ADVERTISEMENT

FRST.txt

Reklamy w przeglądarce, Malwarebytes zatrzymuje się na skanowaniu pamięci

Witam, posiadam komputer w którym non stop wyskakują reklamy ale malwarebytes nie robi pełnego skanu zatrzymuje się na pamięci więc wnioskuje że cos "grubszego" siedzi. Dołączam skany z FRST. Pozdrawiam


Download file - link to post

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-04-2017
Ran by Start (administrator) on ASAS (20-04-2017 09:51:24)
Running from C:\Users\Start\Downloads
Loaded Profiles: Start (Available Profiles: Start)
Platform: Windows 8 (X64) Language: Angielski (Wielka Brytania)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hi-Rez Studios) D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avpui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(© 2015 Microsoft Corporation) C:\Users\Start\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Users\Start\Downloads\adwcleaner_6.045.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ASUSQuickGesture(x86)] = & gt; C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe [20352 2012-08-05] (ASUSTeK Computer Inc.)
HKLM\...\Run: [ASUSTPLoader(x64)] = & gt; C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe [169856 2012-08-05] (AsusTek)
HKLM\...\Run: [ASUSQuickGesture(x64)] = & gt; C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe [22400 2012-08-05] (ASUSTeK Computer Inc.)
HKLM\...\Run: [BtTray] = & gt; C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [764032 2012-08-10] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] = & gt; C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-10] (Atheros Communications)
HKLM\...\Run: [ACMON] = & gt; C:\Program Files (x86)\ASUS\Splendid\ACMON.exe********************************************* [90832 2012-06-07] ()
HKLM\...\Run: [Malwarebytes TrayApp] = & gt; C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] = & gt; C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] = & gt; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] = & gt; C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA)
HKLM-x32\...\Run: [AmIcoSinglun64] = & gt; C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [366720 2012-08-23] (Alcor Micro Corp.)
HKLM-x32\...\Run: [RemoteControl10] = & gt; C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] = & gt; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\Run: [EA Core] = & gt; C:\Program Files (x86)\Electronic Arts\EADM\Core.exe [3325952 2009-03-28] (Electronic Arts)
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\Run: [Steam] = & gt; D:\Program Files (x86)\Steam\steam.exe [2876704 2016-12-09] (Valve Corporation)
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\Run: [BingSvc] = & gt; C:\Users\Start\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-11] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\Run: [Skype] = & gt; C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\MountPoints2: {99abb418-06e8-11e2-be6a-806e6f6e6963} - " E:\setup.exe " /CD
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] - & gt; {6D4133E5-0742-4ADC-8A8C-9303440F7190} = & gt; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] - & gt; {64174815-8D98-4CE6-8646-4C039977D808} = & gt; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] - & gt; {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} = & gt; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-09-25]
ShortcutTarget: AsusVibeLauncher.lnk - & gt; C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D86637E2-1457-47FE-9B20-B511D7F0932E}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction & lt; ======= ATTENTION
HKU\S-1-5-21-1912849403-639712137-414092863-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com
HKU\S-1-5-21-1912849403-639712137-414092863-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKU\S-1-5-21-1912849403-639712137-414092863-1001 - & gt; DefaultScope {0F4E49A8-A765-4F87-839E-B9580988934B} URL = hxxps://uk.search.yahoo.com/search?fr=mcafee & type=C011GB885D20151026 & p={searchTerms}
SearchScopes: HKU\S-1-5-21-1912849403-639712137-414092863-1001 - & gt; {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SK2MDF & PC=SK2M & q={searchTerms} & src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1912849403-639712137-414092863-1001 - & gt; {0F4E49A8-A765-4F87-839E-B9580988934B} URL = hxxps://uk.search.yahoo.com/search?fr=mcafee & type=C011GB885D20151026 & p={searchTerms}
BHO: ASUS Browser Extension x64 - & gt; {78234974-0C4B-4111-BDEB-D9A104418772} - & gt; C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x64\BrowserExtension64.dll [2012-08-05] (ASUSTeK Computer Inc.)
BHO: CIESpeechBHO Class - & gt; {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - & gt; C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-10] (Qualcomm Atheros Commnucations)
BHO: Skype Click to Call for Internet Explorer - & gt; {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - & gt; C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Kaspersky Protection plugin - & gt; {C66D064F-82FE-4E1A-B06A-B2490BA48B18} - & gt; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2016-12-20] (AO Kaspersky Lab)
BHO-x32: Adobe PDF Link Helper - & gt; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - & gt; C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15] (Adobe Systems Incorporated)
BHO-x32: ASUS Browser Extension x86 - & gt; {78234974-0C4B-4111-BDEB-D9A104418771} - & gt; C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x86\BrowserExtension.dll [2012-08-05] (ASUSTeK Computer Inc.)
BHO-x32: Skype Click to Call for Internet Explorer - & gt; {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - & gt; C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Kaspersky Protection plugin - & gt; {C66D064F-82FE-4E1A-B06A-B2490BA48B18} - & gt; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2016-12-20] (AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2016-12-20] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2016-12-20] (AO Kaspersky Lab)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: tmz0p0xq.default
FF ProfilePath: C:\Users\Start\AppData\Roaming\Mozilla\Firefox\Profiles\tmz0p0xq.default [2017-04-20]
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\tmz0p0xq.default - & gt; Secure Search
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\tmz0p0xq.default - & gt; Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\tmz0p0xq.default - & gt; Secure Search
FF Homepage: Mozilla\Firefox\Profiles\tmz0p0xq.default - & gt; hxxp://www.msn.com/?pc=SK2M & ocid=SK2MDHP & osmkt=en-ww
FF Keyword.URL: Mozilla\Firefox\Profiles\tmz0p0xq.default - & gt; hxxp://www.bing.com/search?FORM=SK2MDF & PC=SK2M & q=
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Start\AppData\Roaming\Mozilla\Firefox\Profiles\tmz0p0xq.default\features\{c4420705-7a63-4440-ae90-f13cfb4be0d5}\malware-remediation@mozilla.org.xpi [2016-12-20]
FF SearchPlugin: C:\Users\Start\AppData\Roaming\Mozilla\Firefox\Profiles\tmz0p0xq.default\searchplugins\McSiteAdvisor.xml [2015-10-26]
FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox [2016-12-20]
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-20] ()
FF Plugin-x32: @adobe.com/FlashPlayer - & gt; C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-20] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - & gt; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - & gt; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin HKU\S-1-5-21-1912849403-639712137-414092863-1001: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\Start\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-10] (Qualcomm Atheros Commnucations) [File not signed]
R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe [194000 2015-09-07] (Kaspersky Lab ZAO)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [245544 2015-10-14] (EasyAntiCheat Ltd)
U2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-14] (VIA Technologies, Inc.)
S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\vssbridge64.exe [144640 2015-07-09] (AO Kaspersky Lab)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
R2 ZAtheros Bt & Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-10] (Atheros) [File not signed]
S2 McAfee SiteAdvisor Service; " c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe " [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [50848 2012-08-05] (ASUS Corporation)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-10] (Qualcomm Atheros)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2017-01-20] ()
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [70512 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [77728 2016-03-05] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [181640 2015-12-26] (AO Kaspersky Lab)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [238000 2016-06-29] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [933808 2016-06-30] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [49240 2016-06-30] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [41656 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [41352 2015-12-26] (AO Kaspersky Lab)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [87984 2016-06-30] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [102584 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO)
R0 MBAMChameleon; C:\Windows\System32\drivers\MBAMChameleon.sys [176584 2017-04-20] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [110536 2017-04-20] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-04-20] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251848 2017-04-20] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [91584 2017-04-20] (Malwarebytes)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [281944 2015-07-06] (Microsoft Corporation)
U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X]
U0 msahci; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-20 09:51 - 2017-04-20 09:51 - 00019227 _____ C:\Users\Start\Downloads\FRST.txt
2017-04-20 09:51 - 2017-04-20 09:51 - 00000000 ____D C:\FRST
2017-04-20 09:47 - 2017-04-20 09:48 - 02424832 _____ (Farbar) C:\Users\Start\Downloads\FRST64.exe
2017-04-20 09:33 - 2017-04-20 09:37 - 00000000 ____D C:\AdwCleaner
2017-04-20 09:30 - 2017-04-20 09:30 - 04089296 _____ C:\Users\Start\Downloads\adwcleaner_6.045.exe
2017-04-20 09:28 - 2017-04-20 09:45 - 00091584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-04-20 09:28 - 2017-04-20 09:44 - 00251848 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-04-20 09:28 - 2017-04-20 09:44 - 00176584 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-04-20 09:28 - 2017-04-20 09:44 - 00110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-04-20 09:28 - 2017-04-20 09:44 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-04-20 09:27 - 2017-04-20 09:27 - 00001869 _____ C:\Users\Public\Desktop\jsdfsdf.lnk
2017-04-20 09:27 - 2017-04-20 09:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-04-20 09:27 - 2017-04-20 09:27 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-04-20 09:27 - 2017-04-20 09:27 - 00000000 ____D C:\Program Files\Malwarebytes
2017-04-20 09:27 - 2017-01-20 07:47 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-04-20 09:26 - 2017-04-20 09:27 - 55566792 _____ (Malwarebytes ) C:\Users\Start\Downloads\mb3-setup-consumer-3.0.6.1469.exe

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-20 09:40 - 2015-08-31 07:42 - 00004388 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-04-20 09:40 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-20 09:40 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-20 09:35 - 2016-12-20 18:22 - 00003032 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2017-04-20 09:26 - 2015-07-30 13:16 - 00808428 _____ C:\Windows\system32\perfh015.dat
2017-04-20 09:26 - 2015-07-30 13:16 - 00168776 _____ C:\Windows\system32\perfc015.dat
2017-04-20 09:26 - 2012-07-26 08:28 - 01820604 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-20 09:26 - 2012-07-26 06:37 - 00000000 ____D C:\Windows\Inf
2017-04-20 09:22 - 2015-09-07 15:47 - 00000000 ____D C:\Users\Start\AppData\Roaming\Skype
2017-04-20 09:20 - 2015-12-26 22:30 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-04-20 09:20 - 2015-07-30 12:28 - 00000387 _____ C:\Users\Start\AppData\Roaming\sp_data.sys
2017-04-20 09:19 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT

==================== Files in the root of some directories =======

2015-07-30 12:28 - 2017-04-20 09:20 - 0000387 _____ () C:\Users\Start\AppData\Roaming\sp_data.sys
2012-08-17 01:52 - 2012-07-30 07:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
2012-08-17 01:52 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe

Some files in TEMP:
====================
2015-09-07 15:47 - 2015-09-07 15:47 - 2308240 _____ (Microsoft Corporation) C:\Users\Start\AppData\Local\Temp\BingBarSetup-Partner.exe
2015-11-11 22:07 - 2015-11-11 22:07 - 0144008 _____ (© 2015 Microsoft Corporation) C:\Users\Start\AppData\Local\Temp\BingSvc.exe
2015-09-07 16:19 - 2015-11-11 22:07 - 1118360 _____ (© 2015 Microsoft Corporation) C:\Users\Start\AppData\Local\Temp\BSvcProcessor.exe
2015-09-07 16:19 - 2015-11-11 22:07 - 0170128 _____ (© 2015 Microsoft Corporation) C:\Users\Start\AppData\Local\Temp\BSvcUpdater.exe
2016-12-20 18:21 - 2016-12-20 18:22 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD264B.exe
2016-02-28 17:19 - 2016-02-28 17:19 - 3432448 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD2A2E.exe
2015-12-26 22:38 - 2015-12-26 22:39 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD3668.exe
2016-02-23 21:52 - 2016-02-23 21:52 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD3F0E.exe
2016-02-27 22:23 - 2016-02-27 22:23 - 6172672 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD451B.exe
2016-03-11 22:42 - 2016-03-11 22:42 - 13590528 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD53CF.exe
2016-02-24 20:38 - 2016-02-24 20:39 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD5F04.exe
2015-09-18 14:14 - 2015-09-18 14:15 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD8D6.exe
2015-08-09 06:36 - 2015-08-09 06:36 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD92DC.exe
2016-05-05 17:00 - 2016-05-05 17:03 - 21258240 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD9C0A.exe
2015-12-26 22:26 - 2015-12-26 22:26 - 3213312 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EAD9E9.exe
2016-03-05 00:08 - 2016-03-05 00:08 - 9543680 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADA3ED.exe
2015-07-31 10:27 - 2015-07-31 10:28 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADA759.exe
2016-03-13 18:18 - 2016-03-13 18:21 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADA75D.exe
2016-03-28 18:14 - 2016-03-28 18:23 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADAD8C.exe
2016-02-28 22:15 - 2016-02-28 22:16 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADBEEB.exe
2016-02-20 21:53 - 2016-02-20 21:54 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADC308.exe
2015-07-31 10:24 - 2015-07-31 10:25 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADC64A.exe
2016-02-26 21:27 - 2016-02-26 21:27 - 0681984 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADCBE7.exe
2016-07-03 17:07 - 2016-07-03 17:09 - 47796216 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADE75E.exe
2015-12-26 22:20 - 2015-12-26 22:20 - 2455552 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADFD51.exe
2016-03-30 13:18 - 2016-03-30 13:19 - 23910400 _____ (Electronic Arts, Inc.) C:\Users\Start\AppData\Local\Temp\EADFD71.exe
2015-09-01 12:11 - 2015-09-01 12:11 - 0120336 _____ (McAfee, Inc.) C:\Users\Start\AppData\Local\Temp\McCSPInstall.dll
2015-12-26 22:13 - 2015-09-01 12:11 - 0162120 _____ (McAfee Inc.) C:\Users\Start\AppData\Local\Temp\mccspuninstall.exe
2016-04-29 20:13 - 2016-04-29 20:18 - 47398016 _____ (Skype Technologies S.A.) C:\Users\Start\AppData\Local\Temp\SkypeSetup.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe = & gt; File is digitally signed
C:\Windows\system32\wininit.exe = & gt; File is digitally signed
C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\explorer.exe = & gt; File is digitally signed
C:\Windows\system32\svchost.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\svchost.exe = & gt; File is digitally signed
C:\Windows\system32\services.exe = & gt; File is digitally signed
C:\Windows\system32\User32.dll = & gt; File is digitally signed
C:\Windows\SysWOW64\User32.dll = & gt; File is digitally signed
C:\Windows\system32\userinit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\userinit.exe = & gt; File is digitally signed
C:\Windows\system32\rpcss.dll = & gt; File is digitally signed
C:\Windows\system32\dnsapi.dll = & gt; File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll = & gt; File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys = & gt; File is digitally signed

LastRegBack: 2016-12-20 15:40

==================== End of FRST.txt ============================