Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2021
Ran by user (administrator) on DESKTOP-MG (28-06-2021 20:56:10)
Running from C:\Users\user\Desktop
Loaded Profiles: user
Platform: Windows 10 Pro Version 21H1 19043.1052 (X64) Language: Italiano (Italia)
Default browser: Opera
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files (x86)\NWSoftware\Smart Photo Import 1.0\SI_drivesense.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTeK Computer Inc. -> ) [File not signed] C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(F.lux Software LLC -> f.lux Software LLC) C:\Users\user\AppData\Local\FluxSoftware\Flux\flux.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <11>
(Intel Corporation) [File not signed] C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) Online Connect -> Intel Corporation) C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe
(Intel(R) Online Connect Access -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
(Intel(R) Online Connect Access -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Safe Kids 1.0.5\safekids.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Safe Kids 1.0.5\safekidsui.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\avp.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\avpui.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\plugins_nms.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_b2801df14ec7de03\Display.NvContainer\NVDisplay.Container.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Sonic Studio 3] => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3svc32.exe [1234432 2018-02-22] (ASUSTeK COMPUTER INC.) [File not signed]
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-11-09] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9268680 2019-02-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [Opera Browser Assistant] => C:\Program Files\Opera\assistant\browser_assistant.exe [3989200 2021-06-24] (Opera Software AS -> Opera Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706288 2021-04-09] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4109032 2021-06-09] (Valve -> Valve Corporation)
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [f.lux] => C:\Users\user\AppData\Local\FluxSoftware\Flux\flux.exe [1511824 2021-02-04] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [Discord] => C:\Users\user\AppData\Local\Discord\app-0.0.307\Discord.exe [91023672 2020-08-04] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [Smart Photo Import] => C:\Program Files (x86)\NWSoftware\Smart Photo Import 1.0\SI_drivesense.exe [331776 2012-09-23] () [File not signed]
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [34508416 2021-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [Spotify] => C:\Users\user\AppData\Roaming\Spotify\Spotify.exe [25591712 2019-07-04] (Spotify AB -> Spotify Ltd) <==== ATTENTION
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [735088 2019-02-18] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1774472352-47920936-928243050-1001\...\Run: [Medal] => C:\Users\user\AppData\Local\Medal\update.exe [1845072 2020-09-03] (Ferox Games B.V. -> )
HKLM\Software\...\AppCompatFlags\Custom\Battlegrounds.exe: [{9f3d9623-1935-43fa-9756-e90f3134f675}.sdb] -> STAR WARS - Galactic Battlegrounds Saga
HKLM\Software\...\AppCompatFlags\Custom\battlegrounds_x1.exe: [{9f3d9623-1935-43fa-9756-e90f3134f675}.sdb] -> STAR WARS - Galactic Battlegrounds Saga
HKLM\Software\...\AppCompatFlags\Custom\player.exe: [{9f3d9623-1935-43fa-9756-e90f3134f675}.sdb] -> STAR WARS - Galactic Battlegrounds Saga
HKLM\Software\...\AppCompatFlags\InstalledSDB\{9f3d9623-1935-43fa-9756-e90f3134f675}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{9f3d9623-1935-43fa-9756-e90f3134f675}.sdb [2019-06-29]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.124\Installer\chrmstp.exe [2021-06-26] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {027256DF-F44F-4509-B5B7-BBBFBAD823D8} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {03B1D690-5D22-4C06-A4DB-AC5E9E30FA46} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3336560 2021-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0A58B213-E2DB-4A0F-9F79-F4E192056DDF} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2C0D281E-0F83-4FC3-AF3A-E65C3DAB6D80} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {2CF2B6B6-EF0C-47C8-B758-4FB28E9F17F7} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [743488 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
Task: {3005F1A8-1754-4EB5-8F4C-2CBBA8EA3BE7} - System32\Tasks\SS3Svc32Run => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3Svc32.exe [1234432 2018-02-22] (ASUSTeK COMPUTER INC.) [File not signed]
Task: {3212D90F-FFE4-4EC3-8377-7B18C85B218E} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1790184 2021-04-29] (Avast Software s.r.o. -> Avast Software)
Task: {3FC121E4-5DB8-4BE4-A38B-6BD0D9258042} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 => C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-10-14] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {40CFC116-6E75-485A-8713-428AC15ED0D5} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-29] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {472D0513-DE02-48E6-A7CC-4C49A19923BC} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {4902E8D2-AFB9-433C-9958-8CB246A65DCE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {60EA1950-3764-492B-9CAF-A5A26F296A38} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {70F2CADD-61C4-48C5-A6F7-AF11DD512CA5} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-29] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {78C5D28F-6B6B-40C0-BB05-1C2FF2E867C7} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1551520 2015-05-14] (ASUSTeK Computer Inc. -> ) [File not signed]
Task: {78FAD4B2-0661-4354-AB1C-33E30BBE6BCD} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon => C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-10-14] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {80E34C8B-2986-4406-9335-039569C2C179} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-12-29] (Google Inc -> Google Inc.)
