Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-05-2017
Ran by Alessandro (ATTENTION: The user is not administrator) on ATARU (14-05-2017 00:29:52)
Running from C:\Users\Alessandro\Desktop
Loaded Profiles: John & Alessandro (Available Profiles: John & Alessandro)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> svchost.exe
Failed to access process -> nvvsvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> AvastSvc.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> SASCore.exe
Failed to access process -> armsvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> WUDFHost.exe
Failed to access process -> mscorsvw.exe
Failed to access process -> nvxdsync.exe
Failed to access process -> nvvsvc.exe
Failed to access process -> aswidsagent.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> svchost.exe
Failed to access process -> wmpnetwk.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Alessandro\Desktop\FRST(1).exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-12] (AVAST Software)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-1198036982-2959511957-1623649180-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6828448 2017-04-07] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-05-12] (AVAST Software)
GroupPolicy: Restriction ? <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{CC4A2340-A261-4307-8944-43BD45212F36}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F7D3F3F7-2033-442F-A094-5FE6DDD0AEAC}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
URLSearchHook: [S-1-5-21-1198036982-2959511957-1623649180-1000] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-1198036982-2959511957-1623649180-1003 -> {10AD1955-57C2-4BF5-B9B1-7179CA7572BA} URL = hxxp://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms}
SearchScopes: HKU\S-1-5-21-1198036982-2959511957-1623649180-1003 -> {B8F9323A-27D5-465A-AF33-AC053AA1FEFB} URL = hxxp://it.wikipedia.org/w/index.php?title=Speciale:Ricerca&search={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-04] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-19] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-19] (Google Inc.)
Toolbar: HKU\S-1-5-21-1198036982-2959511957-1623649180-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-19] (Google Inc.)
FireFox:
========
FF DefaultProfile: 0mu29rir.default
FF ProfilePath: C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default [2017-05-14]
FF Extension: (Simple Night Mode) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\@Simple-Night-Mode.xpi [2017-04-03]
FF Extension: (Avast SafePrice) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\sp@avast.com.xpi [2017-05-12]
FF Extension: (Avast Online Security) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\wrc@avast.com.xpi [2017-05-12]
FF Extension: (Adblock Plus) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-04-03]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-12] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-02] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1198036982-2959511957-1623649180-1003: @citrixonline.com/appdetectorplugin -> C:\Users\Alessandro\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2017-03-16] (Citrix Online)
Chrome:
=======
CHR Profile: C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default [2017-04-26]
CHR Extension: (Google Docs) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-06]
CHR Extension: (Google Drive) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-06]
CHR Extension: (YouTube) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-06]
CHR Extension: (Avast SafePrice) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-03-19]
CHR Extension: (Google Docs Offline) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-06]
CHR Extension: (Avast Online Security) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-06]
CHR Extension: (Chrome Media Router) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-26]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [143776 2017-01-31] (SUPERAntiSpyware.com)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5732136 2017-05-12] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-12] (AVAST Software)
R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [258288 2017-05-12] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [148696 2017-05-12] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswblogx.sys [268016 2017-05-12] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [41664 2017-05-12] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [70008 2017-03-20] (AVAST Software)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34136 2017-05-12] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [31064 2017-05-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107928 2017-05-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [90336 2017-05-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [62152 2017-05-12] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [764576 2017-05-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [482608 2017-05-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [115152 2017-05-12] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [279800 2017-05-12] (AVAST Software)
R3 pelmouse; C:\Windows\System32\DRIVERS\pelmouse.sys [16384 2003-01-10] (Primax Electronics Ltd.)
