This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Thunderbird problems [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

From some days ago Thunderbird  connect to mail server, identify new mail and start to download.

But no message is downloaded and no error message is displayed.

 

In addition, immediately or some minutes later Firefox stop to work.

It seems that internet connection is lost but the adls router is perfectly connected.

Few minutes and Firefox crash

 

No way to reconnect Firefox to internet

The only way is shut down the PC and restart without using Thunderbird

 

here attaced the MBR and FRST logs

.

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-25 18:06:51
—————————–
18:06:51.499    OS Version: Windows 6.1.7601 Service Pack 1
18:06:51.499    Number of processors: 2 586 0xF0D
18:06:51.499    ComputerName: MARCO-PC  UserName: Marco
18:09:15.377    Initialize success
18:09:16.220    VM: initialized successfully
18:09:16.223    VM: Intel CPU virtualization not supported
18:12:18.488    AVAST engine defs: 15042401
19:03:20.385    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
19:03:20.385    Disk 0 Vendor: WDC_WD5000BEVT-22ZAT0 01.01A01 Size: 476940MB BusType: 11
19:03:20.557    Disk 0 MBR read successfully
19:03:20.557    Disk 0 MBR scan
19:03:20.573    Disk 0 Windows 7 default MBR code
19:03:20.604    Disk 0 Partition 1 00     27 Hidden NTFS WinRE MSDOS5.0    10000 MB offset 2048
19:03:20.604    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       233482 MB offset 20482048
19:03:20.619    Disk 0 default boot code
19:03:20.666    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       233456 MB offset 498653184
19:03:20.682    Disk 0 scanning sectors +976771072
19:03:20.760    Disk 0 scanning C:\Windows\system32\drivers
19:04:56.666    Service scanning
19:05:13.654    Service cm_km_w C:\Windows\system32\DRIVERS\cm_km_w.sys **LOCKED** 5
19:05:26.088    Service kl1 C:\Windows\system32\DRIVERS\kl1.sys **LOCKED** 5
19:05:26.306    Service kldisk C:\Windows\system32\DRIVERS\kldisk.sys **LOCKED** 5
19:05:26.540    Service klflt C:\Windows\system32\DRIVERS\klflt.sys **LOCKED** 5
19:05:26.727    Service klhk C:\Windows\system32\DRIVERS\klhk.sys **LOCKED** 5
19:05:27.258    Service KLIM6 C:\Windows\system32\DRIVERS\klim6.sys **LOCKED** 5
19:05:27.445    Service klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys **LOCKED** 5
19:05:27.648    Service klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys **LOCKED** 5
19:05:27.866    Service klpd C:\Windows\system32\DRIVERS\klpd.sys **LOCKED** 5
19:05:28.240    Service kltdi C:\Windows\system32\DRIVERS\kltdi.sys **LOCKED** 5
19:05:28.474    Service Klwtp C:\Windows\system32\DRIVERS\klwtp.sys **LOCKED** 5
19:05:28.693    Service kneps C:\Windows\system32\DRIVERS\kneps.sys **LOCKED** 5
19:06:01.858    Modules scanning
19:06:01.874    Disk 0 trace - called modules:
19:06:01.921    ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
19:06:01.936    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8717b888]
19:06:01.952    3 CLASSPNP.SYS[8c7bc59e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x87046908]
19:06:04.074    AVAST engine scan C:\Windows
19:06:09.783    AVAST engine scan C:\Windows\system32
19:15:02.477    Disk 0 MBR has been saved successfully to "C:\Downloads\MBR.dat"
19:15:02.509    The log file has been saved successfully to "C:\Downloads\aswMBR.txt"


aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-26 04:45:07
—————————–
04:45:07.846    OS Version: Windows 6.1.7601 Service Pack 1
04:45:07.846    Number of processors: 2 586 0xF0D
04:45:07.855    ComputerName: MARCO-PC  UserName: Marco
04:45:56.936    Initialize success
04:45:57.202    VM: initialized successfully
04:45:57.209    VM: Intel CPU virtualization not supported
04:56:43.297    AVAST engine defs: 15042501
04:57:11.142    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
04:57:11.149    Disk 0 Vendor: WDC_WD5000BEVT-22ZAT0 01.01A01 Size: 476940MB BusType: 11
04:57:11.317    Disk 0 MBR read successfully
04:57:11.326    Disk 0 MBR scan
04:57:11.343    Disk 0 Windows 7 default MBR code
04:57:11.371    Disk 0 Partition 1 00     27 Hidden NTFS WinRE MSDOS5.0    10000 MB offset 2048
04:57:11.388    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       233482 MB offset 20482048
04:57:11.406    Disk 0 default boot code
04:57:11.447    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       233456 MB offset 498653184
04:57:11.465    Disk 0 scanning sectors +976771072
04:57:11.614    Disk 0 scanning C:\Windows\system32\drivers
04:57:50.216    Service scanning
04:57:57.595    Service cm_km_w C:\Windows\system32\DRIVERS\cm_km_w.sys **LOCKED** 5
04:58:04.961    Service kl1 C:\Windows\system32\DRIVERS\kl1.sys **LOCKED** 5
04:58:05.023    Service kldisk C:\Windows\system32\DRIVERS\kldisk.sys **LOCKED** 5
04:58:05.123    Service klflt C:\Windows\system32\DRIVERS\klflt.sys **LOCKED** 5
04:58:05.195    Service klhk C:\Windows\system32\DRIVERS\klhk.sys **LOCKED** 5
04:58:05.444    Service KLIM6 C:\Windows\system32\DRIVERS\klim6.sys **LOCKED** 5
04:58:05.524    Service klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys **LOCKED** 5
04:58:05.588    Service klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys **LOCKED** 5
04:58:05.647    Service klpd C:\Windows\system32\DRIVERS\klpd.sys **LOCKED** 5
04:58:05.739    Service kltdi C:\Windows\system32\DRIVERS\kltdi.sys **LOCKED** 5
04:58:05.804    Service Klwtp C:\Windows\system32\DRIVERS\klwtp.sys **LOCKED** 5
04:58:05.892    Service kneps C:\Windows\system32\DRIVERS\kneps.sys **LOCKED** 5
04:58:26.951    Modules scanning
04:58:26.976    Disk 0 trace - called modules:
04:58:27.035    ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys ndis.sys athr.sys intelppm.sys
04:58:27.052    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f7e030]
04:58:27.069    3 CLASSPNP.SYS[8c5c559e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86e42908]
04:58:28.704    AVAST engine scan C:\Windows
04:58:33.882    AVAST engine scan C:\Windows\system32
05:07:40.405    AVAST engine scan C:\Windows\system32\drivers
05:08:18.730    AVAST engine scan C:\Users\Marco
05:28:46.205    AVAST engine scan C:\ProgramData
05:42:09.692    Disk 0 statistics 3020706/0/0 @ 1,01 MB/s
05:42:09.706    Scan finished successfully
05:43:13.211    Disk 0 MBR has been saved successfully to "C:\Downloads\MBR.dat"
05:43:13.314    The log file has been saved successfully to "C:\Downloads\aswMBR.txt"


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-04-2015
Ran by [removed] (administrator) on MARCO-PC on 26-04-2015 05:50:05
Running from C:\Downloads
[removed] Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Italiano (Italia)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe
(AOMEI Tech Co., Ltd.) C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Link Wiz) C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(PGP Corporation) C:\Windows\System32\PGPserv.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.EXE


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3898960 2015-04-20] (Tonec Inc.)
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
Lsa: [Notification Packages] scecli PGPpwflt
ShellIconOverlayIdentifiers: [IconOverlayHandlerAccessible] -> {3DBF5F01-3287-46EB-82CF-45AA5C241162} => C:\Windows\system32\PGPfsshl.dll [2010-04-01] (PGP Corporation)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2014-04-21] (Tonec Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.golliver.com
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
SearchScopes: HKLM -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL = http://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dnldmsd&cd;=2XzuyEtN2Y1L1QzutDyCtByEtB0BtDtA0B0E0A0Azyzy0DtCtN0D0Tzu0CyDyByBtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1318093972&ir;=
SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = http://www.istartsurf.com/web/?type=ds&ts;=1425272006&from;=tugs&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL =
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A1C3DFA2-A404-4C14-A7FD-BBA0C9707DE3} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A86D0113-4332-4553-A3F9-124DB478F4B5} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3306061&CUI;=UN30406771052739920&UM;=2
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = http://www.sweet-page.com/web/?type=ds&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {F84F0002-4F7D-43B3-A86D-076D14A000F0} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09] (Oracle Corporation)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09] (Oracle Corporation)
DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Windows\system32\Msdxm6.ocx [2000-04-21] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: sweet-page
FF SelectedSearchEngine: sweet-page
FF Homepage: hxxp://search.golliver.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-12] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-09] (Oracle Corporation)
FF Plugin: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
FF Plugin: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
FF Plugin: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll [2014-06-26] (pdfforge GmbH)
FF user.js: detected! => C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\user.js [2015-03-20]
FF SearchPlugin: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\searchplugins\sweet-page.xml [2015-04-25]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\golliver.xml [2015-04-25]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2014-05-18]
FF Extension: Golliver - C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox\Extensions\[removed] [2015-04-25]
FF Extension: Golliver - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\Extensions\[removed] [2015-04-25]
FF Extension: No Name - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-24]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\extensions\[removed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\extensions\[removed]
FF HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5 [2015-04-18]
FF HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-12-11]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.dregol.com/?f=1&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
CHR StartupUrls: Default -> "hxxp://www.dregol.com/?f=7&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=", "hxxp://www.sweet-page.com/?type=hp&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980"
CHR DefaultSearchKeyword: Default -> dregol.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Kaspersky Protection) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-04-15]
CHR Extension: (IDM Integration Module) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-15]
CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-15]
CHR HKLM\…\Chrome\Extension: [bollbfeakabenkobaocgakdibphdnanj] - http://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\…\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM\…\Chrome\Extension: [lipgolpfajiadodbcbljdpmbmbdmfcil] - C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2015-04-20]
CHR HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lipgolpfajiadodbcbljdpmbmbdmfcil] - C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-17] (SUPERAntiSpyware.com)
R2 AVP15.0.2; C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [193400 2014-12-23] (Kaspersky Lab ZAO)
R2 Backupper Service; C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
R2 lwsvc_1.10.0.14; C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe [278592 2015-04-10] (Link Wiz)
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S4 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
S4 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
R2 PGPserv; C:\Windows\system32\PGPserv.exe [135288 2010-04-01] (PGP Corporation)
S2 uzsvc; C:\Program Files\UltraZip\uzsvc.exe [531744 2015-03-10] ()
S2 uzupd; C:\Program Files\UltraZip\uzupd.exe [44312 2015-03-10] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 asl; "C:\ProgramData\Service\Application\asl.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AF9035BDA; C:\Windows\System32\DRIVERS\AF9035BDA.sys [248744 2012-08-10] (AfaTech                  )
R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [26424 2013-05-07] () [File not signed]
R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [129720 2013-05-07] () [File not signed]
R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [14392 2013-02-06] () [File not signed]
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [189136 2013-01-14] (Kaspersky Lab UK Ltd)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [94336 2014-12-19] (ITE                      )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [143968 2014-03-31] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46280 2015-03-27] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [120008 2014-11-28] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [36040 2014-10-22] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [698568 2015-03-27] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25800 2014-10-10] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [26824 2014-10-30] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [46152 2014-10-09] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [64200 2014-11-22] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [148296 2014-11-10] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-04-26] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 WsAudio_Device(1); C:\Windows\System32\drivers\VirtualAudio1.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(2); C:\Windows\System32\drivers\VirtualAudio2.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(3); C:\Windows\System32\drivers\VirtualAudio3.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(4); C:\Windows\System32\drivers\VirtualAudio4.sys [27496 2013-01-25] (Wondershare)
R3 WsAudio_Device(5); C:\Windows\System32\drivers\VirtualAudio5.sys [27496 2013-01-25] (Wondershare)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Marco\AppData\Local\Temp\catchme.sys [X]
S1 lwnfd_1_10_0_14; system32\drivers\lwnfd_1_10_0_14.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]
U3 aswMBR; \??\C:\Users\Marco\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Marco\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-26 04:33 - 2015-04-26 04:33 - 278896405 _____ () C:\Windows\MEMORY.DMP
2015-04-26 04:33 - 2015-04-26 04:33 - 00158560 _____ () C:\Windows\Minidump\042615-19874-01.dmp
2015-04-25 15:37 - 2015-04-25 15:37 - 00000137 _____ () C:\Users\Marco\Documents\gabriella.txt
2015-04-25 07:31 - 2015-04-26 05:50 - 00000000 ____D () C:\FRST
2015-04-25 07:14 - 2015-04-25 07:14 - 00002928 _____ () C:\Users\Marco\Documents\aswMBR.txt
2015-04-25 07:14 - 2015-04-25 07:14 - 00000512 _____ () C:\Users\Marco\Documents\MBR.dat
2015-04-25 06:34 - 2015-04-25 06:34 - 00000000 ____D () C:\ProgramData\6321271a0000001c
2015-04-25 06:26 - 2015-04-25 17:49 - 00000000 ____D () C:\Program Files\Run_Dregol
2015-04-25 06:26 - 2015-04-25 06:27 - 00000000 ____D () C:\Users\Marco\AppData\Local\nida
2015-04-25 06:12 - 2015-04-25 06:12 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\sweet-page
2015-04-25 06:05 - 2015-04-25 06:27 - 00000000 ___SD () C:\32788R22FWJFW
2015-04-25 06:05 - 2015-04-25 06:06 - 00000000 ____D () C:\Program Files\LinkWiz_1.10.0.14
2015-04-25 06:04 - 2015-04-25 06:21 - 00000000 ____D () C:\Users\Marco\Documents\CleanerPro
2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\Users\Marco\AppData\Local\CleanerPro
2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\ProgramData\UltraZip
2015-04-25 06:03 - 2015-04-25 17:52 - 00000000 ____D () C:\Program Files\UltraZip
2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Service
2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraZip
2015-04-25 06:02 - 2015-04-25 06:06 - 05619466 ____R (Swearware) C:\Users\Marco\Downloads\combofix [1].exe
2015-04-25 05:53 - 2015-04-26 04:33 - 00000392 _____ () C:\Windows\setupact.log
2015-04-25 05:53 - 2015-04-25 19:24 - 00320278 _____ () C:\Windows\PFRO.log
2015-04-25 05:53 - 2015-04-25 05:53 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-25 05:48 - 2015-04-25 05:48 - 00156898 _____ () C:\Users\Marco\Documents\cc_20150425_054751.reg
2015-04-20 14:53 - 2015-04-18 03:06 - 00122432 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
2015-04-19 06:56 - 2015-04-19 07:49 - 370938816 _____ () C:\Users\Marco\Downloads\0d6b8d7ca1.mp4.rar.part
2015-04-18 13:13 - 2015-04-18 17:27 - 742534663 _____ () C:\Users\Marco\Downloads\Cazzo.Grosso.Ma.Non.Troppo.Foreign.S.E.rar.part
2015-04-18 11:10 - 2015-04-18 11:35 - 105298398 _____ () C:\Users\Marco\Downloads\Dana Moravova _ Milada.avi.part
2015-04-18 07:02 - 2015-04-18 07:26 - 175777135 _____ () C:\Users\Marco\Downloads\Brooke_Tyler_-_shutup_and_blow_airport_hd.mp4
2015-04-14 21:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-14 21:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-14 21:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-14 21:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-14 21:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-14 21:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-14 21:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-14 21:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-14 21:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-14 21:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-14 21:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-14 21:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-14 21:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-14 21:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-14 21:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-14 21:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-14 21:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-14 21:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-14 21:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-14 21:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-14 21:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-14 21:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-14 21:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-14 21:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-14 21:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-14 21:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-14 21:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-14 21:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-14 21:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-14 21:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-14 21:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-14 21:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-14 21:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-14 21:40 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-14 21:40 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-14 21:40 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-14 21:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-14 21:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-14 21:40 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-14 21:40 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-14 21:40 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-14 21:40 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-14 21:40 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-14 21:40 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-14 21:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-14 21:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-14 21:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-14 21:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-14 21:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-14 21:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-14 21:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-14 21:40 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-14 21:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-14 21:39 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-14 21:39 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-11 10:13 - 2015-04-11 11:52 - 00000000 ____D () C:\Users\Marco\olimpus
2015-04-05 08:25 - 2015-04-05 08:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\RenPy
2015-04-05 07:20 - 2015-04-05 08:01 - 244140767 _____ () C:\Users\Marco\Downloads\wbc-1.0-all.rar
2015-04-05 06:59 - 2015-04-05 06:59 - 00000000 ____D () C:\Users\Marco\Tracing
2015-04-05 05:44 - 2015-04-05 05:44 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 10:26 - 2015-04-04 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\slac
2015-04-04 10:23 - 2015-04-04 10:23 - 00000000 ____D () C:\Program Files\slac
2015-04-04 08:16 - 2015-04-04 08:16 - 00000000 ____D () C:\Program Files\Common Files\Protexis
2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\Users\Public\Desktop\Corel PaintShop Pro X5.lnk
2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\ProgramData\Desktop\Corel PaintShop Pro X5.lnk
2015-04-04 08:15 - 2015-04-04 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X5
2015-04-03 08:13 - 2015-04-03 08:13 - 09629976 _____ (CyberGhost S.R.L. ) C:\Users\Marco\Downloads\CG_5.0.14.7.exe
2015-03-31 21:34 - 2015-03-31 21:34 - 00036168 _____ () C:\Users\Marco\Desktop\29177662s.pdf.zip
2015-03-28 15:43 - 2015-03-28 15:57 - 97954743 _____ () C:\Users\Marco\Downloads\6720_Возбужденная французская девочка трахнулась в офисе. - .mp4
2015-03-28 07:32 - 2015-03-28 09:08 - 701267673 _____ () C:\Users\Marco\Downloads\Kendra Lust.mp4

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-26 05:49 - 2013-03-05 23:43 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-26 05:34 - 2013-11-01 09:59 - 01869673 _____ () C:\Windows\WindowsUpdate.log
2015-04-26 05:12 - 2013-11-04 23:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-26 04:48 - 2014-05-22 06:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-04-26 04:42 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-26 04:42 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-26 04:33 - 2013-11-04 23:19 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-26 04:33 - 2013-07-12 04:50 - 00000000 ____D () C:\Windows\Minidump
2015-04-26 04:33 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-26 04:29 - 2014-05-21 22:11 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-25 19:20 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\DMCache
2015-04-25 17:56 - 2013-03-05 18:20 - 01786646 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-25 17:56 - 2009-07-14 10:21 - 00791368 _____ () C:\Windows\system32\perfh010.dat
2015-04-25 17:56 - 2009-07-14 10:21 - 00164498 _____ () C:\Windows\system32\perfc010.dat
2015-04-25 17:51 - 2014-05-23 06:31 - 00000000 ____D () C:\Program Files\Internet Download Manager
2015-04-25 17:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\PLA
2015-04-25 16:10 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\IDM
2015-04-25 10:08 - 2013-03-08 00:39 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc
2015-04-25 08:30 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-25 05:45 - 2014-09-08 18:30 - 00000000 ____D () C:\Program Files\PDFCreator
2015-04-25 05:43 - 2013-03-21 22:54 - 00000000 ____D () C:\Users\Marco\AppData\Local\CrashDumps
2015-04-25 05:43 - 2013-03-05 17:42 - 00000000 ____D () C:\Windows\Panther
2015-04-25 05:39 - 2013-11-10 08:53 - 00000000 ____D () C:\Users\Marco\AppData\Local\NativeMessaging
2015-04-25 05:38 - 2014-12-08 08:24 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\FlvPlayer
2015-04-25 05:38 - 2013-11-10 08:53 - 00000000 ____D () C:\ProgramData\Conduit
2015-04-25 04:42 - 2014-05-21 22:11 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-25 04:42 - 2014-05-21 22:11 - 00001024 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-25 04:42 - 2014-05-21 22:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-25 04:42 - 2014-05-21 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-24 18:42 - 2013-03-05 20:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-24 06:25 - 2014-12-11 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-24 06:25 - 2013-03-17 10:18 - 00000000 ____D () C:\Program Files\SpeedFan
2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2015-04-16 01:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-16 01:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-14 23:56 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-14 22:33 - 2014-12-10 07:47 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-14 22:33 - 2014-05-01 08:15 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-14 22:33 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT
2015-04-14 22:10 - 2013-08-14 09:55 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-14 21:55 - 2013-03-10 07:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-12 17:25 - 2014-06-24 21:39 - 00000000 ____D () C:\Users\Marco\AppData\Local\Adobe
2015-04-12 17:25 - 2013-03-05 23:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-12 17:25 - 2013-03-05 23:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-11 10:13 - 2013-03-05 18:23 - 00000000 ____D () C:\Users\Marco
2015-04-07 21:42 - 2014-12-20 17:59 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2015-04-05 07:01 - 2014-08-05 21:03 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\Skype
2015-04-05 06:59 - 2014-08-05 21:02 - 00000000 ___RD () C:\Program Files\Skype
2015-04-05 06:58 - 2014-08-05 21:02 - 00000000 ____D () C:\ProgramData\Skype
2015-04-04 10:26 - 2013-03-06 00:34 - 00023392 _____ () C:\Windows\system32\nscompat.tlb
2015-04-04 08:17 - 2013-03-12 07:21 - 00000000 ____D () C:\ProgramData\Corel
2015-04-04 08:13 - 2013-03-12 07:16 - 00000000 ____D () C:\Program Files\Corel
2015-04-04 08:05 - 2015-02-16 21:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Last_Man
2015-04-03 09:08 - 2014-04-23 05:10 - 00001845 _____ () C:\Users\Marco\Desktop\CyberGhost 5.lnk
2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\Program Files\CyberGhost 5
2015-03-28 10:49 - 2014-10-07 17:44 - 00000000 ____D () C:\ProgramData\XyLwfe
2015-03-27 07:21 - 2014-12-13 19:21 - 00698568 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-03-27 07:21 - 2014-08-19 13:31 - 00046280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kldisk.sys

==================== Files in the root of some directories =======

2013-03-12 07:27 - 2013-03-12 07:27 - 0003584 _____ () C:\Users\Marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-23 06:57 - 2013-05-23 06:59 - 0007602 _____ () C:\Users\Marco\AppData\Local\resmon.resmoncfg
2014-04-21 10:30 - 2014-04-21 10:30 - 0000041 ___SH () C:\ProgramData\.zreglib
2014-07-31 06:26 - 2014-07-31 06:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-03-17 09:07 - 2013-03-17 09:07 - 0000008 __RSH () C:\ProgramData\sysqcl1129067056.dat

Files to move or delete:
====================
C:\ProgramData\sysqcl1129067056.dat


Some content of TEMP:
====================
C:\Users\Marco\AppData\Local\Temp\sfamcc00001.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-14 00:36

==================== End Of Log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-04-2015
Ran by [removed] at 2015-04-26 05:51:26
Running from C:\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4094248773-42424133-2592686105-500 - Administrator - Disabled)
Guest (S-1-5-21-4094248773-42424133-2592686105-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4094248773-42424133-2592686105-1002 - Limited - Enabled)
Marco (S-1-5-21-4094248773-42424133-2592686105-1000 - Administrator - Enabled) => C:\Users\Marco

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Total Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Total Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 15 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Italiano (HKLM\…\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adventure Maker v4.6.1 (build1) (HKLM\…\Adventure Maker v4.6.1_is1) (Version:  - )
Adventure Maker v4.7.1 (build1) (HKLM\…\Adventure Maker v4.7.1_is1) (Version:  - )
Aimersoft DRM Media Converter(Build 1.5.5.0) (HKLM\…\Aimersoft DRM Media Converter_is1) (Version:  - Aimersoft Software)
Alice MOBILE E169 (HKLM\…\Alice MOBILE E169) (Version: 11.002.04.11.192 - Huawei Technologies Co.,Ltd)
Any Video Converter 5.6.3 (HKLM\…\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
AOMEI Backupper Standard Edition 2.2 (HKLM\…\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version:  - AOMEI Technology Co., Ltd.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
BlazeDTV 6.0 (HKLM\…\BlazeDTV 6.0_is1) (Version:  - )
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 4.13 - Piriform)
CDBurnerXP (HKLM\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
Cinergy T Stick Driver Installation (32 Bit) (HKLM\…\{5123EBB5-0CB1-4EF1-8DF7-A4226537BCDC}) (Version: 8.08.18.01 - Nome società)
Comic Life 2 (HKLM\…\{A8405D99-9D76-4456-8752-87DA930CC3A3}) (Version: 2.2.5.0 - plasq LLC)
Core Temp 1.0 RC5 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
Corel PaintShop Pro X5 (HKLM\…\_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.2.0.12 - Corel Corporation)
Corel PaintShop Pro X5 (Version: 15.3.0.8 - Corel Corporation) Hidden
CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
EPSON Scan (HKLM\…\EPSON Scanner) (Version:  - )
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
F24 On Line (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\F24 On Line) (Version:  - Agenzia delle Entrate)
File Splitter and Joiner (FFSJ v3.3) (HKLM\…\File Splitter and Joiner_is1) (Version:  - Le Minh Hoang)
FileInternet (HKLM\…\FileInternet) (Version: 2.9.9.0 - SOGEI)
FlvPlayer (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\FlvPlayer) (Version: ${VERSION} - ) <==== ATTENTION
Free Video Cutter Joiner 9.8 (HKLM\…\{8C5A4758-C782-4200-B337-DB3466D33ADD}}_is1) (Version: 9.8 - DVDVideoMedia, Inc.)
Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Earth (HKLM\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ATTENTION
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
GoToAssist Corporate (HKLM\…\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
HijackThis 2.0.2 (HKLM\…\HijackThis) (Version: 2.0.2 - TrendMicro)
ICA (Version: 15.2.0.12 - Corel Corporation) Hidden
iCloud (HKLM\…\{8D9592B4-7E22-4D1F-B2CB-B5F0F2F619CB}) (Version: 4.0.3.56 - Apple Inc.)
Internet Download Manager (HKLM\…\Internet Download Manager) (Version:  - Tonec Inc.)
IPM_PSP_COM (Version: 15.2.0.12 - Corel Corporation) Hidden
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)
Java 8 Update 40 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Kaspersky Total Security (HKLM\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
Kaspersky Total Security (Version: 15.0.2.361 - Kaspersky Lab) Hidden
Kernel Outlook PST Viewer ver 11.05.01 (HKLM\…\Kernel Outlook PST Viewer_is1) (Version:  - Lepide Software Pvt. Ltd.)
Last Man (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Last Man) (Version:  - )
Link Wiz 1.10.0.14 (HKLM\…\LinkWiz_1.10.0.14) (Version: 1.10.0.14 - Link Wiz)
Malwarebytes Anti-Malware versione 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office XP Professional (HKLM\…\{91110410-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
ModuliControllo2013 (HKLM\…\ModuliControllo2013) (Version: 4.0.0.0 - Sogei S.p.A)
ModuliControlloUnico2014 (HKLM\…\ModuliControlloUnico2014) (Version: 1.1.1.0 - Sogei S.p.A)
Mozilla Firefox 37.0.2 (x86 it) (HKLM\…\Mozilla Firefox 37.0.2 (x86 it)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 31.6.0 (x86 it) (HKLM\…\Mozilla Thunderbird 31.6.0 (x86 it)) (Version: 31.6.0 - Mozilla)
MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Pacchetto di compatibilità per Office System 2007 (HKLM\…\{90120000-0020-0410-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Pacchetto driver Windows - TerraTec  (AF9035BDA) Media  (05/18/2009 8.08.18.01) (HKLM\…\3602780F32D3BB88DB2E972AE797966CC5105334) (Version: 05/18/2009 8.08.18.01 - TerraTec )
PDF Architect 2 (HKLM\…\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM\…\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
PGP Desktop (HKLM\…\{04A8595A-4B2F-4A20-BA5D-E6B371657FF8}) (Version: 10.0.2.13 - PGP Corporation)
PSPPContent (Version: 15.3.0.8 - Corel Corporation) Hidden
PSPPHelp (Version: 15.2.0.12 - Corel Corporation) Hidden
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Recuva (HKLM\…\Recuva) (Version: 1.45 - Piriform)
Setup (Version: 15.2.0.12 - Nome società) Hidden
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.2 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
slac (HKLM\…\slac_is1) (Version:  - )
SpeedFan (remove only) (HKLM\…\SpeedFan) (Version:  - )
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1040 - SUPERAntiSpyware.com)
Supporto applicazioni Apple (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
sweet-page uninstall (HKLM\…\sweet-page uninstall) (Version:  - sweet-page) <==== ATTENTION
TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
TomTom HOME (HKLM\…\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - Nome società)
TomTom HOME (HKLM\…\{BB05590A-6602-43F3-A400-77EA0976BC0A}) (Version: 2.9.8 - Nome società)
TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
UltraZip (HKLM\…\{5E36886D-AE94-4901-82A6-A96381B7B4AD}_is1) (Version: 2.0.2.6 - UltraZip)
UnicOnLine PF 2014 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicOnLine PF 2014) (Version:  - Agenzia delle Entrate)
UnicoOnLine - File Internet 2.9.9 (HKLM\…\File Internet) (Version:  - )
UnicoOnLine PF 2012 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicoOnLine PF 2012) (Version:  - Agenzia delle Entrate)
VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION
WinOff (HKLM\…\{8049EB00-4F62-44FB-AAF7-CB42F588E3C5}_is1) (Version: 1.0.1.5 - )
WinPhone (HKLM\…\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version:  - )
WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Wisdom-soft ScreenHunter 6.0 Free (HKLM\…\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
WriterPad (HKLM\…\{2E4ECAA8-6E82-4502-96BE-48D2DCCFA42A}) (Version: 1.0.0 - North Sky Productions LLC)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