Task: {8B10A8D8-EA45-4849-9EF9-954E5CBEC6C3} - System32\Tasks\kpm_tray.exe => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe [613096 2021-06-08] (Kaspersky Lab JSC -> AO Kaspersky Lab)
Task: {9584F8B5-ABDA-43D9-9726-297F08F9FA0C} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9BA9BAD4-DDF3-4F82-8341-1E0B25BEDCC3} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9F8A5C9B-7F11-4BB9-A615-E9BFBF1DAE8E} - System32\Tasks\Opera scheduled Autoupdate 1514935286 => C:\Program Files\Opera\launcher.exe [2264784 2021-06-17] (Opera Software AS -> Opera Software)
Task: {A4360A3E-2B16-4E31-B7AF-896D0A612D78} - System32\Tasks\Opera GX scheduled Autoupdate 1581077425 => C:\Users\crist\AppData\Local\Programs\Opera GX\launcher.exe [1473048 2020-02-20] (Opera Software AS -> Opera Software)
Task: {B29C4B24-9C21-46A7-A4CC-030E5A0CFC0E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-12-29] (Google Inc -> Google Inc.)
Task: {B920D2FE-A1E1-46F0-AE4F-C038BEA41CC3} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C64F0694-5D4B-4838-A50D-A9DFEDC70D29} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1774472352-47920936-928243050-1002 => C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {CA30B8EF-1FFD-421B-93C1-8BCDCB2CE859} - System32\Tasks\Opera scheduled assistant Autoupdate 1582753193 => C:\Program Files\Opera\launcher.exe [2264784 2021-06-17] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Program Files\Opera\assistant" $(Arg0)
Task: {CA98361E-3ECF-4A78-B66F-D0F88CA26FDA} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CC65F10B-42C2-430B-A81E-4B2DF33FFBE7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28880512 2021-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {D461E9A2-5739-4856-BF42-18B9CBE3C9CD} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-06-17] (Piriform Software Ltd -> Piriform)
Task: {E930236F-5073-461B-8665-61B51D6FCDB0} - System32\Tasks\SS3svc64Run => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\x64\SS3svc64.exe [811520 2018-02-22] (ASUSTeK COMPUTER INC.) [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3614f9c6-f38a-41f2-af91-0e1ec412f891}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3c4239a3-0aca-4e9c-aa79-2aa4b7b98393}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-28]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-06-28]
Edge HKU\S-1-5-21-1774472352-47920936-928243050-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
Edge HKU\S-1-5-21-1774472352-47920936-928243050-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF HKLM\...\Firefox\Extensions: [
light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [
light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\FFExt\light_plugin_firefox\addon.xpi => not found
FF Plugin: @java.com/DTPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\dtplugin\npDeployJava1.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\plugin2\npjp2.dll [2021-06-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default [2021-06-28]
CHR StartupUrls: Default -> "hxxps://www.google.it/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Presentazioni) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-29]
CHR Extension: (Kaspersky Protection) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2021-06-28]
CHR Extension: (Documenti) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-29]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-02]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-29]
CHR Extension: (BlockSite - Website Blocker per Chrome™) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2020-03-27]
CHR Extension: (Avast SafePrice | Confronto, offerte, coupon) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2021-06-28]
CHR Extension: (Fogli) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-29]
CHR Extension: (Documenti Google offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-02]
CHR Extension: (Avast Online Security) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2021-06-28]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-06-28]
CHR Extension: (Pagamenti Chrome Web Store) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-28]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-02]
CHR Extension: (Chrome Media Router) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-28]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Opera:
=======
OPR Profile: C:\Users\user\AppData\Roaming\Opera Software\Opera Stable [2021-06-26]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (BlockSite - Rimani concentrato e controlla il tuo tempo) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2021-06-18]
OPR Extension: (Rich Hints Agent) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-06-26]
