03-02 23:39 - 2016-06-27 10:34 - 00000000 ____D C:\Program Files (x86)\SmartApp
2017-03-02 23:11 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-01 20:39 - 2016-09-17 15:58 - 00000000 ____D C:\Users\Alex\AppData\Roaming\StardewValley
2017-03-01 20:37 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-01 17:39 - 2016-07-17 18:39 - 00000000 ____D C:\Users\Alex\AppData\Roaming\BitTorrent
2017-02-28 23:50 - 2016-06-22 23:03 - 00000000 ____D C:\Program Files (x86)\Overwatch
2017-02-28 23:43 - 2016-07-11 20:48 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2017-02-28 13:26 - 2016-07-16 01:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-27 00:50 - 2016-06-23 00:24 - 00000000 ____D C:\Users\Alex\AppData\Local\Ubisoft Game Launcher
2017-02-27 00:23 - 2016-08-21 22:37 - 00575528 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2017-02-25 12:05 - 2016-06-22 23:09 - 00000000 ____D C:\Users\Alex\AppData\Local\Razer
2017-02-25 12:05 - 2016-06-22 23:00 - 00000000 ____D C:\ProgramData\Razer
2017-02-25 12:05 - 2016-06-22 22:59 - 00000000 ____D C:\Program Files (x86)\Razer
2017-02-24 10:39 - 2017-01-29 00:12 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-02-23 22:59 - 2016-06-23 00:19 - 00000000 ____D C:\Users\Alex\AppData\Roaming\OBS
2017-02-23 13:10 - 2015-12-15 04:32 - 00000000 ____D C:\Users\Alex\Documents\My Games
2017-02-23 12:05 - 2016-08-21 22:37 - 00409128 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
2017-02-23 11:32 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-23 11:31 - 2016-06-24 08:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-23 03:18 - 2016-06-24 08:46 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-22 01:52 - 2016-01-29 10:41 - 00000000 ____D C:\Users\Alex\Documents\Darkest
2017-02-20 21:24 - 2016-09-11 19:01 - 00000000 ____D C:\Users\Alex\AppData\Roaming\obs-studio
2017-02-20 12:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-20 12:08 - 2017-01-16 20:09 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2017-02-20 12:08 - 2016-07-09 18:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-02-20 12:03 - 2016-06-22 21:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
2017-02-20 12:03 - 2016-06-22 21:35 - 00000000 ____D C:\Program Files (x86)\Raptr Inc
2017-02-20 11:53 - 2016-09-16 15:17 - 00000000 ____D C:\Users\Alex\.tmcbeans-installer
2017-02-20 11:42 - 2016-07-16 06:47 - 00000000 __RHD C:\Users\Public\Libraries
2017-02-20 11:42 - 2016-07-06 11:02 - 00000000 ____D C:\Users\Alex\AppData\Local\BlueStacks
2017-02-20 00:09 - 2016-06-27 10:46 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Skype
2017-02-19 20:22 - 2016-06-27 10:46 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-02-19 20:22 - 2016-06-27 10:46 - 00000000 ____D C:\ProgramData\Skype
2017-02-17 23:54 - 2016-10-21 22:30 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-02-17 23:54 - 2016-10-21 22:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-15 19:34 - 2016-10-21 22:30 - 00003964 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-15 19:34 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-15 19:34 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-14 12:39 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-02-14 01:18 - 2016-06-22 23:09 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-09 23:15 - 2016-02-13 08:20 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-08 02:04 - 2016-08-19 00:10 - 00000000 ____D C:\Users\Alex\AppData\Local\Arma 3 Launcher
2017-02-08 02:03 - 2016-08-19 00:14 - 00000000 ____D C:\Users\Alex\AppData\Local\Arma 3
2017-02-07 16:32 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-07 16:32 - 2016-06-22 21:33 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-07 16:29 - 2017-01-10 12:03 - 00000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2017-02-07 16:28 - 2015-12-15 05:53 - 00000000 ____D C:\AMD
2017-02-07 00:35 - 2016-08-22 22:50 - 00000000 ____D C:\Users\Alex\Documents\CPY_SAVES