==================== Restore Points  =========================

25-04-2015 15:17:24 Windows Update
25-04-2015 16:44:04 Windows Backup

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2014-05-21 23:31 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {09289DFA-8809-4294-AFB9-C9F05351A193} - System32\Tasks\{C8F3C4BF-1DF0-4D46-A1FA-731614A02DA6} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {10ED68ED-31D8-46CB-AF5C-5AF06004F5FE} - System32\Tasks\CleanerPro_Start => C:\Program Files\Cleaner Pro\CleanerPro.exe
Task: {1217E9D3-8939-4DCA-B835-08A6B3F9D25D} - System32\Tasks\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40} => C:\Users\Marco\Desktop\installspeedfan447.exe [2013-03-17] () <==== ATTENTION
Task: {167C0E59-CF26-45F6-8EF2-BFEC3799BD95} - System32\Tasks\{C250204F-A2AB-4261-B042-B58AEF0116AE} => C:\Corel\Draw701\programs\photopnt.exe
Task: {19980019-8149-4B71-A0AE-2B1B2C6D5A2A} - System32\Tasks\{3E0476D6-A2AA-4A2B-8F71-50978AD0A832} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {23D073A5-7AA0-47F5-B434-DA0D55C7F3B4} - System32\Tasks\{3CE02DF4-D192-416A-8EE2-8396B8CB6FB4} => C:\photopaint\PHOTOPNT.EXE
Task: {2A1DD022-029F-4067-B593-016E6960BB35} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
Task: {2C02D38D-F40F-447C-864B-90DD5FB6253E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {334F613A-8EE8-4BD7-ACC3-7FD62264BF03} - System32\Tasks\{02D2332A-A21D-4ABE-BD10-62DD01C4BF11} => pcalua.exe -a C:\corel\SETUP\DAOSETUP.EXE -d C:\corel\SETUP
Task: {4063D65F-FBE1-4343-AEF3-6C1DCA8671E0} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {483CD9A1-6E78-455D-B1E7-30F42C1F03C4} - System32\Tasks\{F6AB3366-2EA1-4C45-8745-C16EE86D334C} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {4CF1CB7B-346F-4195-B187-51DE750A68C8} - System32\Tasks\{DD07A107-F0F4-4746-9D64-C4E23A192425} => C:\Corel\Draw701\programs\photopnt.exe
Task: {52FBB622-5E59-464A-9911-3B94DF586442} - System32\Tasks\{5A1164C2-B0A7-48D0-84ED-49A59B0570E1} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {5BC90939-7441-4749-8374-0FAD29BB5DF6} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {5BCFC431-3B77-4BC1-BFA7-B699A44258FC} - System32\Tasks\{90112C02-23E4-42FE-8F5D-97299A848050} => pcalua.exe -a "C:\Program Files\weDownload Manager\Uninstall.exe" -c /fromcontrolpanel=1
Task: {6059284D-1243-46AF-B0A0-A10FCE072B4C} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {63216F46-D65D-4D30-BD8C-29A29223C00B} - System32\Tasks\{831D7081-34DF-4BD4-BC41-204C3B539114} => D:\Corel\Draw70\programs\photopnt.exe
Task: {66B33249-6DCB-485A-82F6-A570B2514A45} - System32\Tasks\{4DCA4D6B-3320-4ECC-9D3F-3391A219CE6E} => pcalua.exe -a L:\Compressed\cd_4.8a\CD_4.8A\CDSetup\setup.exe -d L:\Compressed\cd_4.8a\CD_4.8A\CDSetup
Task: {6D5C45BA-B65B-4FBD-89D0-22CA804D813B} - System32\Tasks\{3FB8CB96-A3C4-4B71-9F07-5FC531C22FFC} => D:\D\DOOM.EXE
Task: {794EBFAB-B0BC-4768-AE28-A37A4CFF2246} - System32\Tasks\{9C279F5D-7348-4DDB-A492-A91C311E3729} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {7AC1FF86-51CB-476C-A65F-108D684F6A55} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
Task: {7B5D3C19-0CDC-4AEE-8193-4A06B5456EEE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {80B2339F-C664-4EA6-8A16-EDE7EA353EE4} - System32\Tasks\{41FE69C8-BF1F-4934-9648-A0A09939AF14} => pcalua.exe -a C:\UnicoOnLine\UNI13\ModuliControllo2013_500.exe -d C:\UnicoOnLine\UNI13
Task: {91152ABF-40E7-47A4-A9EE-4F582F79205D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-12] (Adobe Systems Incorporated)
Task: {93D70EB9-D50F-48F3-9D11-D41103D61C3D} - System32\Tasks\{2DB657D7-D3D0-484F-985C-FF894C37A2C0} => pcalua.exe -a C:\UnicoOnLine\MainWinUNI10.exe -d C:\UnicoOnLine
Task: {99D0E47C-5928-4FF2-83EA-8BAE5279ED61} - System32\Tasks\{D70B1B3A-5B54-49A6-91E6-A08E94605404} => pcalua.exe -a C:\Downloads\JavaRa\JavaRa.exe -d C:\Downloads\JavaRa
Task: {A340BD43-ADF2-40C8-973E-2B761B71C336} - System32\Tasks\{E070B345-71E6-40B6-B67C-E5E15C72506C} => pcalua.exe -a C:\Users\Marco\Downloads\Programs\FileInternet297_ALL.exe -d C:\Users\Marco\AppData\Roaming\IDM
Task: {B891F30E-3144-4BEA-8532-94DAEC0EF6EC} - System32\Tasks\{A3616480-507E-4F82-B3E7-9890FB99A7FC} => pcalua.exe -a E:\Utility\oem\OEMSETUP.EXE -d E:\Utility\oem
Task: {BB5C9905-863B-4262-9B03-BAE445722A28} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {BFC6295F-521A-4DD8-8725-35B399C20BCA} - System32\Tasks\{5181E2DA-A9A2-40D7-B430-C237837B0CBF} => pcalua.exe -a "G:\Alice MOBILE E169\Setup.exe" -d "G:\Alice MOBILE E169"
Task: {C935C2EA-C3E1-45DA-B5A9-239D6413B18D} - System32\Tasks\{430B9F8B-41D9-47D6-B353-8FA97F5EC41D} => pcalua.exe -a G:\DataCard_Setup.exe -d G:\
Task: {CC2864F4-914F-429E-A619-77455BE5EC3E} - System32\Tasks\{AC48D273-25E1-4B48-A02E-752895342551} => pcalua.exe -a C:\Users\Marco\Downloads\Adaware_Installer.exe -d C:\Users\Marco\Downloads
Task: {CC7E475F-C850-4B25-ACEF-CDD11BBA37E2} - System32\Tasks\{CAB04F14-8D9A-4184-AD18-1D6C282DC6EB} => C:\Corel\Draw70\programs\photopnt.exe
Task: {CE056A31-1B02-4BD9-82D0-6BF77A020900} - System32\Tasks\{39990666-AFFE-47CF-9FB3-F8C0AA96CDCA} => C:\Corel\Draw70\programs\photopnt.exe
Task: {D0C0E802-98D1-4274-8A24-D773D3A00D75} - System32\Tasks\{5A25ECBD-0B9B-411F-BC7D-5A6B3BA0F7D7} => C:\Corel\Draw701\programs\photopnt.exe
Task: {D54B238F-5953-460D-88E0-B8048E3132D7} - System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
Task: {D64568DF-23EA-4B48-B558-8078C1D33660} - System32\Tasks\{F635ADB3-1AD0-4DB6-9D4A-AF79A638483D} => D:\Corel\Draw70\programs\photopnt.exe
Task: {D9321925-6B97-4A7D-AE9B-D14B82AB743B} - System32\Tasks\{C1FCF6FF-C6B1-4CE4-A4E8-602EDF5B3CDA} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {DCE67E6D-44BA-4C0A-AD11-A23973613C28} - System32\Tasks\{C9183C48-D1F3-43DF-94DC-905BC79BFC7F} => D:\D\DOOM.EXE
Task: {DCEAEDD8-71FA-4EE3-89A0-4249E42BB92D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
Task: {E82171A9-FF80-4C2F-B235-8E8ECA4BC5AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {ED600DD3-3408-418D-94EE-2D47E8BED7AB} - System32\Tasks\{228862AD-F5BD-40E3-9F7B-0FE46B8AE765} => C:\corel\PROGRAMS\PHOTOPNT.EXE
Task: {EDD2851A-7AC1-44BE-9308-D48A44C2F757} - System32\Tasks\{341FE709-8AFB-4377-9D6D-7344EF71CD9C} => pcalua.exe -a "C:\Program Files\Alice MOBILE E169\uninst.exe"
Task: {F299C7D5-4579-40CB-8652-C2D6F6B189D9} - System32\Tasks\{AC32368B-2CCF-4FDA-B77C-777AB7ED0781} => D:\Corel\Draw70\programs\photopnt.exe
Task: {F5606013-9B0D-40FB-AD90-4B22291BE6F8} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2015-01-15 00:12 - 2014-12-24 19:15 - 00270040 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\UiLogic.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00229080 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\diskmgr.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00278232 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Comn.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00077528 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Ldm.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00061144 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Device.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00265944 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrFat.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00384728 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrNtfs.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00118488 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FuncLogic.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00241368 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Clone.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00343768 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\ImgFile.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00028376 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Encrypt.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00073432 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Compress.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrVol.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00253656 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\GptBcd.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00151256 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FlBackup.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00483032 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\EnumFolder.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Backup.dll
2015-01-15 00:12 - 2014-12-24 19:15 - 00098008 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrLog.dll
2015-01-15 00:12 - 2013-01-17 18:38 - 02403504 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\QtCore4.dll
2014-12-06 21:11 - 2010-11-27 16:53 - 00061440 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.EXE
2014-12-06 21:11 - 2008-12-30 13:40 - 00094208 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\SkinScrollBar.Dll
2014-12-06 21:11 - 2010-11-29 19:33 - 00978944 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\PlayerDll.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00073728 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\VersionInfo.dll
2014-12-06 21:11 - 2010-11-27 11:47 - 00405504 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Configuration.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00167936 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\FileAssocator.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00151552 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\PowerManagementCtrl.dll
2014-12-06 21:11 - 2009-08-28 10:53 - 00196608 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RemoteControlCtrl.dll
2014-12-06 21:11 - 2010-07-05 11:28 - 00159744 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\NetReg.dll
2014-12-06 21:11 - 2010-12-01 17:37 - 00962560 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DTVDeviceManager.dll
2014-12-06 21:11 - 2010-02-08 18:22 - 00499712 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaPlayerCtrl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00077824 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RealMediaControl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00061440 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\QTMediaControl.dll
2014-12-06 21:11 - 2010-04-27 16:01 - 00180224 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\VideoWindow.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00090112 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DibLibDll.dll
2014-12-06 21:11 - 2010-07-21 14:48 - 00155648 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\AudioProcess.dll
2014-12-06 21:11 - 2010-08-16 18:39 - 00290816 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RecorderCtrl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00073728 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\ProfileStore.DLL
2014-12-06 21:11 - 2010-05-06 17:48 - 00024576 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RemoteControl\AF9100EXRC.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00106496 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\mlutil.dll
2014-12-06 21:11 - 2009-11-10 19:11 - 00057344 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\RMACtrl.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00420352 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\EqualizerProcess.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00420352 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\EchoDelayProcess.dll
2014-12-06 21:11 - 2008-12-30 13:40 - 00415744 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DSPAmplifyProcess.dll
2014-12-06 21:11 - 2010-11-13 15:37 - 00479232 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\DTVPlayerCtrl.DLL
2014-12-06 21:11 - 2009-11-03 17:58 - 00163840 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\BlazeMpegDemuxer.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00073728 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\BlazePsiReceiver.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00114688 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\AudioProcessor.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00176128 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\MPEGMuxer.ax
2014-12-06 21:11 - 2008-12-30 13:40 - 00131072 _____ () C:\Program Files\BlazeVideo\BlazeDTV 6.0\Filters\FileWriter.ax

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:4CF8D17E

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

There are 7794 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AdvancedSystemCareService7 => 2
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: CGVPNCliService => 2
MSCONFIG\Services: CSObjectsSrv => 2
MSCONFIG\Services: GoToAssist => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: Intelliservice => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: PDF Architect 2 => 3
MSCONFIG\Services: pdfforge CrashHandler => 3
MSCONFIG\Services: PSI_SVC_2 => 2
MSCONFIG\Services: SCardSvr => 3
MSCONFIG\Services: ServiceLayer => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: TomTomHOMEService => 2
MSCONFIG\Services: WGEGyK => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Advanced SystemCare 7 => "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: BlazeServoTool => "C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
MSCONFIG\startupreg: CloneCDTray => "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart /min
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IDMan => C:\Program Files\Internet Download Manager\IDMan.exe /onboot
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: McAfee McItInfo => C:\Users\Marco\AppData\Local\Temp\mcitinfo_1383311069.exe /itinsfin:C:\Users\Marco\AppData\Local\Temp\mcininfo_1383311069.ini
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: TBHostSupport => "C:\Windows\system32\Rundll32.exe" "C:\Users\Marco\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"

==================== Faulty Device Manager Devices =============

Name: lwnfd_1_10_0_14
Description: lwnfd_1_10_0_14
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: lwnfd_1_10_0_14
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: Impossibile completare il backup a causa di un errore durante la scrittura nel percorso di backup G:\. Errore: Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006).

Error: (04/25/2015 07:25:19 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

Error: (04/25/2015 05:52:23 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Impossibile inizializzare l'indice.

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Impossibile inizializzare l'applicazione.

Contesto: applicazione Windows

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Impossibile inizializzare l'oggetto Gatherer.

Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Impossibile inizializzare il plug-in .

Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Impossibile trovare elemento.  (HRESULT : 0x80070490) (0x80070490)

Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Impossibile inizializzare il plug-in .

Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Impossibile caricare le informazioni dell'archivio di proprietà.

Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Il database dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041800) (0xc0041800)


System errors:
=============
Error: (04/26/2015 04:33:54 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: All'avvio non è stato possibile caricare i seguenti driver:
lwnfd_1_10_0_14

Error: (04/26/2015 04:33:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio lwnfd_1_10_0_14 non è stato avviato per il seguente errore:
%%2

Error: (04/26/2015 04:33:50 AM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)

Error: (04/26/2015 04:33:47 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
%%1058

Error: (04/26/2015 04:33:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
%%2

Error: (04/26/2015 04:33:17 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000007e (0xc0000006, 0x917f8ed3, 0x900e6c58, 0x900e6830)C:\Windows\MEMORY.DMP042615-19874-01

Error: (04/26/2015 04:33:12 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Precedente arresto del sistema inatteso a 04:31:25 su ‎26/‎04/‎2015.

Error: (04/26/2015 04:28:40 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio ShellHWDetection.

Error: (04/25/2015 07:26:21 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: WMPNetworkSvc0x80004005

Error: (04/25/2015 07:25:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: All'avvio non è stato possibile caricare i seguenti driver:
lwnfd_1_10_0_14


Microsoft Office Sessions:
=========================
Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: G:\Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006)

Error: (04/25/2015 07:25:19 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

Error: (04/25/2015 05:52:23 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Contesto: applicazione Windows

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Impossibile trovare elemento.  (HRESULT : 0x80070490) (0x80070490)
Search.TripoliIndexer

Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)
Search.JetPropStore

Error: (04/25/2015 05:54:28 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Contesto: applicazione Windows, catalogo SystemIndex

Dettagli:
    Il database dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041800) (0xc0041800)


CodeIntegrity Errors:
===================================
  Date: 2015-03-10 00:07:34.988
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-10 00:07:34.976
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-10 00:07:34.976
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-10 00:07:34.916
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-10 00:07:34.906
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-10 00:07:34.906
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-09 23:36:43.482
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-09 23:36:43.472
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-09 23:36:43.422
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

  Date: 2015-03-09 23:36:43.402
  Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
Percentage of memory in use: 54%
Total physical RAM: 3000.86 MB
Available physical RAM: 1377.93 MB
Total Pagefile: 6000.02 MB
Available Pagefile: 4098.84 MB
Total Virtual: 2047.88 MB
Available Virtual: 1911.79 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:228.01 GB) (Free:52.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:227.98 GB) (Free:72.54 GB) NTFS
Drive e: (DGN1000v3) (CDROM) (Total:0.06 GB) (Free:0 GB) CDFS
Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:1.35 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: B0387136)
Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
Partition 2: (Active) - (Size=228 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=228 GB) - (Type=07 NTFS)

==================== End Of Log ============================

 

:welcome:

 

You have a lot going on that bad, lets do this

 

 
Your running FRST from your downloads folder, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST exactly where we want it to be. 
 
 
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner To your Desktop
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. <———
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MBAM2010601022_zpsyvzbaddn.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Hi Ken Thanks for your help

          I have done all qhat you suggest and here attached you can find the resuls.

          Take care that malwerebytes han produced no results and I was no able to copu any

          1) FRST Logfile

          can result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2015 01
          Ran by [removed] (administrator) on MARCO-PC on 27-04-2015 22:47:50
          Running from C:\Users\[removed]\Desktop
          [removed] Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Italiano (Italia)
          Internet Explorer Version 11 (Default browser: FF)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

          ==================== Processes (Whitelisted) =================

          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

          (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe
          (AOMEI Tech Co., Ltd.) C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe
          (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
          (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
          (Link Wiz) C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe
          (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
          (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
          (PGP Corporation) C:\Windows\System32\PGPserv.exe
          (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
          (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
          (Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
          (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe
          (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
          (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
          (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
          (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
          (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
          (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


          ==================== Registry (Whitelisted) ==================

          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

          Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
          HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3898960 2015-04-20] (Tonec Inc.)
          HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
          Lsa: [Notification Packages] scecli PGPpwflt
          ShellIconOverlayIdentifiers: [IconOverlayHandlerAccessible] -> {3DBF5F01-3287-46EB-82CF-45AA5C241162} => C:\Windows\system32\PGPfsshl.dll [2010-04-01] (PGP Corporation)
          ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2014-04-21] (Tonec Inc.)
          GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

          ==================== Internet (Whitelisted) ====================

          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

          HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
          HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
          HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
          HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
          HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
          HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
          HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
          HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
          HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
          HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
          SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
          SearchScopes: HKLM -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL = http://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=dnldmsd&cd;=2XzuyEtN2Y1L1QzutDyCtByEtB0BtDtA0B0E0A0Azyzy0DtCtN0D0Tzu0CyDyByBtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1318093972&ir;=
          SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = http://www.istartsurf.com/web/?type=ds&ts;=1425272006&from;=tugs&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms}
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.dregol.com/results.php?f=4&q;={searchTerms}&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL =
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A1C3DFA2-A404-4C14-A7FD-BBA0C9707DE3} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A86D0113-4332-4553-A3F9-124DB478F4B5} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3306061&CUI;=UN30406771052739920&UM;=2
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = http://www.sweet-page.com/web/?type=ds&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms}
          SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {F84F0002-4F7D-43B3-A86D-076D14A000F0} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
          BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
          BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
          BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09] (Oracle Corporation)
          BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
          BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
          BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
          BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09] (Oracle Corporation)
          DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
          Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
          Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Windows\system32\Msdxm6.ocx [2000-04-21] (Microsoft Corporation)
          ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
          Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
          Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
          StartMenuInternet: IEXPLORE.EXE - iexplore.exe

          FireFox:
          ========
          FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco
          FF NewTab: chrome://quick_start/content/index.html
          FF DefaultSearchEngine: sweet-page
          FF SelectedSearchEngine: sweet-page
          FF Homepage: hxxp://www.google.it/
          FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-12] ()
          FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
          FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
          FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-09] (Oracle Corporation)
          FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-09] (Oracle Corporation)
          FF Plugin: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
          FF Plugin: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
          FF Plugin: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
          FF Plugin: @microsoft.com/GENUINE -> disabled No File
          FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
          FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
          FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
          FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
          FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
          FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
          FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
          FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
          FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
          FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll [2014-06-26] (pdfforge GmbH)
          FF user.js: detected! => C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\user.js [2015-03-20]
          FF SearchPlugin: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\searchplugins\sweet-page.xml [2015-04-25]
          FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\golliver.xml [2015-04-25]
          FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2014-05-18]
          FF Extension: Golliver - C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox\Extensions\[removed] [2015-04-25]
          FF Extension: Golliver - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\Extensions\[removed] [2015-04-25]
          FF Extension: No Name - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-24]
          FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
          FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
          FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
          FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
          FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
          FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
          FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
          FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\extensions\[removed]
          FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\extensions\[removed]
          FF HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5
          FF Extension: IDM CC - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5 [2015-04-18]
          FF HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Marco\AppData\Roaming\IDM\idmmzcc5
          FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-12-11]

          Chrome:
          =======
          CHR HomePage: Default -> hxxp://www.dregol.com/?f=1&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=
          CHR StartupUrls: Default -> "hxxp://www.dregol.com/?f=7&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=", "hxxp://www.sweet-page.com/?type=hp&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980"
          CHR DefaultSearchKeyword: Default -> dregol.com
          CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
          CHR Profile: C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default
          CHR Extension: (Kaspersky Protection) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-04-15]
          CHR Extension: (IDM Integration Module) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-15]
          CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-15]
          CHR HKLM\…\Chrome\Extension: [bollbfeakabenkobaocgakdibphdnanj] - http://clients2.google.com/service/update2/crx
          CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
          CHR HKLM\…\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] - https://clients2.google.com/service/update2/crx
          CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
          CHR HKLM\…\Chrome\Extension: [lipgolpfajiadodbcbljdpmbmbdmfcil] - C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx [Not Found]
          CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2015-04-20]
          CHR HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] - https://clients2.google.com/service/update2/crx
          CHR HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lipgolpfajiadodbcbljdpmbmbdmfcil] - C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx [Not Found]

          ========================== Services (Whitelisted) =================

          (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

          S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-17] (SUPERAntiSpyware.com)
          R2 AVP15.0.2; C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [193400 2014-12-23] (Kaspersky Lab ZAO)
          R2 Backupper Service; C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
          R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
          R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
          S3 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
          S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
          R2 lwsvc_1.10.0.14; C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe [278592 2015-04-10] (Link Wiz)
          S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
          S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
          S4 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
          S4 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
          R2 PGPserv; C:\Windows\system32\PGPserv.exe [135288 2010-04-01] (PGP Corporation)
          S2 uzsvc; C:\Program Files\UltraZip\uzsvc.exe [531744 2015-03-10] ()
          S2 uzupd; C:\Program Files\UltraZip\uzupd.exe [44312 2015-03-10] ()
          R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
          S2 asl; "C:\ProgramData\Service\Application\asl.exe" [X]

          ==================== Drivers (Whitelisted) ====================

          (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

          S3 AF9035BDA; C:\Windows\System32\DRIVERS\AF9035BDA.sys [248744 2012-08-10] (AfaTech                  )
          R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [26424 2013-05-07] () [File not signed]
          R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [129720 2013-05-07] () [File not signed]
          R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [14392 2013-02-06] () [File not signed]
          S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
          R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [189136 2013-01-14] (Kaspersky Lab UK Ltd)
          R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
          S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [94336 2014-12-19] (ITE                      )
          R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [143968 2014-03-31] (Kaspersky Lab ZAO)
          R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46280 2015-03-27] (Kaspersky Lab ZAO)
          R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [120008 2014-11-28] (Kaspersky Lab ZAO)
          R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [36040 2014-10-22] (Kaspersky Lab ZAO)
          R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [698568 2015-03-27] (Kaspersky Lab ZAO)
          R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25800 2014-10-10] (Kaspersky Lab ZAO)
          R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [26824 2014-10-30] (Kaspersky Lab ZAO)
          R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO)
          R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
          R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [46152 2014-10-09] (Kaspersky Lab ZAO)
          R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [64200 2014-11-22] (Kaspersky Lab ZAO)
          R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [148296 2014-11-10] (Kaspersky Lab ZAO)
          R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
          S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-04-26] (Malwarebytes Corporation)
          S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
          R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
          R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
          R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
          R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
          R3 WsAudio_Device(1); C:\Windows\System32\drivers\VirtualAudio1.sys [27496 2013-01-25] (Wondershare)
          R3 WsAudio_Device(2); C:\Windows\System32\drivers\VirtualAudio2.sys [27496 2013-01-25] (Wondershare)
          R3 WsAudio_Device(3); C:\Windows\System32\drivers\VirtualAudio3.sys [27496 2013-01-25] (Wondershare)
          R3 WsAudio_Device(4); C:\Windows\System32\drivers\VirtualAudio4.sys [27496 2013-01-25] (Wondershare)
          R3 WsAudio_Device(5); C:\Windows\System32\drivers\VirtualAudio5.sys [27496 2013-01-25] (Wondershare)
          R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
          U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
          S3 catchme; \??\C:\Users\Marco\AppData\Local\Temp\catchme.sys [X]
          S1 lwnfd_1_10_0_14; system32\drivers\lwnfd_1_10_0_14.sys [X]
          S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]

          ==================== NetSvcs (Whitelisted) ===================

          (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


          ==================== One Month Created Files and Folders ========

          (If an entry is included in the fixlist, the file\folder will be moved.)