OPR Extension: (Anti-Porn PoliceWEB.net) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\fjpfeaedoichmjfaaeghijjenilnibdl [2020-03-18]
OPR Extension: (Install Chrome Extensions) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2020-03-27]
OPR Extension: (Adblock Plus - ad-blocker gratuito) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2021-05-20]
StartMenuInternet: (HKU\S-1-5-21-1774472352-47920936-928243050-1002) Opera GXStable - "C:\Users\crist\AppData\Local\Programs\Opera GX\Launcher.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-03-29] (Apple Inc. -> Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2019-02-18] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-24] (ASUSTeK Computer Inc. -> ) [File not signed]
R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\avp.exe [184768 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8413472 2020-03-30] (BattlEye Innovations e.K. -> )
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4133232 2019-02-18] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2021-05-08] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
U3 Intel(R) Online Connect; C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe [25312 2016-11-01] (Intel(R) Online Connect -> Intel Corporation)
S2 Intel(R) Online Connect Helper; C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe [34528 2016-11-01] (Intel(R) Online Connect -> Intel Corporation)
S3 Intel(R) Online Connect Software Asset Manager; C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-10-14] (Intel(R) Software Asset Manager -> Intel Corporation)
R2 Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [506368 2017-10-26] (Intel Corporation) [File not signed]
R2 Intel(R) TechnologyAccessLegacyCSLoader; C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe [173288 2016-10-17] (Intel(R) Online Connect Access -> Intel(R) Corporation)
R2 Intel(R) TechnologyAccessService; C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe [496872 2016-10-17] (Intel(R) Online Connect Access -> Intel(R) Corporation)
S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [368360 2021-06-08] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7391408 2021-06-26] (Malwarebytes Inc -> Malwarebytes)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75064 2020-12-13] (Even Balance, Inc. -> )
R3 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13921616 2021-06-28] (Adlice -> )
R2 SafeKids1.0.5; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Safe Kids 1.0.5\safekids.exe [607536 2021-05-14] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5393304 2021-06-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe [2644776 2021-06-14] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe [136656 2021-06-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_b2801df14ec7de03\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_b2801df14ec7de03\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-04-26] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-04-26] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2016-11-18] (ASUSTeK Computer Inc. -> )
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2019-02-16] (ASUSTeK Computer Inc. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [250032 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2019-02-18] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2019-02-18] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [110336 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [211704 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [126216 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [41656 2021-02-19] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [514840 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klfltks; C:\WINDOWS\system32\DRIVERS\klfltks.sys [527112 2021-05-14] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [657696 2021-05-08] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1439456 2021-05-08] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys [253736 2021-06-26] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1042712 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klifks; C:\WINDOWS\System32\DRIVERS\klifks.sys [985352 2021-05-14] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [98040 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [112392 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [112904 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [85256 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [96008 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [263888 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [309104 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [115744 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [224880 2021-06-26] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [155912 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [327936 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwtpks; C:\WINDOWS\system32\DRIVERS\klwtpks.sys [249624 2021-05-14] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [300808 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-06-26] (Malwarebytes Inc -> Malwarebytes)
