PDA

View Full Version : ROOTKIT fantasma


luigi27
06-12-2015, 23:11
Salve Ho avuto un problema strano.
Ho fatto scansione con avast di sstema ed p risultato presente un rootkit su due file ( altri tre siili non letti da avast per impossibilta'). Ho provato a seguire la procedura ma è uscito solo un messaggioid errore 8Impossibile eliinarli o in qurantena). I file infetti erano di ccleaner in quell'istante.
Il istema operativo è windows 8.1.Esattamente avast diceva :
C:Program FIles\CCleaner\Lang|lang-1035.dll
" " " " 1063.dll

sospetti 1040 1030 2070.dll

Minaccia:Rootkit:hidden file minaccia elevata

Dopo poco che scaricavo tool antirootkit il computer ha inviato un messaggio di necessità si spegnimento.

Ho scollegato internet per impedire altro al rootkit.
ho scansionato ni modalita' provvisoria con tutti i tool che ho potuto scaricare ma nno hanno trovato nulla(malware bite, malware beta, aswmbr, tdskiller, kasperky tool antivirus, ifine rkill ma non hanno trovato nulla) Avast in modalita' provvisoria non funzionava.
Riavviato in modalità normale tramite msconfg (F8 non sembra dare effetti) avast apparentemente funzionava ma non scaricava aggiornamenti con messaggio di errore. Ho disinstallato ccleaner presunto infetto che poi aveva perso l alingua italiana e ho reinstallato, ora funziona regolarmente.
Ho scansionato ancora con i tool di nuovo in modalita' normale senza torvare nulla. Ho reinstallato avast e adesso funziona regolarmente. Ho scansionato il sistema con avast e non sono risultati virus o rootkit.
Inivo se possibile per un esame di nu esperto, il log fatto con Hjaking
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 22:17:34, on 06/12/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)

FIREFOX: 42.0 (x86 it)
Boot mode: Normal

Running processes:
C:\Users\Luigi\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Unknown owner - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: MIDISPORT Audio Device Monitor (MIDISPORTAudioDevMon) - M-Audio - C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - Sandboxie Holdings, LLC - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6652 bytes

grazie fin da ora per eventuali consigli

Da quello che capisco mi mancano alcuni file di sistema....posso provare a ripristinarli mediante il tool tweaking windows repair ola funzione ripair di windows 8.1 ma non so se conviene o meno...

Avatar utente
luigi27
Neo Iscritto
Neo Iscritto

Messaggi: 1
Iscritto il: dom dic 06, 2015 10:31 pm

Top

menatwork
07-12-2015, 00:51
ciao inutile postare hjt perche' anche se ci fosse la presenza di un rootkit il tool non la rileva
per caso ultimamente hai rimosso ccleaner e poi reinstallato? potrebbe essere un falso rilevato da avast, succede con tutti gli antivirus... allega i log di tdskiller e aswmbr poi fai questa scansione

scarica farbar-recovery (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) e mettilo sul desktop


Devi scaricare la versione(32 o 64 bit compatibile con il tuo sistema)

Avvialo e clicca su yes quando ti chiede di accettare le condizioni

Clicca su SCAN

Una volta terminata la scansione il tool creerà nella stessa directory di dove è posizionato FRST un log chiamato FRST.txt.

Allegalo nella tua prossima risposta

luigi27
07-12-2015, 09:30
Ok grazie Allora....ho installato periodicamente ccleaner quando aggiorna ma ho anche ameggiato con keygen analizate con virus total e con un po' di rilevamenti ....ma in zona sandboxie, quindi motivi per avere qualcosa ci sarebbero....ad ogni modo ho fatto la scansione sopra detta e posto il link della scansione:http://www.wikifortio.com/771570/FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
Ran by Luigi (administrator) on PC (07-12-2015 10:23:11)
Running from C:\Users\Luigi\Desktop
Loaded Profiles: Luigi (Available Profiles: Luigi)
Platform: Windows 8.1 (X64) Language: Italiano (Italia)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(M-Audio) C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-11-12] (IvoSoft)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-06] (AVAST Software)
HKU\S-1-5-21-1461667933-2917687346-235261616-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-06] (AVAST Software)
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] ()
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] ()
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] ()
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1 activation.acronis.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5D0B3462-2CD9-40F4-9F25-8DC51C2B3167}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-06] (AVAST Software)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-11-12] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-06] (AVAST Software)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-11-12] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)