          2015-04-27 22:48 - 2015-04-27 22:48 - 02224640 _____ () C:\Users\Marco\Desktop\adwcleaner_4.202.exe
          2015-04-27 22:47 - 2015-04-27 22:48 - 00024118 _____ () C:\Users\Marco\Desktop\FRST.txt
          2015-04-27 22:47 - 2015-04-27 22:47 - 01140736 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe
          2015-04-27 22:47 - 2015-04-27 22:47 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion
          2015-04-26 04:33 - 2015-04-26 04:33 - 278896405 _____ () C:\Windows\MEMORY.DMP
          2015-04-26 04:33 - 2015-04-26 04:33 - 00158560 _____ () C:\Windows\Minidump\042615-19874-01.dmp
          2015-04-25 15:37 - 2015-04-25 15:37 - 00000137 _____ () C:\Users\Marco\Documents\gabriella.txt
          2015-04-25 07:31 - 2015-04-27 22:47 - 00000000 ____D () C:\FRST
          2015-04-25 07:14 - 2015-04-25 07:14 - 00002928 _____ () C:\Users\Marco\Documents\aswMBR.txt
          2015-04-25 07:14 - 2015-04-25 07:14 - 00000512 _____ () C:\Users\Marco\Documents\MBR.dat
          2015-04-25 06:34 - 2015-04-25 06:34 - 00000000 ____D () C:\ProgramData\6321271a0000001c
          2015-04-25 06:26 - 2015-04-25 17:49 - 00000000 ____D () C:\Program Files\Run_Dregol
          2015-04-25 06:26 - 2015-04-25 06:27 - 00000000 ____D () C:\Users\Marco\AppData\Local\nida
          2015-04-25 06:12 - 2015-04-25 06:12 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\sweet-page
          2015-04-25 06:05 - 2015-04-25 06:27 - 00000000 ___SD () C:\32788R22FWJFW
          2015-04-25 06:05 - 2015-04-25 06:06 - 00000000 ____D () C:\Program Files\LinkWiz_1.10.0.14
          2015-04-25 06:04 - 2015-04-25 06:21 - 00000000 ____D () C:\Users\Marco\Documents\CleanerPro
          2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\Users\Marco\AppData\Local\CleanerPro
          2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\ProgramData\UltraZip
          2015-04-25 06:03 - 2015-04-25 17:52 - 00000000 ____D () C:\Program Files\UltraZip
          2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Service
          2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraZip
          2015-04-25 06:02 - 2015-04-25 06:06 - 05619466 ____R (Swearware) C:\Users\Marco\Downloads\combofix [1].exe
          2015-04-25 05:53 - 2015-04-27 22:38 - 00000560 _____ () C:\Windows\setupact.log
          2015-04-25 05:53 - 2015-04-25 19:24 - 00320278 _____ () C:\Windows\PFRO.log
          2015-04-25 05:53 - 2015-04-25 05:53 - 00000000 _____ () C:\Windows\setuperr.log
          2015-04-25 05:48 - 2015-04-25 05:48 - 00156898 _____ () C:\Users\Marco\Documents\cc_20150425_054751.reg
          2015-04-20 14:53 - 2015-04-18 03:06 - 00122432 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
          2015-04-19 06:56 - 2015-04-19 07:49 - 370938816 _____ () C:\Users\Marco\Downloads\0d6b8d7ca1.mp4.rar.part
          2015-04-18 13:13 - 2015-04-18 17:27 - 742534663 _____ () C:\Users\Marco\Downloads\Cazzo.Grosso.Ma.Non.Troppo.Foreign.S.E.rar.part
          2015-04-18 11:10 - 2015-04-18 11:35 - 105298398 _____ () C:\Users\Marco\Downloads\Dana Moravova _ Milada.avi.part
          2015-04-18 07:02 - 2015-04-18 07:26 - 175777135 _____ () C:\Users\Marco\Downloads\Brooke_Tyler_-_shutup_and_blow_airport_hd.mp4
          2015-04-14 21:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
          2015-04-14 21:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
          2015-04-14 21:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
          2015-04-14 21:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
          2015-04-14 21:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
          2015-04-14 21:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
          2015-04-14 21:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
          2015-04-14 21:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
          2015-04-14 21:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
          2015-04-14 21:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
          2015-04-14 21:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
          2015-04-14 21:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
          2015-04-14 21:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
          2015-04-14 21:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
          2015-04-14 21:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
          2015-04-14 21:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
          2015-04-14 21:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
          2015-04-14 21:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
          2015-04-14 21:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
          2015-04-14 21:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
          2015-04-14 21:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
          2015-04-14 21:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
          2015-04-14 21:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
          2015-04-14 21:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
          2015-04-14 21:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
          2015-04-14 21:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
          2015-04-14 21:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
          2015-04-14 21:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
          2015-04-14 21:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
          2015-04-14 21:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
          2015-04-14 21:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
          2015-04-14 21:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
          2015-04-14 21:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
          2015-04-14 21:40 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
          2015-04-14 21:40 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
          2015-04-14 21:40 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
          2015-04-14 21:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
          2015-04-14 21:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
          2015-04-14 21:40 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
          2015-04-14 21:40 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
          2015-04-14 21:40 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
          2015-04-14 21:40 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
          2015-04-14 21:40 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
          2015-04-14 21:40 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
          2015-04-14 21:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
          2015-04-14 21:40 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
          2015-04-14 21:40 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
          2015-04-14 21:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
          2015-04-14 21:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
          2015-04-14 21:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
          2015-04-14 21:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
          2015-04-14 21:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
          2015-04-14 21:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
          2015-04-14 21:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
          2015-04-14 21:40 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
          2015-04-14 21:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
          2015-04-14 21:39 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
          2015-04-14 21:39 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
          2015-04-11 10:13 - 2015-04-26 10:02 - 00000000 ____D () C:\Users\Marco\olimpus
          2015-04-05 08:25 - 2015-04-05 08:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\RenPy
          2015-04-05 07:20 - 2015-04-05 08:01 - 244140767 _____ () C:\Users\Marco\Downloads\wbc-1.0-all.rar
          2015-04-05 06:59 - 2015-04-05 06:59 - 00000000 ____D () C:\Users\Marco\Tracing
          2015-04-05 05:44 - 2015-04-05 05:44 - 00000000 ___SD () C:\Windows\system32\GWX
          2015-04-04 10:26 - 2015-04-04 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\slac
          2015-04-04 10:23 - 2015-04-04 10:23 - 00000000 ____D () C:\Program Files\slac
          2015-04-04 08:16 - 2015-04-04 08:16 - 00000000 ____D () C:\Program Files\Common Files\Protexis
          2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\Users\Public\Desktop\Corel PaintShop Pro X5.lnk
          2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\ProgramData\Desktop\Corel PaintShop Pro X5.lnk
          2015-04-04 08:15 - 2015-04-04 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X5
          2015-04-03 08:13 - 2015-04-03 08:13 - 09629976 _____ (CyberGhost S.R.L. ) C:\Users\Marco\Downloads\CG_5.0.14.7.exe
          2015-03-31 21:34 - 2015-03-31 21:34 - 00036168 _____ () C:\Users\Marco\Desktop\29177662s.pdf.zip
          2015-03-28 15:43 - 2015-03-28 15:57 - 97954743 _____ () C:\Users\Marco\Downloads\6720_Возбужденная французская девочка трахнулась в офисе. - .mp4
          2015-03-28 07:32 - 2015-03-28 09:08 - 701267673 _____ () C:\Users\Marco\Downloads\Kendra Lust.mp4

          ==================== One Month Modified Files and Folders =======

          (If an entry is included in the fixlist, the file\folder will be moved.)

          2015-04-27 22:49 - 2013-03-05 23:43 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
          2015-04-27 22:47 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
          2015-04-27 22:47 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
          2015-04-27 22:44 - 2013-11-01 09:59 - 01913164 _____ () C:\Windows\WindowsUpdate.log
          2015-04-27 22:43 - 2014-05-22 06:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
          2015-04-27 22:38 - 2013-11-04 23:19 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
          2015-04-27 22:38 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
          2015-04-27 06:32 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\DMCache
          2015-04-27 06:12 - 2013-11-04 23:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
          2015-04-26 06:28 - 2013-03-05 18:20 - 01786646 _____ () C:\Windows\system32\PerfStringBackup.INI
          2015-04-26 06:28 - 2009-07-14 10:21 - 00791368 _____ () C:\Windows\system32\perfh010.dat
          2015-04-26 06:28 - 2009-07-14 10:21 - 00164498 _____ () C:\Windows\system32\perfc010.dat
          2015-04-26 04:33 - 2013-07-12 04:50 - 00000000 ____D () C:\Windows\Minidump
          2015-04-26 04:29 - 2014-05-21 22:11 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
          2015-04-25 17:51 - 2014-05-23 06:31 - 00000000 ____D () C:\Program Files\Internet Download Manager
          2015-04-25 17:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\PLA
          2015-04-25 16:10 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\IDM
          2015-04-25 10:08 - 2013-03-08 00:39 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc
          2015-04-25 08:30 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
          2015-04-25 05:45 - 2014-09-08 18:30 - 00000000 ____D () C:\Program Files\PDFCreator
          2015-04-25 05:43 - 2013-03-21 22:54 - 00000000 ____D () C:\Users\Marco\AppData\Local\CrashDumps
          2015-04-25 05:43 - 2013-03-05 17:42 - 00000000 ____D () C:\Windows\Panther
          2015-04-25 05:39 - 2013-11-10 08:53 - 00000000 ____D () C:\Users\Marco\AppData\Local\NativeMessaging
          2015-04-25 05:38 - 2014-12-08 08:24 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\FlvPlayer
          2015-04-25 05:38 - 2013-11-10 08:53 - 00000000 ____D () C:\ProgramData\Conduit
          2015-04-25 04:42 - 2014-05-21 22:11 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
          2015-04-25 04:42 - 2014-05-21 22:11 - 00001024 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
          2015-04-25 04:42 - 2014-05-21 22:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
          2015-04-25 04:42 - 2014-05-21 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
          2015-04-24 18:42 - 2013-03-05 20:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
          2015-04-24 06:25 - 2014-12-11 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
          2015-04-24 06:25 - 2013-03-17 10:18 - 00000000 ____D () C:\Program Files\SpeedFan
          2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
          2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
          2015-04-16 01:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
          2015-04-16 01:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
          2015-04-14 23:56 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
          2015-04-14 22:33 - 2014-12-10 07:47 - 00000000 ____D () C:\Windows\system32\appraiser
          2015-04-14 22:33 - 2014-05-01 08:15 - 00000000 ___SD () C:\Windows\system32\CompatTel
          2015-04-14 22:33 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT
          2015-04-14 22:10 - 2013-08-14 09:55 - 00000000 ____D () C:\Windows\system32\MRT
          2015-04-14 21:55 - 2013-03-10 07:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
          2015-04-12 17:25 - 2014-06-24 21:39 - 00000000 ____D () C:\Users\Marco\AppData\Local\Adobe
          2015-04-12 17:25 - 2013-03-05 23:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
          2015-04-12 17:25 - 2013-03-05 23:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
          2015-04-11 10:13 - 2013-03-05 18:23 - 00000000 ____D () C:\Users\Marco
          2015-04-07 21:42 - 2014-12-20 17:59 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
          2015-04-05 07:01 - 2014-08-05 21:03 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\Skype
          2015-04-05 06:59 - 2014-08-05 21:02 - 00000000 ___RD () C:\Program Files\Skype
          2015-04-05 06:58 - 2014-08-05 21:02 - 00000000 ____D () C:\ProgramData\Skype
          2015-04-04 10:26 - 2013-03-06 00:34 - 00023392 _____ () C:\Windows\system32\nscompat.tlb
          2015-04-04 08:17 - 2013-03-12 07:21 - 00000000 ____D () C:\ProgramData\Corel
          2015-04-04 08:13 - 2013-03-12 07:16 - 00000000 ____D () C:\Program Files\Corel
          2015-04-04 08:05 - 2015-02-16 21:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Last_Man
          2015-04-03 09:08 - 2014-04-23 05:10 - 00001845 _____ () C:\Users\Marco\Desktop\CyberGhost 5.lnk
          2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
          2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\Program Files\CyberGhost 5
          2015-03-28 10:49 - 2014-10-07 17:44 - 00000000 ____D () C:\ProgramData\XyLwfe

          ==================== Files in the root of some directories =======

          2013-03-12 07:27 - 2013-03-12 07:27 - 0003584 _____ () C:\Users\Marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
          2013-05-23 06:57 - 2013-05-23 06:59 - 0007602 _____ () C:\Users\Marco\AppData\Local\resmon.resmoncfg
          2014-04-21 10:30 - 2014-04-21 10:30 - 0000041 ___SH () C:\ProgramData\.zreglib
          2014-07-31 06:26 - 2014-07-31 06:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
          2013-03-17 09:07 - 2013-03-17 09:07 - 0000008 __RSH () C:\ProgramData\sysqcl1129067056.dat

          Files to move or delete:
          ====================
          C:\ProgramData\sysqcl1129067056.dat


          Some content of TEMP:
          ====================
          C:\Users\Marco\AppData\Local\Temp\Quarantine.exe
          C:\Users\Marco\AppData\Local\Temp\sfamcc00001.dll
          C:\Users\Marco\AppData\Local\Temp\sqlite3.dll


          ==================== Bamital & volsnap Check =================

          (There is no automatic fix for files that do not pass verification.)

          C:\Windows\explorer.exe => File is digitally signed
          C:\Windows\system32\winlogon.exe => File is digitally signed
          C:\Windows\system32\wininit.exe => File is digitally signed
          C:\Windows\system32\svchost.exe => File is digitally signed
          C:\Windows\system32\services.exe => File is digitally signed
          C:\Windows\system32\User32.dll => File is digitally signed
          C:\Windows\system32\userinit.exe => File is digitally signed
          C:\Windows\system32\rpcss.dll => File is digitally signed
          C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


          LastRegBack: 2015-04-14 00:36

          ==================== End Of Log ============================

          2) FRST Additionale

          Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-04-2015 01
          Ran by [removed] at 2015-04-27 22:50:03
          Running from C:\Users\[removed]\Desktop
          Boot Mode: Normal
          ==========================================================


          ==================== Accounts: =============================

          Administrator (S-1-5-21-4094248773-42424133-2592686105-500 - Administrator - Disabled)
          Guest (S-1-5-21-4094248773-42424133-2592686105-501 - Limited - Disabled)
          HomeGroupUser$ (S-1-5-21-4094248773-42424133-2592686105-1002 - Limited - Enabled)
          Marco (S-1-5-21-4094248773-42424133-2592686105-1000 - Administrator - Enabled) => C:\Users\Marco

          ==================== Security Center ========================

          (If an entry is included in the fixlist, it will be removed.)

          AV: Kaspersky Total Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
          AS: Kaspersky Total Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
          AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          FW: Kaspersky Total Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

          ==================== Installed Programs ======================

          (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

          Adobe Flash Player 15 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
          Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
          Adobe Reader XI (11.0.10) - Italiano (HKLM\…\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
          Adventure Maker v4.6.1 (build1) (HKLM\…\Adventure Maker v4.6.1_is1) (Version:  - )
          Adventure Maker v4.7.1 (build1) (HKLM\…\Adventure Maker v4.7.1_is1) (Version:  - )
          Aimersoft DRM Media Converter(Build 1.5.5.0) (HKLM\…\Aimersoft DRM Media Converter_is1) (Version:  - Aimersoft Software)
          Alice MOBILE E169 (HKLM\…\Alice MOBILE E169) (Version: 11.002.04.11.192 - Huawei Technologies Co.,Ltd)
          Any Video Converter 5.6.3 (HKLM\…\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
          AOMEI Backupper Standard Edition 2.2 (HKLM\…\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version:  - AOMEI Technology Co., Ltd.)
          Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
          Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
          BlazeDTV 6.0 (HKLM\…\BlazeDTV 6.0_is1) (Version:  - )
          Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
          CCleaner (HKLM\…\CCleaner) (Version: 4.13 - Piriform)
          CDBurnerXP (HKLM\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
          Cinergy T Stick Driver Installation (32 Bit) (HKLM\…\{5123EBB5-0CB1-4EF1-8DF7-A4226537BCDC}) (Version: 8.08.18.01 - Nome società)
          Comic Life 2 (HKLM\…\{A8405D99-9D76-4456-8752-87DA930CC3A3}) (Version: 2.2.5.0 - plasq LLC)
          Core Temp 1.0 RC5 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
          Corel PaintShop Pro X5 (HKLM\…\_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.2.0.12 - Corel Corporation)
          Corel PaintShop Pro X5 (Version: 15.3.0.8 - Corel Corporation) Hidden
          CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
          EPSON Scan (HKLM\…\EPSON Scanner) (Version:  - )
          ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
          F24 On Line (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\F24 On Line) (Version:  - Agenzia delle Entrate)
          File Splitter and Joiner (FFSJ v3.3) (HKLM\…\File Splitter and Joiner_is1) (Version:  - Le Minh Hoang)
          FileInternet (HKLM\…\FileInternet) (Version: 2.9.9.0 - SOGEI)
          FlvPlayer (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\FlvPlayer) (Version: ${VERSION} - ) <==== ATTENTION
          Free Video Cutter Joiner 9.8 (HKLM\…\{8C5A4758-C782-4200-B337-DB3466D33ADD}}_is1) (Version: 9.8 - DVDVideoMedia, Inc.)
          Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
          Google Earth (HKLM\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
          Google Update Helper (Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ATTENTION
          Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
          GoToAssist Corporate (HKLM\…\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
          HijackThis 2.0.2 (HKLM\…\HijackThis) (Version: 2.0.2 - TrendMicro)
          ICA (Version: 15.2.0.12 - Corel Corporation) Hidden
          iCloud (HKLM\…\{8D9592B4-7E22-4D1F-B2CB-B5F0F2F619CB}) (Version: 4.0.3.56 - Apple Inc.)
          Internet Download Manager (HKLM\…\Internet Download Manager) (Version:  - Tonec Inc.)
          IPM_PSP_COM (Version: 15.2.0.12 - Corel Corporation) Hidden
          iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
          J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)
          Java 8 Update 40 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
          Kaspersky Total Security (HKLM\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
          Kaspersky Total Security (Version: 15.0.2.361 - Kaspersky Lab) Hidden
          Kernel Outlook PST Viewer ver 11.05.01 (HKLM\…\Kernel Outlook PST Viewer_is1) (Version:  - Lepide Software Pvt. Ltd.)
          Last Man (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Last Man) (Version:  - )
          Link Wiz 1.10.0.14 (HKLM\…\LinkWiz_1.10.0.14) (Version: 1.10.0.14 - Link Wiz)
          Malwarebytes Anti-Malware versione 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
          Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
          Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
          Microsoft Office XP Professional (HKLM\…\{91110410-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
          Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
          ModuliControllo2013 (HKLM\…\ModuliControllo2013) (Version: 4.0.0.0 - Sogei S.p.A)
          ModuliControlloUnico2014 (HKLM\…\ModuliControlloUnico2014) (Version: 1.1.1.0 - Sogei S.p.A)
          Mozilla Firefox 37.0.2 (x86 it) (HKLM\…\Mozilla Firefox 37.0.2 (x86 it)) (Version: 37.0.2 - Mozilla)
          Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
          Mozilla Thunderbird 31.6.0 (x86 it) (HKLM\…\Mozilla Thunderbird 31.6.0 (x86 it)) (Version: 31.6.0 - Mozilla)
          MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
          MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
          MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
          MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
          Pacchetto di compatibilità per Office System 2007 (HKLM\…\{90120000-0020-0410-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
          Pacchetto driver Windows - TerraTec  (AF9035BDA) Media  (05/18/2009 8.08.18.01) (HKLM\…\3602780F32D3BB88DB2E972AE797966CC5105334) (Version: 05/18/2009 8.08.18.01 - TerraTec )
          PDF Architect 2 (HKLM\…\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
          PDF Architect 2 View Module (HKLM\…\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
          PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
          PGP Desktop (HKLM\…\{04A8595A-4B2F-4A20-BA5D-E6B371657FF8}) (Version: 10.0.2.13 - PGP Corporation)
          PSPPContent (Version: 15.3.0.8 - Corel Corporation) Hidden
          PSPPHelp (Version: 15.2.0.12 - Corel Corporation) Hidden
          QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
          Recuva (HKLM\…\Recuva) (Version: 1.45 - Piriform)
          Setup (Version: 15.2.0.12 - Nome società) Hidden
          Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
          Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
          Skype™ 7.2 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
          slac (HKLM\…\slac_is1) (Version:  - )
          SpeedFan (remove only) (HKLM\…\SpeedFan) (Version:  - )
          SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1040 - SUPERAntiSpyware.com)
          Supporto applicazioni Apple (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
          sweet-page uninstall (HKLM\…\sweet-page uninstall) (Version:  - sweet-page) <==== ATTENTION
          TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
          TomTom HOME (HKLM\…\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - Nome società)
          TomTom HOME (HKLM\…\{BB05590A-6602-43F3-A400-77EA0976BC0A}) (Version: 2.9.8 - Nome società)
          TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
          UltraZip (HKLM\…\{5E36886D-AE94-4901-82A6-A96381B7B4AD}_is1) (Version: 2.0.2.6 - UltraZip)
          UnicOnLine PF 2014 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicOnLine PF 2014) (Version:  - Agenzia delle Entrate)
          UnicoOnLine - File Internet 2.9.9 (HKLM\…\File Internet) (Version:  - )
          UnicoOnLine PF 2012 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicoOnLine PF 2012) (Version:  - Agenzia delle Entrate)
          VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
          weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION
          WinOff (HKLM\…\{8049EB00-4F62-44FB-AAF7-CB42F588E3C5}_is1) (Version: 1.0.1.5 - )
          WinPhone (HKLM\…\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version:  - )
          WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
          Wisdom-soft ScreenHunter 6.0 Free (HKLM\…\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
          WriterPad (HKLM\…\{2E4ECAA8-6E82-4502-96BE-48D2DCCFA42A}) (Version: 1.0.0 - North Sky Productions LLC)

          ==================== Custom CLSID (selected items): ==========================

          (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

          ==================== Restore Points  =========================

          25-04-2015 15:17:24 Windows Update
          25-04-2015 16:44:04 Windows Backup

          ==================== Hosts content: ==========================

          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

          2009-07-14 04:04 - 2014-05-21 23:31 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
          127.0.0.1       localhost

          ==================== Scheduled Tasks (whitelisted) =============

          (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

          Task: {09289DFA-8809-4294-AFB9-C9F05351A193} - System32\Tasks\{C8F3C4BF-1DF0-4D46-A1FA-731614A02DA6} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {10ED68ED-31D8-46CB-AF5C-5AF06004F5FE} - System32\Tasks\CleanerPro_Start => C:\Program Files\Cleaner Pro\CleanerPro.exe
          Task: {1217E9D3-8939-4DCA-B835-08A6B3F9D25D} - System32\Tasks\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40} => C:\Users\Marco\Desktop\installspeedfan447.exe [2013-03-17] () <==== ATTENTION
          Task: {167C0E59-CF26-45F6-8EF2-BFEC3799BD95} - System32\Tasks\{C250204F-A2AB-4261-B042-B58AEF0116AE} => C:\Corel\Draw701\programs\photopnt.exe
          Task: {19980019-8149-4B71-A0AE-2B1B2C6D5A2A} - System32\Tasks\{3E0476D6-A2AA-4A2B-8F71-50978AD0A832} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {23D073A5-7AA0-47F5-B434-DA0D55C7F3B4} - System32\Tasks\{3CE02DF4-D192-416A-8EE2-8396B8CB6FB4} => C:\photopaint\PHOTOPNT.EXE
          Task: {2A1DD022-029F-4067-B593-016E6960BB35} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
          Task: {2C02D38D-F40F-447C-864B-90DD5FB6253E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
          Task: {334F613A-8EE8-4BD7-ACC3-7FD62264BF03} - System32\Tasks\{02D2332A-A21D-4ABE-BD10-62DD01C4BF11} => pcalua.exe -a C:\corel\SETUP\DAOSETUP.EXE -d C:\corel\SETUP
          Task: {4063D65F-FBE1-4343-AEF3-6C1DCA8671E0} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
          Task: {483CD9A1-6E78-455D-B1E7-30F42C1F03C4} - System32\Tasks\{F6AB3366-2EA1-4C45-8745-C16EE86D334C} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {4CF1CB7B-346F-4195-B187-51DE750A68C8} - System32\Tasks\{DD07A107-F0F4-4746-9D64-C4E23A192425} => C:\Corel\Draw701\programs\photopnt.exe
          Task: {52FBB622-5E59-464A-9911-3B94DF586442} - System32\Tasks\{5A1164C2-B0A7-48D0-84ED-49A59B0570E1} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {5BC90939-7441-4749-8374-0FAD29BB5DF6} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
          Task: {5BCFC431-3B77-4BC1-BFA7-B699A44258FC} - System32\Tasks\{90112C02-23E4-42FE-8F5D-97299A848050} => pcalua.exe -a "C:\Program Files\weDownload Manager\Uninstall.exe" -c /fromcontrolpanel=1
          Task: {6059284D-1243-46AF-B0A0-A10FCE072B4C} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
          Task: {63216F46-D65D-4D30-BD8C-29A29223C00B} - System32\Tasks\{831D7081-34DF-4BD4-BC41-204C3B539114} => D:\Corel\Draw70\programs\photopnt.exe
          Task: {66B33249-6DCB-485A-82F6-A570B2514A45} - System32\Tasks\{4DCA4D6B-3320-4ECC-9D3F-3391A219CE6E} => pcalua.exe -a L:\Compressed\cd_4.8a\CD_4.8A\CDSetup\setup.exe -d L:\Compressed\cd_4.8a\CD_4.8A\CDSetup
          Task: {6D5C45BA-B65B-4FBD-89D0-22CA804D813B} - System32\Tasks\{3FB8CB96-A3C4-4B71-9F07-5FC531C22FFC} => D:\D\DOOM.EXE
          Task: {794EBFAB-B0BC-4768-AE28-A37A4CFF2246} - System32\Tasks\{9C279F5D-7348-4DDB-A492-A91C311E3729} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {7AC1FF86-51CB-476C-A65F-108D684F6A55} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
          Task: {7B5D3C19-0CDC-4AEE-8193-4A06B5456EEE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
          Task: {80B2339F-C664-4EA6-8A16-EDE7EA353EE4} - System32\Tasks\{41FE69C8-BF1F-4934-9648-A0A09939AF14} => pcalua.exe -a C:\UnicoOnLine\UNI13\ModuliControllo2013_500.exe -d C:\UnicoOnLine\UNI13
          Task: {91152ABF-40E7-47A4-A9EE-4F582F79205D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-12] (Adobe Systems Incorporated)
          Task: {93D70EB9-D50F-48F3-9D11-D41103D61C3D} - System32\Tasks\{2DB657D7-D3D0-484F-985C-FF894C37A2C0} => pcalua.exe -a C:\UnicoOnLine\MainWinUNI10.exe -d C:\UnicoOnLine
          Task: {99D0E47C-5928-4FF2-83EA-8BAE5279ED61} - System32\Tasks\{D70B1B3A-5B54-49A6-91E6-A08E94605404} => pcalua.exe -a C:\Downloads\JavaRa\JavaRa.exe -d C:\Downloads\JavaRa
          Task: {A340BD43-ADF2-40C8-973E-2B761B71C336} - System32\Tasks\{E070B345-71E6-40B6-B67C-E5E15C72506C} => pcalua.exe -a C:\Users\Marco\Downloads\Programs\FileInternet297_ALL.exe -d C:\Users\Marco\AppData\Roaming\IDM
          Task: {B891F30E-3144-4BEA-8532-94DAEC0EF6EC} - System32\Tasks\{A3616480-507E-4F82-B3E7-9890FB99A7FC} => pcalua.exe -a E:\Utility\oem\OEMSETUP.EXE -d E:\Utility\oem
          Task: {BB5C9905-863B-4262-9B03-BAE445722A28} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
          Task: {BFC6295F-521A-4DD8-8725-35B399C20BCA} - System32\Tasks\{5181E2DA-A9A2-40D7-B430-C237837B0CBF} => pcalua.exe -a "G:\Alice MOBILE E169\Setup.exe" -d "G:\Alice MOBILE E169"
          Task: {C935C2EA-C3E1-45DA-B5A9-239D6413B18D} - System32\Tasks\{430B9F8B-41D9-47D6-B353-8FA97F5EC41D} => pcalua.exe -a G:\DataCard_Setup.exe -d G:\
          Task: {CC2864F4-914F-429E-A619-77455BE5EC3E} - System32\Tasks\{AC48D273-25E1-4B48-A02E-752895342551} => pcalua.exe -a C:\Users\Marco\Downloads\Adaware_Installer.exe -d C:\Users\Marco\Downloads
          Task: {CC7E475F-C850-4B25-ACEF-CDD11BBA37E2} - System32\Tasks\{CAB04F14-8D9A-4184-AD18-1D6C282DC6EB} => C:\Corel\Draw70\programs\photopnt.exe
          Task: {CE056A31-1B02-4BD9-82D0-6BF77A020900} - System32\Tasks\{39990666-AFFE-47CF-9FB3-F8C0AA96CDCA} => C:\Corel\Draw70\programs\photopnt.exe
          Task: {D0C0E802-98D1-4274-8A24-D773D3A00D75} - System32\Tasks\{5A25ECBD-0B9B-411F-BC7D-5A6B3BA0F7D7} => C:\Corel\Draw701\programs\photopnt.exe
          Task: {D54B238F-5953-460D-88E0-B8048E3132D7} - System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
          Task: {D64568DF-23EA-4B48-B558-8078C1D33660} - System32\Tasks\{F635ADB3-1AD0-4DB6-9D4A-AF79A638483D} => D:\Corel\Draw70\programs\photopnt.exe
          Task: {D9321925-6B97-4A7D-AE9B-D14B82AB743B} - System32\Tasks\{C1FCF6FF-C6B1-4CE4-A4E8-602EDF5B3CDA} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {DCE67E6D-44BA-4C0A-AD11-A23973613C28} - System32\Tasks\{C9183C48-D1F3-43DF-94DC-905BC79BFC7F} => D:\D\DOOM.EXE
          Task: {DCEAEDD8-71FA-4EE3-89A0-4249E42BB92D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
          Task: {E82171A9-FF80-4C2F-B235-8E8ECA4BC5AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
          Task: {ED600DD3-3408-418D-94EE-2D47E8BED7AB} - System32\Tasks\{228862AD-F5BD-40E3-9F7B-0FE46B8AE765} => C:\corel\PROGRAMS\PHOTOPNT.EXE
          Task: {EDD2851A-7AC1-44BE-9308-D48A44C2F757} - System32\Tasks\{341FE709-8AFB-4377-9D6D-7344EF71CD9C} => pcalua.exe -a "C:\Program Files\Alice MOBILE E169\uninst.exe"
          Task: {F299C7D5-4579-40CB-8652-C2D6F6B189D9} - System32\Tasks\{AC32368B-2CCF-4FDA-B77C-777AB7ED0781} => D:\Corel\Draw70\programs\photopnt.exe
          Task: {F5606013-9B0D-40FB-AD90-4B22291BE6F8} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)

          (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

          Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

          ==================== Loaded Modules (whitelisted) ==============

          2014-12-23 17:54 - 2014-12-23 17:54 - 01272616 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\kpcengine.2.3.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00270040 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\UiLogic.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00229080 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\diskmgr.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00278232 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Comn.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00077528 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Ldm.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00061144 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Device.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00265944 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrFat.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00384728 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrNtfs.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00118488 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FuncLogic.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00241368 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Clone.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00343768 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\ImgFile.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00028376 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Encrypt.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00073432 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Compress.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrVol.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00253656 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\GptBcd.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00151256 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FlBackup.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00483032 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\EnumFolder.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Backup.dll
          2015-01-15 00:12 - 2014-12-24 19:15 - 00098008 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrLog.dll
          2015-01-15 00:12 - 2013-01-17 18:38 - 02403504 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\QtCore4.dll
          2013-05-04 09:19 - 2008-07-20 21:11 - 00247808 _____ () C:\Windows\system32\FFSJ\FFSJSHL.dll
          2010-05-24 12:09 - 2010-05-24 12:09 - 00091992 _____ () C:\Program Files\Microsoft Office\Office10\OUTLCTL.DLL
          2014-12-23 17:54 - 2014-12-23 17:54 - 00502056 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]\npcontentblocker.dll
          2014-12-23 17:54 - 2014-12-23 17:54 - 00338216 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]\nponlinebanking.dll
          2014-12-23 17:54 - 2014-12-23 17:54 - 00608040 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]\npvkplugin.dll

          ==================== Alternate Data Streams (whitelisted) =========

          (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

          AlternateDataStreams: C:\ProgramData\TEMP:373E1720
          AlternateDataStreams: C:\ProgramData\TEMP:4CF8D17E

          ==================== Safe Mode (whitelisted) ===================

          (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

          ==================== EXE Association (whitelisted) ===============

          (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


          ==================== Internet Explorer trusted/restricted ===============

          (If an entry is included in the fixlist, the associated entry will be removed from the registry.)

          IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
          IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
          IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
          IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
          IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
          IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
          IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
          IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
          IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
          IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
          IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
          IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
          IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
          IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
          IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
          IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
          IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
          IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
          IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
          IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

          There are 7794 more restricted sites.

          ==================== Other Areas ============================

          (Currently there is no automatic fix for this section.)

          HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
          DNS Servers: 192.168.0.1

          ==================== MSCONFIG/TASK MANAGER disabled items ==

          (Currently there is no automatic fix for this section.)

          MSCONFIG\Services: !SASCORE => 2
          MSCONFIG\Services: AdobeARMservice => 2
          MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
          MSCONFIG\Services: AdvancedSystemCareService7 => 2
          MSCONFIG\Services: Apple Mobile Device => 2
          MSCONFIG\Services: Bonjour Service => 2
          MSCONFIG\Services: CGVPNCliService => 2
          MSCONFIG\Services: CSObjectsSrv => 2
          MSCONFIG\Services: GoToAssist => 3
          MSCONFIG\Services: gupdate => 2
          MSCONFIG\Services: gupdatem => 3
          MSCONFIG\Services: Intelliservice => 2
          MSCONFIG\Services: iPod Service => 3
          MSCONFIG\Services: MozillaMaintenance => 3
          MSCONFIG\Services: PDF Architect 2 => 3
          MSCONFIG\Services: pdfforge CrashHandler => 3
          MSCONFIG\Services: PSI_SVC_2 => 2
          MSCONFIG\Services: SCardSvr => 3
          MSCONFIG\Services: ServiceLayer => 3
          MSCONFIG\Services: SkypeUpdate => 2
          MSCONFIG\Services: TomTomHOMEService => 2
          MSCONFIG\Services: WGEGyK => 2
          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
          MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          MSCONFIG\startupreg: Advanced SystemCare 7 => "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
          MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
          MSCONFIG\startupreg: BlazeServoTool => "C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
          MSCONFIG\startupreg: CloneCDTray => "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
          MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart /min
          MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
          MSCONFIG\startupreg: IDMan => C:\Program Files\Internet Download Manager\IDMan.exe /onboot
          MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
          MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
          MSCONFIG\startupreg: McAfee McItInfo => C:\Users\Marco\AppData\Local\Temp\mcitinfo_1383311069.exe /itinsfin:C:\Users\Marco\AppData\Local\Temp\mcininfo_1383311069.ini
          MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
          MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
          MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
          MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
          MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          MSCONFIG\startupreg: TBHostSupport => "C:\Windows\system32\Rundll32.exe" "C:\Users\Marco\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
          MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"

          ==================== FirewallRules (whitelisted) ===============

          (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

          FirewallRules: [{0E499E8F-2CC2-492B-B6E3-DE6571FF9795}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{B01FAA7A-14A0-4104-9BA3-A0C0AECB340D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{ADC8BB10-533C-46BF-828A-6034C271B805}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
          FirewallRules: [{032E0385-BD9B-4F35-B22E-A1C73A91F3FC}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
          FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
          FirewallRules: [{44718332-C76D-4FAC-8FC1-2E8BC5726C68}] => (Allow) C:\Program Files\iTunes\iTunes.exe
          FirewallRules: [{6B609089-96E1-4411-AF63-17C8E30F8837}] => (Allow) C:\Program Files\AOMEI Backupper Standard Edition 2.2\PxeUi.exe
          FirewallRules: [{F2573A31-B37D-4F9F-9FD1-87FF78181875}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
          FirewallRules: [{F6CCA513-7672-4CF2-91D3-4FFD5446DE2A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
          FirewallRules: [{A8125B2D-38FE-4526-A175-F0F0C8A6535F}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

          ==================== Faulty Device Manager Devices =============

          Name: lwnfd_1_10_0_14
          Description: lwnfd_1_10_0_14
          Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
          Manufacturer:
          Service: lwnfd_1_10_0_14
          Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
          Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
          Devices stay in this state if they have been prepared for removal.
          After you remove the device, this error disappears.Remove the device, and this error should be resolved.


          ==================== Event log errors: =========================

          Application errors:
          ==================
          Error: (04/27/2015 10:39:17 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/26/2015 09:33:43 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/26/2015 01:12:53 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/26/2015 01:10:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: Il programma BlazeHDTV.exe versione 1.0.0.1 non interagisce più con Windows ed è stato chiuso. Per vedere se sono disponibili ulteriori informazioni sul problema, verificare la cronologia del problema in Centro operativo nel Pannello di controllo.

          ID processo: 14d8

          Ora di avvio: 01d0800731266d7c

          Ora di chiusura: 60000

          Percorso applicazione: C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.exe

          ID segnalazione: 999ffb4a-ec04-11e4-8084-001d72e8ab06

          Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
          Description: Impossibile completare il backup a causa di un errore durante la scrittura nel percorso di backup G:\. Errore: Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006).

          Error: (04/25/2015 07:25:19 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/25/2015 05:52:23 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
          Description: Impossibile inizializzare l'indice.

          Dettagli:
              Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

          Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
          Description: Impossibile inizializzare l'applicazione.

          Contesto: applicazione Windows

          Dettagli:
              Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)


          System errors:
          =============
          Error: (04/27/2015 10:39:17 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
          Description: All'avvio non è stato possibile caricare i seguenti driver:
          lwnfd_1_10_0_14

          Error: (04/27/2015 10:39:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
          Description: Il servizio lwnfd_1_10_0_14 non è stato avviato per il seguente errore:
          %%2

          Error: (04/27/2015 10:39:05 PM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
          Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)

          Error: (04/27/2015 10:38:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
          %%1058

          Error: (04/27/2015 10:38:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
          Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
          %%2

          Error: (04/27/2015 06:32:57 AM) (Source: DCOM) (EventID: 10010) (User: )
          Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

          Error: (04/27/2015 03:47:43 AM) (Source: atapi) (EventID: 11) (User: )
          Description: Il driver ha rilevato un errore del controller su \Device\Ide\IdePort0.

          Error: (04/27/2015 03:47:43 AM) (Source: atapi) (EventID: 11) (User: )
          Description: Il driver ha rilevato un errore del controller su \Device\Ide\IdePort0.

          Error: (04/27/2015 03:47:43 AM) (Source: atapi) (EventID: 11) (User: )
          Description: Il driver ha rilevato un errore del controller su \Device\Ide\IdePort0.

          Error: (04/27/2015 03:47:43 AM) (Source: atapi) (EventID: 11) (User: )
          Description: Il driver ha rilevato un errore del controller su \Device\Ide\IdePort0.


          Microsoft Office Sessions:
          =========================
          Error: (04/27/2015 10:39:17 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/26/2015 09:33:43 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/26/2015 01:12:53 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/26/2015 01:10:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: BlazeHDTV.exe1.0.0.114d801d0800731266d7c60000C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.exe999ffb4a-ec04-11e4-8084-001d72e8ab06

          Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
          Description: G:\Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006)

          Error: (04/25/2015 07:25:19 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/25/2015 05:52:23 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
          Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

          Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
          Description: Dettagli:
              Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)

          Error: (04/25/2015 05:54:30 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
          Description: Contesto: applicazione Windows

          Dettagli:
              Il catalogo dell'indice del contenuto è danneggiato.  (HRESULT : 0xc0041801) (0xc0041801)


          CodeIntegrity Errors:
          ===================================
            Date: 2015-03-10 00:07:34.988
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-10 00:07:34.976
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-10 00:07:34.976
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-10 00:07:34.916
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-10 00:07:34.906
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-10 00:07:34.906
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-09 23:36:43.482
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-09 23:36:43.472
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-09 23:36:43.422
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

            Date: 2015-03-09 23:36:43.402
            Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.


          ==================== Memory info ===========================

          Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
          Percentage of memory in use: 46%
          Total physical RAM: 3000.86 MB
          Available physical RAM: 1606.14 MB
          Total Pagefile: 6000.02 MB
          Available Pagefile: 4187.5 MB
          Total Virtual: 2047.88 MB
          Available Virtual: 1911.8 MB

          ==================== Drives ================================

          Drive c: (ACER) (Fixed) (Total:228.01 GB) (Free:52.38 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
          Drive d: (DATA) (Fixed) (Total:227.98 GB) (Free:72.54 GB) NTFS
          Drive e: (DGN1000v3) (CDROM) (Total:0.06 GB) (Free:0 GB) CDFS
          Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:1.35 GB) FAT32

          ==================== MBR & Partition Table ==================

          ========================================================
          Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: B0387136)
          Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
          Partition 2: (Active) - (Size=228 GB) - (Type=07 NTFS)
          Partition 3: (Not Active) - (Size=228 GB) - (Type=07 NTFS)

          ==================== End Of Log ============================

          3) JRT logfile

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.6.5 (04.27.2015:1)
          OS: Windows 7 Home Premium x86
          Ran by [removed] on 27/04/2015 at 23:11:07,62
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




          ~~~ Services



          ~~~ Tasks



          ~~~ Registry Values



          ~~~ Registry Keys

          Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}
          Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{c9ab6446-7efc-47fe-966c-dc54324eff9f}
          Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}



          ~~~ Files

          Successfully deleted: [File] C:\Windows\wininit.ini
          Successfully deleted: [File] C:\Windows\prefetch\SPEEDFAN.EXE-DA70FAF2.pf



          ~~~ Folders



          ~~~ FireFox

          Successfully deleted: [Folder] C:\Users\Marco\AppData\Roaming\mozilla\firefox\profiles\uygrla6u.default-1426711383616\extensions\staged
          Successfully deleted the following from C:\Users\Marco\AppData\Roaming\mozilla\firefox\profiles\fdubo8yh.Marco\prefs.js

          user_pref(browser.search.searchengine.alias, sweet-page);
          user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
          user_pref(browser.search.searchengine.iconURL, hxxp://www.sweet-page.com/favicon.ico);
          user_pref(browser.search.searchengine.name, sweet-page);
          user_pref(browser.search.searchengine.ptid, cor);
          user_pref(browser.search.searchengine.uid, WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980);
          user_pref(browser.search.searchengine.url, hxxp://www.sweet-page.com/web/?type=ds&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q;={searchTerms});
          user_pref(browser.search.selectedEngine, sweet-page);
          Emptied folder: C:\Users\Marco\AppData\Roaming\mozilla\firefox\profiles\fdubo8yh.Marco\minidumps [9 files]





          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on 27/04/2015 at 23:25:35,09
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

          4) Malwerebyte logfile

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Data scansione: 27/04/2015
          Ora scansione: 23:33:44
          File di log:
          Amministratore: Si

          Versione: 2.01.6.1022
          Database malware: v2015.04.27.04
          Database rootkit: v2015.04.21.01
          Licenza: Prova
          Protezione da malware: Attivata
          Protezione da siti web nocivi: Attivata
          Auto-protezione: Disattivata

          SO: Windows 7 Service Pack 1
          CPU: x86
          File system: NTFS
          Utente: Marco

          Tipo di scansione: Scansione personalizzata
          Risultati: Completata
          Elementi analizzati: 703374
          Tempo impiegato: 6 ore, 0 min, 2 sec

          Memoria: Attivata
          Esecuzioni automatiche: Attivata
          File system: Attivata
          Archivi compressi: Attivata
          Rootkit: Disattivata
          Euristica: Attivata
          PUP: Attivata
          PUM: Attivata

          Processi: 0
          (Nessun elemento nocivo rilevato)

          Moduli: 0
          (Nessun elemento nocivo rilevato)

          Chiavi di registro: 10
          PUP.Optional.LinkWiz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\lwsvc_1.10.0.14, , [058b87ea51396ec802a2f64f38cef10f],
          PUP.Optional.LinkWiz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\LinkWiz_1.10.0.14, , [c1cf3041dfabab8b3371cc79e6208d73],
          PUP.Optional.LinkWiz.A, HKLM\SOFTWARE\LinkWiz_1.10.0.14, , [c1cff9785337f44226b78640b251a65a],
          PUP.Optional.Dregol.C, HKLM\SOFTWARE\CLASSES\APPID\{DA3128B1-DE9E-4E11-81DC-E12090C8F3B9}\INSTL\DATA, , [8907e8896d1d49edbd37ecd973908f71],
          PUP.Optional.Dregol.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\ihokndmjeombjojnfkmapfnjeghjohim, , [820e5120d8b255e1f4fecefccc3732ce],
          PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\LIPGOLPFAJIADODBCBLJDPMBMBDMFCIL, , [860a3c35b1d933030f1b1babb251e51b],
          PUP.Optional.LinkWiz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\lwnfd_1_10_0_14, , [0090f67b870350e6bc1fa125e51eae52],
          PUP.Optional.Dregol.A, HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\run_dregol, , [622ea6cb1b6ff442ef08f3d7da2937c9],
          PUP.Optional.Dregol.A, HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\ihokndmjeombjojnfkmapfnjeghjohim, , [315ff37e5535d462ab48fbcfb25152ae],
          PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\LIPGOLPFAJIADODBCBLJDPMBMBDMFCIL, , [4d43bab787039e9848e313b3a36022de],

          Valori di registro: 5
          PUP.Optional.Dregol.C, HKLM\SOFTWARE\CLASSES\APPID\{da3128b1-de9e-4e11-81dc-e12090c8f3b9}\INSTL\DATA|tlbrSrchUrl, http://www.dregol.com/?f=3&a;=drg_frmr_15_17&cd;=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr;=1188893128&ir;=&q;=, , [8907e8896d1d49edbd37ecd973908f71]
          PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\lipgolpfajiadodbcbljdpmbmbdmfcil|path, C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx, , [860a3c35b1d933030f1b1babb251e51b]
          PUP.Optional.Dregol.C, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files\Run_Dregol\\, , [256b462bc7c30036718d3a8bec1707f9]
          PUP.Optional.LinkWiz.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\lwsvc_1.10.0.14|ImagePath, "C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe", , [bad6bdb4c0ca3cfa4f8d5a6c5da6718f]
          PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\lipgolpfajiadodbcbljdpmbmbdmfcil|path, C:\Users\Marco\AppData\Local\CRE\lipgolpfajiadodbcbljdpmbmbdmfcil.crx, , [4d43bab787039e9848e313b3a36022de]

          Dati di registro: 0
          (Nessun elemento nocivo rilevato)

          Cartelle: 4
          PUP.Optional.Dregol.A, C:\Program Files\Run_Dregol, , [7d131a57f09a5fd7963b3b8718eb20e0],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\Service, , [fc94076acebc211573f9cbf9956edc24],

          File: 104
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\Service\lwsvc.exe, , [058b87ea51396ec802a2f64f38cef10f],
          PUP.Optional.InstallCore.SID.A, C:\Downloads\combofix.exe, , [4e42373a2a60c1759be5162f7393df21],
          PUP.Optional.InstallCore, C:\Users\Marco\Downloads\Programs\openvpn-install-2.3.1-I001-i686.exe, , [127ecca50783ce68f966a42fe91c7f81],
          PUP.Optional.Somoto.A, C:\Users\Marco\Local Settings\Application Data\Bundled software uninstaller\biclient (1).exe, , [7f1190e1444667cfe0cbc7825da4e41c],
          PUP.Optional.Somoto.A, C:\Users\Marco\Local Settings\Application Data\Bundled software uninstaller\biclient.exe, , [1779a2cfe5a5989e19921d2c1ee33bc5],
          PUP.Optional.Somoto.A, C:\Users\Marco\Local Settings\Application Data\Bundled software uninstaller\bi_client.exe, , [c6ca9ad7ff8b6cca57548abf5fa228d8],
          PUP.Optional.Softonic.A, C:\Windows.old\Windows\Users\marco\Desktop\softonic_ggl_1.5.11.5.exe, , [7c14472a2b5f6fc773c1619b42bff10f],
          PUP.Optional.Softonic.A, C:\Windows.old\Windows\Users\marco\Downloads\SoftonicDownloader_per_hijackthis.exe, , [6c24da97d0ba95a10ddb2a275aa707f9],
          PUP.Optional.SweetIM, C:\Windows.old\Windows\Windows\Installer\2402ebf.msi, , [57390d640288cc6adff0f23e9f675fa1],
          Extension.Mismatch, C:\Program Files\Old Adventure Maker v4.6.1\Data\pic461.bmp, , [bed2d49dbad075c14b2a683650b0e818],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\Uninstall.exe, , [c1cf3041dfabab8b3371cc79e6208d73],
          PUP.Optional.RelevantKnowledge, C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlvknlg.exe.vir, , [e1af264b2169fd3962faff20f90d54ac],
          PUP.DealPly, C:\AdwCleaner\Quarantine\C\Program Files\DealPly\DealPlyIE.dll.vir, , [c4cc6b0661295bdb593d6fc0de2859a7],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\DealPlyLiveBroker.exe.vir, , [325ee190b1d9ae88b129123cb051c13f],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\DealPlyLiveOnDemand.exe.vir, , [1878e88907830135d00a262861a00df3],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdate.dll.vir, , [ff91a6cb5535191d12c870dec23fc040],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_am.dll.vir, , [2a660d64d7b30333cd0d96b80bf6df21],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ar.dll.vir, , [3b55dc951f6b3ff7429897b7d0310bf5],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_bg.dll.vir, , [8a066110a0ea1d19d6042f1fc63b758b],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_bn.dll.vir, , [355b84eda7e301352ab0034ba16021df],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ca.dll.vir, , [f39d88e98307e65020ba430b8d74ae52],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_cs.dll.vir, , [2b65512076143df9a238410dbb4658a8],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_da.dll.vir, , [e8a8630e335779bda8320a4460a11ee2],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_de.dll.vir, , [6e22e48dbcceb383e3f7301e5da452ae],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_el.dll.vir, , [9af65c1565252016f7e3301e5aa7b947],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_en-GB.dll.vir, , [4f41254cb4d6df576476a0aecc3524dc],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_en.dll.vir, , [eaa6e8892367fd39f3e77fcf35cc6b95],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_es-419.dll.vir, , [6030363b5a3065d16278aaa416eb39c7],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_es.dll.vir, , [a5eb1f52e5a591a57b5f8fbfeb16b44c],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_fa.dll.vir, , [662ab9b8187293a38a5090be33ce9769],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_fi.dll.vir, , [07894e237614c175d30770dea65b639d],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_fil.dll.vir, , [92fe4f227a100b2b7268fd51d829f40c],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_fr.dll.vir, , [d9b7a8c9c5c557dfad2d96b8a859ae52],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_gu.dll.vir, , [98f87df4b7d33afca436a3ab4fb2e917],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_hi.dll.vir, , [ff91fe734347ff37eded7bd3639eca36],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_hr.dll.vir, , [bad6c4addcae082e7169cd81629f926e],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_hu.dll.vir, , [eca4f180206abe78b9218dc1a958ce32],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_id.dll.vir, , [4b452b46791190a6a83288c66e93a35d],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_is.dll.vir, , [444c4d24583242f427b3bd9117ea21df],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_it.dll.vir, , [6f216e036c1ec76fa2389cb2c83934cc],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_iw.dll.vir, , [345c264bb6d4cb6b3aa0ada10af76f91],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ja.dll.vir, , [c5cb87ea9dedf2445c7e71dd19e8926e],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_kn.dll.vir, , [2d6397da820877bf8f4b371720e122de],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ko.dll.vir, , [3a56f180800ae155b02a034b1ee3bc44],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_lv.dll.vir, , [4a46244d008ae84efcdeef5f33ce8977],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ml.dll.vir, , [f29eb9b83a5086b05783f856f20ff709],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_mr.dll.vir, , [7b152f42c6c4fa3c6278d579946d3ac6],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ms.dll.vir, , [a1efdd943357082ecd0da5a95ca5bd43],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_nl.dll.vir, , [2a66bdb41c6e5bdb83572c221ee3f40c],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_no.dll.vir, , [5739ea87fa906accb02a5af4e51cc53b],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_pl.dll.vir, , [1e72e28f06842115a93174da857c37c9],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_pt-BR.dll.vir, , [fb958be6e3a71a1cad2d450902ff9d63],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_pt-PT.dll.vir, , [f69aa2cf1f6baf870cce50fe877afc04],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ro.dll.vir, , [e4aca5ccafdbd85e904aa1ad5ca56799],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ru.dll.vir, , [97f9541d2e5c45f109d180ce9869837d],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_sk.dll.vir, , [0888e48def9bdd59a139cb83dc2540c0],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_sl.dll.vir, , [67295d14593138febb1f38164bb6936d],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_sr.dll.vir, , [a9e7a8c90f7be650d40672dc738e1ce4],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_sv.dll.vir, , [dfb1a4cd94f687afcc0e63eb41c0827e],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_et.dll.vir, , [3858b0c197f34cead307bf8f9b66bf41],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_lt.dll.vir, , [6c24c3ae5f2bd264ba205af4f50cfb05],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_sw.dll.vir, , [dbb5acc5f09a37ffecee4d01bb46ef11],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ta.dll.vir, , [0c847ef3ee9cd75fc218a2ac54ad8b75],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_te.dll.vir, , [d0c0f0815436ee4830aa77d70cf5e31d],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_th.dll.vir, , [2e62244db4d6152121b9a2ac17eae917],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_tr.dll.vir, , [a1ef1f52850575c19c3e034b8a776c94],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_uk.dll.vir, , [444cfd74f09a72c401d9e46a38c9728e],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_ur.dll.vir, , [efa14d246327c5710ad051fd3ac7728e],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_vi.dll.vir, , [b1df2d44fa909e98409a87c7e021df21],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_zh-CN.dll.vir, , [018fc3aeb4d6c472af2bc08e12efb050],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\goopdateres_zh-TW.dll.vir, , [2a6696db3d4d50e66a70ff4ff70aca36],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll.vir, , [ade37ef3bfcb9e984298a9a55ba649b7],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\psmachine.dll.vir, , [741cacc586047db93f9b143a40c11fe1],
          PUP.Optional.DealPly.A, C:\AdwCleaner\Quarantine\C\Program Files\DealPlyLive\Update\1.3.23.0\psuser.dll.vir, , [4b45b5bc3852f83ed3070a447b8643bd],
          PUP.Optional.Iminent.A, C:\AdwCleaner\Quarantine\C\Program Files\Iminent\inst\Bootstrapper\Bootstrapper.exe.vir, , [8b05551c1a7025113b383d22867b0ff1],
          PUP.Optional.MiniBar.A, C:\AdwCleaner\Quarantine\C\Program Files\Minibar\Minibar.dll.vir, , [0090442dd8b2072f96dd42e2827ee11f],
          PUP.Optional.Crossrider, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-buttonutil.dll.vir, , [424e026f8307e254b5af9711c243c13f],
          PUP.Optional.Pricora.A, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-bho.dll.vir, , [3c5481f0721844f2efa1fab979883bc5],
          PUP.Optional.Pricora.A, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-buttonutil.exe.vir, , [4c44125f91f94fe7d5bb3182b05109f7],
          PUP.Optional.Pricora.A, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-codedownloader.exe.vir, , [1f71046dcac01b1bccc4842f7d84b749],
          PUP.Optional.Pricora.A, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-enabler.exe.vir, , [810f1f5236548bab0987882b629f09f7],
          PUP.Optional.CrossRider, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-helper.exe.vir, , [216ff37ed5b53402077eec6e8d7418e8],
          PUP.Optional.Pricora.A, C:\AdwCleaner\Quarantine\C\Program Files\Pricora\Pricora-updater.exe.vir, , [b5db5819a0eacb6b8d0308ab669b1ae6],
          PUP.Optional.Delta.A, C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir, , [f49c80f1c6c4ee4856fd307532d31ee2],
          PUP.Optional.Somoto.A, C:\AdwCleaner\Quarantine\C\Users\Marco\AppData\Local\FilesFrog Update Checker\uninstall.exe.vir, , [4f41343ddfabeb4b22c95eded22f35cb],
          PUP.Optional.FilesFrog.A, C:\AdwCleaner\Quarantine\C\Users\Marco\AppData\Local\FilesFrog Update Checker\update_checker.exe.vir, , [8907650cc8c285b1154ae83db34ddc24],
          PUP.Optional.Wilsys.A, C:\AdwCleaner\Quarantine\C\Users\Marco\AppData\Local\Temp\eIntaller\0EA42631DCC54025A1C21967106B7D50\help.exe.vir, , [c8c8cda4cfbbd16563a8d385c938916f],
          PUP.Optional.Dregol.C, C:\Users\Marco\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, , [147c91e0a3e7fa3ca04acef741c235cb],
          PUP.Optional.Dregol.C, C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ihokndmjeombjojnfkmapfnjeghjohim_0.localstorage, , [117fbdb4ccbe7bbbf7cbd7ef7093768a],
          PUP.Optional.Vitruvian.A, C:\Users\Marco\AppData\Local\Temp\vitruvian-installer-install-v0003, , [ddb3ec855d2d2d095949b59d47be36ca],
          PUP.Optional.Vitruvian.A, C:\Users\Marco\AppData\Local\Temp\vitruvian-installer-processes-v0002, , [4f4172ff6228c76fb8ea3f1321e4a45c],
          PUP.Optional.Vitruvian.A, C:\Users\Marco\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, , [6927660b7614a690f8aa51014fb66e92],
          PUP.Optional.Vitruvian.A, C:\Users\Marco\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002, , [256b76fb216942f4772b4a080df821df],
          PUP.Optional.Dregol.A, C:\Program Files\Run_Dregol\config.dat, , [7d131a57f09a5fd7963b3b8718eb20e0],
          PUP.Optional.Dregol.A, C:\Program Files\Run_Dregol\Sqlite3.dll, , [7d131a57f09a5fd7963b3b8718eb20e0],
          PUP.Optional.Dregol.A, C:\Program Files\Run_Dregol\uninst.dat, , [7d131a57f09a5fd7963b3b8718eb20e0],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\terms-of-service.rtf, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\buildcrx-license.txt, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\Info-ZIP-license.txt, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\JSON-simple-license.txt, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\nsJSON-license.txt, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\Nustache-license.txt, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\TaskScheduler-license.txt, , [fc94076acebc211573f9cbf9956edc24],
          PUP.Optional.LinkWiz.A, C:\Program Files\LinkWiz_1.10.0.14\3rd Party Licenses\UAC-license.txt, , [fc94076acebc211573f9cbf9956edc24],

          Settori fisici: 0
          (Nessun elemento nocivo rilevato)


          (end)

          Malwarebytes found a lot of bad entries, they need to go, make sure you followed my instructions to have Malwarebytes remove everything it finds, if those entries where not remove you need to run malwarebytes again and remove it all

           

          • On the Dashboard click on Update Now
          • Go to the Setting Tab
          • Under Setting go to Detection and Protection
          • Under PUP and PUM make sure both are set to show Treat Detections as Malware
          • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
          • Then on the Dashboard click on Scan
          • Make sure to select THREAT SCAN
          • Then click on Scan
          • When the scan is finished and the log pops up…select Copy to Clipboard
          • Please paste the log back into this thread for review
          • Exit Malwarebytes
          •  
             
             
            You never posted the log from AdwCleaner

            Hi Ken,

            I apologize but I forgot to post the ADWClkeaner log file.