R1 ndisrd; C:\WINDOWS\system32\DRIVERS\ndisrfl.sys [59792 2016-09-13] (Intel(R) Technology Access -> Intel Corporation)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2021-06-28] (Adlice -> )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49568 2021-06-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [425184 2021-06-14] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-14] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-28 20:56 - 2021-06-28 20:56 - 000032950 _____ C:\Users\user\Desktop\FRST.txt
2021-06-28 19:42 - 2021-06-28 19:42 - 000000000 ____D C:\AdwCleaner
2021-06-28 19:19 - 2021-06-28 20:34 - 000038032 _____ C:\WINDOWS\system32\Drivers\truesight.sys
2021-06-28 19:19 - 2021-06-28 20:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2021-06-28 19:19 - 2021-06-28 19:25 - 000000000 ____D C:\ProgramData\RogueKiller
2021-06-28 19:19 - 2021-06-28 19:19 - 000000917 _____ C:\Users\user\Desktop\RogueKiller.lnk
2021-06-28 19:19 - 2021-06-28 19:19 - 000000000 ____D C:\Program Files\RogueKiller
2021-06-28 19:13 - 2021-06-28 19:06 - 008534696 _____ (Malwarebytes) C:\Users\user\Desktop\AdwCleaner.exe
2021-06-28 19:06 - 2021-06-28 19:07 - 041847456 _____ (Adlice Software ) C:\Users\user\Downloads\RogueKiller_setup.exe
2021-06-28 19:06 - 2021-06-28 19:06 - 008534696 _____ (Malwarebytes) C:\Users\user\Downloads\AdwCleaner.exe
2021-06-27 18:59 - 2021-06-28 20:56 - 000000000 ____D C:\FRST
2021-06-27 18:58 - 2021-06-27 18:58 - 002300416 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2021-06-26 19:09 - 2021-06-26 19:09 - 000411216 _____ C:\Users\user\Desktop\cc_20210626_190917.reg
2021-06-26 18:11 - 2021-06-26 18:11 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-06-26 18:11 - 2021-06-26 18:11 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-06-26 18:11 - 2021-06-26 18:11 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-06-26 18:11 - 2021-06-26 18:11 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-06-26 18:11 - 2021-06-26 18:11 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-06-26 18:10 - 2021-06-26 18:10 - 000000000 ____D C:\Program Files\Malwarebytes
2021-06-26 16:41 - 2021-06-26 16:41 - 000000000 ____D C:\Users\user\AppData\Local\Kaspersky Lab
2021-06-26 16:20 - 2021-06-26 16:20 - 000309104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2021-06-26 16:19 - 2021-06-26 16:19 - 000003192 _____ C:\WINDOWS\system32\Tasks\kpm_tray.exe
2021-06-26 16:19 - 2021-06-26 16:19 - 000000000 ____D C:\Users\Default\AppData\Local\Kaspersky Lab
2021-06-26 16:19 - 2021-06-26 16:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2021-06-26 16:18 - 2021-06-26 16:18 - 000263888 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2021-06-26 16:18 - 2021-06-26 16:18 - 000224880 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2021-06-26 16:18 - 2021-06-26 16:18 - 000115744 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2021-06-26 16:18 - 2021-06-26 16:18 - 000003392 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2021-06-26 16:18 - 2021-06-26 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Cloud
2021-06-26 16:18 - 2021-06-26 16:18 - 000000000 ____D C:\Program Files\Common Files\AV
2021-06-26 16:18 - 2021-02-19 21:09 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2021-06-26 16:18 - 2021-02-19 21:08 - 001042712 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2021-06-26 16:18 - 2021-02-19 21:08 - 000514840 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2021-06-24 19:24 - 2021-06-26 16:19 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2021-06-24 19:24 - 2021-06-26 16:19 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2021-06-24 19:24 - 2021-06-24 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Safe Kids
2021-06-24 19:24 - 2021-05-14 16:32 - 000985352 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klifks.sys
2021-06-24 19:24 - 2021-05-14 16:32 - 000527112 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klfltks.sys
2021-06-23 23:09 - 2021-06-23 23:09 - 000000064 _____ C:\Users\user\Desktop\Do All Religions Share Faith in One God- - OrthoChristian.Com.url
2021-06-14 23:16 - 2021-06-14 23:16 - 000021992 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_42301891746903.dll