FireFox:
========
FF ProfilePath: C:\Users\Luigi\AppData\Roaming\Mozilla\Firefox\Profiles\xg07ijjq.default
FF Extension: Adblock Plus - C:\Users\Luigi\AppData\Roaming\Mozilla\Firefox\Profiles\xg07ijjq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-27]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-06]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-06]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-06] (AVAST Software)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [0 2015-10-05] () <==== ATTENTION (zero byte File/Folder)
R2 MIDISPORTAudioDevMon; C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe [1638704 2012-02-24] (M-Audio)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [177800 2015-10-22] (Sandboxie Holdings, LLC)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-09-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-09-24] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-06] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-06] (AVAST Software)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 Echo24; C:\Windows\system32\drivers\echo24.sys [572712 2011-12-07] (Echo Digital Audio Corp.)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
S3 MADFUMIDISPORT2010; C:\Windows\System32\drivers\MAudioMIDISPORT_DFU.sys [30512 2012-02-24] (M-Audio)
R3 MAUSBMIDISPORT; C:\Windows\system32\DRIVERS\MAudioMIDISPORT.sys [201008 2012-02-24] (M-Audio)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] ()
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [0 2015-10-05] () <==== ATTENTION (zero byte File/Folder)
R3 mlkumidi; C:\Windows\system32\drivers\mlkumidi.sys [57408 2012-08-29] (MusicLab, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [192648 2015-10-22] (Sandboxie Holdings, LLC)
R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2015-11-27] (Acronis International GmbH)
R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [198432 2015-11-27] (Acronis International GmbH)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-09-24] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-09-24] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-09-24] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-07 10:23 - 2015-12-07 10:23 - 00009653 _____ C:\Users\Luigi\Desktop\FRST.txt
2015-12-07 10:23 - 2015-12-07 10:23 - 00000000 ____D C:\FRST
2015-12-07 10:22 - 2015-12-07 10:20 - 02369024 _____ (Farbar) C:\Users\Luigi\Desktop\FRST64.exe
2015-12-07 10:20 - 2015-12-07 10:20 - 02369024 _____ (Farbar) C:\Users\Luigi\Downloads\FRST64.exe
2015-12-06 15:39 - 2015-12-06 15:37 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-06 15:37 - 2015-12-06 15:39 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-06 15:37 - 2015-12-06 15:37 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-06 15:37 - 2015-12-06 15:37 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-06 15:37 - 2015-12-06 15:37 - 00001938 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-12-06 15:37 - 2015-12-06 15:37 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\AVAST Software
2015-12-06 15:37 - 2015-12-06 15:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-12-06 15:34 - 2015-12-06 15:34 - 00000000 ____D C:\Program Files\AVAST Software
2015-12-06 15:33 - 2015-12-06 15:33 - 05066096 _____ (AVAST Software) C:\Users\Luigi\Downloads\avast_free_antivirus_setup_online.exe
2015-12-06 12:02 - 2015-12-06 12:02 - 00000000 ____D C:\KVRT_Data
2015-12-06 02:33 - 2015-12-06 02:33 - 00002778 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-12-06 02:33 - 2015-12-06 02:33 - 00000834 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-06 02:33 - 2015-12-06 02:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-12-06 02:28 - 2015-12-06 02:29 - 95957160 _____ (Kaspersky Lab ZAO) C:\Users\Luigi\Downloads\KVRT.exe
2015-12-06 02:15 - 2015-12-06 02:17 - 00606644 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_02.15.10_log.txt
2015-12-06 02:12 - 2015-12-06 02:13 - 00004284 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_02.12.47_log.txt
2015-12-06 01:59 - 2015-12-06 02:10 - 00202776 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_01.59.44_log.txt
2015-12-06 01:34 - 2015-12-06 01:34 - 00004426 _____ C:\Users\Luigi\Desktop\Rkill.txt
2015-12-06 01:33 - 2015-12-06 01:34 - 00004014 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_01.33.46_log.txt
2015-12-06 00:45 - 2015-12-06 00:55 - 00000000 ____D C:\Users\Luigi\Desktop\mbar
2015-12-06 00:45 - 2015-12-06 00:55 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-12-06 00:41 - 2015-12-06 00:43 - 00839248 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_00.41.19_log.txt
2015-12-06 00:37 - 2015-12-06 00:39 - 00004280 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_00.37.58_log.txt
2015-12-06 00:36 - 2015-12-06 00:36 - 00000000 ____D C:\Windows\pss
2015-12-06 00:29 - 2015-12-06 02:34 - 00000000 ____D C:\Windows\Minidump
2015-12-06 00:25 - 2015-12-06 00:25 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Luigi\Downloads\mbar-1.09.3.1001.exe
2015-12-06 00:21 - 2015-12-06 00:21 - 05200384 _____ (AVAST Software) C:\Users\Luigi\Downloads\aswmbr.exe
2015-12-06 00:13 - 2015-12-06 00:25 - 00007631 _____ C:\Users\Luigi\Desktop\COME USARE ANTIROOTKIT TOOLS.txt
2015-12-06 00:03 - 2015-12-06 00:05 - 00000154 _____ C:\Users\Luigi\Desktop\Rootkit.txt
2015-12-04 13:05 - 2015-12-04 13:05 - 00000016 _____ C:\Windows\system32\w3data.vss
2015-12-04 13:05 - 2015-12-04 13:05 - 00000016 _____ C:\Windows\system32\msvcsv60.dll
2015-12-04 13:05 - 2015-12-04 13:05 - 00000000 ____D C:\Users\Luigi\Documents\jBridge
2015-12-04 12:58 - 2015-12-04 12:58 - 00001682 _____ C:\Users\Luigi\Desktop\SampleTank 3 - collegamento.lnk
2015-12-04 11:26 - 2015-12-04 11:26 - 00000000 ____D C:\Users\Public\Documents\IK Multimedia
2015-12-04 11:25 - 2015-12-04 11:25 - 00000000 ____D C:\Program Files\IK Multimedia
2015-12-04 11:25 - 2015-12-04 11:25 - 00000000 ____D C:\Program Files\Common Files\VST3
2015-12-04 11:25 - 2012-08-29 13:23 - 00348160 _____ (Microsoft Corporation) C:\Windows\msvcr71.dll
2015-12-04 11:14 - 2015-12-04 11:14 - 00000833 _____ C:\Users\Luigi\Desktop\jBridger.lnk
2015-12-04 11:12 - 2015-12-04 11:12 - 00001055 _____ C:\Users\Public\Desktop\qBittorrent.lnk
2015-12-04 11:12 - 2015-12-04 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2015-12-04 11:12 - 2015-12-04 11:12 - 00000000 ____D C:\Program Files (x86)\qBittorrent
2015-12-04 11:10 - 2015-12-04 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jBridge
2015-12-04 11:10 - 2015-12-04 11:10 - 00000000 ____D C:\Program Files\JBridge
2015-12-04 10:57 - 2015-12-04 10:57 - 14226226 _____ (The qBittorrent project) C:\Users\Luigi\Downloads\qbittorrent_3.3.0_setup.exe
2015-12-03 21:04 - 2015-12-04 00:10 - 00000000 ____D C:\Program Files (x86)\Spectrasonics
2015-12-03 14:48 - 2015-12-03 14:48 - 00001305 _____ C:\Users\Luigi\Desktop\Z3TA+ 2.lnk
2015-12-03 14:48 - 2015-12-03 14:48 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cakewalk
2015-12-03 14:36 - 2015-12-03 14:36 - 00000000 ____D C:\Users\Luigi\AppData\Local\Spectrasonics
2015-12-03 14:36 - 2015-12-03 14:36 - 00000000 ____D C:\ProgramData\Note
2015-12-03 14:30 - 2015-12-03 14:30 - 00000000 ___RD C:\Sandbox
2015-12-03 14:21 - 2015-12-05 01:07 - 00003232 _____ C:\Windows\Sandboxie.ini
2015-12-03 14:21 - 2015-12-03 21:42 - 00001314 _____ C:\Users\Luigi\Desktop\Browser Web nell'area virtuale.lnk
2015-12-03 14:21 - 2015-12-03 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2015-12-03 14:21 - 2015-12-03 14:21 - 00000000 ____D C:\Program Files\Sandboxie
2015-12-03 14:20 - 2015-12-03 14:21 - 08518280 _____ (Sandboxie Holdings, LLC) C:\Users\Luigi\Downloads\SandboxieInstall.exe
2015-12-03 14:12 - 2015-12-03 14:12 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2015-12-03 14:12 - 2015-12-03 14:12 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-03 13:46 - 2015-12-03 13:46 - 00001820 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\SUPERAntiSpyware.com
2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-12-03 13:44 - 2015-12-03 13:44 - 24014984 _____ (SUPERAntiSpyware) C:\Users\Luigi\Downloads\SAS_4905.EXE
2015-12-03 12:31 - 2015-12-03 12:31 - 00000000 ____D C:\Trilian
2015-12-03 12:28 - 2015-12-03 14:34 - 00000000 ____D C:\ProgramData\Spectrasonics
2015-12-03 12:28 - 2015-12-03 12:28 - 00000000 ____D C:\Program Files\Cakewalk
2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\MusicLab
2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Users\Luigi\AppData\Local\MusicLab
2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\ProgramData\MusicLab
2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicLab
2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Program Files\MusicLab
2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Program Files (x86)\MusicLab
2015-12-02 01:14 - 2015-12-02 01:14 - 00000000 ____D C:\Program Files\Common Files\MusicLab
2015-12-02 00:48 - 2015-12-02 00:48 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-02 00:42 - 2015-12-02 01:16 - 00000000 ____D C:\Users\Luigi\Documents\Addictive Drums 2 Logs
2015-12-02 00:42 - 2015-12-02 00:42 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Addictive Drums 2
2015-12-02 00:41 - 2015-12-02 00:47 - 00001273 _____ C:\Users\Luigi\Desktop\Addictive Drums 2.lnk
2015-12-02 00:41 - 2015-12-02 00:44 - 00000000 ____D C:\ProgramData\XLN Audio
2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Users\Luigi\Documents\XLN Online Installer
2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Users\Luigi\Documents\Addictive Drums 2
2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XLN Audio
2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Program Files (x86)\XLN Audio
2015-12-01 16:52 - 2015-12-01 16:54 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Ample Sound
2015-12-01 16:52 - 2015-12-01 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ample Sound
2015-12-01 16:51 - 2015-12-01 16:52 - 00000000 ____D C:\Program Files\Ample Sound
2015-12-01 16:51 - 2015-12-01 16:51 - 00000000 ____D C:\Program Files\Common Files\Avid
2015-11-30 15:14 - 2015-11-30 15:14 - 03802952 _____ (Reason Software Company Inc.) C:\Users\Luigi\Downloads\reason-core-security-setup.exe