            You can Find the original logfili here attached,

            And I apologize again because I have not understood that I have to clean the PC afte Malwarebite scan

            Now I run again malwarebiye and at the I have cleaned all at o messagge that confirm that all the item have been cleaned appers but I was non able to find any logfile.

            So I run again the scan and no suspected item have beeen identified

             

            AdwCleabaer original logfile

            # AdwCleaner v4.202 - Creato file registro eventi 27/04/2015 in 22:59:23
            # Aggiornato 23/04/2015 da Xplode
            # Database : 2015-04-27.1 [Server]
            # Sistema operativo : Windows 7 Home Premium Service Pack 1 (x86)
            # Nome utente : Marco - MARCO-PC
            # In esecuzione da : C:\Users\Marco\Desktop\adwcleaner_4.202.exe
            # Opzione : Pulizia

            ***** [ Servizi ] *****

            Servizio Eliminato : AF9035BDA
            [#] Servizio Eliminato : lwnfd_1_10_0_14

            ***** [ File / Cartelle ] *****

            Cartella Eliminato : C:\ProgramData\Conduit
            Cartella Eliminato : C:\ProgramData\WPM
            Cartella Eliminato : C:\ProgramData\6321271a0000001c
            Cartella Eliminato : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlvPlayer
            Cartella Eliminato : C:\Program Files\Conduit
            Cartella Eliminato : C:\Program Files\SiteLookup
            Cartella Eliminato : C:\Program Files\DriverToolkit
            Cartella Eliminato : C:\Windows\system32\config\systemprofile\AppData\Local\speed browser
            Cartella Eliminato : C:\Users\Marco\AppData\Local\Conduit
            Cartella Eliminato : C:\Users\Marco\AppData\Local\NativeMessaging
            Cartella Eliminato : C:\Users\Marco\AppData\Local\speed browser
            Cartella Eliminato : C:\Users\Marco\AppData\Local\CleanerPro
            Cartella Eliminato : C:\Users\Marco\AppData\Local\DriverToolkit
            Cartella Eliminato : C:\Users\Marco\AppData\LocalLow\Conduit
            Cartella Eliminato : C:\Users\Marco\AppData\Roaming\FlvPlayer
            Cartella Eliminato : C:\Users\Marco\AppData\Roaming\Oxy
            Cartella Eliminato : C:\Users\Marco\AppData\Roaming\pdfforge
            Cartella Eliminato : C:\Users\Marco\AppData\Roaming\sweet-page
            Cartella Eliminato : C:\Users\Marco\AppData\Roaming\Systweak
            Cartella Eliminato : C:\Users\Marco\Documents\CleanerPro
            File Eliminato : C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_boipimhfjpakfgckhbljjengakjhkcbp_0.localstorage
            File Eliminato : C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gbmdkmlcnbapgegninelmjbfibaghdmk_0.localstorage
            File Eliminato : C:\Users\Public\Desktop\FlvPlayer.lnk
            File Eliminato : C:\Windows\system32\drivers\AF9035BDA.sys
            File Eliminato : C:\Users\Marco\Desktop\HDVidCodec.lnk
            File Eliminato : C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\searchplugins\sweet-page.xml
            File Eliminato : C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\user.js
            File Eliminato : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js

            ***** [ Attività pianificate ] *****

            Attività Eliminato : CleanerPro_Start
            Attività Eliminato : LaunchSignup

            ***** [ Collegamenti ] *****


            ***** [ Registry ] *****

            Valore Eliminato : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[removed]]
            Valore Eliminato : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[removed]]
            Chiave Eliminato : HKLM\SOFTWARE\Classes\driverscanner
            Chiave Eliminato : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeupdater
            Chiave Eliminato : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
            Chiave Eliminato : HKCU\Software\Mozilla\Extends
            Chiave Eliminato : HKLM\SOFTWARE\1c39ac5b-c442-9650-5142-fc3eea9bbcde
            Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
            Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
            Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
            Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
            Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
            Chiave Eliminato : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
            Chiave Eliminato : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A86D0113-4332-4553-A3F9-124DB478F4B5}
            Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
            Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4E9A8B55-8719-0F9E-7C7C-29C83943F11F}
            Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{c9ab6446-7efc-47fe-966c-dc54324eff9f}
            Chiave Eliminato : HKCU\Software\Protector
            Chiave Eliminato : HKCU\Software\Softonic
            Chiave Eliminato : HKCU\Software\UpdateStar
            Chiave Eliminato : HKCU\Software\UpToDown
            Chiave Eliminato : HKCU\Software\Super Optimizer
            Chiave Eliminato : HKCU\Software\DriverToolkit
            Chiave Eliminato : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
            Chiave Eliminato : HKCU\Software\AppDataLow\Software\Conduit
            Chiave Eliminato : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
            Chiave Eliminato : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
            Chiave Eliminato : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
            Chiave Eliminato : HKLM\SOFTWARE\Conduit
            Chiave Eliminato : HKLM\SOFTWARE\FlvPlayer
            Chiave Eliminato : HKLM\SOFTWARE\IePlugin
            Chiave Eliminato : HKLM\SOFTWARE\sweet-pageSoftware
            Chiave Eliminato : HKLM\SOFTWARE\SpeedBrowser
            Chiave Eliminato : HKLM\SOFTWARE\Clara
            Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FlvPlayer
            Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstall

            ***** [ Browser web ] *****

            -\\ Internet Explorer v11.0.9600.17728


            -\\ Mozilla Firefox v37.0.2 (x86 it)

            [fdubo8yh.Marco\prefs.js] - Linea Eliminato : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
            [fdubo8yh.Marco\prefs.js] - Linea Eliminato : user_pref("extensions.quick_start.enable_search1", false);
            [fdubo8yh.Marco\prefs.js] - Linea Eliminato : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
            [uygrla6u.default-1426711383616\prefs.js] - Linea Eliminato : user_pref("browser.startup.homepage", "hxxp://www.dregol.com/?f=1&a=drg_frmr_15_17&cd=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1S[…]

            -\\ Google Chrome v42.0.2311.90

            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDyCtByEtB0BtDtA0B0E0A0Azyzy0DtCtN0D0Tzu0CyDzztAtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=952604917&ir=
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://mixidj.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=240E06242B03BEAA&affID=121136&tsp=4959
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss_sps&mntrId=240E06242B03BEAA&affID=121136&tsp=4959
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=240E06242B03BEAA&affID=123884&tsp=4966
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://search.fbdownloader.com/search.php?channel=sfit202fbdgy11&q={searchTerms}
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=240E06242B03BEAA&affID=123925&tsp=5020
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN18597789581088798&ctid=CT3306061&UM=2
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www.qone8.com/web/?type=ds&ts=1397406642&from=ild&uid=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q={searchTerms}
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1425272006&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980&q={searchTerms}
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_frmr_15_17&cd=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr=1188893128&ir=
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Homepage] : hxxp://www.dregol.com/?f=1&a=drg_frmr_15_17&cd=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr=1188893128&ir=
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Startup_URLs] : hxxp://www.dregol.com/?f=7&a=drg_frmr_15_17&cd=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr=1188893128&ir=
            [C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Default_Search_Provider_Data] : hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_frmr_15_17&cd=2XzuyEtN2Y1L1QzutDtD0F0FtA0CtC0BtD0AtBtDzyzy0DtCtN0D0Tzu0StCtBtDzytN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtDzytB0Fzyzz0DtGzz0F0FyBtG0A0C0CyEtGyCyDyDtAtGtBtCtCtB0C0F0F0ByBtD0FyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0CyDyByD0BzzyBtGyBtA0DyCtGyE0FtA0AtGzyyE0B0FtGyBzy0CyBtA0AtDyEyC0AyCtA2QtN0A0LzutB&cr=1188893128&ir=

            *************************

            AdwCleaner[R0].txt - [16391 byte] - [27/09/2013 10:01:45]
            AdwCleaner[R1].txt - [1373 byte] - [27/09/2013 10:10:27]
            AdwCleaner[R2].txt - [1137 byte] - [28/09/2013 21:16:08]
            AdwCleaner[R3].txt - [16738 byte] - [30/09/2013 22:36:32]
            AdwCleaner[R4].txt - [1429 byte] - [30/09/2013 23:12:15]
            AdwCleaner[R5].txt - [1426 byte] - [03/10/2013 22:53:01]
            AdwCleaner[R6].txt - [1546 byte] - [05/10/2013 13:11:38]
            AdwCleaner[R7].txt - [15539 byte] - [30/10/2013 23:30:56]
            AdwCleaner[R8].txt - [10952 byte] - [27/04/2015 22:53:41]
            AdwCleaner[S0].txt - [16616 byte] - [27/09/2013 10:03:51]
            AdwCleaner[S1].txt - [1440 byte] - [27/09/2013 10:11:51]
            AdwCleaner[S2].txt - [17436 byte] - [30/09/2013 22:39:04]
            AdwCleaner[S3].txt - [1492 byte] - [30/09/2013 23:14:06]
            AdwCleaner[S4].txt - [1487 byte] - [03/10/2013 22:54:18]
            AdwCleaner[S5].txt - [1607 byte] - [05/10/2013 13:13:05]
            AdwCleaner[S6].txt - [14057 byte] - [30/10/2013 23:31:52]
            AdwCleaner[S7].txt - [11083 byte] - [27/04/2015 22:59:23]

            ########## EOF - C:\AdwCleaner\AdwCleaner[S7].txt - [11142  byte] ##########

             

            Well, the news  FRST scan

            Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2015 01
            Ran by [removed] (administrator) on MARCO-PC on 29-04-2015 21:42:15
            Running from C:\Users\[removed]\Desktop
            [removed] Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Italiano (Italia)
            Internet Explorer Version 11 (Default browser: FF)
            Boot Mode: Normal
            Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

            ==================== Processes (Whitelisted) =================

            (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

            (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe
            (AOMEI Tech Co., Ltd.) C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe
            (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
            (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
            (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
            (PGP Corporation) C:\Windows\System32\PGPserv.exe
            (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
            (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
            (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
            (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe
            (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
            (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
            (PGP Corporation) C:\Program Files\PGP Corporation\PGP Desktop\PGPdesk.exe
            (PGP Corporation) C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe
            (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
            (Microsoft Corporation) C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
            (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
            (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


            ==================== Registry (Whitelisted) ==================

            (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

            Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
            Lsa: [Notification Packages] scecli PGPpwflt
            ShellIconOverlayIdentifiers: [IconOverlayHandlerAccessible] -> {3DBF5F01-3287-46EB-82CF-45AA5C241162} => C:\Windows\system32\PGPfsshl.dll [2010-04-01] (PGP Corporation)
            GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

            ==================== Internet (Whitelisted) ====================

            (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
            HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
            HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {4E9A8B55-8719-0F9E-7C7C-29C83943F11F} URL =
            SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {A1C3DFA2-A404-4C14-A7FD-BBA0C9707DE3} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
            SearchScopes: HKU\S-1-5-21-4094248773-42424133-2592686105-1000 -> {F84F0002-4F7D-43B3-A86D-076D14A000F0} URL = http://it.search.yahoo.com/search?fr=mcafee&type;=A011IT662&p;={SearchTerms}
            BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
            BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09] (Oracle Corporation)
            BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
            BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
            BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09] (Oracle Corporation)
            DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
            Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Windows\system32\Msdxm6.ocx [2000-04-21] (Microsoft Corporation)
            ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
            Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
            Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
            StartMenuInternet: IEXPLORE.EXE - iexplore.exe

            FireFox:
            ========
            FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco
            FF Homepage: hxxp://www.google.it/
            FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-12] ()
            FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
            FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
            FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-09] (Oracle Corporation)
            FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-09] (Oracle Corporation)
            FF Plugin: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
            FF Plugin: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
            FF Plugin: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
            FF Plugin: @microsoft.com/GENUINE -> disabled No File
            FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
            FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
            FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
            FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
            FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll [2014-06-26] (pdfforge GmbH)
            FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\golliver.xml [2015-04-25]
            FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2014-05-18]
            FF Extension: Golliver - C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox\Extensions\[removed] [2015-04-25]
            FF Extension: Golliver - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\Extensions\[removed] [2015-04-25]
            FF Extension: No Name - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-04-29]
            FF Extension: Adblock Plus - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-24]
            FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
            FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
            FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
            FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
            FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
            FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
            FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]

            Chrome:
            =======
            CHR HomePage: Default ->
            CHR StartupUrls: Default -> "hxxp://www.sweet-page.com/?type=hp&ts;=1429935097&from;=cor&uid;=WDCXWD5000BEVT-22ZAT0_WD-WXNX08NV6980V6980"
            CHR Profile: C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default
            CHR Extension: (Kaspersky Protection) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-04-15]
            CHR Extension: (IDM Integration Module) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-15]
            CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-15]
            CHR HKLM\…\Chrome\Extension: [bollbfeakabenkobaocgakdibphdnanj] - http://clients2.google.com/service/update2/crx
            CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
            CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
            CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [Not Found]

            ========================== Services (Whitelisted) =================

            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

            S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-17] (SUPERAntiSpyware.com)
            R2 AVP15.0.2; C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [193400 2014-12-23] (Kaspersky Lab ZAO)
            R2 Backupper Service; C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
            R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
            R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
            S3 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
            S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
            S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
            S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
            S4 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
            S4 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
            R2 PGPserv; C:\Windows\system32\PGPserv.exe [135288 2010-04-01] (PGP Corporation)
            S2 uzsvc; C:\Program Files\UltraZip\uzsvc.exe [531744 2015-03-10] ()
            S2 uzupd; C:\Program Files\UltraZip\uzupd.exe [44312 2015-03-10] ()
            R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
            S2 asl; "C:\ProgramData\Service\Application\asl.exe" [X]

            ==================== Drivers (Whitelisted) ====================

            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

            R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [26424 2013-05-07] () [File not signed]
            R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [129720 2013-05-07] () [File not signed]
            R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [14392 2013-02-06] () [File not signed]
            S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
            R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [189136 2013-01-14] (Kaspersky Lab UK Ltd)
            R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
            S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [94336 2014-12-19] (ITE                      )
            R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [143968 2014-03-31] (Kaspersky Lab ZAO)
            R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46280 2015-03-27] (Kaspersky Lab ZAO)
            R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [120008 2014-11-28] (Kaspersky Lab ZAO)
            R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [36040 2014-10-22] (Kaspersky Lab ZAO)
            R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [698568 2015-03-27] (Kaspersky Lab ZAO)
            R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25800 2014-10-10] (Kaspersky Lab ZAO)
            R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [26824 2014-10-30] (Kaspersky Lab ZAO)
            R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO)
            R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
            R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [46152 2014-10-09] (Kaspersky Lab ZAO)
            R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [64200 2014-11-22] (Kaspersky Lab ZAO)
            R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [148296 2014-11-10] (Kaspersky Lab ZAO)
            R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
            S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
            R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
            R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
            R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
            R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
            R3 WsAudio_Device(1); C:\Windows\System32\drivers\VirtualAudio1.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(2); C:\Windows\System32\drivers\VirtualAudio2.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(3); C:\Windows\System32\drivers\VirtualAudio3.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(4); C:\Windows\System32\drivers\VirtualAudio4.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(5); C:\Windows\System32\drivers\VirtualAudio5.sys [27496 2013-01-25] (Wondershare)
            R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
            U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
            S3 catchme; \??\C:\Users\Marco\AppData\Local\Temp\catchme.sys [X]
            S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]

            ==================== NetSvcs (Whitelisted) ===================

            (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


            ==================== One Month Created Files and Folders ========

            (If an entry is included in the fixlist, the file\folder will be moved.)

            2015-04-27 23:25 - 2015-04-27 23:25 - 00002193 _____ () C:\Users\Marco\Desktop\JRT.txt
            2015-04-27 23:10 - 2015-04-27 23:10 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-MARCO-PC-Windows-7-Home-Premium-(32-bit).dat
            2015-04-27 23:10 - 2015-04-27 23:10 - 00000000 ____D () C:\RegBackup
            2015-04-27 23:05 - 2015-04-27 23:05 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Marco\Desktop\mbam-setup-2.1.6.1022.exe
            2015-04-27 23:04 - 2015-04-27 23:04 - 02715845 _____ (Thisisu) C:\Users\Marco\Desktop\JRT.exe
            2015-04-27 22:50 - 2015-04-27 22:52 - 00044459 _____ () C:\Users\Marco\Desktop\Addition.txt
            2015-04-27 22:48 - 2015-04-27 22:48 - 02224640 _____ () C:\Users\Marco\Desktop\adwcleaner_4.202.exe
            2015-04-27 22:47 - 2015-04-29 21:43 - 00018144 _____ () C:\Users\Marco\Desktop\FRST.txt
            2015-04-27 22:47 - 2015-04-27 22:47 - 01140736 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe
            2015-04-27 22:47 - 2015-04-27 22:47 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion
            2015-04-26 04:33 - 2015-04-26 04:33 - 278896405 _____ () C:\Windows\MEMORY.DMP
            2015-04-26 04:33 - 2015-04-26 04:33 - 00158560 _____ () C:\Windows\Minidump\042615-19874-01.dmp
            2015-04-25 15:37 - 2015-04-25 15:37 - 00000137 _____ () C:\Users\Marco\Documents\gabriella.txt
            2015-04-25 07:31 - 2015-04-29 21:42 - 00000000 ____D () C:\FRST
            2015-04-25 07:14 - 2015-04-25 07:14 - 00002928 _____ () C:\Users\Marco\Documents\aswMBR.txt
            2015-04-25 07:14 - 2015-04-25 07:14 - 00000512 _____ () C:\Users\Marco\Documents\MBR.dat
            2015-04-25 06:26 - 2015-04-25 06:27 - 00000000 ____D () C:\Users\Marco\AppData\Local\nida
            2015-04-25 06:05 - 2015-04-25 06:27 - 00000000 ___SD () C:\32788R22FWJFW
            2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\ProgramData\UltraZip
            2015-04-25 06:03 - 2015-04-25 17:52 - 00000000 ____D () C:\Program Files\UltraZip
            2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Service
            2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraZip
            2015-04-25 06:02 - 2015-04-25 06:06 - 05619466 ____R (Swearware) C:\Users\Marco\Downloads\combofix [1].exe
            2015-04-25 05:53 - 2015-04-29 21:33 - 00326860 _____ () C:\Windows\PFRO.log
            2015-04-25 05:53 - 2015-04-29 21:33 - 00000784 _____ () C:\Windows\setupact.log
            2015-04-25 05:53 - 2015-04-25 05:53 - 00000000 _____ () C:\Windows\setuperr.log
            2015-04-25 05:48 - 2015-04-25 05:48 - 00156898 _____ () C:\Users\Marco\Documents\cc_20150425_054751.reg
            2015-04-19 06:56 - 2015-04-19 07:49 - 370938816 _____ () C:\Users\Marco\Downloads\0d6b8d7ca1.mp4.rar.part
            2015-04-18 13:13 - 2015-04-18 17:27 - 742534663 _____ () C:\Users\Marco\Downloads\Cazzo.Grosso.Ma.Non.Troppo.Foreign.S.E.rar.part
            2015-04-18 11:10 - 2015-04-18 11:35 - 105298398 _____ () C:\Users\Marco\Downloads\Dana Moravova _ Milada.avi.part
            2015-04-18 07:02 - 2015-04-18 07:26 - 175777135 _____ () C:\Users\Marco\Downloads\Brooke_Tyler_-_shutup_and_blow_airport_hd.mp4
            2015-04-14 21:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
            2015-04-14 21:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
            2015-04-14 21:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
            2015-04-14 21:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
            2015-04-14 21:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
            2015-04-14 21:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
            2015-04-14 21:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
            2015-04-14 21:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
            2015-04-14 21:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
            2015-04-14 21:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
            2015-04-14 21:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
            2015-04-14 21:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
            2015-04-14 21:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
            2015-04-14 21:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
            2015-04-14 21:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
            2015-04-14 21:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
            2015-04-14 21:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
            2015-04-14 21:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
            2015-04-14 21:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
            2015-04-14 21:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
            2015-04-14 21:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
            2015-04-14 21:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
            2015-04-14 21:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
            2015-04-14 21:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
            2015-04-14 21:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
            2015-04-14 21:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
            2015-04-14 21:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
            2015-04-14 21:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
            2015-04-14 21:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
            2015-04-14 21:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
            2015-04-14 21:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
            2015-04-14 21:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
            2015-04-14 21:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
            2015-04-14 21:40 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
            2015-04-14 21:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
            2015-04-14 21:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
            2015-04-14 21:40 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
            2015-04-14 21:40 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
            2015-04-14 21:40 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
            2015-04-14 21:40 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
            2015-04-14 21:40 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
            2015-04-14 21:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
            2015-04-14 21:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
            2015-04-14 21:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
            2015-04-14 21:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
            2015-04-14 21:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
            2015-04-14 21:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
            2015-04-14 21:40 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
            2015-04-14 21:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
            2015-04-14 21:39 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
            2015-04-14 21:39 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
            2015-04-11 10:13 - 2015-04-26 10:02 - 00000000 ____D () C:\Users\Marco\olimpus
            2015-04-05 08:25 - 2015-04-05 08:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\RenPy
            2015-04-05 07:20 - 2015-04-05 08:01 - 244140767 _____ () C:\Users\Marco\Downloads\wbc-1.0-all.rar
            2015-04-05 06:59 - 2015-04-05 06:59 - 00000000 ____D () C:\Users\Marco\Tracing
            2015-04-05 05:44 - 2015-04-05 05:44 - 00000000 ___SD () C:\Windows\system32\GWX
            2015-04-04 10:26 - 2015-04-04 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\slac
            2015-04-04 10:23 - 2015-04-04 10:23 - 00000000 ____D () C:\Program Files\slac
            2015-04-04 08:16 - 2015-04-04 08:16 - 00000000 ____D () C:\Program Files\Common Files\Protexis
            2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\Users\Public\Desktop\Corel PaintShop Pro X5.lnk
            2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\ProgramData\Desktop\Corel PaintShop Pro X5.lnk
            2015-04-04 08:15 - 2015-04-04 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X5
            2015-04-03 08:13 - 2015-04-03 08:13 - 09629976 _____ (CyberGhost S.R.L. ) C:\Users\Marco\Downloads\CG_5.0.14.7.exe
            2015-03-31 21:34 - 2015-03-31 21:34 - 00036168 _____ () C:\Users\Marco\Desktop\29177662s.pdf.zip

            ==================== One Month Modified Files and Folders =======

            (If an entry is included in the fixlist, the file\folder will be moved.)

            2015-04-29 21:42 - 2013-11-01 09:59 - 01981392 _____ () C:\Windows\WindowsUpdate.log
            2015-04-29 21:37 - 2014-05-22 06:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
            2015-04-29 21:33 - 2014-05-23 06:31 - 00000000 ____D () C:\Program Files\Internet Download Manager
            2015-04-29 21:33 - 2013-11-04 23:19 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
            2015-04-29 21:33 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
            2015-04-29 06:49 - 2013-03-05 23:43 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
            2015-04-29 06:12 - 2013-11-04 23:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
            2015-04-28 22:27 - 2014-05-21 22:11 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
            2015-04-28 22:17 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
            2015-04-28 22:17 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
            2015-04-28 22:06 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\DMCache
            2015-04-28 00:13 - 2013-03-21 22:54 - 00000000 ____D () C:\Users\Marco\AppData\Local\CrashDumps
            2015-04-27 23:27 - 2014-05-21 22:11 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
            2015-04-27 23:27 - 2014-05-21 22:11 - 00001024 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
            2015-04-27 23:27 - 2014-05-21 22:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
            2015-04-27 23:27 - 2014-05-21 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
            2015-04-27 22:59 - 2013-09-27 10:01 - 00000000 ____D () C:\AdwCleaner
            2015-04-26 06:28 - 2013-03-05 18:20 - 01786646 _____ () C:\Windows\system32\PerfStringBackup.INI
            2015-04-26 06:28 - 2009-07-14 10:21 - 00791368 _____ () C:\Windows\system32\perfh010.dat
            2015-04-26 06:28 - 2009-07-14 10:21 - 00164498 _____ () C:\Windows\system32\perfc010.dat
            2015-04-26 04:33 - 2013-07-12 04:50 - 00000000 ____D () C:\Windows\Minidump
            2015-04-25 17:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\PLA
            2015-04-25 16:10 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\IDM
            2015-04-25 10:08 - 2013-03-08 00:39 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc
            2015-04-25 08:30 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
            2015-04-25 05:45 - 2014-09-08 18:30 - 00000000 ____D () C:\Program Files\PDFCreator
            2015-04-25 05:43 - 2013-03-05 17:42 - 00000000 ____D () C:\Windows\Panther
            2015-04-24 18:42 - 2013-03-05 20:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
            2015-04-24 06:25 - 2014-12-11 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
            2015-04-24 06:25 - 2013-03-17 10:18 - 00000000 ____D () C:\Program Files\SpeedFan
            2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
            2015-04-17 03:19 - 2013-11-04 23:23 - 00002091 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
            2015-04-16 01:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
            2015-04-16 01:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
            2015-04-14 23:56 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
            2015-04-14 22:33 - 2014-12-10 07:47 - 00000000 ____D () C:\Windows\system32\appraiser
            2015-04-14 22:33 - 2014-05-01 08:15 - 00000000 ___SD () C:\Windows\system32\CompatTel
            2015-04-14 22:33 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT
            2015-04-14 22:10 - 2013-08-14 09:55 - 00000000 ____D () C:\Windows\system32\MRT
            2015-04-14 21:55 - 2013-03-10 07:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
            2015-04-14 09:37 - 2014-05-21 22:10 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
            2015-04-14 09:37 - 2014-05-21 22:10 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
            2015-04-14 09:37 - 2014-05-21 22:10 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
            2015-04-12 17:25 - 2014-06-24 21:39 - 00000000 ____D () C:\Users\Marco\AppData\Local\Adobe
            2015-04-12 17:25 - 2013-03-05 23:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
            2015-04-12 17:25 - 2013-03-05 23:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
            2015-04-11 10:13 - 2013-03-05 18:23 - 00000000 ____D () C:\Users\Marco
            2015-04-07 21:42 - 2014-12-20 17:59 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
            2015-04-05 07:01 - 2014-08-05 21:03 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\Skype
            2015-04-05 06:59 - 2014-08-05 21:02 - 00000000 ___RD () C:\Program Files\Skype
            2015-04-05 06:58 - 2014-08-05 21:02 - 00000000 ____D () C:\ProgramData\Skype
            2015-04-04 10:26 - 2013-03-06 00:34 - 00023392 _____ () C:\Windows\system32\nscompat.tlb
            2015-04-04 08:17 - 2013-03-12 07:21 - 00000000 ____D () C:\ProgramData\Corel
            2015-04-04 08:13 - 2013-03-12 07:16 - 00000000 ____D () C:\Program Files\Corel
            2015-04-04 08:05 - 2015-02-16 21:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Last_Man
            2015-04-03 09:08 - 2014-04-23 05:10 - 00001845 _____ () C:\Users\Marco\Desktop\CyberGhost 5.lnk
            2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
            2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\Program Files\CyberGhost 5

            ==================== Files in the root of some directories =======

            2013-03-12 07:27 - 2013-03-12 07:27 - 0003584 _____ () C:\Users\Marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
            2013-05-23 06:57 - 2013-05-23 06:59 - 0007602 _____ () C:\Users\Marco\AppData\Local\resmon.resmoncfg
            2014-04-21 10:30 - 2014-04-21 10:30 - 0000041 ___SH () C:\ProgramData\.zreglib
            2014-07-31 06:26 - 2014-07-31 06:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
            2013-03-17 09:07 - 2013-03-17 09:07 - 0000008 __RSH () C:\ProgramData\sysqcl1129067056.dat

            Files to move or delete:
            ====================
            C:\ProgramData\sysqcl1129067056.dat


            Some content of TEMP:
            ====================
            C:\Users\Marco\AppData\Local\Temp\Quarantine.exe
            C:\Users\Marco\AppData\Local\Temp\sfamcc00001.dll
            C:\Users\Marco\AppData\Local\Temp\sqlite3.dll


            ==================== Bamital & volsnap Check =================

            (There is no automatic fix for files that do not pass verification.)

