From some days ago Thunderbird connect to mail server, identify new mail and start to download.
But no message is downloaded and no error message is displayed.
In addition, immediately or some minutes later Firefox stop to work.
It seems that internet connection is lost but the adls router is perfectly connected.
Few minutes and Firefox crash
No way to reconnect Firefox to internet
The only way is shut down the PC and restart without using Thunderbird
here attaced the MBR and FRST logs
.
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-25 18:06:51
—————————–
18:06:51.499 OS Version: Windows 6.1.7601 Service Pack 1
18:06:51.499 Number of processors: 2 586 0xF0D
18:06:51.499 ComputerName: MARCO-PC UserName: Marco
18:09:15.377 Initialize success
18:09:16.220 VM: initialized successfully
18:09:16.223 VM: Intel CPU virtualization not supported
18:12:18.488 AVAST engine defs: 15042401
19:03:20.385 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
19:03:20.385 Disk 0 Vendor: WDC_WD5000BEVT-22ZAT0 01.01A01 Size: 476940MB BusType: 11
19:03:20.557 Disk 0 MBR read successfully
19:03:20.557 Disk 0 MBR scan
19:03:20.573 Disk 0 Windows 7 default MBR code
19:03:20.604 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048
19:03:20.604 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 233482 MB offset 20482048
19:03:20.619 Disk 0 default boot code
19:03:20.666 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 233456 MB offset 498653184
19:03:20.682 Disk 0 scanning sectors +976771072
19:03:20.760 Disk 0 scanning C:\Windows\system32\drivers
19:04:56.666 Service scanning
19:05:13.654 Service cm_km_w C:\Windows\system32\DRIVERS\cm_km_w.sys **LOCKED** 5
19:05:26.088 Service kl1 C:\Windows\system32\DRIVERS\kl1.sys **LOCKED** 5
19:05:26.306 Service kldisk C:\Windows\system32\DRIVERS\kldisk.sys **LOCKED** 5
19:05:26.540 Service klflt C:\Windows\system32\DRIVERS\klflt.sys **LOCKED** 5
19:05:26.727 Service klhk C:\Windows\system32\DRIVERS\klhk.sys **LOCKED** 5
19:05:27.258 Service KLIM6 C:\Windows\system32\DRIVERS\klim6.sys **LOCKED** 5
19:05:27.445 Service klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys **LOCKED** 5
19:05:27.648 Service klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys **LOCKED** 5
19:05:27.866 Service klpd C:\Windows\system32\DRIVERS\klpd.sys **LOCKED** 5
19:05:28.240 Service kltdi C:\Windows\system32\DRIVERS\kltdi.sys **LOCKED** 5
19:05:28.474 Service Klwtp C:\Windows\system32\DRIVERS\klwtp.sys **LOCKED** 5
19:05:28.693 Service kneps C:\Windows\system32\DRIVERS\kneps.sys **LOCKED** 5
19:06:01.858 Modules scanning
19:06:01.874 Disk 0 trace - called modules:
19:06:01.921 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
19:06:01.936 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8717b888]
19:06:01.952 3 CLASSPNP.SYS[8c7bc59e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x87046908]
19:06:04.074 AVAST engine scan C:\Windows
19:06:09.783 AVAST engine scan C:\Windows\system32
19:15:02.477 Disk 0 MBR has been saved successfully to "C:\Downloads\MBR.dat"
19:15:02.509 The log file has been saved successfully to "C:\Downloads\aswMBR.txt"
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-26 04:45:07
—————————–
04:45:07.846 OS Version: Windows 6.1.7601 Service Pack 1
04:45:07.846 Number of processors: 2 586 0xF0D
04:45:07.855 ComputerName: MARCO-PC UserName: Marco
04:45:56.936 Initialize success
04:45:57.202 VM: initialized successfully
04:45:57.209 VM: Intel CPU virtualization not supported
04:56:43.297 AVAST engine defs: 15042501
04:57:11.142 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
04:57:11.149 Disk 0 Vendor: WDC_WD5000BEVT-22ZAT0 01.01A01 Size: 476940MB BusType: 11
04:57:11.317 Disk 0 MBR read successfully
04:57:11.326 Disk 0 MBR scan
04:57:11.343 Disk 0 Windows 7 default MBR code
04:57:11.371 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048
04:57:11.388 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 233482 MB offset 20482048
04:57:11.406 Disk 0 default boot code
04:57:11.447 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 233456 MB offset 498653184
04:57:11.465 Disk 0 scanning sectors +976771072
04:57:11.614 Disk 0 scanning C:\Windows\system32\drivers
04:57:50.216 Service scanning
04:57:57.595 Service cm_km_w C:\Windows\system32\DRIVERS\cm_km_w.sys **LOCKED** 5
04:58:04.961 Service kl1 C:\Windows\system32\DRIVERS\kl1.sys **LOCKED** 5
04:58:05.023 Service kldisk C:\Windows\system32\DRIVERS\kldisk.sys **LOCKED** 5
04:58:05.123 Service klflt C:\Windows\system32\DRIVERS\klflt.sys **LOCKED** 5
04:58:05.195 Service klhk C:\Windows\system32\DRIVERS\klhk.sys **LOCKED** 5
04:58:05.444 Service KLIM6 C:\Windows\system32\DRIVERS\klim6.sys **LOCKED** 5
04:58:05.524 Service klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys **LOCKED** 5
04:58:05.588 Service klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys **LOCKED** 5
04:58:05.647 Service klpd C:\Windows\system32\DRIVERS\klpd.sys **LOCKED** 5
04:58:05.739 Service kltdi C:\Windows\system32\DRIVERS\kltdi.sys **LOCKED** 5
04:58:05.804 Service Klwtp C:\Windows\system32\DRIVERS\klwtp.sys **LOCKED** 5
04:58:05.892 Service kneps C:\Windows\system32\DRIVERS\kneps.sys **LOCKED** 5
04:58:26.951 Modules scanning
04:58:26.976 Disk 0 trace - called modules:
04:58:27.035 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys ndis.sys athr.sys intelppm.sys
04:58:27.052 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f7e030]
04:58:27.069 3 CLASSPNP.SYS[8c5c559e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86e42908]
04:58:28.704 AVAST engine scan C:\Windows
04:58:33.882 AVAST engine scan C:\Windows\system32
05:07:40.405 AVAST engine scan C:\Windows\system32\drivers
05:08:18.730 AVAST engine scan C:\Users\Marco
05:28:46.205 AVAST engine scan C:\ProgramData
05:42:09.692 Disk 0 statistics 3020706/0/0 @ 1,01 MB/s
05:42:09.706 Scan finished successfully
05:43:13.211 Disk 0 MBR has been saved successfully to "C:\Downloads\MBR.dat"
05:43:13.314 The log file has been saved successfully to "C:\Downloads\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-04-2015
Ran by [removed] (administrator) on MARCO-PC on 26-04-2015 05:50:05
Running from C:\Downloads
[removed]
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Italiano (Italia)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe
(AOMEI Tech Co., Ltd.) C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Link Wiz) C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(PGP Corporation) C:\Windows\System32\PGPserv.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.EXE
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3898960 2015-04-20] (Tonec Inc.)
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
Lsa: [Notification Packages] scecli PGPpwflt
ShellIconOverlayIdentifiers: [IconOverlayHandlerAccessible] -> {3DBF5F01-3287-46EB-82CF-45AA5C241162} => C:\Windows\system32\PGPfsshl.dll [2010-04-01] (PGP Corporation)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2014-04-21] (Tonec Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.golliver.com
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
SearchScopes: HKLM -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL = http://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dnldmsd&cd;=2XzuyEtN2Y1L1QzutDyCtByEtB0BtDtA0B0E0A0Azyzy0DtCtN0D0Tzu0CyDyByBtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1318093972&ir;=
SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = http://www.istartsurf.com/web/?type=ds&ts;=1425272006&from;=tugs&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL =
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A1C3DFA2-A404-4C14-A7FD-BBA0C9707DE3} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A86D0113-4332-4553-A3F9-124DB478F4B5} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3306061&CUI;=UN30406771052739920&UM;=2
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = http://www.sweet-page.com/web/?type=ds&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {F84F0002-4F7D-43B3-A86D-076D14A000F0} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09] (Oracle Corporation)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09] (Oracle Corporation)
DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Windows\system32\Msdxm6.ocx [2000-04-21] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: sweet-page
FF SelectedSearchEngine: sweet-page
FF Homepage: hxxp://search.golliver.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-12] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-09] (Oracle Corporation)
FF Plugin: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
FF Plugin: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
FF Plugin: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll [2014-06-26] (pdfforge GmbH)
FF user.js: detected! => C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\user.js [2015-03-20]
FF SearchPlugin: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\searchplugins\sweet-page.xml [2015-04-25]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\golliver.xml [2015-04-25]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2014-05-18]
FF Extension: Golliver - C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox\Extensions\[removed] [2015-04-25]
FF Extension: Golliver - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\Extensions\[removed] [2015-04-25]
FF Extension: No Name - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-24]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\extensions\[removed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\extensions\[removed]
FF HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5 [2015-04-18]
FF HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-12-11]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.dregol.com/?f=1&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
CHR StartupUrls: Default -> "hxxp://www.dregol.com/?f=7&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=", "hxxp://www.sweet-page.com/?type=hp&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980"
CHR DefaultSearchKeyword: Default -> dregol.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Kaspersky Protection) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-04-15]
CHR Extension: (IDM Integration Module) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-15]
CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-15]
CHR HKLM\…\Chrome\Extension: [bollbfeakabenkobaocgakdibphdnanj] - http://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\…\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM\…\Chrome\Extension: [lipgolpfajiadodbcbljdpmbmbdmfcil] - C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2015-04-20]
CHR HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lipgolpfajiadodbcbljdpmbmbdmfcil] - C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-17] (SUPERAntiSpyware.com)
R2 AVP15.0.2; C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [193400 2014-12-23] (Kaspersky Lab ZAO)
R2 Backupper Service; C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
R2 lwsvc_1.10.0.14; C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe [278592 2015-04-10] (Link Wiz)
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S4 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
S4 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
R2 PGPserv; C:\Windows\system32\PGPserv.exe [135288 2010-04-01] (PGP Corporation)
S2 uzsvc; C:\Program Files\UltraZip\uzsvc.exe [531744 2015-03-10] ()
S2 uzupd; C:\Program Files\UltraZip\uzupd.exe [44312 2015-03-10] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 asl; "C:\ProgramData\Service\Application\asl.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AF9035BDA; C:\Windows\System32\DRIVERS\AF9035BDA.sys [248744 2012-08-10] (AfaTech )
R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [26424 2013-05-07] () [File not signed]
R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [129720 2013-05-07] () [File not signed]
R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [14392 2013-02-06] () [File not signed]
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [189136 2013-01-14] (Kaspersky Lab UK Ltd)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [94336 2014-12-19] (ITE )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [143968 2014-03-31] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46280 2015-03-27] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [120008 2014-11-28] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [36040 2014-10-22] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [698568 2015-03-27] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25800 2014-10-10] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [26824 2014-10-30] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [46152 2014-10-09] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [64200 2014-11-22] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [148296 2014-11-10] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-04-26] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 WsAudio_Device(1); C:\Windows\System32\drivers\VirtualAudio1.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(2); C:\Windows\System32\drivers\VirtualAudio2.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(3); C:\Windows\System32\drivers\VirtualAudio3.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(4); C:\Windows\System32\drivers\VirtualAudio4.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(5); C:\Windows\System32\drivers\VirtualAudio5.sys [27496 2013-01-25] (Wondershare)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Marco\AppData\Local\Temp\catchme.sys [X]
S1 lwnfd_1_10_0_14; system32\drivers\lwnfd_1_10_0_14.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]
U3 aswMBR; \??\C:\Users\Marco\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Marco\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-26 04:33 - 2015-04-26 04:33 - 278896405 _____ () C:\Windows\MEMORY.DMP
2015-04-26 04:33 - 2015-04-26 04:33 - 00158560 _____ () C:\Windows\Minidump\042615-19874-01.dmp
2015-04-25 15:37 - 2015-04-25 15:37 - 00000137 _____ () C:\Users\Marco\Documents\gabriella.txt
2015-04-25 07:31 - 2015-04-26 05:50 - 00000000 ____D () C:\FRST
2015-04-25 07:14 - 2015-04-25 07:14 - 00002928 _____ () C:\Users\Marco\Documents\aswMBR.txt
2015-04-25 07:14 - 2015-04-25 07:14 - 00000512 _____ () C:\Users\Marco\Documents\MBR.dat
2015-04-25 06:34 - 2015-04-25 06:34 - 00000000 ____D () C:\ProgramData\6321271a0000001c
2015-04-25 06:26 - 2015-04-25 17:49 - 00000000 ____D () C:\Program Files\Run_Dregol
2015-04-25 06:26 - 2015-04-25 06:27 - 00000000 ____D () C:\Users\Marco\AppData\Local\nida
2015-04-25 06:12 - 2015-04-25 06:12 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\sweet-page
2015-04-25 06:05 - 2015-04-25 06:27 - 00000000 ___SD () C:\32788R22FWJFW
2015-04-25 06:05 - 2015-04-25 06:06 - 00000000 ____D () C:\Program Files\LinkWiz_1.10.0.14
2015-04-25 06:04 - 2015-04-25 06:21 - 00000000 ____D () C:\Users\Marco\Documents\CleanerPro
2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\Users\Marco\AppData\Local\CleanerPro
2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\ProgramData\UltraZip
2015-04-25 06:03 - 2015-04-25 17:52 - 00000000 ____D () C:\Program Files\UltraZip
2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Service
2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraZip
2015-04-25 06:02 - 2015-04-25 06:06 - 05619466 ____R (Swearware) C:\Users\Marco\Downloads\combofix [1].exe
2015-04-25 05:53 - 2015-04-26 04:33 - 00000392 _____ () C:\Windows\setupact.log
2015-04-25 05:53 - 2015-04-25 19:24 - 00320278 _____ () C:\Windows\PFRO.log
2015-04-25 05:53 - 2015-04-25 05:53 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-25 05:48 - 2015-04-25 05:48 - 00156898 _____ () C:\Users\Marco\Documents\cc_20150425_054751.reg
2015-04-20 14:53 - 2015-04-18 03:06 - 00122432 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
2015-04-19 06:56 - 2015-04-19 07:49 - 370938816 _____ () C:\Users\Marco\Downloads\0d6b8d7ca1.mp4.rar.part
2015-04-18 13:13 - 2015-04-18 17:27 - 742534663 _____ () C:\Users\Marco\Downloads\Cazzo.Grosso.Ma.Non.Troppo.Foreign.S.E.rar.part
2015-04-18 11:10 - 2015-04-18 11:35 - 105298398 _____ () C:\Users\Marco\Downloads\Dana Moravova _ Milada.avi.part
2015-04-18 07:02 - 2015-04-18 07:26 - 175777135 _____ () C:\Users\Marco\Downloads\Brooke_Tyler_-_shutup_and_blow_airport_hd.mp4
2015-04-14 21:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-14 21:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-14 21:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-14 21:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-14 21:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-14 21:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-14 21:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-14 21:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-14 21:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-14 21:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-14 21:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-14 21:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-14 21:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-14 21:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-14 21:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-14 21:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-14 21:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-14 21:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-14 21:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-14 21:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-14 21:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-14 21:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-14 21:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-14 21:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-14 21:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-14 21:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-14 21:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-14 21:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-14 21:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-14 21:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-14 21:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-14 21:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-14 21:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-14 21:40 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-14 21:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-14 21:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-14 21:40 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-14 21:40 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-14 21:40 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-14 21:40 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-14 21:40 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-14 21:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-14 21:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-14 21:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-14 21:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-14 21:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-14 21:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-14 21:40 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-14 21:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-14 21:39 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-14 21:39 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-11 10:13 - 2015-04-11 11:52 - 00000000 ____D () C:\Users\Marco\olimpus
2015-04-05 08:25 - 2015-04-05 08:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\RenPy
2015-04-05 07:20 - 2015-04-05 08:01 - 244140767 _____ () C:\Users\Marco\Downloads\wbc-1.0-all.rar
2015-04-05 06:59 - 2015-04-05 06:59 - 00000000 ____D () C:\Users\Marco\Tracing
2015-04-05 05:44 - 2015-04-05 05:44 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 10:26 - 2015-04-04 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\slac
2015-04-04 10:23 - 2015-04-04 10:23 - 00000000 ____D () C:\Program Files\slac
2015-04-04 08:16 - 2015-04-04 08:16 - 00000000 ____D () C:\Program Files\Common Files\Protexis
2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\Users\Public\Desktop\Corel PaintShop Pro X5.lnk
2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\ProgramData\Desktop\Corel PaintShop Pro X5.lnk
2015-04-04 08:15 - 2015-04-04 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X5
2015-04-03 08:13 - 2015-04-03 08:13 - 09629976 _____ (CyberGhost S.R.L. ) C:\Users\Marco\Downloads\CG_5.0.14.7.exe
2015-03-31 21:34 - 2015-03-31 21:34 - 00036168 _____ () C:\Users\Marco\Desktop\29177662s.pdf.zip
2015-03-28 15:43 - 2015-03-28 15:57 - 97954743 _____ () C:\Users\Marco\Downloads\6720_Возбужденная французская девочка трахнулась в офисе. - .mp4
2015-03-28 07:32 - 2015-03-28 09:08 - 701267673 _____ () C:\Users\Marco\Downloads\Kendra Lust.mp4
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-26 05:49 - 2013-03-05 23:43 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-26 05:34 - 2013-11-01 09:59 - 01869673 _____ () C:\Windows\WindowsUpdate.log
2015-04-26 05:12 - 2013-11-04 23:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-26 04:48 - 2014-05-22 06:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-04-26 04:42 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-26 04:42 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-26 04:33 - 2013-11-04 23:19 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-26 04:33 - 2013-07-12 04:50 - 00000000 ____D () C:\Windows\Minidump
2015-04-26 04:33 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-26 04:29 - 2014-05-21 22:11 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-25 19:20 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\DMCache
2015-04-25 17:56 - 2013-03-05 18:20 - 01786646 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-25 17:56 - 2009-07-14 10:21 - 00791368 _____ () C:\Windows\system32\perfh010.dat
2015-04-25 17:56 - 2009-07-14 10:21 - 00164498 _____ () C:\Windows\system32\perfc010.dat
2015-04-25 17:51 - 2014-05-23 06:31 - 00000000 ____D () C:\Program Files\Internet Download Manager
2015-04-25 17:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\PLA
2015-04-25 16:10 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\IDM
2015-04-25 10:08 - 2013-03-08 00:39 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc
2015-04-25 08:30 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-25 05:45 - 2014-09-08 18:30 - 00000000 ____D () C:\Program Files\PDFCreator
2015-04-25 05:43 - 2013-03-21 22:54 - 00000000 ____D () C:\Users\Marco\AppData\Local\CrashDumps
2015-04-25 05:43 - 2013-03-05 17:42 - 00000000 ____D () C:\Windows\Panther
2015-04-25 05:39 - 2013-11-10 08:53 - 00000000 ____D () C:\Users\Marco\AppData\Local\NativeMessaging
2015-04-25 05:38 - 2014-12-08 08:24 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\FlvPlayer
2015-04-25 05:38 - 2013-11-10 08:53 - 00000000 ____D () C:\ProgramData\Conduit
2015-04-25 04:42 - 2014-05-21 22:11 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-25 04:42 - 2014-05-21 22:11 - 00001024 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-25 04:42 - 2014-05-21 22:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-25 04:42 - 2014-05-21 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-24 18:42 - 2013-03-05 20:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-24 06:25 - 2014-12-11 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-24 06:25 - 2013-03-17 10:18 - 00000000 ____D () C:\Program Files\SpeedFan
2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2015-04-16 01:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-16 01:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-14 23:56 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-14 22:33 - 2014-12-10 07:47 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-14 22:33 - 2014-05-01 08:15 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-14 22:33 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT
2015-04-14 22:10 - 2013-08-14 09:55 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-14 21:55 - 2013-03-10 07:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-12 17:25 - 2014-06-24 21:39 - 00000000 ____D () C:\Users\Marco\AppData\Local\Adobe
2015-04-12 17:25 - 2013-03-05 23:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-12 17:25 - 2013-03-05 23:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-11 10:13 - 2013-03-05 18:23 - 00000000 ____D () C:\Users\Marco
2015-04-07 21:42 - 2014-12-20 17:59 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2015-04-05 07:01 - 2014-08-05 21:03 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\Skype
2015-04-05 06:59 - 2014-08-05 21:02 - 00000000 ___RD () C:\Program Files\Skype
2015-04-05 06:58 - 2014-08-05 21:02 - 00000000 ____D () C:\ProgramData\Skype
2015-04-04 10:26 - 2013-03-06 00:34 - 00023392 _____ () C:\Windows\system32\nscompat.tlb
2015-04-04 08:17 - 2013-03-12 07:21 - 00000000 ____D () C:\ProgramData\Corel
2015-04-04 08:13 - 2013-03-12 07:16 - 00000000 ____D () C:\Program Files\Corel
2015-04-04 08:05 - 2015-02-16 21:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Last_Man
2015-04-03 09:08 - 2014-04-23 05:10 - 00001845 _____ () C:\Users\Marco\Desktop\CyberGhost 5.lnk
2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\Program Files\CyberGhost 5
2015-03-28 10:49 - 2014-10-07 17:44 - 00000000 ____D () C:\ProgramData\XyLwfe
2015-03-27 07:21 - 2014-12-13 19:21 - 00698568 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-03-27 07:21 - 2014-08-19 13:31 - 00046280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kldisk.sys
==================== Files in the root of some directories =======
2013-03-12 07:27 - 2013-03-12 07:27 - 0003584 _____ () C:\Users\Marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-23 06:57 - 2013-05-23 06:59 - 0007602 _____ () C:\Users\Marco\AppData\Local\resmon.resmoncfg
2014-04-21 10:30 - 2014-04-21 10:30 - 0000041 ___SH () C:\ProgramData\.zreglib
2014-07-31 06:26 - 2014-07-31 06:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-03-17 09:07 - 2013-03-17 09:07 - 0000008 __RSH () C:\ProgramData\sysqcl1129067056.dat
Files to move or delete:
====================
C:\ProgramData\sysqcl1129067056.dat
Some content of TEMP:
====================
C:\Users\Marco\AppData\Local\Temp\sfamcc00001.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 00:36
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-04-2015
Ran by [removed] at 2015-04-26 05:51:26
Running from C:\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4094248773-42424133-2592686105-500 - Administrator - Disabled)
Guest (S-1-5-21-4094248773-42424133-2592686105-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4094248773-42424133-2592686105-1002 - Limited - Enabled)
Marco (S-1-5-21-4094248773-42424133-2592686105-1000 - Administrator - Enabled) => C:\Users\Marco
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Total Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Total Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Italiano (HKLM\…\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adventure Maker v4.6.1 (build1) (HKLM\…\Adventure Maker v4.6.1_is1) (Version: - )
Adventure Maker v4.7.1 (build1) (HKLM\…\Adventure Maker v4.7.1_is1) (Version: - )
Aimersoft DRM Media Converter(Build 1.5.5.0) (HKLM\…\Aimersoft DRM Media Converter_is1) (Version: - Aimersoft Software)
Alice MOBILE E169 (HKLM\…\Alice MOBILE E169) (Version: 11.002.04.11.192 - Huawei Technologies Co.,Ltd)
Any Video Converter 5.6.3 (HKLM\…\Any Video Converter_is1) (Version: - Any-Video-Converter.com)
AOMEI Backupper Standard Edition 2.2 (HKLM\…\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version: - AOMEI Technology Co., Ltd.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
BlazeDTV 6.0 (HKLM\…\BlazeDTV 6.0_is1) (Version: - )
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 4.13 - Piriform)
CDBurnerXP (HKLM\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
Cinergy T Stick Driver Installation (32 Bit) (HKLM\…\{5123EBB5-0CB1-4EF1-8DF7-A4226537BCDC}) (Version: 8.08.18.01 - Nome società)
Comic Life 2 (HKLM\…\{A8405D99-9D76-4456-8752-87DA930CC3A3}) (Version: 2.2.5.0 - plasq LLC)
Core Temp 1.0 RC5 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
Corel PaintShop Pro X5 (HKLM\…\_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.2.0.12 - Corel Corporation)
Corel PaintShop Pro X5 (Version: 15.3.0.8 - Corel Corporation) Hidden
CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version: - CyberGhost S.R.L.)
EPSON Scan (HKLM\…\EPSON Scanner) (Version: - )
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version: - )
F24 On Line (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\F24 On Line) (Version: - Agenzia delle Entrate)
File Splitter and Joiner (FFSJ v3.3) (HKLM\…\File Splitter and Joiner_is1) (Version: - Le Minh Hoang)
FileInternet (HKLM\…\FileInternet) (Version: 2.9.9.0 - SOGEI)
FlvPlayer (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\FlvPlayer) (Version: ${VERSION} - ) <==== ATTENTION
Free Video Cutter Joiner 9.8 (HKLM\…\{8C5A4758-C782-4200-B337-DB3466D33ADD}}_is1) (Version: 9.8 - DVDVideoMedia, Inc.)
Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Earth (HKLM\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ATTENTION
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
GoToAssist Corporate (HKLM\…\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
HijackThis 2.0.2 (HKLM\…\HijackThis) (Version: 2.0.2 - TrendMicro)
ICA (Version: 15.2.0.12 - Corel Corporation) Hidden
iCloud (HKLM\…\{8D9592B4-7E22-4D1F-B2CB-B5F0F2F619CB}) (Version: 4.0.3.56 - Apple Inc.)
Internet Download Manager (HKLM\…\Internet Download Manager) (Version: - Tonec Inc.)
IPM_PSP_COM (Version: 15.2.0.12 - Corel Corporation) Hidden
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)
Java 8 Update 40 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Kaspersky Total Security (HKLM\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
Kaspersky Total Security (Version: 15.0.2.361 - Kaspersky Lab) Hidden
Kernel Outlook PST Viewer ver 11.05.01 (HKLM\…\Kernel Outlook PST Viewer_is1) (Version: - Lepide Software Pvt. Ltd.)
Last Man (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Last Man) (Version: - )
Link Wiz 1.10.0.14 (HKLM\…\LinkWiz_1.10.0.14) (Version: 1.10.0.14 - Link Wiz)
Malwarebytes Anti-Malware versione 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office XP Professional (HKLM\…\{91110410-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
ModuliControllo2013 (HKLM\…\ModuliControllo2013) (Version: 4.0.0.0 - Sogei S.p.A)
ModuliControlloUnico2014 (HKLM\…\ModuliControlloUnico2014) (Version: 1.1.1.0 - Sogei S.p.A)
Mozilla Firefox 37.0.2 (x86 it) (HKLM\…\Mozilla Firefox 37.0.2 (x86 it)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 31.6.0 (x86 it) (HKLM\…\Mozilla Thunderbird 31.6.0 (x86 it)) (Version: 31.6.0 - Mozilla)
MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Pacchetto di compatibilità per Office System 2007 (HKLM\…\{90120000-0020-0410-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Pacchetto driver Windows - TerraTec (AF9035BDA) Media (05/18/2009 8.08.18.01) (HKLM\…\3602780F32D3BB88DB2E972AE797966CC5105334) (Version: 05/18/2009 8.08.18.01 - TerraTec )
PDF Architect 2 (HKLM\…\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM\…\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
PGP Desktop (HKLM\…\{04A8595A-4B2F-4A20-BA5D-E6B371657FF8}) (Version: 10.0.2.13 - PGP Corporation)
PSPPContent (Version: 15.3.0.8 - Corel Corporation) Hidden
PSPPHelp (Version: 15.2.0.12 - Corel Corporation) Hidden
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Recuva (HKLM\…\Recuva) (Version: 1.45 - Piriform)
Setup (Version: 15.2.0.12 - Nome società) Hidden
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.2 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
slac (HKLM\…\slac_is1) (Version: - )
SpeedFan (remove only) (HKLM\…\SpeedFan) (Version: - )
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1040 - SUPERAntiSpyware.com)
Supporto applicazioni Apple (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
sweet-page uninstall (HKLM\…\sweet-page uninstall) (Version: - sweet-page) <==== ATTENTION
TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
TomTom HOME (HKLM\…\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - Nome società)
TomTom HOME (HKLM\…\{BB05590A-6602-43F3-A400-77EA0976BC0A}) (Version: 2.9.8 - Nome società)
TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
UltraZip (HKLM\…\{5E36886D-AE94-4901-82A6-A96381B7B4AD}_is1) (Version: 2.0.2.6 - UltraZip)
UnicOnLine PF 2014 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicOnLine PF 2014) (Version: - Agenzia delle Entrate)
UnicoOnLine - File Internet 2.9.9 (HKLM\…\File Internet) (Version: - )
UnicoOnLine PF 2012 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicoOnLine PF 2012) (Version: - Agenzia delle Entrate)
VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION
WinOff (HKLM\…\{8049EB00-4F62-44FB-AAF7-CB42F588E3C5}_is1) (Version: 1.0.1.5 - )
WinPhone (HKLM\…\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version: - )
WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Wisdom-soft ScreenHunter 6.0 Free (HKLM\…\Wisdom-soft ScreenHunter 6.0 Free) (Version: - Wisdom Software Inc.)
WriterPad (HKLM\…\{2E4ECAA8-6E82-4502-96BE-48D2DCCFA42A}) (Version: 1.0.0 - North Sky Productions LLC)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
==================== Restore Points =========================
25-04-2015 15:17:24 Windows Update
25-04-2015 16:44:04 Windows Backup
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:04 - 2014-05-21 23:31 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {09289DFA-8809-4294-AFB9-C9F05351A193} - System32\Tasks\{C8F3C4BF-1DF0-4D46-A1FA-731614A02DA6} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {10ED68ED-31D8-46CB-AF5C-5AF06004F5FE} - System32\Tasks\CleanerPro_Start => C:\Program Files\Cleaner Pro\CleanerPro.exe
Task: {1217E9D3-8939-4DCA-B835-08A6B3F9D25D} - System32\Tasks\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40} => C:\Users\Marco\Desktop\installspeedfan447.exe [2013-03-17] () <==== ATTENTION
Task: {167C0E59-CF26-45F6-8EF2-BFEC3799BD95} - System32\Tasks\{C250204F-A2AB-4261-B042-B58AEF0116AE} => C:\Corel\Draw701\programs\photopnt.exe
Task: {19980019-8149-4B71-A0AE-2B1B2C6D5A2A} - System32\Tasks\{3E0476D6-A2AA-4A2B-8F71-50978AD0A832} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {23D073A5-7AA0-47F5-B434-DA0D55C7F3B4} - System32\Tasks\{3CE02DF4-D192-416A-8EE2-8396B8CB6FB4} => C:\photopaint\PHOTOPNT.EXE
Task: {2A1DD022-029F-4067-B593-016E6960BB35} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
Task: {2C02D38D-F40F-447C-864B-90DD5FB6253E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {334F613A-8EE8-4BD7-ACC3-7FD62264BF03} - System32\Tasks\{02D2332A-A21D-4ABE-BD10-62DD01C4BF11} => pcalua.exe -a C:\corel\SETUP\DAOSETUP.EXE -d C:\corel\SETUP
Task: {4063D65F-FBE1-4343-AEF3-6C1DCA8671E0} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {483CD9A1-6E78-455D-B1E7-30F42C1F03C4} - System32\Tasks\{F6AB3366-2EA1-4C45-8745-C16EE86D334C} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {4CF1CB7B-346F-4195-B187-51DE750A68C8} - System32\Tasks\{DD07A107-F0F4-4746-9D64-C4E23A192425} => C:\Corel\Draw701\programs\photopnt.exe
Task: {52FBB622-5E59-464A-9911-3B94DF586442} - System32\Tasks\{5A1164C2-B0A7-48D0-84ED-49A59B0570E1} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {5BC90939-7441-4749-8374-0FAD29BB5DF6} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {5BCFC431-3B77-4BC1-BFA7-B699A44258FC} - System32\Tasks\{90112C02-23E4-42FE-8F5D-97299A848050} => pcalua.exe -a "C:\Program Files\weDownload Manager\Uninstall.exe" -c /fromcontrolpanel=1
Task: {6059284D-1243-46AF-B0A0-A10FCE072B4C} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {63216F46-D65D-4D30-BD8C-29A29223C00B} - System32\Tasks\{831D7081-34DF-4BD4-BC41-204C3B539114} => D:\Corel\Draw70\programs\photopnt.exe
Task: {66B33249-6DCB-485A-82F6-A570B2514A45} - System32\Tasks\{4DCA4D6B-3320-4ECC-9D3F-3391A219CE6E} => pcalua.exe -a L:\Compressed\cd_4.8a\CD_4.8A\CDSetup\setup.exe -d L:\Compressed\cd_4.8a\CD_4.8A\CDSetup
Task: {6D5C45BA-B65B-4FBD-89D0-22CA804D813B} - System32\Tasks\{3FB8CB96-A3C4-4B71-9F07-5FC531C22FFC} => D:\D\DOOM.EXE
Task: {794EBFAB-B0BC-4768-AE28-A37A4CFF2246} - System32\Tasks\{9C279F5D-7348-4DDB-A492-A91C311E3729} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {7AC1FF86-51CB-476C-A65F-108D684F6A55} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
Task: {7B5D3C19-0CDC-4AEE-8193-4A06B5456EEE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {80B2339F-C664-4EA6-8A16-EDE7EA353EE4} - System32\Tasks\{41FE69C8-BF1F-4934-9648-A0A09939AF14} => pcalua.exe -a C:\UnicoOnLine\UNI13\ModuliControllo2013_500.exe -d C:\UnicoOnLine\UNI13
Task: {91152ABF-40E7-47A4-A9EE-4F582F79205D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-12] (Adobe Systems Incorporated)
Task: {93D70EB9-D50F-48F3-9D11-D41103D61C3D} - System32\Tasks\{2DB657D7-D3D0-484F-985C-FF894C37A2C0} => pcalua.exe -a C:\UnicoOnLine\MainWinUNI10.exe -d C:\UnicoOnLine
Task: {99D0E47C-5928-4FF2-83EA-8BAE5279ED61} - System32\Tasks\{D70B1B3A-5B54-49A6-91E6-A08E94605404} => pcalua.exe -a C:\Downloads\JavaRa\JavaRa.exe -d C:\Downloads\JavaRa
Task: {A340BD43-ADF2-40C8-973E-2B761B71C336} - System32\Tasks\{E070B345-71E6-40B6-B67C-E5E15C72506C} => pcalua.exe -a C:\Users\Marco\Downloads\Programs\FileInternet297_ALL.exe -d C:\Users\Marco\AppData\Roaming\IDM
Task: {B891F30E-3144-4BEA-8532-94DAEC0EF6EC} - System32\Tasks\{A3616480-507E-4F82-B3E7-9890FB99A7FC} => pcalua.exe -a E:\Utility\oem\OEMSETUP.EXE -d E:\Utility\oem
Task: {BB5C9905-863B-4262-9B03-BAE445722A28} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {BFC6295F-521A-4DD8-8725-35B399C20BCA} - System32\Tasks\{5181E2DA-A9A2-40D7-B430-C237837B0CBF} => pcalua.exe -a "G:\Alice MOBILE E169\Setup.exe" -d "G:\Alice MOBILE E169"
Task: {C935C2EA-C3E1-45DA-B5A9-239D6413B18D} - System32\Tasks\{430B9F8B-41D9-47D6-B353-8FA97F5EC41D} => pcalua.exe -a G:\DataCard_Setup.exe -d G:\
Task: {CC2864F4-914F-429E-A619-77455BE5EC3E} - System32\Tasks\{AC48D273-25E1-4B48-A02E-752895342551} => pcalua.exe -a C:\Users\Marco\Downloads\Adaware_Installer.exe -d C:\Users\Marco\Downloads
Task: {CC7E475F-C850-4B25-ACEF-CDD11BBA37E2} - System32\Tasks\{CAB04F14-8D9A-4184-AD18-1D6C282DC6EB} => C:\Corel\Draw70\programs\photopnt.exe
Task: {CE056A31-1B02-4BD9-82D0-6BF77A020900} - System32\Tasks\{39990666-AFFE-47CF-9FB3-F8C0AA96CDCA} => C:\Corel\Draw70\programs\photopnt.exe
Task: {D0C0E802-98D1-4274-8A24-D773D3A00D75} - System32\Tasks\{5A25ECBD-0B9B-411F-BC7D-5A6B3BA0F7D7} => C:\Corel\Draw701\programs\photopnt.exe
Task: {D54B238F-5953-460D-88E0-B8048E3132D7} - System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
Task: {D64568DF-23EA-4B48-B558-8078C1D33660} - System32\Tasks\{F635ADB3-1AD0-4DB6-9D4A-AF79A638483D} => D:\Corel\Draw70\programs\photopnt.exe
Task: {D9321925-6B97-4A7D-AE9B-D14B82AB743B} - System32\Tasks\{C1FCF6FF-C6B1-4CE4-A4E8-602EDF5B3CDA} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {DCE67E6D-44BA-4C0A-AD11-A23973613C28} - System32\Tasks\{C9183C48-D1F3-43DF-94DC-905BC79BFC7F} => D:\D\DOOM.EXE
Task: {DCEAEDD8-71FA-4EE3-89A0-4249E42BB92D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
Task: {E82171A9-FF80-4C2F-B235-8E8ECA4BC5AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {ED600DD3-3408-418D-94EE-2D47E8BED7AB} - System32\Tasks\{228862AD-F5BD-40E3-9F7B-0FE46B8AE765} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {EDD2851A-7AC1-44BE-9308-D48A44C2F757} - System32\Tasks\{341FE709-8AFB-4377-9D6D-7344EF71CD9C} => pcalua.exe -a "C:\Program Files\Alice MOBILE E169\uninst.exe"
Task: {F299C7D5-4579-40CB-8652-C2D6F6B189D9} - System32\Tasks\{AC32368B-2CCF-4FDA-B77C-777AB7ED0781} => D:\Corel\Draw70\programs\photopnt.exe
Task: {F5606013-9B0D-40FB-AD90-4B22291BE6F8} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2015-01-15 00:12 - 2014-12-24 19:15 - 00270040 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\UiLogic.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00229080 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\diskmgr.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00278232 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Comn.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00077528 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Ldm.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00061144 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Device.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00265944 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrFat.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00384728 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrNtfs.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00118488 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FuncLogic.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00241368 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Clone.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00343768 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\ImgFile.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00028376 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Encrypt.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00073432 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Compress.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrVol.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00253656 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\GptBcd.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00151256 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FlBackup.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00483032 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\EnumFolder.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Backup.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00098008 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrLog.dll
2015-01-15 00:12 - 2013-01-17 18:38 - 02403504 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\QtCore4.dll
2014-12-06 21:11 - 2010-11-27 16:53 - 00061440 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.EXE
2014-12-06 21:11 - 2008-12-30 13:40 - 00094208 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\SkinScrollBar.Dll
2014-12-06 21:11 - 2010-11-29 19:33 - 00978944 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\PlayerDll.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00073728 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\VersionInfo.dll
2014-12-06 21:11 - 2010-11-27 11:47 - 00405504 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Configuration.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00167936 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\FileAssocator.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00151552 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\PowerManagementCtrl.dll
2014-12-06 21:11 - 2009-08-28 10:53 - 00196608 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RemoteControlCtrl.dll
2014-12-06 21:11 - 2010-07-05 11:28 - 00159744 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\NetReg.dll
2014-12-06 21:11 - 2010-12-01 17:37 - 00962560 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DTVDeviceManager.dll
2014-12-06 21:11 - 2010-02-08 18:22 - 00499712 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaPlayerCtrl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00077824 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RealMediaControl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00061440 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\QTMediaControl.dll
2014-12-06 21:11 - 2010-04-27 16:01 - 00180224 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\VideoWindow.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00090112 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DibLibDll.dll
2014-12-06 21:11 - 2010-07-21 14:48 - 00155648 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\AudioProcess.dll
2014-12-06 21:11 - 2010-08-16 18:39 - 00290816 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RecorderCtrl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00073728 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\ProfileStore.DLL
2014-12-06 21:11 - 2010-05-06 17:48 - 00024576 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RemoteControl\AF9100EXRC.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00106496 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\mlutil.dll
2014-12-06 21:11 - 2009-11-10 19:11 - 00057344 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RMACtrl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00420352 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\EqualizerProcess.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00420352 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\EchoDelayProcess.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00415744 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DSPAmplifyProcess.dll
2014-12-06 21:11 - 2010-11-13 15:37 - 00479232 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DTVPlayerCtrl.DLL
2014-12-06 21:11 - 2009-11-03 17:58 - 00163840 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\BlazeMpegDemuxer.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00073728 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\BlazePsiReceiver.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00114688 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\AudioProcessor.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00176128 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\MPEGMuxer.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00131072 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\FileWriter.ax
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:4CF8D17E
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
There are 7794 more restricted sites.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AdvancedSystemCareService7 => 2
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: CGVPNCliService => 2
MSCONFIG\Services: CSObjectsSrv => 2
MSCONFIG\Services: GoToAssist => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: Intelliservice => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: PDF Architect 2 => 3
MSCONFIG\Services: pdfforge CrashHandler => 3
MSCONFIG\Services: PSI_SVC_2 => 2
MSCONFIG\Services: SCardSvr => 3
MSCONFIG\Services: ServiceLayer => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: TomTomHOMEService => 2
MSCONFIG\Services: WGEGyK => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Advanced SystemCare 7 => "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: BlazeServoTool => "C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
MSCONFIG\startupreg: CloneCDTray => "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart /min
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IDMan => C:\Program Files\Internet Download Manager\IDMan.exe /onboot
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: McAfee McItInfo => C:\Users\Marco\AppData\Local\Temp\mcitinfo_1383311069.exe /itinsfin:C:\Users\Marco\AppData\Local\Temp\mcininfo_1383311069.ini
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: TBHostSupport => "C:\Windows\system32\Rundll32.exe" "C:\Users\Marco\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
==================== Faulty Device Manager Devices =============
Name: lwnfd_1_10_0_14
Description: lwnfd_1_10_0_14
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: lwnfd_1_10_0_14
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver
Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: Impossibile completare il backup a causa di un errore durante la scrittura nel percorso di backup G:\. Errore: Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006).
Error: (04/25/2015 07:25:19 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver
Error: (04/25/2015 05:52:23 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Impossibile inizializzare l'indice.
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Impossibile inizializzare l'applicazione.
Contesto: applicazione Windows
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Impossibile inizializzare l'oggetto Gatherer.
Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Impossibile inizializzare il plug-in .
Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Impossibile trovare elemento. (HRESULT : 0x80070490) (0x80070490)
Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Impossibile inizializzare il plug-in .
Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Impossibile caricare le informazioni dell'archivio di proprietà.
Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Il database dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041800) (0xc0041800)
System errors:
=============
Error: (04/26/2015 04:33:54 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: All'avvio non è stato possibile caricare i seguenti driver:
lwnfd_1_10_0_14
Error: (04/26/2015 04:33:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio lwnfd_1_10_0_14 non è stato avviato per il seguente errore:
%%2
Error: (04/26/2015 04:33:50 AM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)
Error: (04/26/2015 04:33:47 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
%%1058
Error: (04/26/2015 04:33:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
%%2
Error: (04/26/2015 04:33:17 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000007e (0xc0000006, 0x917f8ed3, 0x900e6c58, 0x900e6830)C:\Windows\MEMORY.DMP042615-19874-01
Error: (04/26/2015 04:33:12 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Precedente arresto del sistema inatteso a 04:31:25 su 26/04/2015.
Error: (04/26/2015 04:28:40 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio ShellHWDetection.
Error: (04/25/2015 07:26:21 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: WMPNetworkSvc0x80004005
Error: (04/25/2015 07:25:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: All'avvio non è stato possibile caricare i seguenti driver:
lwnfd_1_10_0_14
Microsoft Office Sessions:
=========================
Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver
Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: G:\Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006)
Error: (04/25/2015 07:25:19 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver
Error: (04/25/2015 05:52:23 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Contesto: applicazione Windows
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Impossibile trovare elemento. (HRESULT : 0x80070490) (0x80070490)
Search.TripoliIndexer
Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Il catalogo dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041801) (0xc0041801)
Search.JetPropStore
Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex
Dettagli:
Il database dell'indice del contenuto è danneggiato. (HRESULT : 0xc0041800) (0xc0041800)
CodeIntegrity Errors:
===================================
Date: 2015-03-10 00:07:34.988
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-10 00:07:34.976
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-10 00:07:34.976
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-10 00:07:34.916
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-10 00:07:34.906
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-10 00:07:34.906
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-09 23:36:43.482
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-09 23:36:43.472
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-09 23:36:43.422
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
Date: 2015-03-09 23:36:43.402
Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
Percentage of memory in use: 54%
Total physical RAM: 3000.86 MB
Available physical RAM: 1377.93 MB
Total Pagefile: 6000.02 MB
Available Pagefile: 4098.84 MB
Total Virtual: 2047.88 MB
Available Virtual: 1911.79 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:228.01 GB) (Free:52.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:227.98 GB) (Free:72.54 GB) NTFS
Drive e: (DGN1000v3) (CDROM) (Total:0.06 GB) (Free:0 GB) CDFS
Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:1.35 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: B0387136)
Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
Partition 2: (Active) - (Size=228 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=228 GB) - (Type=07 NTFS)
==================== End Of Log ============================