2015-11-30 15:00 - 2015-11-30 15:00 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\Luigi\Downloads\rkill.com
2015-11-30 14:58 - 2015-11-30 14:58 - 04398264 _____ (Kaspersky Lab ZAO) C:\Users\Luigi\Downloads\tdsskiller.exe
2015-11-30 14:30 - 2015-11-30 14:30 - 00388608 _____ (Trend Micro Inc.) C:\Users\Luigi\Desktop\HijackThis.exe
2015-11-29 15:02 - 2015-12-04 13:43 - 00000000 ____D C:\Users\Luigi\Documents\ISTRUZIONI PER
2015-11-29 14:53 - 2015-12-04 13:05 - 00000032 _____ C:\Users\Luigi\AppData\Roaming\msregsvv.dll
2015-11-29 14:53 - 2015-12-04 13:05 - 00000032 _____ C:\ProgramData\autobk.inc
2015-11-29 14:32 - 2015-12-04 13:05 - 00000032 _____ C:\Windows\msocreg32.dat
2015-11-29 14:32 - 2015-12-04 11:26 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\IK Multimedia
2015-11-29 14:32 - 2015-11-29 16:37 - 00001239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Authorization Manager.lnk
2015-11-29 14:32 - 2015-11-29 16:37 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SampleTank 2.5.lnk
2015-11-29 14:32 - 2015-11-29 16:37 - 00000016 _____ C:\Windows\SysWOW64\w3data.vss
2015-11-29 14:32 - 2015-11-29 16:37 - 00000016 _____ C:\Windows\SysWOW64\msvcsv60.dll
2015-11-29 14:32 - 2015-11-29 14:32 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-11-29 14:31 - 2015-11-29 14:31 - 00000000 ____D C:\ProgramData\IK Multimedia
2015-11-29 13:31 - 2015-11-29 13:31 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rob Papen
2015-11-29 13:31 - 2015-11-29 13:31 - 00000000 ____D C:\Program Files (x86)\Rob Papen
2015-11-29 01:10 - 2015-11-29 01:00 - 02405584 _____ (Trend Micro Inc.) C:\Users\Luigi\Desktop\HousecallLauncher64.exe
2015-11-29 01:09 - 2015-11-29 01:10 - 00000000 _____ C:\Users\Luigi\AppData\Local\census.cache
2015-11-29 01:09 - 2015-11-29 01:10 - 00000000 _____ C:\Users\Luigi\AppData\Local\ars.cache
2015-11-29 01:00 - 2015-11-29 01:00 - 02405584 _____ (Trend Micro Inc.) C:\Users\Luigi\Downloads\HousecallLauncher64.exe
2015-11-29 01:00 - 2015-11-29 01:00 - 00000036 _____ C:\Users\Luigi\AppData\Local\housecall.guid.cache
2015-11-29 00:59 - 2015-11-29 00:59 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\QuickScan
2015-11-29 00:39 - 2015-12-02 01:03 - 00000000 ____D C:\Users\Luigi\Desktop\BLU 2
2015-11-28 23:42 - 2015-11-30 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX
2015-11-28 23:34 - 2015-11-28 23:34 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IK Multimedia
2015-11-28 23:34 - 2015-11-28 23:34 - 00000000 ____D C:\Program Files (x86)\Digidesign
2015-11-28 23:31 - 2015-11-28 23:31 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TCWorks
2015-11-28 23:31 - 2015-11-28 23:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TCWorks
2015-11-28 23:31 - 2015-11-28 23:31 - 00000000 ____D C:\Program Files (x86)\TCWorks
2015-11-28 23:31 - 2010-10-08 16:09 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2015-11-28 23:25 - 2015-11-28 23:25 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2015-11-28 23:23 - 2015-12-04 11:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IK Multimedia
2015-11-28 23:23 - 2012-12-04 16:26 - 04249197 _____ (IK Multimedia ) C:\Windows\SysWOW64\WIN Installer Authorization Manager (Ver. 1.0.9 RC4).exe
2015-11-28 23:23 - 2012-11-30 19:43 - 08600667 _____ (IK Multimedia ) C:\Windows\SysWOW64\CustomShopInstallerTR4.exe
2015-11-28 23:23 - 2012-08-29 12:23 - 12708016 _____ (Intel Corporation) C:\Windows\system32\mkl_def.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 12474544 _____ (Intel Corporation) C:\Windows\system32\mkl_core.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 09917616 _____ (Intel Corporation) C:\Windows\system32\mkl_intel_thread.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 09410736 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4m.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 09210032 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 09078960 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4p.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 09033904 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4m3.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 06944944 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_core.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 03868848 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_intel_thread.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 00530608 _____ (Intel Corporation) C:\Windows\SysWOW64\libiomp5md.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 00529072 _____ (Intel Corporation) C:\Windows\system32\libiomp5md.dll
2015-11-28 23:23 - 2012-08-29 12:23 - 00499712 ____N (Microsoft Corporation) C:\Windows\msvcp71.dll
2015-11-28 23:23 - 2010-10-08 16:09 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2015-11-28 23:22 - 2015-12-04 11:25 - 00000000 ____D C:\Program Files\VstPlugIns
2015-11-28 23:22 - 2015-11-29 14:31 - 00000000 ____D C:\Program Files (x86)\IK Multimedia
2015-11-28 23:22 - 2015-11-28 23:24 - 00000000 ____D C:\Users\Luigi\Documents\IK Multimedia
2015-11-28 23:22 - 2015-11-28 23:22 - 00000000 ____D C:\Program Files (x86)\VstPlugIns
2015-11-28 01:40 - 2015-11-28 01:40 - 00000000 ____D C:\Users\Public\Documents\NI Resources
2015-11-28 01:32 - 2015-11-28 01:32 - 00001030 _____ C:\Users\Public\Desktop\Kontakt 5.lnk
2015-11-28 01:32 - 2015-11-28 01:32 - 00000000 __HDC C:\ProgramData\{1DC78BF5-AFEA-45C8-9EFE-C64A1962F937}
2015-11-28 01:31 - 2015-11-28 01:32 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-28 00:52 - 2015-11-28 01:32 - 00000000 ____D C:\Users\Luigi\Documents\Native Instruments
2015-11-28 00:52 - 2015-11-28 00:52 - 00000000 ____D C:\Users\Luigi\AppData\Local\Native Instruments
2015-11-28 00:51 - 2015-11-28 01:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2015-11-28 00:51 - 2015-11-28 01:32 - 00000000 ____D C:\Program Files\Native Instruments
2015-11-28 00:51 - 2015-11-28 00:51 - 00001075 _____ C:\Users\Public\Desktop\Service Center.lnk
2015-11-28 00:51 - 2015-11-28 00:51 - 00000000 __HDC C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
2015-11-28 00:51 - 2015-11-28 00:51 - 00000000 ____D C:\ProgramData\Native Instruments
2015-11-28 00:51 - 2015-11-28 00:51 - 00000000 ____D C:\Program Files\Common Files\Native Instruments
2015-11-27 16:01 - 2015-11-27 16:01 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\VST3 Presets
2015-11-27 16:00 - 2010-01-16 23:27 - 02440704 _____ (AD © 2010) C:\Windows\SysWOW64\SYNSOEMU.DLL
2015-11-27 15:59 - 2015-11-27 15:59 - 00000000 ____D C:\ProgramData\VST3 Presets
2015-11-27 15:58 - 2015-12-03 21:39 - 00000000 ____D C:\Program Files (x86)\Steinberg
2015-11-27 15:58 - 2015-11-27 16:01 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Steinberg
2015-11-27 15:58 - 2015-11-27 16:00 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg Cubase 5
2015-11-27 15:58 - 2015-11-27 15:58 - 00002146 _____ C:\Users\Luigi\Desktop\Cubase 5.lnk
2015-11-27 15:58 - 2015-11-27 15:58 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg HALionOne
2015-11-27 15:58 - 2015-11-27 15:58 - 00000000 ____D C:\ProgramData\Steinberg
2015-11-27 15:55 - 2015-11-27 15:55 - 00001019 _____ C:\Users\Public\Desktop\UltraISO.lnk
2015-11-27 15:55 - 2015-11-27 15:55 - 00000000 ____D C:\Users\Luigi\Documents\My ISO Files
2015-11-27 15:55 - 2015-11-27 15:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO
2015-11-27 15:55 - 2015-11-27 15:55 - 00000000 ____D C:\Program Files (x86)\UltraISO
2015-11-27 15:42 - 2015-11-27 15:42 - 00001332 _____ C:\Users\Luigi\Desktop\WinRAR - collegamento.lnk
2015-11-27 15:36 - 2015-11-27 15:36 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-27 15:36 - 2015-11-27 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-27 15:12 - 2015-12-06 02:33 - 00000000 ____D C:\Program Files\CCleaner
2015-11-27 15:05 - 2015-11-27 15:38 - 00000000 ____D C:\Program Files\WinRAR
2015-11-27 15:05 - 2015-11-27 15:05 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\WinRAR
2015-11-27 14:59 - 2015-12-04 11:18 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\qBittorrent
2015-11-27 14:59 - 2015-11-27 14:59 - 00000000 ____D C:\Users\Luigi\AppData\Local\qBittorrent
2015-11-27 14:44 - 2015-12-07 10:15 - 00001679 _____ C:\Echo PCI driver log.txt
2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\M-Audio
2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\ProgramData\AVID
2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\Program Files\M-Audio
2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\Program Files (x86)\M-Audio
2015-11-27 14:40 - 2015-11-27 14:40 - 00001150 _____ C:\Users\Public\Desktop\Echo24 Console.lnk
2015-11-27 14:40 - 2015-11-27 14:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Echo Digital Audio
2015-11-27 14:40 - 2015-11-27 14:40 - 00000000 ____D C:\Program Files (x86)\Echo Digital Audio
2015-11-27 11:49 - 2015-11-27 11:49 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Acronis
2015-11-27 11:45 - 2015-11-27 12:55 - 00000000 ____D C:\ProgramData\Acronis
2015-11-27 11:45 - 2015-11-27 11:45 - 01464096 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tdrpman.sys
2015-11-27 11:45 - 2015-11-27 11:45 - 01120032 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tib.sys
2015-11-27 11:45 - 2015-11-27 11:45 - 00367200 _____ (Acronis) C:\Windows\system32\Drivers\afcdp.sys
2015-11-27 11:45 - 2015-11-27 11:45 - 00269600 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\snapman.sys
2015-11-27 11:45 - 2015-11-27 11:45 - 00198432 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tib_mounter.sys
2015-11-27 11:45 - 2015-11-27 11:45 - 00116000 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\fltsrv.sys
2015-11-27 11:45 - 2015-11-27 11:45 - 00001217 _____ C:\Users\Public\Desktop\Acronis True Image 2014.lnk
2015-11-27 11:45 - 2015-11-27 11:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
2015-11-27 11:44 - 2015-11-27 11:44 - 00000000 ____D C:\Program Files (x86)\Acronis
2015-11-27 10:53 - 2015-11-27 10:53 - 08849283 _____ C:\Users\Luigi\Downloads\ATIH2014_userguide_it-IT.pdf
2015-11-27 10:45 - 2015-11-27 10:45 - 00000144 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-27 01:41 - 2015-11-27 01:41 - 00001758 _____ C:\Users\Luigi\Desktop\OnlineScannerApp - collegamento.lnk