2021-06-10 23:03 - 2021-06-09 05:58 - 000037664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2021-06-10 22:51 - 2021-06-09 16:18 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-06-10 22:51 - 2021-06-09 16:18 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-06-10 22:51 - 2021-06-09 16:18 - 001453328 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-06-10 22:51 - 2021-06-09 16:18 - 001435856 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-06-10 22:51 - 2021-06-09 16:18 - 001435856 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-06-10 22:51 - 2021-06-09 16:18 - 001192720 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-06-10 22:51 - 2021-06-09 16:18 - 001094864 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-06-10 22:51 - 2021-06-09 16:18 - 001094864 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-06-10 22:51 - 2021-06-09 16:18 - 000948936 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-06-10 22:51 - 2021-06-09 16:18 - 000948936 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-06-10 22:51 - 2021-06-09 16:14 - 000715552 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-06-10 22:51 - 2021-06-09 16:14 - 000626976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2021-06-10 22:51 - 2021-06-09 16:14 - 000575776 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 002106128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 001590544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 001514768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 001166096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 000811792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 000689936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2021-06-10 22:51 - 2021-06-09 16:13 - 000675088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 000656160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-06-10 22:51 - 2021-06-09 16:13 - 000563984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-06-10 22:51 - 2021-06-09 16:12 - 008317232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-06-10 22:51 - 2021-06-09 16:12 - 007434016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-06-10 22:51 - 2021-06-09 16:12 - 004795184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-06-10 22:51 - 2021-06-09 16:12 - 002823472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-06-10 22:51 - 2021-06-09 16:12 - 000445744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2021-06-10 22:51 - 2021-06-09 16:11 - 000848672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2021-06-10 22:51 - 2021-06-09 16:10 - 006159144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-06-10 22:51 - 2021-06-09 05:58 - 000087164 _____ C:\WINDOWS\system32\nvinfo.pb
2021-06-09 21:06 - 2021-06-09 21:06 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-06-09 21:06 - 2021-06-09 21:06 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-06-09 21:06 - 2021-06-09 21:06 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-06-09 21:06 - 2021-06-09 21:06 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-06-09 21:05 - 2021-06-09 21:05 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2021-06-09 21:05 - 2021-06-09 21:05 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2021-06-09 21:05 - 2021-06-09 21:05 - 001823792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-06-09 21:05 - 2021-06-09 21:05 - 001393496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-06-09 21:05 - 2021-06-09 21:05 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-06-09 21:05 - 2021-06-09 21:05 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-06-09 21:05 - 2021-06-09 21:05 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-06-09 21:05 - 2021-06-09 21:05 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-06-09 21:05 - 2021-06-09 21:05 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-06-09 21:05 - 2021-06-09 21:05 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2021-06-09 21:05 - 2021-06-09 21:05 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-06-09 21:05 - 2021-06-09 21:05 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-06-09 21:05 - 2021-06-09 21:05 - 000097280 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-06-09 21:05 - 2021-06-09 21:05 - 000011353 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-06-06 00:01 - 2021-06-06 01:42 - 000000000 ____D C:\Users\user\AppData\Roaming\EasyAntiCheat
2021-06-03 20:52 - 2021-05-31 18:09 - 005678880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-28 20:54 - 2018-01-02 19:43 - 000000000 ____D C:\Program Files (x86)\Steam
2021-06-28 20:37 - 2020-10-06 05:32 - 001785598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-06-28 20:37 - 2019-12-07 17:09 - 000789842 _____ C:\WINDOWS\system32\perfh010.dat
2021-06-28 20:37 - 2019-12-07 17:09 - 000151104 _____ C:\WINDOWS\system32\perfc010.dat
2021-06-28 20:37 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-06-28 20:33 - 2018-01-03 20:01 - 000000000 ____D C:\Program Files\CCleaner
2021-06-28 20:32 - 2017-12-29 19:02 - 000000000 ____D C:\ProgramData\NVIDIA
2021-06-28 20:31 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-28 20:30 - 2020-10-05 03:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-06-28 20:30 - 2020-10-05 03:30 - 000008192 ___SH C:\DumpStack.log.tmp
2021-06-28 20:30 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-06-28 20:30 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-06-28 20:28 - 2020-01-20 23:50 - 000009589 _____ C:\WINDOWS\SysWOW64\hosttmp1
2021-06-28 19:20 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-06-28 18:54 - 2020-10-05 03:35 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-06-28 18:35 - 2017-12-29 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2021-06-28 18:35 - 2017-12-29 19:04 - 000000000 ____D C:\Program Files\CPUID
2021-06-27 19:05 - 2018-01-05 20:39 - 000000000 ____D C:\Users\user\AppData\Roaming\Telegram Desktop
2021-06-27 18:58 - 2018-01-16 01:09 - 000000000 ____D C:\Users\user\Downloads\Telegram Desktop
2021-06-27 18:55 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-06-27 18:51 - 2020-07-03 20:48 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-06-26 20:06 - 2020-10-05 03:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-06-26 19:13 - 2018-01-03 19:57 - 000000000 ____D C:\Users\user\AppData\Local\NVIDIA
2021-06-26 19:12 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-06-26 19:10 - 2019-01-01 16:50 - 000191776 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2021-06-26 19:10 - 2019-01-01 16:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2021-06-26 19:10 - 2019-01-01 16:49 - 000000000 ____D C:\Program Files\Java
2021-06-26 18:11 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-06-26 17:57 - 2021-02-19 21:09 - 000096008 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2021-06-26 16:25 - 2021-02-17 00:07 - 000000000 ____D C:\Users\user\Desktop\importazione
2021-06-26 16:18 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-06-26 16:14 - 2017-12-29 19:01 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-06-26 15:30 - 2018-01-03 01:20 - 000000000 ____D C:\Program Files\Opera
2021-06-26 05:51 - 2020-10-04 20:19 - 000000000 ___DC C:\WINDOWS\Panther
2021-06-26 05:51 - 2018-01-08 22:47 - 000000000 ____D C:\Users\user\AppData\Local\CrashDumps
2021-06-24 19:27 - 2020-10-05 03:35 - 000004160 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1582753193
2021-06-21 20:11 - 2020-10-05 03:35 - 000003954 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1514935286
2021-06-21 20:11 - 2018-01-03 01:21 - 000001113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Opera.lnk
2021-06-20 13:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-06-15 02:08 - 2020-10-04 23:00 - 000000000 ____D C:\Users\user
2021-06-14 23:50 - 2018-03-01 19:43 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-06-10 22:48 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-06-10 22:45 - 2020-10-05 03:30 - 000438648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-06-10 03:08 - 2019-12-07 17:12 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-06-10 03:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-06-10 03:04 - 2020-05-09 19:50 - 000000000 ____D C:\Users\user\Desktop\sticker freki
2021-06-09 20:55 - 2017-12-29 19:13 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-06-09 20:54 - 2018-01-02 21:00 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-06-09 20:52 - 2018-01-02 21:00 - 132447432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-06-09 16:10 - 2020-08-30 00:23 - 007212216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-06-09 05:58 - 2020-08-30 00:23 - 000136472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2021-06-06 02:02 - 2019-12-04 23:50 - 000000000 ____D C:\Users\user\AppData\LocalLow\MCC
2021-06-05 20:48 - 2017-12-29 19:00 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-06-04 17:46 - 2020-10-02 00:11 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-06-03 21:04 - 2018-12-23 15:06 - 000000000 ____D C:\ProgramData\Packages
2021-06-03 21:04 - 2018-01-08 19:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2021-06-03 21:04 - 2017-12-29 17:59 - 000000000 ____D C:\Users\user\AppData\Local\Packages
2021-06-03 21:02 - 2017-12-29 19:02 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2021-05-30 13:46 - 2020-03-14 08:11 - 000000000 ____D C:\Users\user\Desktop\L'Offerta del Mattino