R3 pelusblf; C:\Windows\System32\DRIVERS\pelusblf.sys [9216 2003-02-11] (Primax Electronics Ltd.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-14 00:29 - 2017-05-14 00:30 - 00011997 _____ C:\Users\Alessandro\Desktop\FRST.txt
2017-05-14 00:21 - 2017-05-14 00:21 - 01769984 _____ (Farbar) C:\Users\Alessandro\Desktop\FRST(1).exe
2017-05-13 23:54 - 2017-05-13 23:54 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-05-12 20:57 - 2017-04-16 09:49 - 20278272 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-05-12 20:56 - 2017-04-28 02:36 - 04000488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-05-12 20:56 - 2017-04-28 02:36 - 03945192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-05-12 20:56 - 2017-04-28 02:36 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-05-12 20:56 - 2017-04-28 02:36 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-05-12 20:56 - 2017-04-28 02:34 - 01310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-05-12 20:56 - 2017-04-28 02:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-05-12 20:56 - 2017-04-28 02:11 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-05-12 20:56 - 2017-04-28 02:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-05-12 20:56 - 2017-04-28 02:11 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-05-12 20:56 - 2017-04-28 02:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-05-12 20:56 - 2017-04-28 02:09 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-05-12 20:56 - 2017-04-28 02:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-05-12 20:56 - 2017-04-28 02:07 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-05-12 20:56 - 2017-04-28 02:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-05-12 20:56 - 2017-04-28 02:07 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-05-12 20:56 - 2017-04-28 02:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-05-12 20:56 - 2017-04-28 02:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-05-12 20:56 - 2017-04-28 02:07 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-05-12 20:56 - 2017-04-26 16:51 - 02400768 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-05-12 20:56 - 2017-04-21 17:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-05-12 20:56 - 2017-04-20 01:16 - 00346320 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00377344 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-05-12 20:56 - 2017-04-17 16:51 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-05-12 20:56 - 2017-04-17 16:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-12 20:56 - 2017-04-16 10:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-05-12 20:56 - 2017-04-16 10:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-05-12 20:56 - 2017-04-16 10:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-05-12 20:56 - 2017-04-16 10:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-05-12 20:56 - 2017-04-16 10:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-05-12 20:56 - 2017-04-16 10:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-05-12 20:56 - 2017-04-16 10:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-05-12 20:56 - 2017-04-16 09:53 - 02290176 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-05-12 20:56 - 2017-04-16 09:52 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-05-12 20:56 - 2017-04-16 09:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-05-12 20:56 - 2017-04-16 09:48 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-05-12 20:56 - 2017-04-16 09:47 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-05-12 20:56 - 2017-04-16 09:47 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-05-12 20:56 - 2017-04-16 09:47 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-05-12 20:56 - 2017-04-16 09:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-05-12 20:56 - 2017-04-16 09:39 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-05-12 20:56 - 2017-04-16 09:35 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-05-12 20:56 - 2017-04-16 09:30 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-05-12 20:56 - 2017-04-16 09:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-05-12 20:56 - 2017-04-16 09:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-05-12 20:56 - 2017-04-16 09:25 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-05-12 20:56 - 2017-04-16 09:24 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-05-12 20:56 - 2017-04-16 09:22 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-05-12 20:56 - 2017-04-16 09:20 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-05-12 20:56 - 2017-04-16 09:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-05-12 20:56 - 2017-04-16 09:10 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-05-12 20:56 - 2017-04-16 09:10 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-05-12 20:56 - 2017-04-16 09:08 - 04548608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-05-12 20:56 - 2017-04-16 09:08 - 02057216 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-05-12 20:56 - 2017-04-16 09:08 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-05-12 20:56 - 2017-04-16 08:53 - 13661184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-05-12 20:56 - 2017-04-16 08:37 - 02767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-05-12 20:56 - 2017-04-16 08:34 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-05-12 20:56 - 2017-04-16 08:34 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-05-12 20:56 - 2017-04-12 17:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-05-12 20:56 - 2017-04-12 17:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-05-12 20:56 - 2017-04-12 17:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-05-12 20:56 - 2017-04-12 17:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-05-12 20:56 - 2017-04-07 17:26 - 00730344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-05-12 20:56 - 2017-04-07 17:26 - 00218856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-05-12 20:56 - 2017-04-07 17:21 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-05-12 20:56 - 2017-04-07 17:20 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-05-12 20:56 - 2017-04-05 17:00 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-05-12 20:56 - 2017-04-05 17:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-05-12 20:56 - 2017-04-05 17:00 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-05-12 20:56 - 2017-04-04 17:25 - 01309928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-05-12 20:56 - 2017-04-04 17:25 - 00240872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-05-12 20:56 - 2017-04-04 17:25 - 00187624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-05-12 20:56 - 2017-04-04 16:52 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-05-12 20:56 - 2017-04-04 16:52 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-05-12 20:56 - 2017-03-10 18:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-05-12 20:56 - 2017-03-10 18:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-05-12 20:56 - 2017-03-10 17:52 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-05-12 20:56 - 2017-03-10 17:51 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-05-12 20:56 - 2017-03-10 17:51 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-05-12 20:56 - 2017-03-09 18:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-05-12 20:42 - 2017-05-12 20:42 - 00330768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-04-27 17:35 - 2017-04-27 17:35 - 00000000 ____D C:\Users\Alessandro\AppData\Roaming\polychat-client
2017-04-27 17:20 - 2017-04-27 17:20 - 00000000 ____D C:\Program Files\PVproctor
2017-04-26 16:40 - 2017-04-26 16:40 - 00000009 _____ C:\Users\Alessandro\Documents\test.txt
2017-04-26 16:08 - 2017-04-26 16:08 - 00000080 _____ C:\Users\Alessandro\Documents\exam.txt
2017-04-20 22:17 - 2017-04-20 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2017-04-20 22:16 - 2017-04-20 22:17 - 00000000 ____D C:\Program Files\K-Lite Codec Pack
2017-04-20 22:09 - 2017-05-06 22:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-04-18 19:59 - 2017-05-12 20:50 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-04-18 19:59 - 2017-05-12 20:50 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-04-18 19:59 - 2017-05-12 20:50 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-18 19:59 - 2017-04-18 19:59 - 00000000 ____D C:\Users\Alessandro\AppData\Local\Macromedia
2017-04-18 19:24 - 2017-04-18 19:24 - 04713984 _____ (Geza Kovacs) C:\Users\Alessandro\Downloads\unetbootin-windows-625.exe
2017-04-18 19:19 - 2017-04-18 19:20 - 51380224 _____ C:\Users\Alessandro\Downloads\mini.iso
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-14 00:29 - 2017-04-04 18:45 - 00000000 ____D C:\FRST
2017-05-14 00:22 - 2017-03-16 18:18 - 00000592 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1198036982-2959511957-1623649180-1003.job
2017-05-14 00:12 - 2017-04-03 23:01 - 00000000 ____D C:\Users\Alessandro\AppData\LocalLow\Mozilla
2017-05-13 23:57 - 2009-07-14 06:34 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-13 23:57 - 2009-07-14 06:34 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-13 23:47 - 2010-11-20 23:01 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-13 23:47 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\inf
2017-05-13 23:42 - 2017-03-16 18:18 - 00000688 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1198036982-2959511957-1623649180-1003.job
2017-05-13 23:42 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-13 23:42 - 2009-07-14 06:33 - 00408544 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-13 23:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-05-12 21:18 - 2017-02-04 23:00 - 00000000 ____D C:\Windows\system32\MRT
2017-05-12 21:15 - 2017-02-04 23:00 - 153591048 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-05-12 20:43 - 2016-11-19 18:55 - 00115152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00268016 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00258288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00148696 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00041664 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-05-12 20:42 - 2016-11-19 18:57 - 00031064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00764576 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00482608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00279800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00107928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00090336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00062152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00034136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-05-06 22:30 - 2017-04-03 23:00 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-05-04 23:22 - 2017-02-27 00:23 - 00000000 ____D C:\Users\Alessandro\AppData\Roaming\Skype
2017-05-03 22:09 - 2016-11-19 18:59 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-03 22:09 - 2016-11-19 18:59 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-27 18:29 - 2016-12-25 00:42 - 00000000 ____D C:\Users\Alessandro
2017-04-27 17:20 - 2017-02-24 18:50 - 00000863 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PVproctor.lnk
2017-04-27 17:20 - 2017-02-24 18:50 - 00000851 _____ C:\Users\Public\Desktop\PVproctor.lnk
2017-04-18 17:19 - 2009-07-14 06:53 - 00032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-14 22:08 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2017-04-14 21:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2017-04-14 00:17 - 2017-04-04 18:31 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD. The user is not administrator
==================== End of FRST.txt ============================
Ran by Alessandro (ATTENTION: The user is not administrator) on ATARU (14-05-2017 00:29:52)
Running from C:\Users\Alessandro\Desktop
Loaded Profiles: John & Alessandro (Available Profiles: John & Alessandro)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> svchost.exe
Failed to access process -> nvvsvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> AvastSvc.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> SASCore.exe
Failed to access process -> armsvc.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> WUDFHost.exe
Failed to access process -> mscorsvw.exe
Failed to access process -> nvxdsync.exe
Failed to access process -> nvvsvc.exe
Failed to access process -> aswidsagent.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> svchost.exe
Failed to access process -> wmpnetwk.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Alessandro\Desktop\FRST(1).exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-12] (AVAST Software)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-1198036982-2959511957-1623649180-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6828448 2017-04-07] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-05-12] (AVAST Software)
GroupPolicy: Restriction ? <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{CC4A2340-A261-4307-8944-43BD45212F36}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F7D3F3F7-2033-442F-A094-5FE6DDD0AEAC}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
URLSearchHook: [S-1-5-21-1198036982-2959511957-1623649180-1000] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-1198036982-2959511957-1623649180-1003 -> {10AD1955-57C2-4BF5-B9B1-7179CA7572BA} URL = hxxp://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms}
SearchScopes: HKU\S-1-5-21-1198036982-2959511957-1623649180-1003 -> {B8F9323A-27D5-465A-AF33-AC053AA1FEFB} URL = hxxp://it.wikipedia.org/w/index.php?title=Speciale:Ricerca&search={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-04] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-19] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-19] (Google Inc.)
Toolbar: HKU\S-1-5-21-1198036982-2959511957-1623649180-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-19] (Google Inc.)
FireFox:
========
FF DefaultProfile: 0mu29rir.default
FF ProfilePath: C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default [2017-05-14]
FF Extension: (Simple Night Mode) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\@Simple-Night-Mode.xpi [2017-04-03]
FF Extension: (Avast SafePrice) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\sp@avast.com.xpi [2017-05-12]
FF Extension: (Avast Online Security) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\wrc@avast.com.xpi [2017-05-12]
FF Extension: (Adblock Plus) - C:\Users\Alessandro\AppData\Roaming\Mozilla\Firefox\Profiles\0mu29rir.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-04-03]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-12] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-02] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1198036982-2959511957-1623649180-1003: @citrixonline.com/appdetectorplugin -> C:\Users\Alessandro\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2017-03-16] (Citrix Online)
Chrome:
=======
CHR Profile: C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default [2017-04-26]
CHR Extension: (Google Docs) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-06]
CHR Extension: (Google Drive) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-06]
CHR Extension: (YouTube) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-06]
CHR Extension: (Avast SafePrice) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-03-19]
CHR Extension: (Google Docs Offline) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-06]
CHR Extension: (Avast Online Security) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-06]
CHR Extension: (Chrome Media Router) - C:\Users\Alessandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-26]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [143776 2017-01-31] (SUPERAntiSpyware.com)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5732136 2017-05-12] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-12] (AVAST Software)
R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [258288 2017-05-12] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [148696 2017-05-12] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswblogx.sys [268016 2017-05-12] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [41664 2017-05-12] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [70008 2017-03-20] (AVAST Software)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34136 2017-05-12] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [31064 2017-05-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107928 2017-05-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [90336 2017-05-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [62152 2017-05-12] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [764576 2017-05-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [482608 2017-05-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [115152 2017-05-12] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [279800 2017-05-12] (AVAST Software)
R3 pelmouse; C:\Windows\System32\DRIVERS\pelmouse.sys [16384 2003-01-10] (Primax Electronics Ltd.)
R3 pelusblf; C:\Windows\System32\DRIVERS\pelusblf.sys [9216 2003-02-11] (Primax Electronics Ltd.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-14 00:29 - 2017-05-14 00:30 - 00011997 _____ C:\Users\Alessandro\Desktop\FRST.txt
2017-05-14 00:21 - 2017-05-14 00:21 - 01769984 _____ (Farbar) C:\Users\Alessandro\Desktop\FRST(1).exe
2017-05-13 23:54 - 2017-05-13 23:54 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-05-12 20:57 - 2017-04-16 09:49 - 20278272 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-05-12 20:56 - 2017-04-28 02:36 - 04000488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-05-12 20:56 - 2017-04-28 02:36 - 03945192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-05-12 20:56 - 2017-04-28 02:36 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-05-12 20:56 - 2017-04-28 02:36 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-05-12 20:56 - 2017-04-28 02:34 - 01310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-05-12 20:56 - 2017-04-28 02:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-05-12 20:56 - 2017-04-28 02:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-05-12 20:56 - 2017-04-28 02:11 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-05-12 20:56 - 2017-04-28 02:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-05-12 20:56 - 2017-04-28 02:11 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-05-12 20:56 - 2017-04-28 02:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-05-12 20:56 - 2017-04-28 02:09 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-05-12 20:56 - 2017-04-28 02:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-05-12 20:56 - 2017-04-28 02:07 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-05-12 20:56 - 2017-04-28 02:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-05-12 20:56 - 2017-04-28 02:07 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-05-12 20:56 - 2017-04-28 02:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-05-12 20:56 - 2017-04-28 02:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-05-12 20:56 - 2017-04-28 02:07 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-05-12 20:56 - 2017-04-26 16:51 - 02400768 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-05-12 20:56 - 2017-04-21 17:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-05-12 20:56 - 2017-04-20 01:16 - 00346320 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00377344 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 17:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-05-12 20:56 - 2017-04-17 16:51 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-05-12 20:56 - 2017-04-17 16:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-12 20:56 - 2017-04-17 16:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-12 20:56 - 2017-04-16 10:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-05-12 20:56 - 2017-04-16 10:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-05-12 20:56 - 2017-04-16 10:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-05-12 20:56 - 2017-04-16 10:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-05-12 20:56 - 2017-04-16 10:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-05-12 20:56 - 2017-04-16 10:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-05-12 20:56 - 2017-04-16 10:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-05-12 20:56 - 2017-04-16 09:53 - 02290176 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-05-12 20:56 - 2017-04-16 09:52 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-05-12 20:56 - 2017-04-16 09:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-05-12 20:56 - 2017-04-16 09:48 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-05-12 20:56 - 2017-04-16 09:47 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-05-12 20:56 - 2017-04-16 09:47 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-05-12 20:56 - 2017-04-16 09:47 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-05-12 20:56 - 2017-04-16 09:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-05-12 20:56 - 2017-04-16 09:39 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-05-12 20:56 - 2017-04-16 09:35 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-05-12 20:56 - 2017-04-16 09:30 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-05-12 20:56 - 2017-04-16 09:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-05-12 20:56 - 2017-04-16 09:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-05-12 20:56 - 2017-04-16 09:25 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-05-12 20:56 - 2017-04-16 09:24 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-05-12 20:56 - 2017-04-16 09:22 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-05-12 20:56 - 2017-04-16 09:20 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-05-12 20:56 - 2017-04-16 09:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-05-12 20:56 - 2017-04-16 09:10 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-05-12 20:56 - 2017-04-16 09:10 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-05-12 20:56 - 2017-04-16 09:08 - 04548608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-05-12 20:56 - 2017-04-16 09:08 - 02057216 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-05-12 20:56 - 2017-04-16 09:08 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-05-12 20:56 - 2017-04-16 08:53 - 13661184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-05-12 20:56 - 2017-04-16 08:37 - 02767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-05-12 20:56 - 2017-04-16 08:34 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-05-12 20:56 - 2017-04-16 08:34 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-05-12 20:56 - 2017-04-12 17:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-05-12 20:56 - 2017-04-12 17:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-05-12 20:56 - 2017-04-12 17:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-05-12 20:56 - 2017-04-12 17:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-05-12 20:56 - 2017-04-07 17:26 - 00730344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-05-12 20:56 - 2017-04-07 17:26 - 00218856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-05-12 20:56 - 2017-04-07 17:21 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-05-12 20:56 - 2017-04-07 17:20 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-05-12 20:56 - 2017-04-05 17:00 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-05-12 20:56 - 2017-04-05 17:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-05-12 20:56 - 2017-04-05 17:00 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-05-12 20:56 - 2017-04-04 17:25 - 01309928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-05-12 20:56 - 2017-04-04 17:25 - 00240872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-05-12 20:56 - 2017-04-04 17:25 - 00187624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-05-12 20:56 - 2017-04-04 16:52 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-05-12 20:56 - 2017-04-04 16:52 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-05-12 20:56 - 2017-03-10 18:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-05-12 20:56 - 2017-03-10 18:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-05-12 20:56 - 2017-03-10 17:52 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-05-12 20:56 - 2017-03-10 17:51 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-05-12 20:56 - 2017-03-10 17:51 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-05-12 20:56 - 2017-03-09 18:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-05-12 20:42 - 2017-05-12 20:42 - 00330768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-04-27 17:35 - 2017-04-27 17:35 - 00000000 ____D C:\Users\Alessandro\AppData\Roaming\polychat-client
2017-04-27 17:20 - 2017-04-27 17:20 - 00000000 ____D C:\Program Files\PVproctor
2017-04-26 16:40 - 2017-04-26 16:40 - 00000009 _____ C:\Users\Alessandro\Documents\test.txt
2017-04-26 16:08 - 2017-04-26 16:08 - 00000080 _____ C:\Users\Alessandro\Documents\exam.txt
2017-04-20 22:17 - 2017-04-20 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2017-04-20 22:16 - 2017-04-20 22:17 - 00000000 ____D C:\Program Files\K-Lite Codec Pack
2017-04-20 22:09 - 2017-05-06 22:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-04-18 19:59 - 2017-05-12 20:50 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-04-18 19:59 - 2017-05-12 20:50 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-04-18 19:59 - 2017-05-12 20:50 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-18 19:59 - 2017-04-18 19:59 - 00000000 ____D C:\Users\Alessandro\AppData\Local\Macromedia
2017-04-18 19:24 - 2017-04-18 19:24 - 04713984 _____ (Geza Kovacs) C:\Users\Alessandro\Downloads\unetbootin-windows-625.exe
2017-04-18 19:19 - 2017-04-18 19:20 - 51380224 _____ C:\Users\Alessandro\Downloads\mini.iso
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-14 00:29 - 2017-04-04 18:45 - 00000000 ____D C:\FRST
2017-05-14 00:22 - 2017-03-16 18:18 - 00000592 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1198036982-2959511957-1623649180-1003.job
2017-05-14 00:12 - 2017-04-03 23:01 - 00000000 ____D C:\Users\Alessandro\AppData\LocalLow\Mozilla
2017-05-13 23:57 - 2009-07-14 06:34 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-13 23:57 - 2009-07-14 06:34 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-13 23:47 - 2010-11-20 23:01 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-13 23:47 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\inf
2017-05-13 23:42 - 2017-03-16 18:18 - 00000688 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1198036982-2959511957-1623649180-1003.job
2017-05-13 23:42 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-13 23:42 - 2009-07-14 06:33 - 00408544 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-13 23:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-05-12 21:18 - 2017-02-04 23:00 - 00000000 ____D C:\Windows\system32\MRT
2017-05-12 21:15 - 2017-02-04 23:00 - 153591048 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-05-12 20:43 - 2016-11-19 18:55 - 00115152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00268016 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00258288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00148696 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-05-12 20:42 - 2017-02-08 17:49 - 00041664 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-05-12 20:42 - 2016-11-19 18:57 - 00031064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00764576 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00482608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00279800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00107928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00090336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00062152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-05-12 20:42 - 2016-11-19 18:55 - 00034136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-05-06 22:30 - 2017-04-03 23:00 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-05-04 23:22 - 2017-02-27 00:23 - 00000000 ____D C:\Users\Alessandro\AppData\Roaming\Skype
2017-05-03 22:09 - 2016-11-19 18:59 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-03 22:09 - 2016-11-19 18:59 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-27 18:29 - 2016-12-25 00:42 - 00000000 ____D C:\Users\Alessandro
2017-04-27 17:20 - 2017-02-24 18:50 - 00000863 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PVproctor.lnk
2017-04-27 17:20 - 2017-02-24 18:50 - 00000851 _____ C:\Users\Public\Desktop\PVproctor.lnk
2017-04-18 17:19 - 2009-07-14 06:53 - 00032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-14 22:08 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2017-04-14 21:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2017-04-14 00:17 - 2017-04-04 18:31 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD. The user is not administrator
==================== End of FRST.txt ============================