2015-11-27 01:28 - 2015-12-07 10:15 - 00000000 __SHD C:\Users\Luigi\IntelGraphicsProfiles
2015-11-27 01:28 - 2015-11-27 01:28 - 00000451 _____ C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2015-11-27 00:52 - 2015-11-27 00:52 - 00000000 ____D C:\Program Files (x86)\ESET
2015-11-27 00:44 - 2015-12-06 22:52 - 00000000 ____D C:\Users\Luigi\AppData\Local\ClassicShell
2015-11-27 00:43 - 2015-11-27 00:43 - 00000000 ____D C:\ProgramData\ClassicShell
2015-11-27 00:43 - 2015-11-27 00:42 - 00002170 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\startscreen.lnk
2015-11-27 00:42 - 2015-11-27 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2015-11-27 00:42 - 2015-11-27 00:42 - 00000000 ____D C:\Program Files\Classic Shell
2015-11-27 00:41 - 2015-11-27 00:41 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-11-27 00:31 - 2015-12-06 01:42 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-27 00:31 - 2015-12-06 00:45 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-11-27 00:31 - 2015-11-27 00:31 - 00001114 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-27 00:31 - 2015-11-27 00:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-27 00:31 - 2015-11-27 00:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-27 00:31 - 2015-11-27 00:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-27 00:31 - 2015-10-05 09:50 - 00025816 _____ C:\Windows\system32\Drivers\mbam.sys
2015-11-27 00:31 - 2015-10-05 09:50 - 00000000 _____ C:\Windows\system32\Drivers\mwac.sys
2015-11-27 00:18 - 2015-11-27 00:36 - 00000000 ____D C:\Users\Luigi\AppData\Local\Mozilla
2015-11-27 00:18 - 2015-11-27 00:26 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Mozilla
2015-11-27 00:18 - 2015-11-27 00:18 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-27 00:18 - 2015-11-27 00:18 - 00001159 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-27 00:18 - 2015-11-27 00:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-27 00:18 - 2015-11-27 00:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-26 23:58 - 2015-12-06 15:33 - 00000000 ____D C:\ProgramData\AVAST Software
2015-11-26 23:57 - 2015-12-07 10:20 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{7B5EEE9D-7363-4BD2-81F5-2770E6723DC5}
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\LocalLow\EmieUserList
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\LocalLow\EmieSiteList
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\Local\EmieUserList
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\Local\EmieSiteList
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Macromedia
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Users\Luigi\AppData\Local\GWX
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Program Files\Intel
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Program Files (x86)\Intel
2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Intel
2015-11-26 23:57 - 2015-08-27 18:20 - 00072704 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL
2015-11-26 23:57 - 2015-08-27 18:20 - 00069120 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL
2015-11-26 23:55 - 2015-12-06 16:30 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1461667933-2917687346-235261616-1001
2015-11-26 23:50 - 2015-12-06 00:36 - 00000000 ____D C:\Users\Luigi
2015-11-26 23:50 - 2015-12-03 23:20 - 00000000 ____D C:\Users\Luigi\AppData\Local\VirtualStore
2015-11-26 23:50 - 2015-11-28 23:19 - 00000000 ____D C:\Users\Luigi\AppData\Local\Packages
2015-11-26 23:50 - 2015-11-26 23:50 - 00001422 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-11-26 23:50 - 2015-11-26 23:50 - 00000020 ___SH C:\Users\Luigi\ntuser.ini
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Risorse di stampa
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Risorse di rete
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Recenti
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Modelli
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Menu Avvio
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Impostazioni locali
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documents\Video
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documents\Musica
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documents\Immagini
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documenti
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Dati applicazioni
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\AppData\Local\Dati applicazioni
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\AppData\Local\Cronologia
2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Adobe
2015-11-26 23:50 - 2014-09-24 16:07 - 00000369 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-11-26 23:50 - 2014-09-24 16:07 - 00000369 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-11-26 23:49 - 2015-11-26 23:51 - 00000000 ___SD C:\Windows\system32\GWX
2015-11-26 23:49 - 2015-11-26 23:49 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-11-26 23:47 - 2015-11-14 15:50 - 00133248 _____ (Microsoft Corporation) C:\Windows\system32\RestoreOptIn.exe
2015-11-26 23:47 - 2015-11-14 15:50 - 00114160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RestoreOptIn.exe
2015-11-26 23:47 - 2015-10-20 22:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-26 23:47 - 2015-10-20 15:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-26 23:47 - 2015-10-20 15:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-26 23:47 - 2015-10-20 15:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-26 23:47 - 2015-10-20 15:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-11-26 23:47 - 2015-10-20 15:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-26 23:47 - 2015-10-20 15:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-26 23:47 - 2015-10-20 15:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-26 23:47 - 2015-10-20 15:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-26 23:47 - 2015-10-20 15:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-26 23:47 - 2015-10-20 15:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-26 23:47 - 2015-10-20 15:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-26 23:47 - 2015-08-11 03:47 - 02757072 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-11-26 23:47 - 2015-08-11 03:47 - 02414096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-11-26 23:46 - 2015-07-09 19:40 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-26 23:46 - 2015-06-27 04:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-26 23:46 - 2015-06-27 04:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-26 23:46 - 2015-06-27 03:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-26 23:46 - 2015-03-14 02:51 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-26 23:46 - 2014-10-18 07:50 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Public\Documents\Video
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Public\Documents\Musica
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Public\Documents\Immagini
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Risorse di stampa
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Risorse di rete
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Recenti
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Modelli
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Menu Avvio
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Impostazioni locali
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documents\Video
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documents\Musica
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documents\Immagini
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documenti
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Dati applicazioni
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dati applicazioni
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\AppData\Local\Cronologia
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\Documents\Video
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\Documents\Musica
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\Documents\Immagini
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dati applicazioni
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Cronologia
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Programmi
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Modelli
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programmi
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Menu Avvio
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Documenti
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Dati applicazioni
2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Program Files\File comuni
2015-11-26 23:39 - 2015-11-27 16:06 - 00000000 ____D C:\Windows\Panther
2015-11-12 22:55 - 2015-11-12 22:55 - 00289216 _____ (IvoSoft) C:\Windows\system32\StartMenuHelper64.dll
2015-11-12 22:55 - 2015-11-12 22:55 - 00247744 _____ (IvoSoft) C:\Windows\SysWOW64\StartMenuHelper32.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-07 10:23 - 2013-08-22 14:36 - 00000000 ____D C:\Windows
2015-12-07 10:20 - 2014-09-24 16:06 - 01724056 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-07 10:20 - 2014-09-24 15:33 - 00766482 _____ C:\Windows\system32\perfh010.dat
2015-12-07 10:20 - 2014-09-24 15:33 - 00148702 _____ C:\Windows\system32\perfc010.dat
2015-12-07 10:20 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf
2015-12-07 10:15 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-05 02:05 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-12-01 16:52 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-11-29 10:57 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache
2015-11-28 23:24 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness
2015-11-28 22:50 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2015-11-27 16:59 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\LiveKernelReports
2015-11-27 00:11 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp
2015-11-26 23:47 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-11-26 23:44 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows NT
2015-11-26 23:39 - 2013-08-22 16:36 - 00262144 _____ C:\Windows\system32\config\BCD-Template