            C:\Windows\explorer.exe => File is digitally signed
            C:\Windows\system32\winlogon.exe => File is digitally signed
            C:\Windows\system32\wininit.exe => File is digitally signed
            C:\Windows\system32\svchost.exe => File is digitally signed
            C:\Windows\system32\services.exe => File is digitally signed
            C:\Windows\system32\User32.dll => File is digitally signed
            C:\Windows\system32\userinit.exe => File is digitally signed
            C:\Windows\system32\rpcss.dll => File is digitally signed
            C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


            LastRegBack: 2015-04-14 00:36

            ==================== End Of Log ============================

            Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-04-2015 01
            Ran by [removed] at 2015-04-29 21:45:09
            Running from C:\Users\[removed]\Desktop
            Boot Mode: Normal
            ==========================================================


            ==================== Accounts: =============================

            Administrator (S-1-5-21-4094248773-42424133-2592686105-500 - Administrator - Disabled)
            Guest (S-1-5-21-4094248773-42424133-2592686105-501 - Limited - Disabled)
            HomeGroupUser$ (S-1-5-21-4094248773-42424133-2592686105-1002 - Limited - Enabled)
            Marco (S-1-5-21-4094248773-42424133-2592686105-1000 - Administrator - Enabled) => C:\Users\Marco

            ==================== Security Center ========================

            (If an entry is included in the fixlist, it will be removed.)

            AV: Kaspersky Total Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
            AS: Kaspersky Total Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
            AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            FW: Kaspersky Total Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

            ==================== Installed Programs ======================

            (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

            Adobe Flash Player 15 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
            Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
            Adobe Reader XI (11.0.10) - Italiano (HKLM\…\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
            Adventure Maker v4.6.1 (build1) (HKLM\…\Adventure Maker v4.6.1_is1) (Version:  - )
            Adventure Maker v4.7.1 (build1) (HKLM\…\Adventure Maker v4.7.1_is1) (Version:  - )
            Aimersoft DRM Media Converter(Build 1.5.5.0) (HKLM\…\Aimersoft DRM Media Converter_is1) (Version:  - Aimersoft Software)
            Alice MOBILE E169 (HKLM\…\Alice MOBILE E169) (Version: 11.002.04.11.192 - Huawei Technologies Co.,Ltd)
            Any Video Converter 5.6.3 (HKLM\…\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
            AOMEI Backupper Standard Edition 2.2 (HKLM\…\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version:  - AOMEI Technology Co., Ltd.)
            Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
            Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
            BlazeDTV 6.0 (HKLM\…\BlazeDTV 6.0_is1) (Version:  - )
            Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
            CCleaner (HKLM\…\CCleaner) (Version: 4.13 - Piriform)
            CDBurnerXP (HKLM\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
            Cinergy T Stick Driver Installation (32 Bit) (HKLM\…\{5123EBB5-0CB1-4EF1-8DF7-A4226537BCDC}) (Version: 8.08.18.01 - Nome società)
            Comic Life 2 (HKLM\…\{A8405D99-9D76-4456-8752-87DA930CC3A3}) (Version: 2.2.5.0 - plasq LLC)
            Core Temp 1.0 RC5 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
            Corel PaintShop Pro X5 (HKLM\…\_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.2.0.12 - Corel Corporation)
            Corel PaintShop Pro X5 (Version: 15.3.0.8 - Corel Corporation) Hidden
            CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
            EPSON Scan (HKLM\…\EPSON Scanner) (Version:  - )
            ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
            F24 On Line (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\F24 On Line) (Version:  - Agenzia delle Entrate)
            File Splitter and Joiner (FFSJ v3.3) (HKLM\…\File Splitter and Joiner_is1) (Version:  - Le Minh Hoang)
            FileInternet (HKLM\…\FileInternet) (Version: 2.9.9.0 - SOGEI)
            Free Video Cutter Joiner 9.8 (HKLM\…\{8C5A4758-C782-4200-B337-DB3466D33ADD}}_is1) (Version: 9.8 - DVDVideoMedia, Inc.)
            Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
            Google Earth (HKLM\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
            Google Update Helper (Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ATTENTION
            Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
            GoToAssist Corporate (HKLM\…\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
            HijackThis 2.0.2 (HKLM\…\HijackThis) (Version: 2.0.2 - TrendMicro)
            ICA (Version: 15.2.0.12 - Corel Corporation) Hidden
            iCloud (HKLM\…\{8D9592B4-7E22-4D1F-B2CB-B5F0F2F619CB}) (Version: 4.0.3.56 - Apple Inc.)
            IPM_PSP_COM (Version: 15.2.0.12 - Corel Corporation) Hidden
            iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
            J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)
            Java 8 Update 40 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
            Kaspersky Total Security (HKLM\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
            Kaspersky Total Security (Version: 15.0.2.361 - Kaspersky Lab) Hidden
            Kernel Outlook PST Viewer ver 11.05.01 (HKLM\…\Kernel Outlook PST Viewer_is1) (Version:  - Lepide Software Pvt. Ltd.)
            Last Man (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Last Man) (Version:  - )
            Malwarebytes Anti-Malware versione 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
            Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
            Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
            Microsoft Office XP Professional (HKLM\…\{91110410-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
            Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
            ModuliControllo2013 (HKLM\…\ModuliControllo2013) (Version: 4.0.0.0 - Sogei S.p.A)
            ModuliControlloUnico2014 (HKLM\…\ModuliControlloUnico2014) (Version: 1.1.1.0 - Sogei S.p.A)
            Mozilla Firefox 37.0.2 (x86 it) (HKLM\…\Mozilla Firefox 37.0.2 (x86 it)) (Version: 37.0.2 - Mozilla)
            Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
            Mozilla Thunderbird 31.6.0 (x86 it) (HKLM\…\Mozilla Thunderbird 31.6.0 (x86 it)) (Version: 31.6.0 - Mozilla)
            MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
            MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
            MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
            MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
            Pacchetto di compatibilità per Office System 2007 (HKLM\…\{90120000-0020-0410-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
            Pacchetto driver Windows - TerraTec  (AF9035BDA) Media  (05/18/2009 8.08.18.01) (HKLM\…\3602780F32D3BB88DB2E972AE797966CC5105334) (Version: 05/18/2009 8.08.18.01 - TerraTec )
            PDF Architect 2 (HKLM\…\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
            PDF Architect 2 View Module (HKLM\…\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
            PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
            PGP Desktop (HKLM\…\{04A8595A-4B2F-4A20-BA5D-E6B371657FF8}) (Version: 10.0.2.13 - PGP Corporation)
            PSPPContent (Version: 15.3.0.8 - Corel Corporation) Hidden
            PSPPHelp (Version: 15.2.0.12 - Corel Corporation) Hidden
            QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
            Recuva (HKLM\…\Recuva) (Version: 1.45 - Piriform)
            Setup (Version: 15.2.0.12 - Nome società) Hidden
            Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
            Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
            Skype™ 7.2 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
            slac (HKLM\…\slac_is1) (Version:  - )
            SpeedFan (remove only) (HKLM\…\SpeedFan) (Version:  - )
            SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1040 - SUPERAntiSpyware.com)
            Supporto applicazioni Apple (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
            TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
            TomTom HOME (HKLM\…\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - Nome società)
            TomTom HOME (HKLM\…\{BB05590A-6602-43F3-A400-77EA0976BC0A}) (Version: 2.9.8 - Nome società)
            TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
            UltraZip (HKLM\…\{5E36886D-AE94-4901-82A6-A96381B7B4AD}_is1) (Version: 2.0.2.6 - UltraZip)
            UnicOnLine PF 2014 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicOnLine PF 2014) (Version:  - Agenzia delle Entrate)
            UnicoOnLine - File Internet 2.9.9 (HKLM\…\File Internet) (Version:  - )
            UnicoOnLine PF 2012 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicoOnLine PF 2012) (Version:  - Agenzia delle Entrate)
            VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
            weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION
            WinOff (HKLM\…\{8049EB00-4F62-44FB-AAF7-CB42F588E3C5}_is1) (Version: 1.0.1.5 - )
            WinPhone (HKLM\…\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version:  - )
            WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
            Wisdom-soft ScreenHunter 6.0 Free (HKLM\…\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
            WriterPad (HKLM\…\{2E4ECAA8-6E82-4502-96BE-48D2DCCFA42A}) (Version: 1.0.0 - North Sky Productions LLC)

            ==================== Custom CLSID (selected items): ==========================

            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

            ==================== Restore Points  =========================

            25-04-2015 15:17:24 Windows Update
            25-04-2015 16:44:04 Windows Backup
            28-04-2015 21:25:23 Windows Update

            ==================== Hosts content: ==========================

            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

            2009-07-14 04:04 - 2014-05-21 23:31 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
            127.0.0.1       localhost

            ==================== Scheduled Tasks (whitelisted) =============

            (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

            Task: {09289DFA-8809-4294-AFB9-C9F05351A193} - System32\Tasks\{C8F3C4BF-1DF0-4D46-A1FA-731614A02DA6} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {1217E9D3-8939-4DCA-B835-08A6B3F9D25D} - System32\Tasks\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40} => C:\Users\Marco\Desktop\installspeedfan447.exe [2013-03-17] () <==== ATTENTION
            Task: {167C0E59-CF26-45F6-8EF2-BFEC3799BD95} - System32\Tasks\{C250204F-A2AB-4261-B042-B58AEF0116AE} => C:\Corel\Draw701\programs\photopnt.exe
            Task: {19980019-8149-4B71-A0AE-2B1B2C6D5A2A} - System32\Tasks\{3E0476D6-A2AA-4A2B-8F71-50978AD0A832} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {23D073A5-7AA0-47F5-B434-DA0D55C7F3B4} - System32\Tasks\{3CE02DF4-D192-416A-8EE2-8396B8CB6FB4} => C:\photopaint\PHOTOPNT.EXE
            Task: {2A1DD022-029F-4067-B593-016E6960BB35} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
            Task: {2C02D38D-F40F-447C-864B-90DD5FB6253E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
            Task: {334F613A-8EE8-4BD7-ACC3-7FD62264BF03} - System32\Tasks\{02D2332A-A21D-4ABE-BD10-62DD01C4BF11} => pcalua.exe -a C:\corel\SETUP\DAOSETUP.EXE -d C:\corel\SETUP
            Task: {4063D65F-FBE1-4343-AEF3-6C1DCA8671E0} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
            Task: {483CD9A1-6E78-455D-B1E7-30F42C1F03C4} - System32\Tasks\{F6AB3366-2EA1-4C45-8745-C16EE86D334C} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {4CF1CB7B-346F-4195-B187-51DE750A68C8} - System32\Tasks\{DD07A107-F0F4-4746-9D64-C4E23A192425} => C:\Corel\Draw701\programs\photopnt.exe
            Task: {52FBB622-5E59-464A-9911-3B94DF586442} - System32\Tasks\{5A1164C2-B0A7-48D0-84ED-49A59B0570E1} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {5BCFC431-3B77-4BC1-BFA7-B699A44258FC} - System32\Tasks\{90112C02-23E4-42FE-8F5D-97299A848050} => pcalua.exe -a "C:\Program Files\weDownload Manager\Uninstall.exe" -c /fromcontrolpanel=1
            Task: {6059284D-1243-46AF-B0A0-A10FCE072B4C} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
            Task: {63216F46-D65D-4D30-BD8C-29A29223C00B} - System32\Tasks\{831D7081-34DF-4BD4-BC41-204C3B539114} => D:\Corel\Draw70\programs\photopnt.exe
            Task: {66B33249-6DCB-485A-82F6-A570B2514A45} - System32\Tasks\{4DCA4D6B-3320-4ECC-9D3F-3391A219CE6E} => pcalua.exe -a L:\Compressed\cd_4.8a\CD_4.8A\CDSetup\setup.exe -d L:\Compressed\cd_4.8a\CD_4.8A\CDSetup
            Task: {6D5C45BA-B65B-4FBD-89D0-22CA804D813B} - System32\Tasks\{3FB8CB96-A3C4-4B71-9F07-5FC531C22FFC} => D:\D\DOOM.EXE
            Task: {794EBFAB-B0BC-4768-AE28-A37A4CFF2246} - System32\Tasks\{9C279F5D-7348-4DDB-A492-A91C311E3729} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {7AC1FF86-51CB-476C-A65F-108D684F6A55} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
            Task: {7B5D3C19-0CDC-4AEE-8193-4A06B5456EEE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
            Task: {80B2339F-C664-4EA6-8A16-EDE7EA353EE4} - System32\Tasks\{41FE69C8-BF1F-4934-9648-A0A09939AF14} => pcalua.exe -a C:\UnicoOnLine\UNI13\ModuliControllo2013_500.exe -d C:\UnicoOnLine\UNI13
            Task: {91152ABF-40E7-47A4-A9EE-4F582F79205D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-12] (Adobe Systems Incorporated)
            Task: {93D70EB9-D50F-48F3-9D11-D41103D61C3D} - System32\Tasks\{2DB657D7-D3D0-484F-985C-FF894C37A2C0} => pcalua.exe -a C:\UnicoOnLine\MainWinUNI10.exe -d C:\UnicoOnLine
            Task: {99D0E47C-5928-4FF2-83EA-8BAE5279ED61} - System32\Tasks\{D70B1B3A-5B54-49A6-91E6-A08E94605404} => pcalua.exe -a C:\Downloads\JavaRa\JavaRa.exe -d C:\Downloads\JavaRa
            Task: {A340BD43-ADF2-40C8-973E-2B761B71C336} - System32\Tasks\{E070B345-71E6-40B6-B67C-E5E15C72506C} => pcalua.exe -a C:\Users\Marco\Downloads\Programs\FileInternet297_ALL.exe -d C:\Users\Marco\AppData\Roaming\IDM
            Task: {B891F30E-3144-4BEA-8532-94DAEC0EF6EC} - System32\Tasks\{A3616480-507E-4F82-B3E7-9890FB99A7FC} => pcalua.exe -a E:\Utility\oem\OEMSETUP.EXE -d E:\Utility\oem
            Task: {BB5C9905-863B-4262-9B03-BAE445722A28} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
            Task: {BFC6295F-521A-4DD8-8725-35B399C20BCA} - System32\Tasks\{5181E2DA-A9A2-40D7-B430-C237837B0CBF} => pcalua.exe -a "G:\Alice MOBILE E169\Setup.exe" -d "G:\Alice MOBILE E169"
            Task: {C935C2EA-C3E1-45DA-B5A9-239D6413B18D} - System32\Tasks\{430B9F8B-41D9-47D6-B353-8FA97F5EC41D} => pcalua.exe -a G:\DataCard_Setup.exe -d G:\
            Task: {CC2864F4-914F-429E-A619-77455BE5EC3E} - System32\Tasks\{AC48D273-25E1-4B48-A02E-752895342551} => pcalua.exe -a C:\Users\Marco\Downloads\Adaware_Installer.exe -d C:\Users\Marco\Downloads
            Task: {CC7E475F-C850-4B25-ACEF-CDD11BBA37E2} - System32\Tasks\{CAB04F14-8D9A-4184-AD18-1D6C282DC6EB} => C:\Corel\Draw70\programs\photopnt.exe
            Task: {CE056A31-1B02-4BD9-82D0-6BF77A020900} - System32\Tasks\{39990666-AFFE-47CF-9FB3-F8C0AA96CDCA} => C:\Corel\Draw70\programs\photopnt.exe
            Task: {D0C0E802-98D1-4274-8A24-D773D3A00D75} - System32\Tasks\{5A25ECBD-0B9B-411F-BC7D-5A6B3BA0F7D7} => C:\Corel\Draw701\programs\photopnt.exe
            Task: {D54B238F-5953-460D-88E0-B8048E3132D7} - System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
            Task: {D64568DF-23EA-4B48-B558-8078C1D33660} - System32\Tasks\{F635ADB3-1AD0-4DB6-9D4A-AF79A638483D} => D:\Corel\Draw70\programs\photopnt.exe
            Task: {D9321925-6B97-4A7D-AE9B-D14B82AB743B} - System32\Tasks\{C1FCF6FF-C6B1-4CE4-A4E8-602EDF5B3CDA} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {DCE67E6D-44BA-4C0A-AD11-A23973613C28} - System32\Tasks\{C9183C48-D1F3-43DF-94DC-905BC79BFC7F} => D:\D\DOOM.EXE
            Task: {DCEAEDD8-71FA-4EE3-89A0-4249E42BB92D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
            Task: {E82171A9-FF80-4C2F-B235-8E8ECA4BC5AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
            Task: {ED600DD3-3408-418D-94EE-2D47E8BED7AB} - System32\Tasks\{228862AD-F5BD-40E3-9F7B-0FE46B8AE765} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {EDD2851A-7AC1-44BE-9308-D48A44C2F757} - System32\Tasks\{341FE709-8AFB-4377-9D6D-7344EF71CD9C} => pcalua.exe -a "C:\Program Files\Alice MOBILE E169\uninst.exe"
            Task: {F299C7D5-4579-40CB-8652-C2D6F6B189D9} - System32\Tasks\{AC32368B-2CCF-4FDA-B77C-777AB7ED0781} => D:\Corel\Draw70\programs\photopnt.exe
            Task: {F5606013-9B0D-40FB-AD90-4B22291BE6F8} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)

            (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

            Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

            ==================== Loaded Modules (whitelisted) ==============

            2014-12-23 17:54 - 2014-12-23 17:54 - 01272616 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\kpcengine.2.3.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00270040 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\UiLogic.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00229080 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\diskmgr.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00278232 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Comn.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00077528 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Ldm.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00061144 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Device.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00265944 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrFat.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00384728 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrNtfs.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00118488 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FuncLogic.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00241368 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Clone.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00343768 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\ImgFile.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00028376 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Encrypt.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00073432 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Compress.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrVol.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00253656 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\GptBcd.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00151256 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FlBackup.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00483032 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\EnumFolder.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Backup.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00098008 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrLog.dll
            2015-01-15 00:12 - 2013-01-17 18:38 - 02403504 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\QtCore4.dll
            2010-05-24 12:09 - 2010-05-24 12:09 - 00091992 _____ () C:\Program Files\Microsoft Office\Office10\OUTLCTL.DLL
            2014-12-23 17:54 - 2014-12-23 17:54 - 00502056 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]\npcontentblocker.dll
            2014-12-23 17:54 - 2014-12-23 17:54 - 00338216 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]\nponlinebanking.dll
            2014-12-23 17:54 - 2014-12-23 17:54 - 00608040 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]\npvkplugin.dll

            ==================== Alternate Data Streams (whitelisted) =========

            (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

            AlternateDataStreams: C:\ProgramData\TEMP:373E1720
            AlternateDataStreams: C:\ProgramData\TEMP:4CF8D17E

            ==================== Safe Mode (whitelisted) ===================

            (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

            ==================== EXE Association (whitelisted) ===============

            (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


            ==================== Internet Explorer trusted/restricted ===============

            (If an entry is included in the fixlist, the associated entry will be removed from the registry.)

            IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
            IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
            IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
            IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
            IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
            IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
            IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
            IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
            IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
            IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
            IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
            IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
            IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
            IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
            IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
            IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
            IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
            IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
            IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
            IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

            There are 7794 more restricted sites.

            ==================== Other Areas ============================

            (Currently there is no automatic fix for this section.)

            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: 192.168.0.1

            ==================== MSCONFIG/TASK MANAGER disabled items ==

            (Currently there is no automatic fix for this section.)

            MSCONFIG\Services: !SASCORE => 2
            MSCONFIG\Services: AdobeARMservice => 2
            MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
            MSCONFIG\Services: AdvancedSystemCareService7 => 2
            MSCONFIG\Services: Apple Mobile Device => 2
            MSCONFIG\Services: Bonjour Service => 2
            MSCONFIG\Services: CGVPNCliService => 2
            MSCONFIG\Services: CSObjectsSrv => 2
            MSCONFIG\Services: GoToAssist => 3
            MSCONFIG\Services: gupdate => 2
            MSCONFIG\Services: gupdatem => 3
            MSCONFIG\Services: Intelliservice => 2
            MSCONFIG\Services: iPod Service => 3
            MSCONFIG\Services: MozillaMaintenance => 3
            MSCONFIG\Services: PDF Architect 2 => 3
            MSCONFIG\Services: pdfforge CrashHandler => 3
            MSCONFIG\Services: PSI_SVC_2 => 2
            MSCONFIG\Services: SCardSvr => 3
            MSCONFIG\Services: ServiceLayer => 3
            MSCONFIG\Services: SkypeUpdate => 2
            MSCONFIG\Services: TomTomHOMEService => 2
            MSCONFIG\Services: WGEGyK => 2
            MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
            MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
            MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
            MSCONFIG\startupreg: Advanced SystemCare 7 => "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
            MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
            MSCONFIG\startupreg: BlazeServoTool => "C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
            MSCONFIG\startupreg: CloneCDTray => "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
            MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart /min
            MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
            MSCONFIG\startupreg: IDMan => C:\Program Files\Internet Download Manager\IDMan.exe /onboot
            MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
            MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
            MSCONFIG\startupreg: McAfee McItInfo => C:\Users\Marco\AppData\Local\Temp\mcitinfo_1383311069.exe /itinsfin:C:\Users\Marco\AppData\Local\Temp\mcininfo_1383311069.ini
            MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
            MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
            MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
            MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
            MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            MSCONFIG\startupreg: TBHostSupport => "C:\Windows\system32\Rundll32.exe" "C:\Users\Marco\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
            MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"

            ==================== FirewallRules (whitelisted) ===============

            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

            FirewallRules: [{0E499E8F-2CC2-492B-B6E3-DE6571FF9795}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{B01FAA7A-14A0-4104-9BA3-A0C0AECB340D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{ADC8BB10-533C-46BF-828A-6034C271B805}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
            FirewallRules: [{032E0385-BD9B-4F35-B22E-A1C73A91F3FC}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
            FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
            FirewallRules: [{44718332-C76D-4FAC-8FC1-2E8BC5726C68}] => (Allow) C:\Program Files\iTunes\iTunes.exe
            FirewallRules: [{6B609089-96E1-4411-AF63-17C8E30F8837}] => (Allow) C:\Program Files\AOMEI Backupper Standard Edition 2.2\PxeUi.exe
            FirewallRules: [{F2573A31-B37D-4F9F-9FD1-87FF78181875}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
            FirewallRules: [{F6CCA513-7672-4CF2-91D3-4FFD5446DE2A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
            FirewallRules: [{A8125B2D-38FE-4526-A175-F0F0C8A6535F}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

            ==================== Faulty Device Manager Devices =============


            ==================== Event log errors: =========================

            Application errors:
            ==================
            Error: (04/28/2015 09:19:58 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/28/2015 00:12:39 AM) (Source: Application Error) (EventID: 1005) (User: )
            Description: Impossibile accedere al file C:\Windows\System32\adtschema.dll per uno dei motivi seguenti:
            Si è verificato un problema relativo alla connessione di rete, al disco in cui è archiviato il file o ai driver
            di archiviazione installati nel computer oppure il disco è assente.
            Il programma Processo host per servizi di Windows è stato chiuso a causa dell'errore.

            Programma: Processo host per servizi di Windows
            File: C:\Windows\System32\adtschema.dll

            Il valore dell'errore è indicato nella sezione Dati aggiuntivi.
            Azione utente
            1. Aprire nuovamente il file.
            Potrebbe trattarsi di un problema temporaneo che si risolverà automaticamente rieseguendo il programma.
            2.
            Se il file risulta comunque non accessibile e:
                - Si trova in rete,
            è necessario che l'amministratore della rete verifichi la presenza di eventuali problemi di rete e che sia possibile contattare il server.
                - Si trova in un disco rimovibile, ad esempio un disco floppy o un CD, verificare che il disco sia inserito correttamente nel computer.
            3. Controllare e ripristinare il file system eseguendo CHKDSK. Per eseguire CHKDSK, fare clic sul pulsante Start, scegliere Esegui, digitare CMD, quindi scegliere OK. Al prompt dei comandi, digitare CHKDSK /F, quindi premere INVIO.
            4. Se il problema persiste, ripristinare il file da una copia di backup.
            5. Determinare se è possibile aprire altri file nello stesso disco. Se non è possibile, il disco potrebbe essere danneggiato. Se si tratta di un disco rigido, contattare l'amministratore o il fornitore dell'hardware
            del computer per ottenere assistenza.

            Dati aggiuntivi
            Valore errore: C0000185
            Tipo disco: 3

            Error: (04/28/2015 00:12:32 AM) (Source: Application Error) (EventID: 1000) (User: )
            Description: Nome dell'applicazione che ha generato l'errore: svchost.exe_eventlog, versione: 6.1.7600.16385, timestamp: 0x4a5bc100
            Nome del modulo che ha generato l'errore: wevtsvc.dll, versione: 6.1.7601.17514, timestamp: 0x4ce7ba2e
            Codice eccezione: 0xc0000006
            Offset errore 0x00011c21
            ID processo che ha generato l'errore: 0x3a4
            Ora di avvio dell'applicazione che ha generato l'errore: 0xsvchost.exe_eventlog0
            Percorso dell'applicazione che ha generato l'errore: svchost.exe_eventlog1
            Percorso del modulo che ha generato l'errore: svchost.exe_eventlog2
            ID segnalazione: svchost.exe_eventlog3

            Error: (04/27/2015 11:01:51 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/27/2015 10:39:17 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 09:33:43 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 01:12:53 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 01:10:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
            Description: Il programma BlazeHDTV.exe versione 1.0.0.1 non interagisce più con Windows ed è stato chiuso. Per vedere se sono disponibili ulteriori informazioni sul problema, verificare la cronologia del problema in Centro operativo nel Pannello di controllo.

            ID processo: 14d8

            Ora di avvio: 01d0800731266d7c

            Ora di chiusura: 60000

            Percorso applicazione: C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.exe

            ID segnalazione: 999ffb4a-ec04-11e4-8084-001d72e8ab06

            Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
            Description: Impossibile completare il backup a causa di un errore durante la scrittura nel percorso di backup G:\. Errore: Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006).


            System errors:
            =============
            Error: (04/29/2015 09:37:56 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
            Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio ShellHWDetection.

            Error: (04/29/2015 09:33:52 PM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
            Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)

            Error: (04/29/2015 09:33:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
            Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
            %%1058

            Error: (04/29/2015 09:33:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
            %%2

            Error: (04/28/2015 10:08:40 PM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
            Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)

            Error: (04/28/2015 10:08:35 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
            Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
            %%1058

            Error: (04/28/2015 10:08:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
            %%2

            Error: (04/28/2015 09:19:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: Il servizio lwnfd_1_10_0_14 non è stato avviato per il seguente errore:
            %%2

            Error: (04/28/2015 09:19:58 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
            Description: All'avvio non è stato possibile caricare i seguenti driver:
            lwnfd_1_10_0_14

            Error: (04/28/2015 09:19:34 PM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
            Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)


            Microsoft Office Sessions:
            =========================
            Error: (04/28/2015 09:19:58 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/28/2015 00:12:39 AM) (Source: Application Error) (EventID: 1005) (User: )
            Description: C:\Windows\System32\adtschema.dllProcesso host per servizi di WindowsC00001853

            Error: (04/28/2015 00:12:32 AM) (Source: Application Error) (EventID: 1000) (User: )
            Description: svchost.exe_eventlog6.1.7600.163854a5bc100wevtsvc.dll6.1.7601.175144ce7ba2ec000000600011c213a401d0812d446cab68C:\Windows\System32\svchost.exec:\windows\system32\wevtsvc.dll7fc592ba-ed2a-11e4-b7ae-001d72e8ab06

            Error: (04/27/2015 11:01:51 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/27/2015 10:39:17 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 09:33:43 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 01:12:53 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 01:10:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
            Description: BlazeHDTV.exe1.0.0.114d801d0800731266d7c60000C:\Program Files\BlazeVideo\BlazeDTV 6.0\BlazeHDTV.exe999ffb4a-ec04-11e4-8084-001d72e8ab06

            Error: (04/26/2015 04:33:54 AM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/25/2015 11:00:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
            Description: G:\Percorso di backup non trovato o non valido. Verificare le impostazioni di backup e controllare il percorso di backup. (0x81000006)


            CodeIntegrity Errors:
            ===================================
              Date: 2015-03-10 00:07:34.988
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-10 00:07:34.976
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-10 00:07:34.976
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-10 00:07:34.916
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-10 00:07:34.906
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-10 00:07:34.906
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-09 23:36:43.482
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-09 23:36:43.472
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-09 23:36:43.422
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.

              Date: 2015-03-09 23:36:43.402
              Description: Controllo dell'integrità del codice: impossibile verificare l'integrità dell'immagine del file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\KLELAMX86\klelam.sys. Impossibile trovare l'insieme di hash dell'immagine per pagina nel sistema.


            ==================== Memory info ===========================

            Processor: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
            Percentage of memory in use: 55%
            Total physical RAM: 3000.86 MB
            Available physical RAM: 1347.3 MB
            Total Pagefile: 6000.02 MB
            Available Pagefile: 4059.87 MB
            Total Virtual: 2047.88 MB
            Available Virtual: 1907.66 MB

            ==================== Drives ================================

            Drive c: (ACER) (Fixed) (Total:228.01 GB) (Free:51.02 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
            Drive d: (DATA) (Fixed) (Total:227.98 GB) (Free:72.54 GB) NTFS
            Drive e: (DGN1000v3) (CDROM) (Total:0.06 GB) (Free:0 GB) CDFS
            Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:1.35 GB) FAT32
            Drive l: () (Fixed) (Total:149.93 GB) (Free:1.81 GB) FAT32

            ==================== MBR & Partition Table ==================

            ========================================================
            Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: B0387136)
            Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
            Partition 2: (Active) - (Size=228 GB) - (Type=07 NTFS)
            Partition 3: (Not Active) - (Size=228 GB) - (Type=07 NTFS)

            ==================== End Of Log ============================

            A few things to go over

             

            IObit
             
            I want to give you a heads up on IObit , its a program from China and not recommended. The Chinese company behind this product was found to be stealing Malwarebytes database. I would like you to uninstall it as there are better program out there,   why use one from from a questional company with unethical business practices.
             
            http://blogs.computerworld.com/15026/iobit_accused_of_stealing_from_malwarebytes
             
             
            ===========================================================
             
            weDownload Manager
             
            This program is also not recommended, after you run the fix see if you can uninstall it
             
             
             
            ===========================================================
             
            You have a few discrepancies with Internet Explorer, lets set it back to default

            •  
            • Open IE
            • Go to Tools> Internet Options > Advanced Tab
            • Reset Internet Explorer Setting
            • Reset
            • This will take a few seconds
            • Close IE and then reopen it 
             
             
            ===========================================================
             
             
            I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST or the fix wont work, use your mouse to drag FIXLIST right next to FRST, either above or below it but not right on top of it, after its downloaded open up FRST and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know if there has been any improvement with your system.

            Attachments:

            Hi Ken,

            1) I have completed your suggestion with the exception on IoBit unistalling. The reason is that I am non able to do it, Iobit does not appear in windows unistall programm list how can unistall it ?

            2) The system now looks running better. Firefox now is working

            3)The only problem that i have is that very oftem Mozilla show the message tha a script of the webpage is buisy or blocked and I have to block it to coninue surfing.

            Thaks again for your help and let me know if there is any additional task

             

            Here attachet FRST Fixlog

            C:\ProgramData\sysqcl1129067056.dat
            weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION
            Task: {1217E9D3-8939-4DCA-B835-08A6B3F9D25D} - System32\Tasks\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40} => C:\Users\Marco\Desktop\installspeedfan447.exe [2013-03-17] () <==== ATTENTION
            Task: {5BCFC431-3B77-4BC1-BFA7-B699A44258FC} - System32\Tasks\{90112C02-23E4-42FE-8F5D-97299A848050} => pcalua.exe -a "C:\Program Files\weDownload Manager\Uninstall.exe" -c /fromcontrolpan
            CMD: ipconfig /flushdns
            Hosts:
            EmptyTemp:
            End










            *****************

            Processes closed successfully.
            Restore point was successfully created.
            HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
            C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\fdubo8yh.Marco\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi => Moved successfully.
            Chrome StartupUrls deleted successfully.
            C:\ProgramData\sysqcl1129067056.dat => Moved successfully.
            weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION => Error: No automatic fix found for this entry.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1217E9D3-8939-4DCA-B835-08A6B3F9D25D}" => Key deleted successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1217E9D3-8939-4DCA-B835-08A6B3F9D25D}" => Key deleted successfully.
            C:\Windows\System32\Tasks\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40} => Moved successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2533C84E-4B4C-458A-9B9B-7F6E8CF2DF40}" => Key deleted successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5BCFC431-3B77-4BC1-BFA7-B699A44258FC}" => Key deleted successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BCFC431-3B77-4BC1-BFA7-B699A44258FC}" => Key deleted successfully.
            C:\Windows\System32\Tasks\{90112C02-23E4-42FE-8F5D-97299A848050} => Moved successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{90112C02-23E4-42FE-8F5D-97299A848050}" => Key deleted successfully.

            =========  ipconfig /flushdns =========


            Configurazione IP di Windows

            Cache del resolver DNS svuotata.

            ========= End of CMD: =========

            "C:\Windows\System32\Drivers\etc\hosts" => Could not move.
            Could not reset Hosts.
            EmptyTemp: => Removed 680.2 MB temporary data.


            The system needed a reboot.

            ==== End

            Lets set Firefox back to default as well

             

            •  
            • Open Firefox
            • Click on Help > Troubleshooting Information > Reset Firefox to its default state
             
             
             
            Then reboot your system, open up FRST, make sure to checkmark Additions and run a new scan and post both new logs please, you can delete the older FRST logs on your desktop so as not to get them confused with the new ones

            Ok Firefox reset done

            Her FRST logs

            Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2015 01
            Ran by [removed] (administrator) on MARCO-PC on 02-05-2015 16:03:56
            Running from C:\Users\[removed]\Desktop
            [removed] Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Italiano (Italia)
            Internet Explorer Version 11 (Default browser: FF)
            Boot Mode: Normal
            Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

            ==================== Processes (Whitelisted) =================

            (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

            (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe
            (AOMEI Tech Co., Ltd.) C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe
            (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
            (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
            (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
            (PGP Corporation) C:\Windows\System32\PGPserv.exe
            (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
            (Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe
            (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
            (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
            (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe
            (Microsoft Corporation) C:\Windows\System32\dllhost.exe
            (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\wmi32.exe


            ==================== Registry (Whitelisted) ==================

            (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

            Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\896\G2AWinLogon.dll [2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation)
            Lsa: [Notification Packages] scecli PGPpwflt
            ShellIconOverlayIdentifiers: [IconOverlayHandlerAccessible] -> {3DBF5F01-3287-46EB-82CF-45AA5C241162} => C:\Windows\system32\PGPfsshl.dll [2010-04-01] (PGP Corporation)
            GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

            ==================== Internet (Whitelisted) ====================

            (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
            HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
            BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09] (Oracle Corporation)
            BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
            BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
            BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09] (Oracle Corporation)
            DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
            Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Windows\system32\Msdxm6.ocx [2000-04-21] (Microsoft Corporation)
            ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
            Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
            Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 [removed] [removed]

            FireFox:
            ========
            FF ProfilePath: C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox
            FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-12] ()
            FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
            FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
            FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-09] (Oracle Corporation)
            FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-09] (Oracle Corporation)
            FF Plugin: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
            FF Plugin: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
            FF Plugin: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24] ()
            FF Plugin: @microsoft.com/GENUINE -> disabled No File
            FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
            FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
            FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
            FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
            FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
            FF Plugin: PDF Architect 2 -> C:\Program Files\PDF Architect 2\np-previewer.dll [2014-06-26] (pdfforge GmbH)
            FF user.js: detected! => C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox\user.js [2015-05-02]
            FF user.js: detected! => C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\user.js [2015-05-02]
            FF user.js: detected! => C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\xosco58r.default-1430575142942\user.js [2015-05-02]
            FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\golliver.xml [2015-04-25]
            FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2014-05-18]
            FF Extension: Golliver - C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-4094248773-42424133-2592686105-1000\FireFox\Extensions\[removed] [2015-04-25]
            FF Extension: Golliver - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\uygrla6u.default-1426711383616\Extensions\[removed] [2015-04-25]
            FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
            FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
            FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
            FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
            FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]
            FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed]
            FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\[removed] [2015-02-24]

            Chrome:
            =======
            CHR Profile: C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default
            CHR Extension: (Kaspersky Protection) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-04-15]
            CHR Extension: (Bookmark Manager) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-01]
            CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-01]
            CHR Extension: (Skype Click to Call) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-05-01]
            CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-15]
            CHR HKLM\…\Chrome\Extension: [bollbfeakabenkobaocgakdibphdnanj] - http://clients2.google.com/service/update2/crx
            CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
            CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
            CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [Not Found]

            ========================== Services (Whitelisted) =================

            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

            S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-17] (SUPERAntiSpyware.com)
            R2 AVP15.0.2; C:\Program Files\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [193400 2014-12-23] (Kaspersky Lab ZAO)
            R2 Backupper Service; C:\Program Files\AOMEI Backupper Standard Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
            R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
            R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
            S3 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64616 2014-11-03] (CyberGhost S.R.L)
            S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\896\g2aservice.exe [13720 2013-11-03] (Citrix Online, a division of Citrix Systems, Inc.)
            S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
            S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
            S4 PDF Architect 2; C:\Program Files\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
            S4 pdfforge CrashHandler; C:\Program Files\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
            R2 PGPserv; C:\Windows\system32\PGPserv.exe [135288 2010-04-01] (PGP Corporation)
            S2 uzsvc; C:\Program Files\UltraZip\uzsvc.exe [531744 2015-03-10] ()
            S2 uzupd; C:\Program Files\UltraZip\uzupd.exe [44312 2015-03-10] ()
            R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
            S2 asl; "C:\ProgramData\Service\Application\asl.exe" [X]

            ==================== Drivers (Whitelisted) ====================

            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

            R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [26424 2013-05-07] () [File not signed]
            R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [129720 2013-05-07] () [File not signed]
            R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [14392 2013-02-06] () [File not signed]
            S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
            R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [189136 2013-01-14] (Kaspersky Lab UK Ltd)
            R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
            S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [94336 2014-12-19] (ITE                      )
            R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [143968 2014-03-31] (Kaspersky Lab ZAO)
            R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46280 2015-03-27] (Kaspersky Lab ZAO)
            R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [120008 2014-11-28] (Kaspersky Lab ZAO)
            R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [36040 2014-10-22] (Kaspersky Lab ZAO)
            R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [698568 2015-03-27] (Kaspersky Lab ZAO)
            R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25800 2014-10-10] (Kaspersky Lab ZAO)
            R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [26824 2014-10-30] (Kaspersky Lab ZAO)
            R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO)
            R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
            R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [46152 2014-10-09] (Kaspersky Lab ZAO)
            R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [64200 2014-11-22] (Kaspersky Lab ZAO)
            R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [148296 2014-11-10] (Kaspersky Lab ZAO)
            R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
            S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
            R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
            R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
            R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
            R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
            R3 WsAudio_Device(1); C:\Windows\System32\drivers\VirtualAudio1.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(2); C:\Windows\System32\drivers\VirtualAudio2.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(3); C:\Windows\System32\drivers\VirtualAudio3.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(4); C:\Windows\System32\drivers\VirtualAudio4.sys [27496 2013-01-25] (Wondershare)
            R3 WsAudio_Device(5); C:\Windows\System32\drivers\VirtualAudio5.sys [27496 2013-01-25] (Wondershare)
            R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
            U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
            S3 catchme; \??\C:\Users\Marco\AppData\Local\Temp\catchme.sys [X]
            S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]

            ==================== NetSvcs (Whitelisted) ===================

            (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


            ==================== One Month Created Files and Folders ========

            (If an entry is included in the fixlist, the file\folder will be moved.)

            2015-05-02 16:03 - 2015-05-02 16:05 - 00017348 _____ () C:\Users\Marco\Desktop\FRST.txt
            2015-05-01 10:31 - 2015-05-01 10:31 - 00013824 _____ () C:\Users\Marco\Documents\spesa gab 3004.xls
            2015-04-29 22:54 - 2015-04-29 22:54 - 00000000 ____D () C:\Users\Marco\dwhelper
            2015-04-27 23:25 - 2015-04-27 23:25 - 00002193 _____ () C:\Users\Marco\Desktop\JRT.txt
            2015-04-27 23:10 - 2015-04-27 23:10 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-MARCO-PC-Windows-7-Home-Premium-(32-bit).dat
            2015-04-27 23:10 - 2015-04-27 23:10 - 00000000 ____D () C:\RegBackup
            2015-04-27 23:05 - 2015-04-27 23:05 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Marco\Desktop\mbam-setup-2.1.6.1022.exe
            2015-04-27 23:04 - 2015-04-27 23:04 - 02715845 _____ (Thisisu) C:\Users\Marco\Desktop\JRT.exe
            2015-04-27 22:48 - 2015-04-27 22:48 - 02224640 _____ () C:\Users\Marco\Desktop\adwcleaner_4.202.exe
            2015-04-27 22:47 - 2015-04-27 22:47 - 01140736 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe
            2015-04-27 22:47 - 2015-04-27 22:47 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion
            2015-04-26 04:33 - 2015-04-26 04:33 - 278896405 _____ () C:\Windows\MEMORY.DMP
            2015-04-26 04:33 - 2015-04-26 04:33 - 00158560 _____ () C:\Windows\Minidump\042615-19874-01.dmp
            2015-04-25 15:37 - 2015-04-25 15:37 - 00000137 _____ () C:\Users\Marco\Documents\gabriella.txt
            2015-04-25 07:31 - 2015-05-02 16:04 - 00000000 ____D () C:\FRST
            2015-04-25 07:14 - 2015-04-25 07:14 - 00002928 _____ () C:\Users\Marco\Documents\aswMBR.txt
            2015-04-25 07:14 - 2015-04-25 07:14 - 00000512 _____ () C:\Users\Marco\Documents\MBR.dat
            2015-04-25 06:26 - 2015-04-25 06:27 - 00000000 ____D () C:\Users\Marco\AppData\Local\nida
            2015-04-25 06:05 - 2015-04-25 06:27 - 00000000 ___SD () C:\32788R22FWJFW
            2015-04-25 06:04 - 2015-04-25 06:04 - 00000000 ____D () C:\ProgramData\UltraZip
            2015-04-25 06:03 - 2015-04-25 17:52 - 00000000 ____D () C:\Program Files\UltraZip
            2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Service
            2015-04-25 06:03 - 2015-04-25 06:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraZip
            2015-04-25 06:02 - 2015-04-25 06:06 - 05619466 ____R (Swearware) C:\Users\Marco\Downloads\combofix [1].exe
            2015-04-25 05:53 - 2015-05-02 16:02 - 00001120 _____ () C:\Windows\setupact.log
            2015-04-25 05:53 - 2015-04-30 05:59 - 00327154 _____ () C:\Windows\PFRO.log
            2015-04-25 05:53 - 2015-04-25 05:53 - 00000000 _____ () C:\Windows\setuperr.log
            2015-04-25 05:48 - 2015-04-25 05:48 - 00156898 _____ () C:\Users\Marco\Documents\cc_20150425_054751.reg
            2015-04-19 06:56 - 2015-04-19 07:49 - 370938816 _____ () C:\Users\Marco\Downloads\0d6b8d7ca1.mp4.rar.part
            2015-04-18 13:13 - 2015-04-18 17:27 - 742534663 _____ () C:\Users\Marco\Downloads\Cazzo.Grosso.Ma.Non.Troppo.Foreign.S.E.rar.part
            2015-04-18 11:10 - 2015-04-18 11:35 - 105298398 _____ () C:\Users\Marco\Downloads\Dana Moravova _ Milada.avi.part
            2015-04-18 07:02 - 2015-04-18 07:26 - 175777135 _____ () C:\Users\Marco\Downloads\Brooke_Tyler_-_shutup_and_blow_airport_hd.mp4
            2015-04-14 21:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
            2015-04-14 21:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
            2015-04-14 21:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
            2015-04-14 21:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
            2015-04-14 21:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
            2015-04-14 21:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
            2015-04-14 21:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
            2015-04-14 21:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
            2015-04-14 21:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
            2015-04-14 21:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
            2015-04-14 21:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
            2015-04-14 21:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
            2015-04-14 21:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
            2015-04-14 21:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
            2015-04-14 21:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
            2015-04-14 21:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
            2015-04-14 21:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
            2015-04-14 21:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
            2015-04-14 21:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
            2015-04-14 21:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
            2015-04-14 21:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
            2015-04-14 21:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
            2015-04-14 21:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
            2015-04-14 21:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
            2015-04-14 21:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
            2015-04-14 21:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
            2015-04-14 21:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
            2015-04-14 21:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
            2015-04-14 21:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
            2015-04-14 21:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
            2015-04-14 21:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
            2015-04-14 21:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
            2015-04-14 21:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
            2015-04-14 21:40 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
            2015-04-14 21:40 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
            2015-04-14 21:40 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
            2015-04-14 21:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
            2015-04-14 21:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
            2015-04-14 21:40 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
            2015-04-14 21:40 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
            2015-04-14 21:40 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
            2015-04-14 21:40 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
            2015-04-14 21:40 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
            2015-04-14 21:40 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
            2015-04-14 21:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
            2015-04-14 21:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
            2015-04-14 21:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
            2015-04-14 21:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
            2015-04-14 21:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
            2015-04-14 21:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
            2015-04-14 21:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
            2015-04-14 21:40 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
            2015-04-14 21:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
            2015-04-14 21:39 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
            2015-04-14 21:39 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
            2015-04-11 10:13 - 2015-04-26 10:02 - 00000000 ____D () C:\Users\Marco\olimpus
            2015-04-05 08:25 - 2015-04-05 08:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\RenPy
            2015-04-05 07:20 - 2015-04-05 08:01 - 244140767 _____ () C:\Users\Marco\Downloads\wbc-1.0-all.rar
            2015-04-05 06:59 - 2015-04-05 06:59 - 00000000 ____D () C:\Users\Marco\Tracing
            2015-04-05 05:44 - 2015-04-05 05:44 - 00000000 ___SD () C:\Windows\system32\GWX
            2015-04-04 10:26 - 2015-04-04 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\slac
            2015-04-04 10:23 - 2015-04-04 10:23 - 00000000 ____D () C:\Program Files\slac
            2015-04-04 08:16 - 2015-04-04 08:16 - 00000000 ____D () C:\Program Files\Common Files\Protexis
            2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\Users\Public\Desktop\Corel PaintShop Pro X5.lnk
            2015-04-04 08:15 - 2015-04-04 09:45 - 00001024 _____ () C:\ProgramData\Desktop\Corel PaintShop Pro X5.lnk
            2015-04-04 08:15 - 2015-04-04 09:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X5
            2015-04-03 08:13 - 2015-04-03 08:13 - 09629976 _____ (CyberGhost S.R.L. ) C:\Users\Marco\Downloads\CG_5.0.14.7.exe

            ==================== One Month Modified Files and Folders =======

            (If an entry is included in the fixlist, the file\folder will be moved.)

            2015-05-02 16:03 - 2014-05-22 06:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
            2015-05-02 16:02 - 2013-11-04 23:19 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
            2015-05-02 16:02 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
            2015-05-02 16:01 - 2013-11-01 09:59 - 02079951 _____ () C:\Windows\WindowsUpdate.log
            2015-05-02 15:59 - 2014-06-26 21:27 - 00000000 ____D () C:\Users\Marco\Desktop\Dati precedenti di Firefox
            2015-05-02 15:49 - 2013-03-05 23:43 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
            2015-05-02 15:44 - 2013-03-05 18:20 - 01786646 _____ () C:\Windows\system32\PerfStringBackup.INI
            2015-05-02 15:44 - 2009-07-14 10:21 - 00791368 _____ () C:\Windows\system32\perfh010.dat
            2015-05-02 15:44 - 2009-07-14 10:21 - 00164498 _____ () C:\Windows\system32\perfc010.dat
            2015-05-02 15:38 - 2013-11-04 23:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
            2015-05-02 14:09 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
            2015-05-02 14:09 - 2009-07-14 06:34 - 00022576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
            2015-05-01 10:53 - 2013-03-21 22:54 - 00000000 ____D () C:\Users\Marco\AppData\Local\CrashDumps
            2015-05-01 09:12 - 2013-03-08 00:39 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc
            2015-04-30 03:18 - 2013-11-04 23:23 - 00002091 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
            2015-04-30 03:18 - 2013-11-04 23:23 - 00002091 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
            2015-04-29 22:54 - 2013-03-05 18:23 - 00000000 ____D () C:\Users\Marco
            2015-04-29 21:33 - 2014-05-23 06:31 - 00000000 ____D () C:\Program Files\Internet Download Manager
            2015-04-28 22:27 - 2014-05-21 22:11 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
            2015-04-28 22:06 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\DMCache
            2015-04-27 23:27 - 2014-05-21 22:11 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
            2015-04-27 23:27 - 2014-05-21 22:11 - 00001024 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
            2015-04-27 23:27 - 2014-05-21 22:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
            2015-04-27 23:27 - 2014-05-21 22:10 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
            2015-04-27 22:59 - 2013-09-27 10:01 - 00000000 ____D () C:\AdwCleaner
            2015-04-26 04:33 - 2013-07-12 04:50 - 00000000 ____D () C:\Windows\Minidump
            2015-04-25 17:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\PLA
            2015-04-25 16:10 - 2014-05-23 06:32 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\IDM
            2015-04-25 08:30 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
            2015-04-25 05:45 - 2014-09-08 18:30 - 00000000 ____D () C:\Program Files\PDFCreator
            2015-04-25 05:43 - 2013-03-05 17:42 - 00000000 ____D () C:\Windows\Panther
            2015-04-24 18:42 - 2013-03-05 20:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
            2015-04-24 06:25 - 2014-12-11 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox
            2015-04-24 06:25 - 2013-03-17 10:18 - 00000000 ____D () C:\Program Files\SpeedFan
            2015-04-16 01:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
            2015-04-16 01:35 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
            2015-04-14 23:56 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
            2015-04-14 22:33 - 2014-12-10 07:47 - 00000000 ____D () C:\Windows\system32\appraiser
            2015-04-14 22:33 - 2014-05-01 08:15 - 00000000 ___SD () C:\Windows\system32\CompatTel
            2015-04-14 22:33 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT
            2015-04-14 22:10 - 2013-08-14 09:55 - 00000000 ____D () C:\Windows\system32\MRT
            2015-04-14 21:55 - 2013-03-10 07:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
            2015-04-14 09:37 - 2014-05-21 22:10 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
            2015-04-14 09:37 - 2014-05-21 22:10 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
            2015-04-14 09:37 - 2014-05-21 22:10 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
            2015-04-12 17:25 - 2014-06-24 21:39 - 00000000 ____D () C:\Users\Marco\AppData\Local\Adobe
            2015-04-12 17:25 - 2013-03-05 23:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
            2015-04-12 17:25 - 2013-03-05 23:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
            2015-04-07 21:42 - 2014-12-20 17:59 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
            2015-04-05 07:01 - 2014-08-05 21:03 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\Skype
            2015-04-05 06:59 - 2014-08-05 21:02 - 00000000 ___RD () C:\Program Files\Skype
            2015-04-05 06:58 - 2014-08-05 21:02 - 00000000 ____D () C:\ProgramData\Skype
            2015-04-04 10:26 - 2013-03-06 00:34 - 00023392 _____ () C:\Windows\system32\nscompat.tlb
            2015-04-04 08:17 - 2013-03-12 07:21 - 00000000 ____D () C:\ProgramData\Corel
            2015-04-04 08:13 - 2013-03-12 07:16 - 00000000 ____D () C:\Program Files\Corel
            2015-04-04 08:05 - 2015-02-16 21:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Last_Man
            2015-04-03 09:08 - 2014-04-23 05:10 - 00001845 _____ () C:\Users\Marco\Desktop\CyberGhost 5.lnk
            2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
            2015-04-03 09:08 - 2014-04-23 05:10 - 00000000 ____D () C:\Program Files\CyberGhost 5

            ==================== Files in the root of some directories =======

            2013-03-12 07:27 - 2013-03-12 07:27 - 0003584 _____ () C:\Users\Marco\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
            2013-05-23 06:57 - 2013-05-23 06:59 - 0007602 _____ () C:\Users\Marco\AppData\Local\resmon.resmoncfg
            2014-04-21 10:30 - 2014-04-21 10:30 - 0000041 ___SH () C:\ProgramData\.zreglib
            2014-07-31 06:26 - 2014-07-31 06:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

            ==================== Bamital & volsnap Check =================

            (There is no automatic fix for files that do not pass verification.)

            C:\Windows\explorer.exe => File is digitally signed
            C:\Windows\system32\winlogon.exe => File is digitally signed
            C:\Windows\system32\wininit.exe => File is digitally signed
            C:\Windows\system32\svchost.exe => File is digitally signed
            C:\Windows\system32\services.exe => File is digitally signed
            C:\Windows\system32\User32.dll => File is digitally signed
            C:\Windows\system32\userinit.exe => File is digitally signed
            C:\Windows\system32\rpcss.dll => File is digitally signed
            C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


            LastRegBack: 2015-05-01 21:13

            ==================== End Of Log ============================

            Ran by [removed] at 2015-05-02 16:06:16
            Running from C:\Users\[removed]\Desktop
            Boot Mode: Normal
            ==========================================================


            ==================== Accounts: =============================

            Administrator (S-1-5-21-4094248773-42424133-2592686105-500 - Administrator - Disabled)
            Guest (S-1-5-21-4094248773-42424133-2592686105-501 - Limited - Disabled)
            HomeGroupUser$ (S-1-5-21-4094248773-42424133-2592686105-1002 - Limited - Enabled)
            Marco (S-1-5-21-4094248773-42424133-2592686105-1000 - Administrator - Enabled) => C:\Users\Marco

            ==================== Security Center ========================

            (If an entry is included in the fixlist, it will be removed.)

            AV: Kaspersky Total Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
            AS: Kaspersky Total Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
            AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            FW: Kaspersky Total Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

            ==================== Installed Programs ======================

            (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

            Adobe Flash Player 15 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
            Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
            Adobe Reader XI (11.0.10) - Italiano (HKLM\…\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
            Adventure Maker v4.6.1 (build1) (HKLM\…\Adventure Maker v4.6.1_is1) (Version:  - )
            Adventure Maker v4.7.1 (build1) (HKLM\…\Adventure Maker v4.7.1_is1) (Version:  - )
            Aimersoft DRM Media Converter(Build 1.5.5.0) (HKLM\…\Aimersoft DRM Media Converter_is1) (Version:  - Aimersoft Software)
            Alice MOBILE E169 (HKLM\…\Alice MOBILE E169) (Version: 11.002.04.11.192 - Huawei Technologies Co.,Ltd)
            Any Video Converter 5.6.3 (HKLM\…\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
            AOMEI Backupper Standard Edition 2.2 (HKLM\…\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version:  - AOMEI Technology Co., Ltd.)
            Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
            Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
            BlazeDTV 6.0 (HKLM\…\BlazeDTV 6.0_is1) (Version:  - )
            Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
            CCleaner (HKLM\…\CCleaner) (Version: 4.13 - Piriform)
            CDBurnerXP (HKLM\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
            Cinergy T Stick Driver Installation (32 Bit) (HKLM\…\{5123EBB5-0CB1-4EF1-8DF7-A4226537BCDC}) (Version: 8.08.18.01 - Nome società)
            Comic Life 2 (HKLM\…\{A8405D99-9D76-4456-8752-87DA930CC3A3}) (Version: 2.2.5.0 - plasq LLC)
            Core Temp 1.0 RC5 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
            Corel PaintShop Pro X5 (HKLM\…\_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.2.0.12 - Corel Corporation)
            Corel PaintShop Pro X5 (Version: 15.3.0.8 - Corel Corporation) Hidden
            CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
            EPSON Scan (HKLM\…\EPSON Scanner) (Version:  - )
            ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
            F24 On Line (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\F24 On Line) (Version:  - Agenzia delle Entrate)
            File Splitter and Joiner (FFSJ v3.3) (HKLM\…\File Splitter and Joiner_is1) (Version:  - Le Minh Hoang)
            FileInternet (HKLM\…\FileInternet) (Version: 2.9.9.0 - SOGEI)
            Free Video Cutter Joiner 9.8 (HKLM\…\{8C5A4758-C782-4200-B337-DB3466D33ADD}}_is1) (Version: 9.8 - DVDVideoMedia, Inc.)
            Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
            Google Earth (HKLM\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
            Google Update Helper (Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ATTENTION
            Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
            GoToAssist Corporate (HKLM\…\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.)
            HijackThis 2.0.2 (HKLM\…\HijackThis) (Version: 2.0.2 - TrendMicro)
            ICA (Version: 15.2.0.12 - Corel Corporation) Hidden
            iCloud (HKLM\…\{8D9592B4-7E22-4D1F-B2CB-B5F0F2F619CB}) (Version: 4.0.3.56 - Apple Inc.)
            IPM_PSP_COM (Version: 15.2.0.12 - Corel Corporation) Hidden
            iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
            J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)
            Java 8 Update 40 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
            Kaspersky Total Security (HKLM\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
            Kaspersky Total Security (Version: 15.0.2.361 - Kaspersky Lab) Hidden
            Kernel Outlook PST Viewer ver 11.05.01 (HKLM\…\Kernel Outlook PST Viewer_is1) (Version:  - Lepide Software Pvt. Ltd.)
            Last Man (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\Last Man) (Version:  - )
            Malwarebytes Anti-Malware versione 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
            Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
            Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
            Microsoft Office XP Professional (HKLM\…\{91110410-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
            Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
            ModuliControllo2013 (HKLM\…\ModuliControllo2013) (Version: 4.0.0.0 - Sogei S.p.A)
            ModuliControlloUnico2014 (HKLM\…\ModuliControlloUnico2014) (Version: 1.1.1.0 - Sogei S.p.A)
            Mozilla Firefox 37.0.2 (x86 it) (HKLM\…\Mozilla Firefox 37.0.2 (x86 it)) (Version: 37.0.2 - Mozilla)
            Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
            Mozilla Thunderbird 31.6.0 (x86 it) (HKLM\…\Mozilla Thunderbird 31.6.0 (x86 it)) (Version: 31.6.0 - Mozilla)
            MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
            MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
            MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
            MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
            Pacchetto di compatibilità per Office System 2007 (HKLM\…\{90120000-0020-0410-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
            Pacchetto driver Windows - TerraTec  (AF9035BDA) Media  (05/18/2009 8.08.18.01) (HKLM\…\3602780F32D3BB88DB2E972AE797966CC5105334) (Version: 05/18/2009 8.08.18.01 - TerraTec )
            PDF Architect 2 (HKLM\…\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
            PDF Architect 2 View Module (HKLM\…\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
            PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
            PGP Desktop (HKLM\…\{04A8595A-4B2F-4A20-BA5D-E6B371657FF8}) (Version: 10.0.2.13 - PGP Corporation)
            PSPPContent (Version: 15.3.0.8 - Corel Corporation) Hidden
            PSPPHelp (Version: 15.2.0.12 - Corel Corporation) Hidden
            QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
            Recuva (HKLM\…\Recuva) (Version: 1.45 - Piriform)
            Setup (Version: 15.2.0.12 - Nome società) Hidden
            Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
            Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
            Skype™ 7.2 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
            slac (HKLM\…\slac_is1) (Version:  - )
            SpeedFan (remove only) (HKLM\…\SpeedFan) (Version:  - )
            SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1040 - SUPERAntiSpyware.com)
            Supporto applicazioni Apple (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
            TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
            TomTom HOME (HKLM\…\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - Nome società)
            TomTom HOME (HKLM\…\{BB05590A-6602-43F3-A400-77EA0976BC0A}) (Version: 2.9.8 - Nome società)
            TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
            UltraZip (HKLM\…\{5E36886D-AE94-4901-82A6-A96381B7B4AD}_is1) (Version: 2.0.2.6 - UltraZip)
            UnicOnLine PF 2014 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicOnLine PF 2014) (Version:  - Agenzia delle Entrate)
            UnicoOnLine - File Internet 2.9.9 (HKLM\…\File Internet) (Version:  - )
            UnicoOnLine PF 2012 (HKU\S-1-5-21-4094248773-42424133-2592686105-1000\…\UnicoOnLine PF 2012) (Version:  - Agenzia delle Entrate)
            VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
            weDownload Manager (HKLM\…\weDownload Manager) (Version: 1.29.153.0 - weDownload) <==== ATTENTION
            WinOff (HKLM\…\{8049EB00-4F62-44FB-AAF7-CB42F588E3C5}_is1) (Version: 1.0.1.5 - )
            WinPhone (HKLM\…\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version:  - )
            WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
            Wisdom-soft ScreenHunter 6.0 Free (HKLM\…\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
            WriterPad (HKLM\…\{2E4ECAA8-6E82-4502-96BE-48D2DCCFA42A}) (Version: 1.0.0 - North Sky Productions LLC)

            ==================== Custom CLSID (selected items): ==========================

            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-4094248773-42424133-2592686105-1000_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

            ==================== Restore Points  =========================

            25-04-2015 15:17:24 Windows Update
            25-04-2015 16:44:04 Windows Backup
            28-04-2015 21:25:23 Windows Update
            30-04-2015 05:50:08 Restore Point Created by FRST
            01-05-2015 07:46:48 Windows Backup
            01-05-2015 08:21:06 Windows Backup
            02-05-2015 14:08:56 Windows Update

            ==================== Hosts content: ==========================

            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

            2009-07-14 04:04 - 2014-05-21 23:31 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
            127.0.0.1       localhost

            ==================== Scheduled Tasks (whitelisted) =============

            (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

            Task: {09289DFA-8809-4294-AFB9-C9F05351A193} - System32\Tasks\{C8F3C4BF-1DF0-4D46-A1FA-731614A02DA6} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {167C0E59-CF26-45F6-8EF2-BFEC3799BD95} - System32\Tasks\{C250204F-A2AB-4261-B042-B58AEF0116AE} => C:\Corel\Draw701\programs\photopnt.exe
            Task: {19980019-8149-4B71-A0AE-2B1B2C6D5A2A} - System32\Tasks\{3E0476D6-A2AA-4A2B-8F71-50978AD0A832} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {23D073A5-7AA0-47F5-B434-DA0D55C7F3B4} - System32\Tasks\{3CE02DF4-D192-416A-8EE2-8396B8CB6FB4} => C:\photopaint\PHOTOPNT.EXE
            Task: {2A1DD022-029F-4067-B593-016E6960BB35} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
            Task: {2C02D38D-F40F-447C-864B-90DD5FB6253E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
            Task: {334F613A-8EE8-4BD7-ACC3-7FD62264BF03} - System32\Tasks\{02D2332A-A21D-4ABE-BD10-62DD01C4BF11} => pcalua.exe -a C:\corel\SETUP\DAOSETUP.EXE -d C:\corel\SETUP
            Task: {4063D65F-FBE1-4343-AEF3-6C1DCA8671E0} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
            Task: {483CD9A1-6E78-455D-B1E7-30F42C1F03C4} - System32\Tasks\{F6AB3366-2EA1-4C45-8745-C16EE86D334C} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {4CF1CB7B-346F-4195-B187-51DE750A68C8} - System32\Tasks\{DD07A107-F0F4-4746-9D64-C4E23A192425} => C:\Corel\Draw701\programs\photopnt.exe
            Task: {52FBB622-5E59-464A-9911-3B94DF586442} - System32\Tasks\{5A1164C2-B0A7-48D0-84ED-49A59B0570E1} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {6059284D-1243-46AF-B0A0-A10FCE072B4C} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
            Task: {63216F46-D65D-4D30-BD8C-29A29223C00B} - System32\Tasks\{831D7081-34DF-4BD4-BC41-204C3B539114} => D:\Corel\Draw70\programs\photopnt.exe
            Task: {66B33249-6DCB-485A-82F6-A570B2514A45} - System32\Tasks\{4DCA4D6B-3320-4ECC-9D3F-3391A219CE6E} => pcalua.exe -a L:\Compressed\cd_4.8a\CD_4.8A\CDSetup\setup.exe -d L:\Compressed\cd_4.8a\CD_4.8A\CDSetup
            Task: {6D5C45BA-B65B-4FBD-89D0-22CA804D813B} - System32\Tasks\{3FB8CB96-A3C4-4B71-9F07-5FC531C22FFC} => D:\D\DOOM.EXE
            Task: {794EBFAB-B0BC-4768-AE28-A37A4CFF2246} - System32\Tasks\{9C279F5D-7348-4DDB-A492-A91C311E3729} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {7AC1FF86-51CB-476C-A65F-108D684F6A55} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-04] (Google Inc.)
            Task: {7B5D3C19-0CDC-4AEE-8193-4A06B5456EEE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
            Task: {80B2339F-C664-4EA6-8A16-EDE7EA353EE4} - System32\Tasks\{41FE69C8-BF1F-4934-9648-A0A09939AF14} => pcalua.exe -a C:\UnicoOnLine\UNI13\ModuliControllo2013_500.exe -d C:\UnicoOnLine\UNI13
            Task: {91152ABF-40E7-47A4-A9EE-4F582F79205D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-12] (Adobe Systems Incorporated)
            Task: {93D70EB9-D50F-48F3-9D11-D41103D61C3D} - System32\Tasks\{2DB657D7-D3D0-484F-985C-FF894C37A2C0} => pcalua.exe -a C:\UnicoOnLine\MainWinUNI10.exe -d C:\UnicoOnLine
            Task: {99D0E47C-5928-4FF2-83EA-8BAE5279ED61} - System32\Tasks\{D70B1B3A-5B54-49A6-91E6-A08E94605404} => pcalua.exe -a C:\Downloads\JavaRa\JavaRa.exe -d C:\Downloads\JavaRa
            Task: {A340BD43-ADF2-40C8-973E-2B761B71C336} - System32\Tasks\{E070B345-71E6-40B6-B67C-E5E15C72506C} => pcalua.exe -a C:\Users\Marco\Downloads\Programs\FileInternet297_ALL.exe -d C:\Users\Marco\AppData\Roaming\IDM
            Task: {B891F30E-3144-4BEA-8532-94DAEC0EF6EC} - System32\Tasks\{A3616480-507E-4F82-B3E7-9890FB99A7FC} => pcalua.exe -a E:\Utility\oem\OEMSETUP.EXE -d E:\Utility\oem
            Task: {BB5C9905-863B-4262-9B03-BAE445722A28} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
            Task: {BFC6295F-521A-4DD8-8725-35B399C20BCA} - System32\Tasks\{5181E2DA-A9A2-40D7-B430-C237837B0CBF} => pcalua.exe -a "G:\Alice MOBILE E169\Setup.exe" -d "G:\Alice MOBILE E169"
            Task: {C935C2EA-C3E1-45DA-B5A9-239D6413B18D} - System32\Tasks\{430B9F8B-41D9-47D6-B353-8FA97F5EC41D} => pcalua.exe -a G:\DataCard_Setup.exe -d G:\
            Task: {CC2864F4-914F-429E-A619-77455BE5EC3E} - System32\Tasks\{AC48D273-25E1-4B48-A02E-752895342551} => pcalua.exe -a C:\Users\Marco\Downloads\Adaware_Installer.exe -d C:\Users\Marco\Downloads
            Task: {CC7E475F-C850-4B25-ACEF-CDD11BBA37E2} - System32\Tasks\{CAB04F14-8D9A-4184-AD18-1D6C282DC6EB} => C:\Corel\Draw70\programs\photopnt.exe
            Task: {CE056A31-1B02-4BD9-82D0-6BF77A020900} - System32\Tasks\{39990666-AFFE-47CF-9FB3-F8C0AA96CDCA} => C:\Corel\Draw70\programs\photopnt.exe
            Task: {D0C0E802-98D1-4274-8A24-D773D3A00D75} - System32\Tasks\{5A25ECBD-0B9B-411F-BC7D-5A6B3BA0F7D7} => C:\Corel\Draw701\programs\photopnt.exe
            Task: {D54B238F-5953-460D-88E0-B8048E3132D7} - System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
            Task: {D64568DF-23EA-4B48-B558-8078C1D33660} - System32\Tasks\{F635ADB3-1AD0-4DB6-9D4A-AF79A638483D} => D:\Corel\Draw70\programs\photopnt.exe
            Task: {D9321925-6B97-4A7D-AE9B-D14B82AB743B} - System32\Tasks\{C1FCF6FF-C6B1-4CE4-A4E8-602EDF5B3CDA} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {DCE67E6D-44BA-4C0A-AD11-A23973613C28} - System32\Tasks\{C9183C48-D1F3-43DF-94DC-905BC79BFC7F} => D:\D\DOOM.EXE
            Task: {DCEAEDD8-71FA-4EE3-89A0-4249E42BB92D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
            Task: {E82171A9-FF80-4C2F-B235-8E8ECA4BC5AF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
            Task: {ED600DD3-3408-418D-94EE-2D47E8BED7AB} - System32\Tasks\{228862AD-F5BD-40E3-9F7B-0FE46B8AE765} => C:\corel\PROGRAMS\PHOTOPNT.EXE
            Task: {EDD2851A-7AC1-44BE-9308-D48A44C2F757} - System32\Tasks\{341FE709-8AFB-4377-9D6D-7344EF71CD9C} => pcalua.exe -a "C:\Program Files\Alice MOBILE E169\uninst.exe"
            Task: {F299C7D5-4579-40CB-8652-C2D6F6B189D9} - System32\Tasks\{AC32368B-2CCF-4FDA-B77C-777AB7ED0781} => D:\Corel\Draw70\programs\photopnt.exe
            Task: {F5606013-9B0D-40FB-AD90-4B22291BE6F8} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)

            (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

            Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

            ==================== Loaded Modules (whitelisted) ==============

            2015-01-15 00:12 - 2014-12-24 19:15 - 00270040 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\UiLogic.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00229080 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\diskmgr.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00278232 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Comn.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00077528 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Ldm.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00061144 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Device.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00265944 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrFat.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00384728 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrNtfs.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00118488 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FuncLogic.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00241368 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Clone.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00343768 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\ImgFile.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00028376 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Encrypt.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00073432 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Compress.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrVol.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00253656 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\GptBcd.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00151256 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\FlBackup.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00483032 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\EnumFolder.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00102104 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\Backup.dll
            2015-01-15 00:12 - 2014-12-24 19:15 - 00098008 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\BrLog.dll
            2015-01-15 00:12 - 2013-01-17 18:38 - 02403504 _____ () C:\Program Files\AOMEI Backupper Standard Edition 2.2\QtCore4.dll

            ==================== Alternate Data Streams (whitelisted) =========

            (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

            AlternateDataStreams: C:\ProgramData\TEMP:373E1720
            AlternateDataStreams: C:\ProgramData\TEMP:4CF8D17E

            ==================== Safe Mode (whitelisted) ===================

            (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

            ==================== EXE Association (whitelisted) ===============

            (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


            ==================== Internet Explorer trusted/restricted ===============

            (If an entry is included in the fixlist, the associated entry will be removed from the registry.)

            IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
            IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
            IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
            IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
            IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
            IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
            IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
            IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
            IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
            IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
            IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
            IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
            IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
            IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
            IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
            IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
            IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
            IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
            IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
            IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

            There are 7794 more restricted sites.

            ==================== Other Areas ============================

            (Currently there is no automatic fix for this section.)

            HKU\S-1-5-21-4094248773-42424133-2592686105-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: 192.168.1.254 - [removed]

            ==================== MSCONFIG/TASK MANAGER disabled items ==

            (Currently there is no automatic fix for this section.)

            MSCONFIG\Services: !SASCORE => 2
            MSCONFIG\Services: AdobeARMservice => 2
            MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
            MSCONFIG\Services: AdvancedSystemCareService7 => 2
            MSCONFIG\Services: Apple Mobile Device => 2
            MSCONFIG\Services: Bonjour Service => 2
            MSCONFIG\Services: CGVPNCliService => 2
            MSCONFIG\Services: CSObjectsSrv => 2
            MSCONFIG\Services: GoToAssist => 3
            MSCONFIG\Services: gupdate => 2
            MSCONFIG\Services: gupdatem => 3
            MSCONFIG\Services: Intelliservice => 2
            MSCONFIG\Services: iPod Service => 3
            MSCONFIG\Services: MozillaMaintenance => 3
            MSCONFIG\Services: PDF Architect 2 => 3
            MSCONFIG\Services: pdfforge CrashHandler => 3
            MSCONFIG\Services: PSI_SVC_2 => 2
            MSCONFIG\Services: SCardSvr => 3
            MSCONFIG\Services: ServiceLayer => 3
            MSCONFIG\Services: SkypeUpdate => 2
            MSCONFIG\Services: TomTomHOMEService => 2
            MSCONFIG\Services: WGEGyK => 2
            MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
            MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
            MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
            MSCONFIG\startupreg: Advanced SystemCare 7 => "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
            MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
            MSCONFIG\startupreg: BlazeServoTool => "C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
            MSCONFIG\startupreg: CloneCDTray => "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
            MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart /min
            MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
            MSCONFIG\startupreg: IDMan => C:\Program Files\Internet Download Manager\IDMan.exe /onboot
            MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
            MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
            MSCONFIG\startupreg: McAfee McItInfo => C:\Users\Marco\AppData\Local\Temp\mcitinfo_1383311069.exe /itinsfin:C:\Users\Marco\AppData\Local\Temp\mcininfo_1383311069.ini
            MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
            MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
            MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
            MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
            MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            MSCONFIG\startupreg: TBHostSupport => "C:\Windows\system32\Rundll32.exe" "C:\Users\Marco\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
            MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"

            ==================== FirewallRules (whitelisted) ===============

            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

            FirewallRules: [{0E499E8F-2CC2-492B-B6E3-DE6571FF9795}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{B01FAA7A-14A0-4104-9BA3-A0C0AECB340D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{ADC8BB10-533C-46BF-828A-6034C271B805}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
            FirewallRules: [{032E0385-BD9B-4F35-B22E-A1C73A91F3FC}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
            FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
            FirewallRules: [{44718332-C76D-4FAC-8FC1-2E8BC5726C68}] => (Allow) C:\Program Files\iTunes\iTunes.exe
            FirewallRules: [{6B609089-96E1-4411-AF63-17C8E30F8837}] => (Allow) C:\Program Files\AOMEI Backupper Standard Edition 2.2\PxeUi.exe
            FirewallRules: [{F2573A31-B37D-4F9F-9FD1-87FF78181875}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
            FirewallRules: [{F6CCA513-7672-4CF2-91D3-4FFD5446DE2A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
            FirewallRules: [{2762DDC4-D31E-48F1-B24D-0C14E83AC209}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

            ==================== Faulty Device Manager Devices =============


            ==================== Event log errors: =========================

            Application errors:
            ==================
            Error: (05/01/2015 06:43:09 PM) (Source: Application Error) (EventID: 1000) (User: )
            Description: Nome dell'applicazione che ha generato l'errore: WINWORD.EXE, versione: 10.0.6866.0, timestamp: 0x4c6486a7
            Nome del modulo che ha generato l'errore: MSGRIT32.DLL, versione: 3.0.0.37, timestamp: 0x3eb8c67e
            Codice eccezione: 0xc0000005
            Offset errore 0x0004fb98
            ID processo che ha generato l'errore: 0x1974
            Ora di avvio dell'applicazione che ha generato l'errore: 0xWINWORD.EXE0
            Percorso dell'applicazione che ha generato l'errore: WINWORD.EXE1
            Percorso del modulo che ha generato l'errore: WINWORD.EXE2
            ID segnalazione: WINWORD.EXE3

            Error: (05/01/2015 10:51:34 AM) (Source: Application Error) (EventID: 1000) (User: )
            Description: Nome dell'applicazione che ha generato l'errore: BlazeHDTV.EXE, versione: 1.0.0.1, timestamp: 0x4cf0b901
            Nome del modulo che ha generato l'errore: VideoDecoder.ax, versione: 4.5.0.1, timestamp: 0x4c8443af
            Codice eccezione: 0xc0000005
            Offset errore 0x00068076
            ID processo che ha generato l'errore: 0x1224
            Ora di avvio dell'applicazione che ha generato l'errore: 0xBlazeHDTV.EXE0
            Percorso dell'applicazione che ha generato l'errore: BlazeHDTV.EXE1
            Percorso del modulo che ha generato l'errore: BlazeHDTV.EXE2
            ID segnalazione: BlazeHDTV.EXE3

            Error: (05/01/2015 07:54:48 AM) (Source: Microsoft-Windows-Backup) (EventID: 517) (User: NT AUTHORITY)
            Description: Operazione di backup avviata alle ore '2015-05-01T05:46:48.526303700Z' non riuscita. Codice errore: '2147942402' (%%2147942402). Per una soluzione esaminare i dettagli dell'evento, quindi eseguire di nuovo l'operazione di backup dopo aver risolto il problema.

            Error: (04/30/2015 05:50:07 AM) (Source: VSS) (EventID: 8194) (User: )
            Description: Errore del servizio Copia Shadow del volume: errore imprevisto durante la ricerca dell'interfaccia IVssWriterCallback. hr = 0x80070005, Accesso negato.
            .
            L'errore è spesso causato da impostazioni di sicurezza non corrette nel processo di scrittura o richiedente.


            Operazione:
               Raccolta dei dati del processo di scrittura

            Contesto:
               ID della classe del processo di scrittura: {e8132975-6f93-4464-a53e-1050253ae220}
               Nome del processo di scrittura: System Writer
               ID dell'istanza del processo di scrittura: {1142e507-711e-464e-b3e1-e67e33f5da1b}

            Error: (04/28/2015 09:19:58 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/28/2015 00:12:39 AM) (Source: Application Error) (EventID: 1005) (User: )
            Description: Impossibile accedere al file C:\Windows\System32\adtschema.dll per uno dei motivi seguenti:
            Si è verificato un problema relativo alla connessione di rete, al disco in cui è archiviato il file o ai driver
            di archiviazione installati nel computer oppure il disco è assente.
            Il programma Processo host per servizi di Windows è stato chiuso a causa dell'errore.

            Programma: Processo host per servizi di Windows
            File: C:\Windows\System32\adtschema.dll

            Il valore dell'errore è indicato nella sezione Dati aggiuntivi.
            Azione utente
            1. Aprire nuovamente il file.
            Potrebbe trattarsi di un problema temporaneo che si risolverà automaticamente rieseguendo il programma.
            2.
            Se il file risulta comunque non accessibile e:
                - Si trova in rete,
            è necessario che l'amministratore della rete verifichi la presenza di eventuali problemi di rete e che sia possibile contattare il server.
                - Si trova in un disco rimovibile, ad esempio un disco floppy o un CD, verificare che il disco sia inserito correttamente nel computer.
            3. Controllare e ripristinare il file system eseguendo CHKDSK. Per eseguire CHKDSK, fare clic sul pulsante Start, scegliere Esegui, digitare CMD, quindi scegliere OK. Al prompt dei comandi, digitare CHKDSK /F, quindi premere INVIO.
            4. Se il problema persiste, ripristinare il file da una copia di backup.
            5. Determinare se è possibile aprire altri file nello stesso disco. Se non è possibile, il disco potrebbe essere danneggiato. Se si tratta di un disco rigido, contattare l'amministratore o il fornitore dell'hardware
            del computer per ottenere assistenza.

            Dati aggiuntivi
            Valore errore: C0000185
            Tipo disco: 3

            Error: (04/28/2015 00:12:32 AM) (Source: Application Error) (EventID: 1000) (User: )
            Description: Nome dell'applicazione che ha generato l'errore: svchost.exe_eventlog, versione: 6.1.7600.16385, timestamp: 0x4a5bc100
            Nome del modulo che ha generato l'errore: wevtsvc.dll, versione: 6.1.7601.17514, timestamp: 0x4ce7ba2e
            Codice eccezione: 0xc0000006
            Offset errore 0x00011c21
            ID processo che ha generato l'errore: 0x3a4
            Ora di avvio dell'applicazione che ha generato l'errore: 0xsvchost.exe_eventlog0
            Percorso dell'applicazione che ha generato l'errore: svchost.exe_eventlog1
            Percorso del modulo che ha generato l'errore: svchost.exe_eventlog2
            ID segnalazione: svchost.exe_eventlog3

            Error: (04/27/2015 11:01:51 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/27/2015 10:39:17 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver

            Error: (04/26/2015 09:33:43 PM) (Source: lwsvc_1.10.0.14) (EventID: 0) (User: )
            Description: lwsvc_1.10.0.14Link Wiz Client Service failed to connect to driver


            System errors:
            =============
            Error: (05/02/2015 04:02:53 PM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
            Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)

            Error: (05/02/2015 04:02:47 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
            Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
            %%1058

            Error: (05/02/2015 04:02:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
            %%2

            Error: (05/02/2015 02:01:36 PM) (Source: Microsoft-Windows-Time-Service) (EventID: 4) (User: NT AUTHORITY)
            Description: Impossibile avviare il provider servizi orari 'VMICTimeProvider' a causa del seguente errore: Impossibile trovare il modulo specificato. (0x8007007E)

            Error: (05/02/2015 02:01:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
            Description: Il servizio Condivisione connessione Internet (ICS) dipende dal servizio Connection Manager di Accesso remoto che non è stato avviato per il seguente errore:
            %%1058

            Error: (05/02/2015 02:01:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: Il servizio Servizio di gestione non è stato avviato per il seguente errore:
            %%2

            Error: (05/02/2015 06:57:25 AM) (Source: DCOM) (EventID: 10010) (User: )
            Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

            Error: (05/02/2015 05:59:27 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
            Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio AVP15.0.2.

            Error: (05/01/2015 02:23:21 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
            Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio Netman.

            Error: (05/01/2015 07:56:47 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
            Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio LanmanServer.


            Microsoft Office Sessions:
            =========================
            Error: (05/01/2015 06:43:09 PM) (Source: Application Error) (EventID: 1000) (User: )
            Description: WINWORD.EXE10.0.6866.04c6486a7MSGRIT32.DLL3.0.0.373eb8c67ec00000050004fb98197401d0842d57947f9dC:\Program Files\Microsoft Office\Office10\WINWORD.EXEC:\Program Files\Common Files\Microsoft Shared\Proof\1040\MSGRIT32.DLL256a7118-f021-11e4-b73d-001d72e8ab06
             

            I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST or the fix wont work, use your mouse to drag FIXLIST right next to FRST, either above or below it but not right on top of it, after its downloaded open up FRST and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know if there has been any improvement with your system.

            Attachments:

            Hi ken,

            sorry for the delay but I have some HW problems on my PC (Not related to the problem we are working on)

            Hera attached the figlog.

            Now the system seems working quite properly.

            Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-04-2015 01
            Ran by [removed] at 2015-05-02 23:43:51 Run:2
            Running from C:\Users\[removed]\Desktop
            [removed] Boot Mode: Normal

            ==============================================

            Content of fixlist:
            *****************
            Start
            CloseProcesses:
            CreateRestorePoint:
            Task: {6059284D-1243-46AF-B0A0-A10FCE072B4C} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
            C:\Program Files\IObit
            Task: {D54B238F-5953-460D-88E0-B8048E3132D7} - System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
            C:\Program Files\RelevantKnowledge
            EmptyTemp:
            End















            *****************

            Processes closed successfully.
            Restore point was successfully created.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6059284D-1243-46AF-B0A0-A10FCE072B4C}" => Key deleted successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6059284D-1243-46AF-B0A0-A10FCE072B4C}" => Key deleted successfully.
            C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator => Moved successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator" => Key deleted successfully.
            C:\Program Files\IObit => Moved successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D54B238F-5953-460D-88E0-B8048E3132D7}" => Key deleted successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D54B238F-5953-460D-88E0-B8048E3132D7}" => Key deleted successfully.
            C:\Windows\System32\Tasks\{22DBA72C-C565-44AA-A124-EF626A0FCF93} => Moved successfully.
            "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{22DBA72C-C565-44AA-A124-EF626A0FCF93}" => Key deleted successfully.
            "C:\Program Files\RelevantKnowledge" => File/Directory not found.
            EmptyTemp: => Removed 87.4 MB temporary data.


            The system needed a reboot.

            ==== End of Fixlog 23:47:30 ====

            Ask AI

            AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

            Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI