Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 Ran by Edyta (administrator) on EDYTKA (27-03-2016 20:27:13) Running from C:\Users\Edyta\Downloads Loaded Profiles: Edyta (Available Profiles: Edyta & Administrator) Platform: Windows 10 Home Version 1511 (X64) Language: English (United Kingdom) Internet Explorer Version 11 (Default browser: Edge) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Intel Corporation) C:\Windows\System32\SET5B84.tmp (Intel Corporation) C:\Windows\SysWOW64\SET4E0B.tmp (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (AMD) C:\Windows\System32\atieclxx.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe (Intel Corporation) C:\Windows\System32\SET5243.tmp (Intel Corporation) C:\Windows\System32\SET5D10.tmp (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.27.2.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe () C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511\updater.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugincontainer.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\2\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\4\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\6\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\8\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\5\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\7\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\7\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\12\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\3\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\12\Plugin.exe () C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugins\3\Plugin.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Windows\System32\LockAppHost.exe () C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Farbar) C:\Users\Edyta\Downloads\FRST64 (1).exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3251408 2015-09-23] (ELAN Microelectronics Corp.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040296 2015-08-29] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-4279228227-215742994-1318027649-1001\...\RunOnce: [Uninstall C:\Users\Edyta\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Edyta\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" HKU\S-1-5-21-4279228227-215742994-1318027649-1001\...\RunOnce: [Uninstall C:\Users\Edyta\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Edyta\AppData\Local\Microsoft\OneDrive\17.3.5892.0626" ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{d25b177e-e246-454c-86b2-24906ec3c2a7}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1ADB0VXfVBdFElXTwh0IVdcBEszVEdQNA== HKU\S-1-5-21-4279228227-215742994-1318027649-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1ADB0VXfVBdFElXTwh0IVdcBEszVEdQNA== HKU\S-1-5-21-4279228227-215742994-1318027649-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com SearchScopes: HKLM -> DefaultScope {A9A9ECA3-DEA4-482B-AD43-46692B227404} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKLM -> {A9A9ECA3-DEA4-482B-AD43-46692B227404} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> DefaultScope {5B31877C-3856-4258-9A5F-AC0CDA29EF5D} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> OldSearch URL = SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> {5B31877C-3856-4258-9A5F-AC0CDA29EF5D} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> {A9A9ECA3-DEA4-482B-AD43-46692B227404} URL = BHO-x32: Wander Burst -> {0f4e02f8-f10e-493d-a1a7-3aed7ba7b110} -> C:\Program Files (x86)\Wander Burst\Extensions\0f4e02f8-f10e-493d-a1a7-3aed7ba7b110.dll [2015-07-19] () FireFox: ======== FF ProfilePath: C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default FF NewTab: hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHFQacgoKVFoSDANBcgsVVQBEGRgbclxZTAhHElQUI1tdAAlFFxNBNARaB0tXUUEeGGlxR1dMdlRNJFxKI0wDUkE= FF DefaultSearchEngine: Default FF SelectedSearchEngine: Default FF Homepage: hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA18DB0VXfWFoKB8fHGJCLl1dE3sEU0ZX FF Keyword.URL: hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTR0cFME0FB18EURNNfW5ZD10UU3dWMkpM&q={searchTerms} FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-08] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-08] (Google Inc.) FF user.js: detected! => C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default\user.js [2015-12-12] FF SearchPlugin: C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default\searchplugins\default.xml [2015-10-31] FF SearchPlugin: C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default\searchplugins\yahoo-search.xml [2015-08-26] FF SearchPlugin: C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default\searchplugins\yahoo_ff.xml [2015-08-13] FF Extension: Wander Burst - C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default\Extensions\{a6ca3081-13fe-4701-a2c2-304a8dddc34c}.xpi [2015-08-11] [not signed] FF Extension: Adblock Plus - C:\Users\Edyta\AppData\Roaming\Mozilla\Firefox\Profiles\7cnbbitf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-18] Chrome: ======= CHR RestoreOnStartup: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA==" CHR StartupUrls: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA==" CHR DefaultSearchURL: Default -> hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTQkcFME0FBloEURNNfW5ZD10UU3dWMkpM&q={searchTerms} CHR DefaultSearchKeyword: Default -> searchinterneat-a.akamaihd.net CHR DefaultNewTabURL: Default -> hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHFQacgoKVFoSDANBcgsVVQBEGRgbclxZTAhHElQUI1tdAAlFFxNBNARaAktXUUEeJ1pNER8fHGJCLl1dE3sEU0ZX CHR Profile: C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Prezentacje Google) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-08] CHR Extension: (Dokumenty Google) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-08] CHR Extension: (Dysk Google) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-08] CHR Extension: (YouTube) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-08] CHR Extension: (Google Search) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-08] CHR Extension: (Arkusze Google) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-08] CHR Extension: (Dokumenty Google offline) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-27] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-08] CHR Extension: (Gmail) - C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-08] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [139984 2015-09-23] (ELAN Microelectronics Corp.) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [329280 2016-02-19] (Intel Corporation) R2 Service Mgr WanderBurst; C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugincontainer.exe [1408224 2016-02-29] () <==== ATTENTION R2 Update Mgr WanderBurst; C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511\updater.exe [1272544 2016-02-29] () <==== ATTENTION R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.) S3 AtiDCM; C:\AMD\WU-CCC2\ccc2_install\Support64\atdcm64a.sys [33992 2015-03-26] (Advanced Micro Devices, Inc.) R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [41024 2015-09-23] (ELAN Microelectronic Corp.) R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3343872 2015-10-30] (Intel Corporation) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-30] (Windows (R) Win 7 DDK provider) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-27 20:24 - 2016-03-27 20:25 - 02374144 _____ (Farbar) C:\Users\Edyta\Downloads\FRST64 (1).exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-27 20:28 - 2015-07-19 17:34 - 00014937 _____ C:\Users\Edyta\Downloads\FRST.txt 2016-03-27 20:27 - 2015-07-11 19:36 - 00000000 ____D C:\FRST 2016-03-27 20:26 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-03-27 20:23 - 2015-07-23 20:21 - 00004148 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6E0C1E03-AA6D-4BE2-B88B-84E1375B9762} 2016-03-27 20:19 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-03-27 20:19 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-03-14 17:14 - 2016-02-24 01:59 - 00002399 _____ C:\Users\Edyta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-03-14 17:14 - 2015-07-22 21:46 - 00000000 ___RD C:\Users\Edyta\OneDrive 2016-02-29 22:32 - 2015-07-19 16:45 - 00000000 ____D C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511 2016-02-29 22:31 - 2016-02-08 21:26 - 00001060 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-29 22:19 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF ==================== Files in the root of some directories ======= 2016-02-24 01:03 - 2016-02-24 01:03 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== C:\Users\Edyta\AppData\Local\Temp\ICReinstall_Adblock Plus 1.5 - Internet Explorer.exe C:\Users\Edyta\AppData\Local\Temp\{40B54925-2428-4A2B-BAD3-ACA0AB6B405A}.dll C:\Users\Edyta\AppData\Local\Temp\{992911C9-C87E-45D4-8045-320C3F39B7B2}.dll ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-02-24 00:53 ==================== End of FRST.txt ============================