==================== Files in the root of some directories =======

2015-11-29 14:53 - 2015-12-04 13:05 - 0000032 _____ () C:\Users\Luigi\AppData\Roaming\msregsvv.dll
2015-11-29 01:09 - 2015-11-29 01:10 - 0000000 _____ () C:\Users\Luigi\AppData\Local\ars.cache
2015-11-29 01:09 - 2015-11-29 01:10 - 0000000 _____ () C:\Users\Luigi\AppData\Local\census.cache
2015-11-29 01:00 - 2015-11-29 01:00 - 0000036 _____ () C:\Users\Luigi\AppData\Local\housecall.guid.cache
2015-11-29 14:53 - 2015-12-04 13:05 - 0000032 _____ () C:\ProgramData\autobk.inc

Some zero byte size files/folders:
==========================
C:\Windows\System32\Drivers\mwac.sys

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-12-06 02:25

luigi27
07-12-2015, 09:33
nonch' l'addiction: http://www.wikifortio.com/703090/Addition.txt

luigi27
07-12-2015, 09:34
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by Luigi (2015-12-07 10:23:37)
Running from C:\Users\Luigi\Desktop
Windows 8.1 (X64) (2015-11-26 22:49:59)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1461667933-2917687346-235261616-500 - Administrator - Disabled)
Guest (S-1-5-21-1461667933-2917687346-235261616-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1461667933-2917687346-235261616-1003 - Limited - Enabled)
Luigi (S-1-5-21-1461667933-2917687346-235261616-1001 - Administrator - Enabled) => C:\Users\Luigi

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis True Image 2014 (HKLM-x32\...\{6607759B-0CDE-4106-B461-6371935EAB57}Visible) (Version: 17.0.6614 - Acronis)
Acronis True Image 2014 (x32 Version: 17.0.6614 - Acronis) Hidden
Ample Guitar M Lite version 1.1.7 (HKLM-x32\...\{BA6E19BD-02E5-4472-BE88-0D5FCFA0BA24}_is1) (Version: 1.1.7 - Ample Sound Technology Co., Ltd.)
AmpliTube 3 version 3.10.0 (HKLM\...\{DA5202AC-12BF-4330-B8EA-BC77F991FA1C}_is1) (Version: 3.10.0 - IK Multimedia)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2245 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
Classic Shell (HKLM\...\{D4B3454F-7529-4F5F-851D-2C36933F7D64}) (Version: 4.2.5 - IvoSoft)
Custom Shop version 1.1.0 (HKLM-x32\...\{21BAD046-50EC-49E2-BE7B-F9729704F2C3}_is1) (Version: 1.1.0 - IK Multimedia)
Echo24 PCI (HKLM-x32\...\Echo24 PCI) (Version: 8.6 - Echo Digital Audio)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
IK Multimedia Amplitube DX/VST/RTAS v2.0 (HKLM-x32\...\IK Multimedia Amplitube DX/VST/RTAS v2.0) (Version: - )
IK Multimedia Authorization Manager version 1.0.10 (HKLM\...\{85BC0DCB-69E5-4279-AA25-F108EF896588}_is1) (Version: 1.0.10 - IK Multimedia)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
JBridge (HKLM-x32\...\JBridge) (Version: - JBridge)
Malwarebytes Anti-Malware versione 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
M-Audio MIDISPORT 6.1.3 (x64) (HKLM\...\{AED2A1D4-19B4-4692-8004-E1A3E8A9E85B}) (Version: 6.1.3 - M-Audio)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 it) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 it)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0 - Mozilla)
MusicLab RealGuitar (HKLM\...\{1864B4F0-8888-5A57-9930-C2B307597966}) (Version: 3.0 - MusicLab, Inc.)
MusicLab RealLPC (HKLM\...\{38209080-8888-4418-8117-D190FC71BF58}) (Version: 3.0 - MusicLab, Inc.)
MusicLab RealStrat (HKLM\...\{58206080-8888-4418-8117-D190FC71BF58}) (Version: 3.0 - MusicLab, Inc.)
MusicLab Virtual MIDI Driver (HKLM\...\{A30B7FD7-04A1-46e1-ABDF-FD592C113253}) (Version: 2.0.1.0 - MusicLab, Inc.)
Native Instruments Kontakt 5 (HKLM-x32\...\Native Instruments Kontakt 5) (Version: 5.5.0.409 - Native Instruments)
Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments)
qBittorrent 3.3.0 (HKLM-x32\...\qBittorrent) (Version: 3.3.0 - The qBittorrent project)
reFX Nexus VSTi RTAS v2.2.0 (HKLM-x32\...\reFX Nexus_is1) (Version: - )
reFX Vanguard 1.7.2 (HKLM-x32\...\reFX Vanguard 1.7.2_is1) (Version: - )
SampleTank (HKLM-x32\...\{6559654F-2F38-491F-8411-211517C3E635}) (Version: 2.5.5 - IK Multimedia)
SampleTank 3 version 3.0.1 (HKLM\...\{4A5CE684-33A5-4EE6-AB22-4B92D92D37D8}_is1) (Version: 3.0.1 - IK Multimedia)
Sandboxie 5.06 (64-bit) (HKLM\...\Sandboxie) (Version: 5.06 - Sandboxie Holdings, LLC)
Steinberg Cubase 5 (HKLM-x32\...\{4A19D6AC-ADE0-4A07-80FF-9C9812C45557}) (Version: 5.1.2 - Steinberg Media Technologies GmbH)
Steinberg Drum Loop Expansion 01 (HKLM-x32\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 1.0.0.1 - Steinberg Media Technologies GmbH)
Steinberg Groove Agent ONE Content (HKLM-x32\...\{BD86F1AC-B594-46E4-85DC-1258AC9E2232}) (Version: 1.0.0.003 - Steinberg Media Technologies GmbH)
Steinberg HALionOne (HKLM-x32\...\{E70E7159-93B1-470D-9FBD-D8E9EF34B538}) (Version: 1.1.0.457 - Steinberg Media Technologies GmbH)
Steinberg HALionOne Additional Content Set 01 (HKLM-x32\...\{F3AFD063-8BAD-485E-B641-E7F5A2C5AE71}) (Version: 1.0.0.001 - Steinberg Media Technologies GmbH)
Steinberg HALionOne Expression Set (HKLM-x32\...\{E22AD5D3-EB60-4A8F-835C-6C10E369DCE2}) (Version: 1.0.1.0 - Steinberg Media Technologies GmbH)
Steinberg HALionOne GM Drum Set (HKLM-x32\...\{AC997F93-0757-4ED4-A701-F40C2D654D09}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH)
Steinberg HALionOne GM Set (HKLM-x32\...\{F057965A-D974-4C64-ADB1-4381CD4B8956}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH)
Steinberg HALionOne Pro Set (HKLM-x32\...\{D82CDA0D-C182-42C8-8FF2-5649C98D6003}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH)
Steinberg HALionOne Studio Drum Set (HKLM-x32\...\{865D9ED1-EAC2-436D-AFA7-0B750EB5AAAB}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH)
Steinberg HALionOne Studio Set (HKLM-x32\...\{D23CBFDA-C46B-4920-BA70-FC7878A3F05A}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH)
Steinberg LoopMash Content (HKLM-x32\...\{4D454CF8-12FD-464D-B57B-B46FE27B78BB}) (Version: 1.0.0.005 - Steinberg Media Technologies GmbH)
Steinberg REVerence Content 01 (HKLM-x32\...\{532B917B-8235-4FA5-BE36-643A8BB053A5}) (Version: 1.0.0.006 - Steinberg Media Technologies GmbH)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1210 - SUPERAntiSpyware.com)
TC Native Bundle v3.1 (HKLM-x32\...\TC Native Bundle v3.1) (Version: - )
UltraISO Premium V9.53 (HKLM-x32\...\UltraISO_is1) (Version: - )
WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1461667933-2917687346-235261616-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2015-11-27 11:46 - 00000861 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 activation.acronis.com