2017-02-06 20:23 - 2016-09-23 12:13 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-06 20:23 - 2016-09-23 12:13 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-06 14:48 - 2016-07-16 06:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 14:48 - 2016-07-16 06:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2016-06-17 01:54 - 2016-06-17 01:54 - 0000217 _____ () C:\Users\Alex\AppData\Roaming\10-unhinted.conf
2016-06-17 01:54 - 2016-06-17 01:54 - 0000524 _____ () C:\Users\Alex\AppData\Roaming\159 dk orange bl 1.ADO
2016-06-17 01:54 - 2016-06-17 01:54 - 0000303 _____ () C:\Users\Alex\AppData\Roaming\3.png
2016-06-17 01:54 - 2016-06-17 01:54 - 0001283 _____ () C:\Users\Alex\AppData\Roaming\404-1.htm
2016-06-17 01:54 - 2016-06-17 01:54 - 0004365 _____ () C:\Users\Alex\AppData\Roaming\Adobe-CNS1-4
2016-06-17 01:54 - 2016-06-17 01:54 - 0002190 _____ () C:\Users\Alex\AppData\Roaming\annotation.css.xml
2016-06-17 01:54 - 2016-06-17 01:54 - 0000379 _____ () C:\Users\Alex\AppData\Roaming\AsapiLoggerConfig.xml
2016-06-17 01:53 - 2016-06-17 01:53 - 0000027 _____ () C:\Users\Alex\AppData\Roaming\AST4
2016-06-17 01:53 - 2016-06-17 01:53 - 0004205 _____ () C:\Users\Alex\AppData\Roaming\back.png
2016-06-17 01:53 - 2016-06-17 01:53 - 0000430 _____ () C:\Users\Alex\AppData\Roaming\doc_to_epub.xsl
2016-06-17 01:53 - 2016-06-17 01:53 - 0002385 _____ () C:\Users\Alex\AppData\Roaming\dsfksvcsw2k.inf
2016-06-17 01:53 - 2016-06-17 01:53 - 0003749 _____ () C:\Users\Alex\AppData\Roaming\ExampleAWTViewer.java
2016-06-17 01:53 - 2016-06-17 01:53 - 0001194 _____ () C:\Users\Alex\AppData\Roaming\f39.png
2016-06-17 01:53 - 2016-06-17 01:53 - 0001150 _____ () C:\Users\Alex\AppData\Roaming\fast_forward.png
2016-06-17 01:53 - 2016-06-17 01:53 - 0003405 _____ () C:\Users\Alex\AppData\Roaming\finphon.env
2016-06-17 01:53 - 2016-06-17 01:53 - 0000935 _____ () C:\Users\Alex\AppData\Roaming\glossterm.width.xml
2016-06-17 01:52 - 2016-06-17 01:52 - 0000518 _____ () C:\Users\Alex\AppData\Roaming\goURL_lr_photoshop_fr.csv
2016-06-17 01:52 - 2016-06-17 01:52 - 0000518 _____ () C:\Users\Alex\AppData\Roaming\goURL_lr_photoshop_jp.csv
2016-06-17 01:52 - 2016-06-17 01:52 - 0000524 _____ () C:\Users\Alex\AppData\Roaming\gray 423 bl soft.ADO
2013-11-13 03:00 - 2013-11-13 03:00 - 0049948 _____ () C:\Users\Alex\AppData\Roaming\Plangency.P
1989-01-27 03:00 - 1989-01-27 03:00 - 0003406 _____ () C:\Users\Alex\AppData\Roaming\Stereophony.t
2016-12-03 21:56 - 2016-12-03 21:56 - 0007605 _____ () C:\Users\Alex\AppData\Local\Resmon.ResmonCfg
2016-12-20 23:03 - 2016-11-23 08:37 - 0000570 _____ () C:\Users\Alex\AppData\Local\TroubleshooterConfig.json
2016-06-23 00:12 - 2016-06-23 00:12 - 0000003 _____ () C:\Users\Alex\AppData\Local\updater.log
2016-06-23 00:12 - 2016-08-06 21:17 - 0000424 _____ () C:\Users\Alex\AppData\Local\UserProducts.xml
2016-08-16 10:20 - 2016-08-16 10:20 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-01-10 12:03 - 2017-02-07 16:29 - 0000060 _____ () C:\ProgramData\SoftwareUpdateTemp.xml
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-05 00:51
==================== End of FRST.txt ============================Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017
Ran by Alex (administrator) on ALEXSPC (08-03-2017 16:20:12)
Running from C:\Users\Alex\Desktop
Loaded Profiles: Alex (Available Profiles: Alex)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Electronic Arts) D:\Program Files\Origin\OriginWebHelperService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Verto Analytics Inc.) C:\Program Files (x86)\SmartApp\SmartAppMonitor.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Verto Analytics Inc.) C:\Program Files (x86)\SmartApp\SmartApp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Valve Corporation) D:\Program Files\Steam.exe
(Flux Software LLC) C:\Users\Alex\AppData\Local\FluxSoftware\Flux\flux.exe
(Rainmeter) C:\Program Files\Rainmeter\Rainmeter.exe
(Corsair Components, Inc.) D:\Program Files\Corsair\Corsair Utility Engine\CorsairHID.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Valve Corporation) D:\Program Files\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.693_none_42ff55c9655f38bf\TiWorker.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8844032 2016-01-26] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [17305208 2016-12-08] (Logitech Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-06] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2016-09-28] (Raptr, Inc)
HKLM-x32\...\Run: [Corsair Utility Engine] => D:\Program Files\Corsair\Corsair Utility Engine\CorsairHID.exe [14885552 2016-03-23] (Corsair Components, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Steam] => D:\Program Files\steam.exe [2881824 2017-01-18] (Valve Corporation)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27427808 2017-02-08] (Skype Technologies S.A.)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Discord] => C:\Users\Alex\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [3970112 2016-11-28] (GOG.com)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [f.lux] => C:\Users\Alex\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\...\Run: [Chromium] => "c:\users\alex\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2016-08-30] ()
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2017-01-19]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Rainmeter)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-482574108-2876646391-2450146034-1001] => Proxy is enabled.
ProxyServer: [S-1-5-21-482574108-2876646391-2450146034-1001] => http=127.0.0.1:64550;https=127.0.0.1:64550
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0efaab83-d67b-48ad-8f6c-a73e40ad1d2a}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{0efaab83-d67b-48ad-8f6c-a73e40ad1d2a}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7c160b3a-5445-4256-9fc0-e44e6feddd46}: [NameServer] 173.244.211.97,8.8.8.8
Tcpip\..\Interfaces\{80fe19d2-3f40-431f-ba78-c6175d1cfaad}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{999cdded-6345-4aba-ba99-46751f4637de}: [DhcpNameServer] 192.168.1.1
ManualProxies: 1http=127.0.0.1:64550;https=127.0.0.1:64550
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-19c53ff0
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-19c53ff0
HKU\S-1-5-21-482574108-2876646391-2450146034-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-19c53ff0
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-19c53ff0&q={searchTerms}
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21] (Oracle Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF DefaultProfile: xzezvwlb.default
FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xzezvwlb.default [2017-02-24]
FF Extension: (All Aboard) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xzezvwlb.default\Extensions\@all-aboard-v1 [2016-07-26]
FF Extension: (Notification Manager) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\xzezvwlb.default\Extensions\{1ACA5BE8-BFF0-B122-637B-00976A61FF79} [2017-02-08] [not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-482574108-2876646391-2450146034-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Alex\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-07-14] (Unity Technologies ApS)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://mystart.incredibar.com/?a=6Oz8ZpUKl9&loc=skw
CHR StartupUrls: Default -> "","hxxp://mystart.incredibar.com/?a=6R9m9Z7cl4&i=26&loc=skw","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.0.5.292&pid=safeguard&sg=0&sap=hp","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.0.443&pid=safeguard&sg=0&sap=hp","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.5.512&pid=safeguard&sg=0&sap=hp","hxxp://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.7.598&pid=safeguard&sg=0&sap=hp","hxxps://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.9.786&pid=safeguard&sg=0&sap=hp","hxxps://mysearch.avg.com?cid={EAC1DF63-03D4-4D08-AA9D-6884E1AF8A6D}&mid=115329c8301347d6a438b1a22fbcac4a-d47c504e3b45933e927aff2f306beaa1108f39d0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-09-26 19:46:02&v=18.1.9.799&pid=safeguard&sg=0&sap=hp","hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=55&CUI=&UM=8&UP=SPDE37641D-D109-4BCC-9802-91C3E5978CAE&D=061215&SSPV="
CHR Plugin: (Widevine Content Decryption Module) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\WidevineCdm\_platform_specific\win_x64\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\pepflashplayer64_24_0_0_186.dll => No File
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2017-03-08]
CHR Extension: (BetterTTV) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2016-07-28]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-22]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-22]
CHR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-12-09]
CHR Extension: (uBlock Origin) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-02-10]
CHR Extension: (8 Ball Pool Chat) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmamjkbajpfchgmmmjcffiaoilhnckei [2017-02-09]
CHR Extension: (OP.GG Summoner Search) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfnoddgekoeiljeaekobnchnedoipgpc [2016-11-25]
CHR Extension: (Google Play Music) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-03-01]
CHR Extension: (AdBlock) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-25]
CHR Extension: (KingsRoad) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbcbablgmkkdnioiekpgjfacejkfomlg [2016-06-22]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-02-15]
CHR Extension: (TwitchAlerts Stream Labels) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg [2017-01-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-22]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-02-24]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-08]
CHR Extension: (Google Slides) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-08-22]
CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-22]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-22]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-22]
CHR Extension: (Google Sheets) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-08-22]
CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-29]
CHR Extension: (Gmail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-22]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\System Profile [2017-02-24]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2016-08-11] (Advanced Micro Devices) [File not signed]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1486344 2017-02-07] ()
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [409128 2017-02-23] (EasyAntiCheat Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [284224 2016-11-28] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6625856 2016-11-17] (GOG.com)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2015-11-20] (Logitech Inc.)
S3 Origin Client Service; D:\Program Files\Origin\OriginClientService.exe [2121736 2017-01-24] (Electronic Arts)
R2 Origin Web Helper Service; D:\Program Files\Origin\OriginWebHelperService.exe [2183696 2017-01-24] (Electronic Arts)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-04] ()
S3 VSStandardCollectorService140; D:\Program Files\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-06-20] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 amdacpksd; C:\WINDOWS\system32\drivers\amdacpksd.sys [305392 2016-04-05] (Advanced Micro Devices)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0310791.inf_amd64_1a41492ddaa53f63\atikmdag.sys [28762648 2017-01-27] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0310791.inf_amd64_1a41492ddaa53f63\atikmpag.sys [530968 2017-01-27] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47840 2016-01-20] (Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21728 2016-01-20] (Corsair)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-12-08] (Logitech Inc.)
S3 mt7612US; C:\WINDOWS\System32\drivers\mt7612US.sys [377864 2015-12-09] (MediaTek Inc.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 netr28ux; C:\WINDOWS\System32\drivers\netr28ux.sys [2224128 2016-07-16] (MediaTek Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-09-22] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-08 16:17 - 2017-03-08 16:17 - 00004613 _____ C:\Users\Alex\Desktop\AdwCleaner[C0].txt
2017-03-08 16:08 - 2017-03-08 16:16 - 00000000 ____D C:\AdwCleaner
2017-03-08 16:08 - 2017-03-08 16:08 - 04031440 _____ C:\Users\Alex\Desktop\AdwCleaner.exe
2017-03-08 15:24 - 2017-03-08 15:24 - 00412660 _____ C:\WINDOWS\Minidump\030817-6031-01.dmp
2017-03-07 10:40 - 2017-03-07 10:40 - 00412692 _____ C:\WINDOWS\Minidump\030717-6000-01.dmp
2017-03-03 23:09 - 2017-03-03 23:09 - 00412484 _____ C:\WINDOWS\Minidump\030317-6015-01.dmp
2017-03-03 09:40 - 2017-03-08 16:17 - 00004414 _____ C:\WINDOWS\System32\Tasks\SmartAppLiveUpdater
2017-03-02 23:39 - 2017-03-08 16:16 - 00003360 _____ C:\WINDOWS\System32\Tasks\SmartAppMonitor
2017-03-02 01:27 - 2017-03-02 01:27 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Mastfire Studios
2017-03-01 20:11 - 2017-03-03 09:40 - 00000000 ____D C:\Users\Alex\AppData\Local\Verto Analytics
2017-02-25 02:51 - 2017-02-25 02:51 - 00000537 _____ C:\Users\Public\Desktop\Overwatch Test.lnk
2017-02-25 02:51 - 2017-02-25 02:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch Test
2017-02-24 10:42 - 2017-02-24 10:45 - 00000688 _____ C:\Users\Alex\Desktop\JRT.txt
2017-02-24 10:37 - 2017-03-08 16:19 - 00000000 ____D C:\Users\Alex\Desktop\FRST-OlderVersion
2017-02-24 10:37 - 2017-02-24 10:37 - 00005840 _____ C:\Users\Alex\Desktop\Fixlog.txt
2017-02-24 02:59 - 2017-03-08 16:20 - 00021125 _____ C:\Users\Alex\Desktop\FRST.txt
2017-02-23 23:05 - 2017-03-08 16:19 - 02423808 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe
2017-02-23 22:58 - 2017-02-23 22:58 - 00356516 _____ C:\WINDOWS\Minidump\022317-6390-01.dmp
2017-02-22 21:19 - 2017-02-22 21:19 - 00001100 _____ C:\Users\Alex\Desktop\WinDirStat.lnk
2017-02-22 21:19 - 2017-02-22 21:19 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinDirStat
2017-02-22 21:19 - 2017-02-22 21:19 - 00000000 ____D C:\Program Files (x86)\WinDirStat
2017-02-22 20:39 - 2017-02-22 20:39 - 00000044 _____ C:\Users\Alex\Documents\TS recovery key.txt
2017-02-22 20:38 - 2017-02-22 21:18 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TS3Client
2017-02-22 20:38 - 2017-02-22 20:38 - 00000970 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2017-02-22 20:38 - 2017-02-22 20:38 - 00000000 ____D C:\Users\Alex\AppData\Local\TeamSpeak 3
2017-02-22 20:38 - 2017-02-22 20:38 - 00000000 ____D C:\Users\Alex\.TeamSpeak 3
2017-02-22 20:38 - 2017-02-22 20:38 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2017-02-17 23:56 - 2017-03-08 16:20 - 00000000 ____D C:\FRST
2017-02-17 23:54 - 2017-02-17 23:54 - 00543684 _____ C:\WINDOWS\Minidump\021717-6140-01.dmp
2017-02-15 17:07 - 2017-02-15 17:07 - 00543652 _____ C:\WINDOWS\Minidump\021517-8078-01.dmp
2017-02-15 01:38 - 2017-02-23 13:10 - 00000000 ____D C:\Users\Alex\AppData\Roaming\EasyAntiCheat
2017-02-15 01:38 - 2017-02-15 01:38 - 00000000 ____D C:\ProgramData\For Honor Data
2017-02-14 12:39 - 2017-02-14 12:40 - 00412612 _____ C:\WINDOWS\Minidump\021417-5984-01.dmp
2017-02-08 21:23 - 2017-02-08 21:23 - 00000000 ____D C:\Users\Alex\.Plays.tv
2017-02-08 00:26 - 2017-02-08 17:03 - 00000000 ____D C:\Users\Alex\AppData\Local\Oqdlics
2017-02-07 16:34 - 2017-02-07 16:34 - 00003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2017-02-07 16:34 - 2017-02-07 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2017-02-07 16:32 - 2017-02-07 16:32 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\AMD
2017-02-07 16:25 - 2017-02-07 16:28 - 34390000 _____ (AMD Inc.) C:\Users\Alex\Downloads\radeon-crimson-relive-17.1.2-minimalsetup-170130_64bit.exe
2017-02-07 16:19 - 2017-02-07 16:19 - 00412660 _____ C:\WINDOWS\Minidump\020717-5671-01.dmp
2017-02-07 00:25 - 2017-02-08 00:25 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Metal.Gear.Solid.V.The.Phantom.Pain-ALI213
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-08 16:18 - 2016-12-16 23:00 - 00000000 ____D C:\Users\Alex\AppData\Local\Personify
2017-03-08 16:16 - 2016-08-16 10:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-08 16:16 - 2016-08-16 10:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-03-08 16:16 - 2016-07-16 01:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-03-08 16:15 - 2016-08-16 10:21 - 00000000 ____D C:\Users\Alex
2017-03-08 15:30 - 2016-08-16 10:21 - 02545600 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-08 15:24 - 2016-08-24 22:38 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-08 15:24 - 2016-08-16 10:20 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-08 15:24 - 2016-06-22 22:57 - 1350516210 _____ C:\WINDOWS\MEMORY.DMP
2017-03-05 01:52 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\rescache
2017-03-03 09:38 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-03 00:17 - 2016-07-27 13:02 - 00000000 ____D C:\Users\Alex\AppData\Local\Battle.net
2017-03-03 00:17 - 2016-06-22 21:27 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-03-02 23:39 - 2016-06-27 10:34 - 00000000 ____D C:\Program Files (x86)\SmartApp
2017-03-02 23:11 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-01 20:39 - 2016-09-17 15:58 - 00000000 ____D C:\Users\Alex\AppData\Roaming\StardewValley
2017-03-01 20:37 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-01 17:39 - 2016-07-17 18:39 - 00000000 ____D C:\Users\Alex\AppData\Roaming\BitTorrent
2017-02-28 23:50 - 2016-06-22 23:03 - 00000000 ____D C:\Program Files (x86)\Overwatch
2017-02-28 23:43 - 2016-07-11 20:48 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2017-02-28 13:26 - 2016-07-16 01:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-27 00:50 - 2016-06-23 00:24 - 00000000 ____D C:\Users\Alex\AppData\Local\Ubisoft Game Launcher
2017-02-27 00:23 - 2016-08-21 22:37 - 00575528 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2017-02-25 12:05 - 2016-06-22 23:09 - 00000000 ____D C:\Users\Alex\AppData\Local\Razer
2017-02-25 12:05 - 2016-06-22 23:00 - 00000000 ____D C:\ProgramData\Razer
2017-02-25 12:05 - 2016-06-22 22:59 - 00000000 ____D C:\Program Files (x86)\Razer
2017-02-24 10:39 - 2017-01-29 00:12 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-02-23 22:59 - 2016-06-23 00:19 - 00000000 ____D C:\Users\Alex\AppData\Roaming\OBS
2017-02-23 13:10 - 2015-12-15 04:32 - 00000000 ____D C:\Users\Alex\Documents\My Games
2017-02-23 12:05 - 2016-08-21 22:37 - 00409128 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
2017-02-23 11:32 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-23 11:31 - 2016-06-24 08:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-23 03:18 - 2016-06-24 08:46 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-22 01:52 - 2016-01-29 10:41 - 00000000 ____D C:\Users\Alex\Documents\Darkest
2017-02-20 21:24 - 2016-09-11 19:01 - 00000000 ____D C:\Users\Alex\AppData\Roaming\obs-studio
2017-02-20 12:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-20 12:08 - 2017-01-16 20:09 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2017-02-20 12:08 - 2016-07-09 18:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-02-20 12:03 - 2016-06-22 21:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
2017-02-20 12:03 - 2016-06-22 21:35 - 00000000 ____D C:\Program Files (x86)\Raptr Inc
2017-02-20 11:53 - 2016-09-16 15:17 - 00000000 ____D C:\Users\Alex\.tmcbeans-installer
2017-02-20 11:42 - 2016-07-16 06:47 - 00000000 __RHD C:\Users\Public\Libraries
2017-02-20 11:42 - 2016-07-06 11:02 - 00000000 ____D C:\Users\Alex\AppData\Local\BlueStacks
2017-02-20 00:09 - 2016-06-27 10:46 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Skype
2017-02-19 20:22 - 2016-06-27 10:46 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-02-19 20:22 - 2016-06-27 10:46 - 00000000 ____D C:\ProgramData\Skype
2017-02-17 23:54 - 2016-10-21 22:30 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-02-17 23:54 - 2016-10-21 22:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-15 19:34 - 2016-10-21 22:30 - 00003964 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-15 19:34 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-15 19:34 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-14 12:39 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-02-14 01:18 - 2016-06-22 23:09 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-09 23:15 - 2016-02-13 08:20 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-08 02:04 - 2016-08-19 00:10 - 00000000 ____D C:\Users\Alex\AppData\Local\Arma 3 Launcher
2017-02-08 02:03 - 2016-08-19 00:14 - 00000000 ____D C:\Users\Alex\AppData\Local\Arma 3
2017-02-07 16:32 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-07 16:32 - 2016-06-22 21:33 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-07 16:29 - 2017-01-10 12:03 - 00000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2017-02-07 16:28 - 2015-12-15 05:53 - 00000000 ____D C:\AMD
2017-02-07 00:35 - 2016-08-22 22:50 - 00000000 ____D C:\Users\Alex\Documents\CPY_SAVES
2017-02-06 20:23 - 2016-09-23 12:13 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-06 20:23 - 2016-09-23 12:13 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-06 14:48 - 2016-07-16 06:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 14:48 - 2016-07-16 06:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2016-06-17 01:54 - 2016-06-17 01:54 - 0000217 _____ () C:\Users\Alex\AppData\Roaming\10-unhinted.conf
2016-06-17 01:54 - 2016-06-17 01:54 - 0000524 _____ () C:\Users\Alex\AppData\Roaming\159 dk orange bl 1.ADO
2016-06-17 01:54 - 2016-06-17 01:54 - 0000303 _____ () C:\Users\Alex\AppData\Roaming\3.png
2016-06-17 01:54 - 2016-06-17 01:54 - 0001283 _____ () C:\Users\Alex\AppData\Roaming\404-1.htm
2016-06-17 01:54 - 2016-06-17 01:54 - 0004365 _____ () C:\Users\Alex\AppData\Roaming\Adobe-CNS1-4
2016-06-17 01:54 - 2016-06-17 01:54 - 0002190 _____ () C:\Users\Alex\AppData\Roaming\annotation.css.xml
2016-06-17 01:54 - 2016-06-17 01:54 - 0000379 _____ () C:\Users\Alex\AppData\Roaming\AsapiLoggerConfig.xml
2016-06-17 01:53 - 2016-06-17 01:53 - 0000027 _____ () C:\Users\Alex\AppData\Roaming\AST4
2016-06-17 01:53 - 2016-06-17 01:53 - 0004205 _____ () C:\Users\Alex\AppData\Roaming\back.png
2016-06-17 01:53 - 2016-06-17 01:53 - 0000430 _____ () C:\Users\Alex\AppData\Roaming\doc_to_epub.xsl
2016-06-17 01:53 - 2016-06-17 01:53 - 0002385 _____ () C:\Users\Alex\AppData\Roaming\dsfksvcsw2k.inf
2016-06-17 01:53 - 2016-06-17 01:53 - 0003749 _____ () C:\Users\Alex\AppData\Roaming\ExampleAWTViewer.java
2016-06-17 01:53 - 2016-06-17 01:53 - 0001194 _____ () C:\Users\Alex\AppData\Roaming\f39.png
2016-06-17 01:53 - 2016-06-17 01:53 - 0001150 _____ () C:\Users\Alex\AppData\Roaming\fast_forward.png
2016-06-17 01:53 - 2016-06-17 01:53 - 0003405 _____ () C:\Users\Alex\AppData\Roaming\finphon.env
2016-06-17 01:53 - 2016-06-17 01:53 - 0000935 _____ () C:\Users\Alex\AppData\Roaming\glossterm.width.xml
2016-06-17 01:52 - 2016-06-17 01:52 - 0000518 _____ () C:\Users\Alex\AppData\Roaming\goURL_lr_photoshop_fr.csv
2016-06-17 01:52 - 2016-06-17 01:52 - 0000518 _____ () C:\Users\Alex\AppData\Roaming\goURL_lr_photoshop_jp.csv
2016-06-17 01:52 - 2016-06-17 01:52 - 0000524 _____ () C:\Users\Alex\AppData\Roaming\gray 423 bl soft.ADO
2013-11-13 03:00 - 2013-11-13 03:00 - 0049948 _____ () C:\Users\Alex\AppData\Roaming\Plangency.P
1989-01-27 03:00 - 1989-01-27 03:00 - 0003406 _____ () C:\Users\Alex\AppData\Roaming\Stereophony.t
2016-12-03 21:56 - 2016-12-03 21:56 - 0007605 _____ () C:\Users\Alex\AppData\Local\Resmon.ResmonCfg
2016-12-20 23:03 - 2016-11-23 08:37 - 0000570 _____ () C:\Users\Alex\AppData\Local\TroubleshooterConfig.json
2016-06-23 00:12 - 2016-06-23 00:12 - 0000003 _____ () C:\Users\Alex\AppData\Local\updater.log
2016-06-23 00:12 - 2016-08-06 21:17 - 0000424 _____ () C:\Users\Alex\AppData\Local\UserProducts.xml
2016-08-16 10:20 - 2016-08-16 10:20 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-01-10 12:03 - 2017-02-07 16:29 - 0000060 _____ () C:\ProgramData\SoftwareUpdateTemp.xml
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-05 00:51
==================== End of FRST.txt ============================