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {065FEFD8-D82D-4D0E-ADC9-4AEA09E49792} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-12-06] (AVAST Software)
Task: {5925502A-A4E9-4AE5-A5B4-2EA2C93DC1AD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)
Task: {CB2CDA11-9EE6-4E2B-89C6-2F9BA3B5EFA9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-12-06] (AVAST Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2013-10-01 10:48 - 2013-10-01 10:48 - 02815536 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll
2015-11-16 17:55 - 2015-11-16 17:55 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1040.dll
2015-12-06 15:37 - 2015-12-06 15:37 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-12-06 15:37 - 2015-12-06 15:37 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-12-06 15:39 - 2015-12-06 15:39 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15120600\algo.dll
2015-12-06 15:37 - 2015-12-06 15:37 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-06 15:37 - 2015-12-06 15:37 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-11-14 22:22 - 2013-11-14 22:22 - 00028992 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll
2013-11-14 22:25 - 2013-11-14 22:25 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2013-10-01 11:00 - 2013-10-01 11:00 - 00022336 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\62325471.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\76543075.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\62325471.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\76543075.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1461667933-2917687346-235261616-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{8DD8236C-708A-4141-BB60-9A3DADE17131}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D94B15C4-8B73-4769-BD6A-703A99C88550}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0A22DE97-A28E-466F-ABD2-58314CA01567}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{488A88FC-322B-4CCF-B027-BAF1AA9046FC}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{C84333CE-C2DE-4D13-8405-D2C88C01173B}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [{C84D5C38-D8B7-418A-9F8E-B599E8D327E7}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/06/2015 04:30:39 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Impossibile accedere al file per uno dei motivi seguenti:
Si è verificato un problema relativo alla connessione di rete, al disco in cui è archiviato il file o ai driver
di archiviazione installati nel computer oppure il disco è assente.
Il programma Processo host per servizi di Windows è stato chiuso a causa dell'errore.

Programma: Processo host per servizi di Windows
File:

Il valore dell'errore è indicato nella sezione Dati aggiuntivi.
Azione utente
1. Aprire nuovamente il file.
Potrebbe trattarsi di un problema temporaneo che si risolverà automaticamente rieseguendo il programma.
2.
Se il file risulta comunque non accessibile e:
- Si trova in rete,
è necessario che l'amministratore della rete verifichi la presenza di eventuali problemi di rete e che sia possibile contattare il server.
- Si trova in un disco rimovibile, ad esempio un disco floppy o un CD, verificare che il disco sia inserito correttamente nel computer.
3. Controllare e ripristinare il file system eseguendo CHKDSK. Per eseguire CHKDSK, fare clic sul pulsante Start, scegliere Esegui, digitare CMD, quindi scegliere OK. Al prompt dei comandi, digitare CHKDSK /F, quindi premere INVIO.
4. Se il problema persiste, ripristinare il file da una copia di backup.
5. Determinare se è possibile aprire altri file nello stesso disco. Se non è possibile, il disco potrebbe essere danneggiato. Se si tratta di un disco rigido, contattare l'amministratore o il fornitore dell'hardware
del computer per ottenere assistenza.

Dati aggiuntivi
Valore errore: C000003F
Tipo disco: 0

Error: (12/06/2015 04:30:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome dell'applicazione che ha generato l'errore: svchost.exe_SysMain, versione: 6.3.9600.16384, timestamp: 0x5215dfe3
Nome del modulo che ha generato l'errore: ntdll.dll, versione: 6.3.9600.17031, timestamp: 0x530895af
Codice eccezione: 0xc0000006
Offset errore 0x000000000003f14b
ID processo che ha generato l'errore: 0x13c
Ora di avvio dell'applicazione che ha generato l'errore: 0xsvchost.exe_SysMain0
Percorso dell'applicazione che ha generato l'errore: svchost.exe_SysMain1
Percorso del modulo che ha generato l'errore: svchost.exe_SysMain2
ID segnalazione: svchost.exe_SysMain3
Nome completo pacchetto che ha generato l'errore: svchost.exe_SysMain4
ID applicazione relativo al pacchetto che ha generato l'errore: svchost.exe_SysMain5

Error: (12/06/2015 02:58:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: Servizi di crittografia: impossibile inizializzare il database del catalogo. Errore ESENT: -501.

Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 454) (User: )
Description: Catalog Database (1224) Catalog Database: Ripristino database non riuscito. Errore imprevisto -501.

Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 465) (User: )
Description: Catalog Database (1224) Catalog Database: Sono stati rilevati dati danneggiati durante il ripristino software del file di registro C:\Windows\system32\CatRoot2\edb.log. Il record che origina l'errore nel checksum si trova nella seguente posizione: END. I primi dati non corrispondenti al criterio di riempimento del file di registro sono comparsi nel settore 285 (0x0000011D). Il file di registro è danneggiato. Impossibile utilizzarlo.

Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 477) (User: )
Description: Catalog Database (1224) Catalog Database: Impossibile leggere l'intervallo di registro dal file "C:\Windows\system32\CatRoot2\edb.log" all'offset 1167360 (0x000000000011d000) per 4096 (0x00001000) byte a causa di una mancata corrispondenza del checksum dell'intervallo. Checksum previsto: 47007039726499975 (0xa700a750d73887). Checksum effettivo: 47007039726499975 (0xa700a750d73887). L'operazione di lettura non verrà effettuata con errore -501 (0xfffffe0b). Se tale condizione persiste, ripristinare il file di registro da un backup precedente.

Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 465) (User: )
Description: Catalog Database (1224) Catalog Database: Sono stati rilevati dati danneggiati durante il ripristino software del file di registro C:\Windows\system32\CatRoot2\edb.log. Il record che origina l'errore nel checksum si trova nella seguente posizione: END. I primi dati non corrispondenti al criterio di riempimento del file di registro sono comparsi nel settore 285 (0x0000011D). Il file di registro è danneggiato. Impossibile utilizzarlo.

Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 477) (User: )
Description: Catalog Database (1224) Catalog Database: Impossibile leggere l'intervallo di registro dal file "C:\Windows\system32\CatRoot2\edb.log" all'offset 1167360 (0x000000000011d000) per 4096 (0x00001000) byte a causa di una mancata corrispondenza del checksum dell'intervallo. Checksum previsto: 47007039726499975 (0xa700a750d73887). Checksum effettivo: 47007039726499975 (0xa700a750d73887). L'operazione di lettura non verrà effettuata con errore -501 (0xfffffe0b). Se tale condizione persiste, ripristinare il file di registro da un backup precedente.

Error: (12/06/2015 02:57:30 PM) (Source: Windows Search Service) (EventID: 1006) (User: )
Description: Servizio Windows Search: impossibile creare il nuovo indice di ricerca. Errore interno <4, 0x80070020, Impossibile aggiungere il progetto: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.

Error: (12/06/2015 02:56:54 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Impossibile inizializzare l'indice.

Dettagli:
Impossibile trovare l'oggetto specificato. Specificare il nome di un oggetto esistente. (HRESULT : 0x80040d06) (0x80040d06)


System errors:
=============
Error: (12/07/2015 10:18:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 millisecondi) durante l'attesa della connessione del servizio Servizio Segnalazione errori Windows.

Error: (12/07/2015 10:15:31 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio MBAMService dipende dal servizio MBAMProtector che non è stato avviato per il seguente errore:
%%193

Error: (12/07/2015 10:15:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio MBAMProtector non è stato avviato per il seguente errore:
%%193

Error: (12/07/2015 10:15:10 AM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY)
Description: C:\Device\HarddiskVolume23

Error: (12/06/2015 10:04:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio MBAMService dipende dal servizio MBAMProtector che non è stato avviato per il seguente errore:
%%193

Error: (12/06/2015 10:04:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio MBAMProtector non è stato avviato per il seguente errore:
%%193

Error: (12/06/2015 10:04:19 PM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY)
Description: C:\Device\HarddiskVolume23

Error: (12/06/2015 04:32:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Servizio Generatore endpoint audio Windows terminato con l'errore:
%%1115

Error: (12/06/2015 04:32:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio Client di Criteri di gruppo non è stato avviato per il seguente errore:
%%1053

Error: (12/06/2015 04:32:16 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio gpsvc.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Percentage of memory in use: 10%
Total physical RAM: 16069.32 MB
Available physical RAM: 14377.74 MB
Total Virtual: 32453.32 MB
Available Virtual: 30773.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:777.48 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DD5CACA0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt

menatwork
07-12-2015, 09:37
vorrei vedere anche i log di tdskiller e aswmbr, allegali non copiarli per cortesia

con tds killer per caso hai cliccato su ''delete'' ?

luigi27
07-12-2015, 11:24
NOn mi sembra proprio di aver cliccate delete su tds killer ma lo posso dire al 99 % ....magari per errore ho cliccato qualcosa ha fatto una scansione lui e se ha cancellato qualcosa era in automatico... Ok allrgo solo i LINK va bene.
Nell'ordine:
un link di una scansione fatta ieri con Rkill http://www.wikifortio.com/778640/Rkill.txt

poi link con scansione di aswmbr (con cui nella precedente scansione non ho cancellato nulla):
quick scan:http://www.wikifortio.com/800057/aswMBR%20quick.txt

C scan: http://www.wikifortio.com/817504/aswMBR%20C.txt

riguardo TDS KILLER: http://www.wikifortio.com/771063/TDSSKiller.3.1.0.7_07.12.2015_12.15.18_log.txt fatto ora


e un altro fatto ieri:
http://www.wikifortio.com/700474/TDSSKiller.3.1.0.7_06.12.2015_02.15.10_log.txt

menatwork
07-12-2015, 11:34
prova ad usare tds killer settato cosi'

scarica TDSSKiller (http://www.bleepingcomputer.com/download/tdsskiller/dl/4/) sul desktop ed estrai il contenuto

Clicca su "Change parameters"
Metti la spunta sulle caselline: verify driver digital singatures e poi Detect TDLFS file system .
Conferma cliccando OK.
Poi clicca su "Start Scan"
Se trova qualche infezione di default avrai l'opzione "Cure" per cui, clicca su "Continue".
Se un file sospetto viene trovato,l'azione di default sarà "skip",clicca su "Continue".
Se è richiesto il riavvio,(Reboot) acconsenti. (per eliminare l'infezione è necessario riavviare il pc)
Se nessun riavvio è richiesto clicca su report e salva il contenuto in un file di testo.


Fai anche questa scansione, oltre a cercare elementi nocivi dovrebbe ripristinare qualche filesystem che e' stato corrotto

scarica combofix (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) sul desktop

alla richiesta se vuoi installare la recovery console clicca su NO

esegui ComboFix.exe

segui le instruzioni

finita la scansione portati in C:\ e allega nella tua prossima risposta, il contenuto del file di testo Combofix.txt

luigi27
07-12-2015, 11:45
OK ora eseguo ma combofix purtroppo non funziona con windows 8.1 , ma solo fino a win 8----!!! Almeno cosi' ho trovato sul sito... esiste un programma analogo alternativo o una nuova versione per win 8.1 ? Llo avrei usato per primo infatti...

luigi27
07-12-2015, 11:48
La scansione che mi hai indicato l'ho postata sopra come fatta 15 minuti fa E' la prima delle due...i settaggi erano proprio quelli infatti ci avevo pensato; per sicurezza la rifaccio (quella fatta ieri aveva altro settaggio non considerarla... ) e la riposto. Ma mi manca combo fix un casino

luigi27
07-12-2015, 11:51
COn TDSSkiller non ho avuto problemi non mi ha trovato alcuna infeizone di default ad ogni modo. Per ripristinare i file di sistema potrei usare tweaking windows repair ? O si fa peggio? O col disco originale di winb.1 (ma ho apura che mi rispoda impossibile ripristinare ) oppure dal prompt di wind scannow ripristino ?

menatwork
07-12-2015, 11:58
lascia stare i programmini falla nel modo consueto

Ripristinare i file di sistema danneggiati (http://www.ilsoftware.it/articoli.asp?tag=Ripristinare-i-file-di-sistema-danneggiati-in-Windows-7-e-Windows-81_10899)

luigi27
07-12-2015, 12:16
Ok la faccio dal DVD riavviando il tutto poi ti faccio sapere

luigi27
07-12-2015, 12:50
Ecco di nuovo una stranezza.... ho fatto un primo tentativo dal sistema in ambiente windows da ricerca ho digitato cmd ... dal prompt previa disabilitazione di avast e dei programi in esecuzione: .- ho utlizzato i privilegi di amministrtore (tasto destro esegio come amministratore) - e mi è uscito C: Windows/system32
e poi sfc /scannow Lui ha controllato scrivendo " avvio in corso dell'analisi di sistema " ecc... a fine controllo dei file di C mi ha risposto: protezione risorse di windows impossibile eseguire l'operazione richiesta ?????

luigi27
07-12-2015, 13:32
Lo stesso aviene se utilizzo il disco di windows 8.1 seguendo la procedura dal boot settato con dvd come prima opzione... la risposta è a stessa: proteizone di risorse di windows impossibile eseguire l'operazione richiesta dopo sfc scannow (ma anche con l'altro comando). Niente da fare l'intrusione avvenuta deve aver bloccato qualcosa nei servizi di windows forse....Sto cercando di farmi venire qualche idea

luigi27
07-12-2015, 14:11
nel frattempo posto di nuovo il log di TDSS KILLER con le modifiche settate per un ulteriore controllo
http://www.wikifortio.com/771063/TDSSKiller.3.1.0.7_07.12.2015_12.15.18_log.txt

luigi27
07-12-2015, 14:20
Allora a beneficio pure di altri utenti in caso uguale ho trovato come utile suggerimento nel mio caso di risposta di scannow impossibile da effettaure, essendo risultati file di sistema mancanti o danneggaiti da tutte le scansioni, quello di utilizzare i comandi DISM dal prompt come amministratore per correggere l'immagine di sistema:

dism.exe /online /cleanup-image /scanhealth

alla fine del procesos mi è uscita la risposta : l'archivio dei componenti è ripristinabile
al che ho provato
dism.exe /online /cleanup-image /restorehealth
tuttavia questa seconda operazione mi ha dato esito negativo in quanto non riusciva a tovare la cartella o al directory source per correggere
Infine ho riprovato a usare il comando scannow e questa volta il risultato finale è stato positivo
Proteione di windows: nessuna violazione di integrità trovata

Probabilmente i file mancanti sono stati ripristinati con la prima delle due operazioni!!! Adesso che scansione faccio per far eun ultimo controllo di integrita' del sistema???? Di nuovo con FARBAR?????

menatwork
07-12-2015, 19:43
ora che hai eseguito Sfc /scannow controlla i risultato nella cartella C:\WINDOWS\logs\cbs\CBS.log

Allegalo qui


una domanda: il pc e' lento o instabile dopo queste operazioni?

facciamo anche un controllo sui servizi

Scarica Farbar Service (http://download.bleepingcomputer.com/farbar/FSS.exe )
metti la spunta a tutte le caselle e clicca su ''scan''

Allega il log di fine scansione

luigi27
08-12-2015, 00:18
Piu' che altro il pc tende a bloccarsi nei cambi di link su internet o nei comandi di apertura icone o programmi ad esempio ho scaricato faber e come ho aperto la cartella download si è bloccata quest'utima lasciando in esecuzione il comando del mouse per un po' poi si sblocca ; specie quando si sovrappongono i comandi ;
ora posto i link

a) link di scannow : http://www.wikifortio.com/712234/CBS.log

b) link di FFS farbar servizi tutte le caselle spuntate : http://www.wikifortio.com/844720/FSS.txt

menatwork
08-12-2015, 08:29
hai Windows Update e Windows Defender disattivati, ti consiglio di attivarli quanto prima

dimmi il problema principale qual'e' o se il pc e' migliorato, rootkit nemmeno l'ombra

luigi27
08-12-2015, 13:07
Ti ringrazio per l'aiuto datomi in ogni caso. Detto questo windows update lo teno disattivato volutamente in questa fase poi in seguito lo riattivero'. NOn mi ero accorto invece della disattivazione di wind defender.... non l'avevo mai toccato. A questo punto secondo te, pur contento del fatto che il presunto rootkit (o falso positivo di avast ) non ci sia, essendoci stati degli indizi di un'attivita' anomala (virus o rootkit presunto), secondo te si puo' cocludere che non c'è stato nulla? Infine mancano o meno dei file di sistema ( non sono riuscito ad utilzzare scannow per due volte sia dall'ambiente windows che dal boot, mentre ci sono riuscito dopo aver fatto un amanovra di check dell'immagine di sistema (che forse in qualche maniera si è riattivata automaticamente???) . NOn trovo una spiegazione .... Infine mi chiedo se scannow abbia ripristinato eventuali file mancanti o modificati????? Se non c'è comunque nulla di rilevante e non ci sono file mancanti di sistema, possiamo chiudere qui. Se invece secondo te c'è stata una modiia di sistema anche minima , allora il tutto ha avuto molta piu' importanza di quanto non sembri ora. I comportamenti del pc possono essere delle semplici impressioni mie, dovute anche al fatto che ho dovuto manovrare con file di keygen molto sospetti (dalla scansione gratuita su virus total) in ambiente sandboxie (ma che mai da' certezze assolute...). Dammi se puoi un tuo parere (se c'è stata una modifica o meno su fille di sistema e servizio wind defender a mia insaputa) per regolarmi di conseguenza su eventuali future anomalie che dovessi riscontrare.

luigi27
08-12-2015, 14:33
Tra l'altro da scansione fatt risultano ocme corrotti alcuni file dei pacchetti di aggiornamento windows...ora se provo a reinstallarli manualmente mi si dice che osno gia' installati.... non riesco a disinstallarli manualmente allo stesso modo . Ho paura che proseguendo nelgli update potrei avere problemi dopo di conflitto di sistema per cui mi sono fermato Inoltre da quanto leggo qui mi si dice che SFC non puo' replicare questi file. QUindi la domanda è se si puo' updatar senza questi singoli file senza problemi o meno. Ecco i file di update mancanti:
Scanning Windows Packages Files.
│ Started at (08/12/2015 14:51:57)

│ These Files Are Possibly Corrupt (Bad Digital Signature): (Total: 6)
C:\Windows\servicing\Packages\Package_1075_for_KB2975719~31bf3856ad364e35~amd64~~6.3.1.8.cat
C:\Windows\servicing\Packages\Package_346_for_KB2934018~31bf3856ad364e35~amd64~~6.3.1.5.cat
C:\Windows\servicing\Packages\Package_6_for_KB2975061~31bf3856ad364e35~amd64~~6.3.1.0.cat
C:\Windows\servicing\Packages\Package_1075_for_KB2975719~31bf3856ad364e35~amd64~~6.3.1.8.mum
C:\Windows\servicing\Packages\Package_346_for_KB2934018~31bf3856ad364e35~amd64~~6.3.1.5.mum
C:\Windows\servicing\Packages\Package_6_for_KB2975061~31bf3856ad364e35~amd64~~6.3.1.0.mum

6 Combined Problems were found with the packages files, these files need to be replaced (These mainly only effect installing Windows Updates.)
│ The SFC (System File Checker) doesn't scan and replace some of these files, so you may need to replace them manually.

│ THESE FILES DO NOT KEEP THE REPAIRS FROM WORKING; YOU MAY STILL RUN THE REPAIRS IN THE PROGRAM.

│ If you need help in replacing these files, post on the Forums at Tweaking.com for help.

│ Files Checked & Verified: 4.531

│ Done Scanning Windows Packages Files.(08/12/2015 14:52:10)

luigi27
08-12-2015, 14:41
Infine noto un'altra cosa strana ...in fase di avvio per tre secondi compare la schermata C ..scan; poi scompare (come se volesse riparare o scansionare per controllo C ) e si avvia normalmente

Chill-Out
11-12-2015, 17:06
http://www.hwupgrade.it/forum/showthread.php?t=1751598 :read: