|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
ROOTKIT fantasma
Salve Ho avuto un problema strano.
Ho fatto scansione con avast di sstema ed p risultato presente un rootkit su due file ( altri tre siili non letti da avast per impossibilta'). Ho provato a seguire la procedura ma è uscito solo un messaggioid errore 8Impossibile eliinarli o in qurantena). I file infetti erano di ccleaner in quell'istante. Il istema operativo è windows 8.1.Esattamente avast diceva : C:Program FIles\CCleaner\Lang|lang-1035.dll " " " " 1063.dll sospetti 1040 1030 2070.dll Minaccia:Rootkit:hidden file minaccia elevata Dopo poco che scaricavo tool antirootkit il computer ha inviato un messaggio di necessità si spegnimento. Ho scollegato internet per impedire altro al rootkit. ho scansionato ni modalita' provvisoria con tutti i tool che ho potuto scaricare ma nno hanno trovato nulla(malware bite, malware beta, aswmbr, tdskiller, kasperky tool antivirus, ifine rkill ma non hanno trovato nulla) Avast in modalita' provvisoria non funzionava. Riavviato in modalità normale tramite msconfg (F8 non sembra dare effetti) avast apparentemente funzionava ma non scaricava aggiornamenti con messaggio di errore. Ho disinstallato ccleaner presunto infetto che poi aveva perso l alingua italiana e ho reinstallato, ora funziona regolarmente. Ho scansionato ancora con i tool di nuovo in modalita' normale senza torvare nulla. Ho reinstallato avast e adesso funziona regolarmente. Ho scansionato il sistema con avast e non sono risultati virus o rootkit. Inivo se possibile per un esame di nu esperto, il log fatto con Hjaking Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 22:17:34, on 06/12/2015 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.17126) FIREFOX: 42.0 (x86 it) Boot mode: Normal Running processes: C:\Users\Luigi\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: MBAMService - Unknown owner - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: MIDISPORT Audio Device Monitor (MIDISPORTAudioDevMon) - M-Audio - C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Sandboxie Service (SbieSvc) - Sandboxie Holdings, LLC - C:\Program Files\Sandboxie\SbieSvc.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 6652 bytes grazie fin da ora per eventuali consigli Da quello che capisco mi mancano alcuni file di sistema....posso provare a ripristinarli mediante il tool tweaking windows repair ola funzione ripair di windows 8.1 ma non so se conviene o meno... Avatar utente luigi27 Neo Iscritto Neo Iscritto Messaggi: 1 Iscritto il: dom dic 06, 2015 10:31 pm Top |
|
|
|
|
|
#2 |
|
Member
Iscritto dal: Dec 2015
Messaggi: 54
|
ciao inutile postare hjt perche' anche se ci fosse la presenza di un rootkit il tool non la rileva
per caso ultimamente hai rimosso ccleaner e poi reinstallato? potrebbe essere un falso rilevato da avast, succede con tutti gli antivirus... allega i log di tdskiller e aswmbr poi fai questa scansione scarica farbar-recovery e mettilo sul desktop Devi scaricare la versione(32 o 64 bit compatibile con il tuo sistema) Avvialo e clicca su yes quando ti chiede di accettare le condizioni Clicca su SCAN Una volta terminata la scansione il tool creerà nella stessa directory di dove è posizionato FRST un log chiamato FRST.txt. Allegalo nella tua prossima risposta |
|
|
|
|
|
#3 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Ok grazie Allora....ho installato periodicamente ccleaner quando aggiorna ma ho anche ameggiato con keygen analizate con virus total e con un po' di rilevamenti ....ma in zona sandboxie, quindi motivi per avere qualcosa ci sarebbero....ad ogni modo ho fatto la scansione sopra detta e posto il link della scansione:http://www.wikifortio.com/771570/FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015 Ran by Luigi (administrator) on PC (07-12-2015 10:23:11) Running from C:\Users\Luigi\Desktop Loaded Profiles: Luigi (Available Profiles: Luigi) Platform: Windows 8.1 (X64) Language: Italiano (Italia) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (M-Audio) C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-11-12] (IvoSoft) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-06] (AVAST Software) HKU\S-1-5-21-1461667933-2917687346-235261616-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-06] (AVAST Software) ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: 127.0.0.1 activation.acronis.com Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{5D0B3462-2CD9-40F4-9F25-8DC51C2B3167}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-06] (AVAST Software) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-11-12] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-06] (AVAST Software) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-11-12] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft) FireFox: ======== FF ProfilePath: C:\Users\Luigi\AppData\Roaming\Mozilla\Firefox\Profiles\xg07ijjq.default FF Extension: Adblock Plus - C:\Users\Luigi\AppData\Roaming\Mozilla\Firefox\Profiles\xg07ijjq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-27] FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-06] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-06] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-06] (AVAST Software) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [0 2015-10-05] () <==== ATTENTION (zero byte File/Folder) R2 MIDISPORTAudioDevMon; C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe [1638704 2012-02-24] (M-Audio) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [177800 2015-10-22] (Sandboxie Holdings, LLC) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-09-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-09-24] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-06] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-06] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-06] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-06] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-06] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-06] (AVAST Software) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) R3 Echo24; C:\Windows\system32\drivers\echo24.sys [572712 2011-12-07] (Echo Digital Audio Corp.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) S3 MADFUMIDISPORT2010; C:\Windows\System32\drivers\MAudioMIDISPORT_DFU.sys [30512 2012-02-24] (M-Audio) R3 MAUSBMIDISPORT; C:\Windows\system32\DRIVERS\MAudioMIDISPORT.sys [201008 2012-02-24] (M-Audio) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] () S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [0 2015-10-05] () <==== ATTENTION (zero byte File/Folder) R3 mlkumidi; C:\Windows\system32\drivers\mlkumidi.sys [57408 2012-08-29] (MusicLab, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [192648 2015-10-22] (Sandboxie Holdings, LLC) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2015-11-27] (Acronis International GmbH) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [198432 2015-11-27] (Acronis International GmbH) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-09-24] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-09-24] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-09-24] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-07 10:23 - 2015-12-07 10:23 - 00009653 _____ C:\Users\Luigi\Desktop\FRST.txt 2015-12-07 10:23 - 2015-12-07 10:23 - 00000000 ____D C:\FRST 2015-12-07 10:22 - 2015-12-07 10:20 - 02369024 _____ (Farbar) C:\Users\Luigi\Desktop\FRST64.exe 2015-12-07 10:20 - 2015-12-07 10:20 - 02369024 _____ (Farbar) C:\Users\Luigi\Downloads\FRST64.exe 2015-12-06 15:39 - 2015-12-06 15:37 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-12-06 15:37 - 2015-12-06 15:39 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-06 15:37 - 2015-12-06 15:37 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-12-06 15:37 - 2015-12-06 15:37 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2015-12-06 15:37 - 2015-12-06 15:37 - 00001938 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-12-06 15:37 - 2015-12-06 15:37 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\AVAST Software 2015-12-06 15:37 - 2015-12-06 15:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-12-06 15:34 - 2015-12-06 15:34 - 00000000 ____D C:\Program Files\AVAST Software 2015-12-06 15:33 - 2015-12-06 15:33 - 05066096 _____ (AVAST Software) C:\Users\Luigi\Downloads\avast_free_antivirus_setup_online.exe 2015-12-06 12:02 - 2015-12-06 12:02 - 00000000 ____D C:\KVRT_Data 2015-12-06 02:33 - 2015-12-06 02:33 - 00002778 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-12-06 02:33 - 2015-12-06 02:33 - 00000834 _____ C:\Users\Public\Desktop\CCleaner.lnk 2015-12-06 02:33 - 2015-12-06 02:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-12-06 02:28 - 2015-12-06 02:29 - 95957160 _____ (Kaspersky Lab ZAO) C:\Users\Luigi\Downloads\KVRT.exe 2015-12-06 02:15 - 2015-12-06 02:17 - 00606644 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_02.15.10_log.txt 2015-12-06 02:12 - 2015-12-06 02:13 - 00004284 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_02.12.47_log.txt 2015-12-06 01:59 - 2015-12-06 02:10 - 00202776 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_01.59.44_log.txt 2015-12-06 01:34 - 2015-12-06 01:34 - 00004426 _____ C:\Users\Luigi\Desktop\Rkill.txt 2015-12-06 01:33 - 2015-12-06 01:34 - 00004014 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_01.33.46_log.txt 2015-12-06 00:45 - 2015-12-06 00:55 - 00000000 ____D C:\Users\Luigi\Desktop\mbar 2015-12-06 00:45 - 2015-12-06 00:55 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-12-06 00:41 - 2015-12-06 00:43 - 00839248 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_00.41.19_log.txt 2015-12-06 00:37 - 2015-12-06 00:39 - 00004280 _____ C:\TDSSKiller.3.1.0.7_06.12.2015_00.37.58_log.txt 2015-12-06 00:36 - 2015-12-06 00:36 - 00000000 ____D C:\Windows\pss 2015-12-06 00:29 - 2015-12-06 02:34 - 00000000 ____D C:\Windows\Minidump 2015-12-06 00:25 - 2015-12-06 00:25 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Luigi\Downloads\mbar-1.09.3.1001.exe 2015-12-06 00:21 - 2015-12-06 00:21 - 05200384 _____ (AVAST Software) C:\Users\Luigi\Downloads\aswmbr.exe 2015-12-06 00:13 - 2015-12-06 00:25 - 00007631 _____ C:\Users\Luigi\Desktop\COME USARE ANTIROOTKIT TOOLS.txt 2015-12-06 00:03 - 2015-12-06 00:05 - 00000154 _____ C:\Users\Luigi\Desktop\Rootkit.txt 2015-12-04 13:05 - 2015-12-04 13:05 - 00000016 _____ C:\Windows\system32\w3data.vss 2015-12-04 13:05 - 2015-12-04 13:05 - 00000016 _____ C:\Windows\system32\msvcsv60.dll 2015-12-04 13:05 - 2015-12-04 13:05 - 00000000 ____D C:\Users\Luigi\Documents\jBridge 2015-12-04 12:58 - 2015-12-04 12:58 - 00001682 _____ C:\Users\Luigi\Desktop\SampleTank 3 - collegamento.lnk 2015-12-04 11:26 - 2015-12-04 11:26 - 00000000 ____D C:\Users\Public\Documents\IK Multimedia 2015-12-04 11:25 - 2015-12-04 11:25 - 00000000 ____D C:\Program Files\IK Multimedia 2015-12-04 11:25 - 2015-12-04 11:25 - 00000000 ____D C:\Program Files\Common Files\VST3 2015-12-04 11:25 - 2012-08-29 13:23 - 00348160 _____ (Microsoft Corporation) C:\Windows\msvcr71.dll 2015-12-04 11:14 - 2015-12-04 11:14 - 00000833 _____ C:\Users\Luigi\Desktop\jBridger.lnk 2015-12-04 11:12 - 2015-12-04 11:12 - 00001055 _____ C:\Users\Public\Desktop\qBittorrent.lnk 2015-12-04 11:12 - 2015-12-04 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent 2015-12-04 11:12 - 2015-12-04 11:12 - 00000000 ____D C:\Program Files (x86)\qBittorrent 2015-12-04 11:10 - 2015-12-04 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jBridge 2015-12-04 11:10 - 2015-12-04 11:10 - 00000000 ____D C:\Program Files\JBridge 2015-12-04 10:57 - 2015-12-04 10:57 - 14226226 _____ (The qBittorrent project) C:\Users\Luigi\Downloads\qbittorrent_3.3.0_setup.exe 2015-12-03 21:04 - 2015-12-04 00:10 - 00000000 ____D C:\Program Files (x86)\Spectrasonics 2015-12-03 14:48 - 2015-12-03 14:48 - 00001305 _____ C:\Users\Luigi\Desktop\Z3TA+ 2.lnk 2015-12-03 14:48 - 2015-12-03 14:48 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cakewalk 2015-12-03 14:36 - 2015-12-03 14:36 - 00000000 ____D C:\Users\Luigi\AppData\Local\Spectrasonics 2015-12-03 14:36 - 2015-12-03 14:36 - 00000000 ____D C:\ProgramData\Note 2015-12-03 14:30 - 2015-12-03 14:30 - 00000000 ___RD C:\Sandbox 2015-12-03 14:21 - 2015-12-05 01:07 - 00003232 _____ C:\Windows\Sandboxie.ini 2015-12-03 14:21 - 2015-12-03 21:42 - 00001314 _____ C:\Users\Luigi\Desktop\Browser Web nell'area virtuale.lnk 2015-12-03 14:21 - 2015-12-03 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2015-12-03 14:21 - 2015-12-03 14:21 - 00000000 ____D C:\Program Files\Sandboxie 2015-12-03 14:20 - 2015-12-03 14:21 - 08518280 _____ (Sandboxie Holdings, LLC) C:\Users\Luigi\Downloads\SandboxieInstall.exe 2015-12-03 14:12 - 2015-12-03 14:12 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-03 14:12 - 2015-12-03 14:12 - 00000000 ____D C:\Program Files\Common Files\AV 2015-12-03 13:46 - 2015-12-03 13:46 - 00001820 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\SUPERAntiSpyware.com 2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2015-12-03 13:46 - 2015-12-03 13:46 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2015-12-03 13:44 - 2015-12-03 13:44 - 24014984 _____ (SUPERAntiSpyware) C:\Users\Luigi\Downloads\SAS_4905.EXE 2015-12-03 12:31 - 2015-12-03 12:31 - 00000000 ____D C:\Trilian 2015-12-03 12:28 - 2015-12-03 14:34 - 00000000 ____D C:\ProgramData\Spectrasonics 2015-12-03 12:28 - 2015-12-03 12:28 - 00000000 ____D C:\Program Files\Cakewalk 2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\MusicLab 2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Users\Luigi\AppData\Local\MusicLab 2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\ProgramData\MusicLab 2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicLab 2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Program Files\MusicLab 2015-12-02 01:14 - 2015-12-02 01:21 - 00000000 ____D C:\Program Files (x86)\MusicLab 2015-12-02 01:14 - 2015-12-02 01:14 - 00000000 ____D C:\Program Files\Common Files\MusicLab 2015-12-02 00:48 - 2015-12-02 00:48 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-12-02 00:42 - 2015-12-02 01:16 - 00000000 ____D C:\Users\Luigi\Documents\Addictive Drums 2 Logs 2015-12-02 00:42 - 2015-12-02 00:42 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Addictive Drums 2 2015-12-02 00:41 - 2015-12-02 00:47 - 00001273 _____ C:\Users\Luigi\Desktop\Addictive Drums 2.lnk 2015-12-02 00:41 - 2015-12-02 00:44 - 00000000 ____D C:\ProgramData\XLN Audio 2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Users\Luigi\Documents\XLN Online Installer 2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Users\Luigi\Documents\Addictive Drums 2 2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XLN Audio 2015-12-02 00:41 - 2015-12-02 00:41 - 00000000 ____D C:\Program Files (x86)\XLN Audio 2015-12-01 16:52 - 2015-12-01 16:54 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Ample Sound 2015-12-01 16:52 - 2015-12-01 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ample Sound 2015-12-01 16:51 - 2015-12-01 16:52 - 00000000 ____D C:\Program Files\Ample Sound 2015-12-01 16:51 - 2015-12-01 16:51 - 00000000 ____D C:\Program Files\Common Files\Avid 2015-11-30 15:14 - 2015-11-30 15:14 - 03802952 _____ (Reason Software Company Inc.) C:\Users\Luigi\Downloads\reason-core-security-setup.exe 2015-11-30 15:00 - 2015-11-30 15:00 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\Luigi\Downloads\rkill.com 2015-11-30 14:58 - 2015-11-30 14:58 - 04398264 _____ (Kaspersky Lab ZAO) C:\Users\Luigi\Downloads\tdsskiller.exe 2015-11-30 14:30 - 2015-11-30 14:30 - 00388608 _____ (Trend Micro Inc.) C:\Users\Luigi\Desktop\HijackThis.exe 2015-11-29 15:02 - 2015-12-04 13:43 - 00000000 ____D C:\Users\Luigi\Documents\ISTRUZIONI PER 2015-11-29 14:53 - 2015-12-04 13:05 - 00000032 _____ C:\Users\Luigi\AppData\Roaming\msregsvv.dll 2015-11-29 14:53 - 2015-12-04 13:05 - 00000032 _____ C:\ProgramData\autobk.inc 2015-11-29 14:32 - 2015-12-04 13:05 - 00000032 _____ C:\Windows\msocreg32.dat 2015-11-29 14:32 - 2015-12-04 11:26 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\IK Multimedia 2015-11-29 14:32 - 2015-11-29 16:37 - 00001239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Authorization Manager.lnk 2015-11-29 14:32 - 2015-11-29 16:37 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SampleTank 2.5.lnk 2015-11-29 14:32 - 2015-11-29 16:37 - 00000016 _____ C:\Windows\SysWOW64\w3data.vss 2015-11-29 14:32 - 2015-11-29 16:37 - 00000016 _____ C:\Windows\SysWOW64\msvcsv60.dll 2015-11-29 14:32 - 2015-11-29 14:32 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-11-29 14:31 - 2015-11-29 14:31 - 00000000 ____D C:\ProgramData\IK Multimedia 2015-11-29 13:31 - 2015-11-29 13:31 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rob Papen 2015-11-29 13:31 - 2015-11-29 13:31 - 00000000 ____D C:\Program Files (x86)\Rob Papen 2015-11-29 01:10 - 2015-11-29 01:00 - 02405584 _____ (Trend Micro Inc.) C:\Users\Luigi\Desktop\HousecallLauncher64.exe 2015-11-29 01:09 - 2015-11-29 01:10 - 00000000 _____ C:\Users\Luigi\AppData\Local\census.cache 2015-11-29 01:09 - 2015-11-29 01:10 - 00000000 _____ C:\Users\Luigi\AppData\Local\ars.cache 2015-11-29 01:00 - 2015-11-29 01:00 - 02405584 _____ (Trend Micro Inc.) C:\Users\Luigi\Downloads\HousecallLauncher64.exe 2015-11-29 01:00 - 2015-11-29 01:00 - 00000036 _____ C:\Users\Luigi\AppData\Local\housecall.guid.cache 2015-11-29 00:59 - 2015-11-29 00:59 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\QuickScan 2015-11-29 00:39 - 2015-12-02 01:03 - 00000000 ____D C:\Users\Luigi\Desktop\BLU 2 2015-11-28 23:42 - 2015-11-30 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX 2015-11-28 23:34 - 2015-11-28 23:34 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IK Multimedia 2015-11-28 23:34 - 2015-11-28 23:34 - 00000000 ____D C:\Program Files (x86)\Digidesign 2015-11-28 23:31 - 2015-11-28 23:31 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TCWorks 2015-11-28 23:31 - 2015-11-28 23:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TCWorks 2015-11-28 23:31 - 2015-11-28 23:31 - 00000000 ____D C:\Program Files (x86)\TCWorks 2015-11-28 23:31 - 2010-10-08 16:09 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2015-11-28 23:25 - 2015-11-28 23:25 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2015-11-28 23:23 - 2015-12-04 11:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IK Multimedia 2015-11-28 23:23 - 2012-12-04 16:26 - 04249197 _____ (IK Multimedia ) C:\Windows\SysWOW64\WIN Installer Authorization Manager (Ver. 1.0.9 RC4).exe 2015-11-28 23:23 - 2012-11-30 19:43 - 08600667 _____ (IK Multimedia ) C:\Windows\SysWOW64\CustomShopInstallerTR4.exe 2015-11-28 23:23 - 2012-08-29 12:23 - 12708016 _____ (Intel Corporation) C:\Windows\system32\mkl_def.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 12474544 _____ (Intel Corporation) C:\Windows\system32\mkl_core.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 09917616 _____ (Intel Corporation) C:\Windows\system32\mkl_intel_thread.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 09410736 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4m.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 09210032 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 09078960 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4p.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 09033904 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_p4m3.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 06944944 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_core.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 03868848 _____ (Intel Corporation) C:\Windows\SysWOW64\mkl_intel_thread.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 00530608 _____ (Intel Corporation) C:\Windows\SysWOW64\libiomp5md.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 00529072 _____ (Intel Corporation) C:\Windows\system32\libiomp5md.dll 2015-11-28 23:23 - 2012-08-29 12:23 - 00499712 ____N (Microsoft Corporation) C:\Windows\msvcp71.dll 2015-11-28 23:23 - 2010-10-08 16:09 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2015-11-28 23:22 - 2015-12-04 11:25 - 00000000 ____D C:\Program Files\VstPlugIns 2015-11-28 23:22 - 2015-11-29 14:31 - 00000000 ____D C:\Program Files (x86)\IK Multimedia 2015-11-28 23:22 - 2015-11-28 23:24 - 00000000 ____D C:\Users\Luigi\Documents\IK Multimedia 2015-11-28 23:22 - 2015-11-28 23:22 - 00000000 ____D C:\Program Files (x86)\VstPlugIns 2015-11-28 01:40 - 2015-11-28 01:40 - 00000000 ____D C:\Users\Public\Documents\NI Resources 2015-11-28 01:32 - 2015-11-28 01:32 - 00001030 _____ C:\Users\Public\Desktop\Kontakt 5.lnk 2015-11-28 01:32 - 2015-11-28 01:32 - 00000000 __HDC C:\ProgramData\{1DC78BF5-AFEA-45C8-9EFE-C64A1962F937} 2015-11-28 01:31 - 2015-11-28 01:32 - 00000000 ____D C:\ProgramData\Package Cache 2015-11-28 00:52 - 2015-11-28 01:32 - 00000000 ____D C:\Users\Luigi\Documents\Native Instruments 2015-11-28 00:52 - 2015-11-28 00:52 - 00000000 ____D C:\Users\Luigi\AppData\Local\Native Instruments 2015-11-28 00:51 - 2015-11-28 01:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments 2015-11-28 00:51 - 2015-11-28 01:32 - 00000000 ____D C:\Program Files\Native Instruments 2015-11-28 00:51 - 2015-11-28 00:51 - 00001075 _____ C:\Users\Public\Desktop\Service Center.lnk 2015-11-28 00:51 - 2015-11-28 00:51 - 00000000 __HDC C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B} 2015-11-28 00:51 - 2015-11-28 00:51 - 00000000 ____D C:\ProgramData\Native Instruments 2015-11-28 00:51 - 2015-11-28 00:51 - 00000000 ____D C:\Program Files\Common Files\Native Instruments 2015-11-27 16:01 - 2015-11-27 16:01 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\VST3 Presets 2015-11-27 16:00 - 2010-01-16 23:27 - 02440704 _____ (AD © 2010) C:\Windows\SysWOW64\SYNSOEMU.DLL 2015-11-27 15:59 - 2015-11-27 15:59 - 00000000 ____D C:\ProgramData\VST3 Presets 2015-11-27 15:58 - 2015-12-03 21:39 - 00000000 ____D C:\Program Files (x86)\Steinberg 2015-11-27 15:58 - 2015-11-27 16:01 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Steinberg 2015-11-27 15:58 - 2015-11-27 16:00 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg Cubase 5 2015-11-27 15:58 - 2015-11-27 15:58 - 00002146 _____ C:\Users\Luigi\Desktop\Cubase 5.lnk 2015-11-27 15:58 - 2015-11-27 15:58 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg HALionOne 2015-11-27 15:58 - 2015-11-27 15:58 - 00000000 ____D C:\ProgramData\Steinberg 2015-11-27 15:55 - 2015-11-27 15:55 - 00001019 _____ C:\Users\Public\Desktop\UltraISO.lnk 2015-11-27 15:55 - 2015-11-27 15:55 - 00000000 ____D C:\Users\Luigi\Documents\My ISO Files 2015-11-27 15:55 - 2015-11-27 15:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO 2015-11-27 15:55 - 2015-11-27 15:55 - 00000000 ____D C:\Program Files (x86)\UltraISO 2015-11-27 15:42 - 2015-11-27 15:42 - 00001332 _____ C:\Users\Luigi\Desktop\WinRAR - collegamento.lnk 2015-11-27 15:36 - 2015-11-27 15:36 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-27 15:36 - 2015-11-27 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-27 15:12 - 2015-12-06 02:33 - 00000000 ____D C:\Program Files\CCleaner 2015-11-27 15:05 - 2015-11-27 15:38 - 00000000 ____D C:\Program Files\WinRAR 2015-11-27 15:05 - 2015-11-27 15:05 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\WinRAR 2015-11-27 14:59 - 2015-12-04 11:18 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\qBittorrent 2015-11-27 14:59 - 2015-11-27 14:59 - 00000000 ____D C:\Users\Luigi\AppData\Local\qBittorrent 2015-11-27 14:44 - 2015-12-07 10:15 - 00001679 _____ C:\Echo PCI driver log.txt 2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\M-Audio 2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\ProgramData\AVID 2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\Program Files\M-Audio 2015-11-27 14:44 - 2015-11-27 14:44 - 00000000 ____D C:\Program Files (x86)\M-Audio 2015-11-27 14:40 - 2015-11-27 14:40 - 00001150 _____ C:\Users\Public\Desktop\Echo24 Console.lnk 2015-11-27 14:40 - 2015-11-27 14:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Echo Digital Audio 2015-11-27 14:40 - 2015-11-27 14:40 - 00000000 ____D C:\Program Files (x86)\Echo Digital Audio 2015-11-27 11:49 - 2015-11-27 11:49 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Acronis 2015-11-27 11:45 - 2015-11-27 12:55 - 00000000 ____D C:\ProgramData\Acronis 2015-11-27 11:45 - 2015-11-27 11:45 - 01464096 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tdrpman.sys 2015-11-27 11:45 - 2015-11-27 11:45 - 01120032 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tib.sys 2015-11-27 11:45 - 2015-11-27 11:45 - 00367200 _____ (Acronis) C:\Windows\system32\Drivers\afcdp.sys 2015-11-27 11:45 - 2015-11-27 11:45 - 00269600 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\snapman.sys 2015-11-27 11:45 - 2015-11-27 11:45 - 00198432 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\tib_mounter.sys 2015-11-27 11:45 - 2015-11-27 11:45 - 00116000 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\fltsrv.sys 2015-11-27 11:45 - 2015-11-27 11:45 - 00001217 _____ C:\Users\Public\Desktop\Acronis True Image 2014.lnk 2015-11-27 11:45 - 2015-11-27 11:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis 2015-11-27 11:44 - 2015-11-27 11:44 - 00000000 ____D C:\Program Files (x86)\Acronis 2015-11-27 10:53 - 2015-11-27 10:53 - 08849283 _____ C:\Users\Luigi\Downloads\ATIH2014_userguide_it-IT.pdf 2015-11-27 10:45 - 2015-11-27 10:45 - 00000144 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2015-11-27 01:41 - 2015-11-27 01:41 - 00001758 _____ C:\Users\Luigi\Desktop\OnlineScannerApp - collegamento.lnk 2015-11-27 01:28 - 2015-12-07 10:15 - 00000000 __SHD C:\Users\Luigi\IntelGraphicsProfiles 2015-11-27 01:28 - 2015-11-27 01:28 - 00000451 _____ C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2015-11-27 00:52 - 2015-11-27 00:52 - 00000000 ____D C:\Program Files (x86)\ESET 2015-11-27 00:44 - 2015-12-06 22:52 - 00000000 ____D C:\Users\Luigi\AppData\Local\ClassicShell 2015-11-27 00:43 - 2015-11-27 00:43 - 00000000 ____D C:\ProgramData\ClassicShell 2015-11-27 00:43 - 2015-11-27 00:42 - 00002170 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\startscreen.lnk 2015-11-27 00:42 - 2015-11-27 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell 2015-11-27 00:42 - 2015-11-27 00:42 - 00000000 ____D C:\Program Files\Classic Shell 2015-11-27 00:41 - 2015-11-27 00:41 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2015-11-27 00:31 - 2015-12-06 01:42 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-11-27 00:31 - 2015-12-06 00:45 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-11-27 00:31 - 2015-11-27 00:31 - 00001114 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-11-27 00:31 - 2015-11-27 00:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-11-27 00:31 - 2015-11-27 00:31 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-11-27 00:31 - 2015-11-27 00:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-11-27 00:31 - 2015-10-05 09:50 - 00025816 _____ C:\Windows\system32\Drivers\mbam.sys 2015-11-27 00:31 - 2015-10-05 09:50 - 00000000 _____ C:\Windows\system32\Drivers\mwac.sys 2015-11-27 00:18 - 2015-11-27 00:36 - 00000000 ____D C:\Users\Luigi\AppData\Local\Mozilla 2015-11-27 00:18 - 2015-11-27 00:26 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Mozilla 2015-11-27 00:18 - 2015-11-27 00:18 - 00001171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-11-27 00:18 - 2015-11-27 00:18 - 00001159 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-11-27 00:18 - 2015-11-27 00:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-11-27 00:18 - 2015-11-27 00:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-11-26 23:58 - 2015-12-06 15:33 - 00000000 ____D C:\ProgramData\AVAST Software 2015-11-26 23:57 - 2015-12-07 10:20 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{7B5EEE9D-7363-4BD2-81F5-2770E6723DC5} 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\LocalLow\EmieUserList 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\LocalLow\EmieSiteList 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\Local\EmieUserList 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 __SHD C:\Users\Luigi\AppData\Local\EmieSiteList 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Macromedia 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Users\Luigi\AppData\Local\GWX 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Program Files\Intel 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Program Files (x86)\Intel 2015-11-26 23:57 - 2015-11-26 23:57 - 00000000 ____D C:\Intel 2015-11-26 23:57 - 2015-08-27 18:20 - 00072704 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL 2015-11-26 23:57 - 2015-08-27 18:20 - 00069120 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL 2015-11-26 23:55 - 2015-12-06 16:30 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1461667933-2917687346-235261616-1001 2015-11-26 23:50 - 2015-12-06 00:36 - 00000000 ____D C:\Users\Luigi 2015-11-26 23:50 - 2015-12-03 23:20 - 00000000 ____D C:\Users\Luigi\AppData\Local\VirtualStore 2015-11-26 23:50 - 2015-11-28 23:19 - 00000000 ____D C:\Users\Luigi\AppData\Local\Packages 2015-11-26 23:50 - 2015-11-26 23:50 - 00001422 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-11-26 23:50 - 2015-11-26 23:50 - 00000020 ___SH C:\Users\Luigi\ntuser.ini 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Risorse di stampa 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Risorse di rete 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Recenti 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Modelli 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Menu Avvio 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Impostazioni locali 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documents\Video 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documents\Musica 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documents\Immagini 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Documenti 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\Dati applicazioni 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\AppData\Local\Dati applicazioni 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 _SHDL C:\Users\Luigi\AppData\Local\Cronologia 2015-11-26 23:50 - 2015-11-26 23:50 - 00000000 ____D C:\Users\Luigi\AppData\Roaming\Adobe 2015-11-26 23:50 - 2014-09-24 16:07 - 00000369 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk 2015-11-26 23:50 - 2014-09-24 16:07 - 00000369 _____ C:\Users\Luigi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk 2015-11-26 23:49 - 2015-11-26 23:51 - 00000000 ___SD C:\Windows\system32\GWX 2015-11-26 23:49 - 2015-11-26 23:49 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-11-26 23:47 - 2015-11-14 15:50 - 00133248 _____ (Microsoft Corporation) C:\Windows\system32\RestoreOptIn.exe 2015-11-26 23:47 - 2015-11-14 15:50 - 00114160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RestoreOptIn.exe 2015-11-26 23:47 - 2015-10-20 22:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-11-26 23:47 - 2015-10-20 15:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-11-26 23:47 - 2015-10-20 15:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-11-26 23:47 - 2015-10-20 15:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-11-26 23:47 - 2015-10-20 15:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2015-11-26 23:47 - 2015-10-20 15:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-11-26 23:47 - 2015-10-20 15:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-11-26 23:47 - 2015-10-20 15:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-11-26 23:47 - 2015-10-20 15:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-11-26 23:47 - 2015-10-20 15:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-11-26 23:47 - 2015-10-20 15:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-11-26 23:47 - 2015-10-20 15:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-11-26 23:47 - 2015-08-11 03:47 - 02757072 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-11-26 23:47 - 2015-08-11 03:47 - 02414096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2015-11-26 23:46 - 2015-07-09 19:40 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-11-26 23:46 - 2015-06-27 04:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-11-26 23:46 - 2015-06-27 04:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-11-26 23:46 - 2015-06-27 03:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-11-26 23:46 - 2015-03-14 02:51 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-11-26 23:46 - 2014-10-18 07:50 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Public\Documents\Video 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Public\Documents\Musica 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Public\Documents\Immagini 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Risorse di stampa 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Risorse di rete 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Recenti 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Modelli 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Menu Avvio 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Impostazioni locali 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documents\Video 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documents\Musica 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documents\Immagini 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Documenti 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\Dati applicazioni 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dati applicazioni 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default\AppData\Local\Cronologia 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\Documents\Video 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\Documents\Musica 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\Documents\Immagini 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dati applicazioni 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Cronologia 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Programmi 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Modelli 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programmi 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Menu Avvio 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Documenti 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\ProgramData\Dati applicazioni 2015-11-26 23:44 - 2015-11-26 23:44 - 00000000 _SHDL C:\Program Files\File comuni 2015-11-26 23:39 - 2015-11-27 16:06 - 00000000 ____D C:\Windows\Panther 2015-11-12 22:55 - 2015-11-12 22:55 - 00289216 _____ (IvoSoft) C:\Windows\system32\StartMenuHelper64.dll 2015-11-12 22:55 - 2015-11-12 22:55 - 00247744 _____ (IvoSoft) C:\Windows\SysWOW64\StartMenuHelper32.dll ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-07 10:23 - 2013-08-22 14:36 - 00000000 ____D C:\Windows 2015-12-07 10:20 - 2014-09-24 16:06 - 01724056 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-07 10:20 - 2014-09-24 15:33 - 00766482 _____ C:\Windows\system32\perfh010.dat 2015-12-07 10:20 - 2014-09-24 15:33 - 00148702 _____ C:\Windows\system32\perfc010.dat 2015-12-07 10:20 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf 2015-12-07 10:15 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-05 02:05 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-12-01 16:52 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-11-29 10:57 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache 2015-11-28 23:24 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness 2015-11-28 22:50 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps 2015-11-27 16:59 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\LiveKernelReports 2015-11-27 00:11 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp 2015-11-26 23:47 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\system32\AdvancedInstallers 2015-11-26 23:44 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Windows NT 2015-11-26 23:39 - 2013-08-22 16:36 - 00262144 _____ C:\Windows\system32\config\BCD-Template ==================== Files in the root of some directories ======= 2015-11-29 14:53 - 2015-12-04 13:05 - 0000032 _____ () C:\Users\Luigi\AppData\Roaming\msregsvv.dll 2015-11-29 01:09 - 2015-11-29 01:10 - 0000000 _____ () C:\Users\Luigi\AppData\Local\ars.cache 2015-11-29 01:09 - 2015-11-29 01:10 - 0000000 _____ () C:\Users\Luigi\AppData\Local\census.cache 2015-11-29 01:00 - 2015-11-29 01:00 - 0000036 _____ () C:\Users\Luigi\AppData\Local\housecall.guid.cache 2015-11-29 14:53 - 2015-12-04 13:05 - 0000032 _____ () C:\ProgramData\autobk.inc Some zero byte size files/folders: ========================== C:\Windows\System32\Drivers\mwac.sys ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-12-06 02:25 |
|
|
|
|
|
#4 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
FARBAR SCAN
nonch' l'addiction: http://www.wikifortio.com/703090/Addition.txt
|
|
|
|
|
|
#5 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by Luigi (2015-12-07 10:23:37) Running from C:\Users\Luigi\Desktop Windows 8.1 (X64) (2015-11-26 22:49:59) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1461667933-2917687346-235261616-500 - Administrator - Disabled) Guest (S-1-5-21-1461667933-2917687346-235261616-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1461667933-2917687346-235261616-1003 - Limited - Enabled) Luigi (S-1-5-21-1461667933-2917687346-235261616-1001 - Administrator - Enabled) => C:\Users\Luigi ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acronis True Image 2014 (HKLM-x32\...\{6607759B-0CDE-4106-B461-6371935EAB57}Visible) (Version: 17.0.6614 - Acronis) Acronis True Image 2014 (x32 Version: 17.0.6614 - Acronis) Hidden Ample Guitar M Lite version 1.1.7 (HKLM-x32\...\{BA6E19BD-02E5-4472-BE88-0D5FCFA0BA24}_is1) (Version: 1.1.7 - Ample Sound Technology Co., Ltd.) AmpliTube 3 version 3.10.0 (HKLM\...\{DA5202AC-12BF-4330-B8EA-BC77F991FA1C}_is1) (Version: 3.10.0 - IK Multimedia) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2245 - AVAST Software) CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform) Classic Shell (HKLM\...\{D4B3454F-7529-4F5F-851D-2C36933F7D64}) (Version: 4.2.5 - IvoSoft) Custom Shop version 1.1.0 (HKLM-x32\...\{21BAD046-50EC-49E2-BE7B-F9729704F2C3}_is1) (Version: 1.1.0 - IK Multimedia) Echo24 PCI (HKLM-x32\...\Echo24 PCI) (Version: 8.6 - Echo Digital Audio) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) IK Multimedia Amplitube DX/VST/RTAS v2.0 (HKLM-x32\...\IK Multimedia Amplitube DX/VST/RTAS v2.0) (Version: - ) IK Multimedia Authorization Manager version 1.0.10 (HKLM\...\{85BC0DCB-69E5-4279-AA25-F108EF896588}_is1) (Version: 1.0.10 - IK Multimedia) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) JBridge (HKLM-x32\...\JBridge) (Version: - JBridge) Malwarebytes Anti-Malware versione 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) M-Audio MIDISPORT 6.1.3 (x64) (HKLM\...\{AED2A1D4-19B4-4692-8004-E1A3E8A9E85B}) (Version: 6.1.3 - M-Audio) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Mozilla Firefox 42.0 (x86 it) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 it)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0 - Mozilla) MusicLab RealGuitar (HKLM\...\{1864B4F0-8888-5A57-9930-C2B307597966}) (Version: 3.0 - MusicLab, Inc.) MusicLab RealLPC (HKLM\...\{38209080-8888-4418-8117-D190FC71BF58}) (Version: 3.0 - MusicLab, Inc.) MusicLab RealStrat (HKLM\...\{58206080-8888-4418-8117-D190FC71BF58}) (Version: 3.0 - MusicLab, Inc.) MusicLab Virtual MIDI Driver (HKLM\...\{A30B7FD7-04A1-46e1-ABDF-FD592C113253}) (Version: 2.0.1.0 - MusicLab, Inc.) Native Instruments Kontakt 5 (HKLM-x32\...\Native Instruments Kontakt 5) (Version: 5.5.0.409 - Native Instruments) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments) qBittorrent 3.3.0 (HKLM-x32\...\qBittorrent) (Version: 3.3.0 - The qBittorrent project) reFX Nexus VSTi RTAS v2.2.0 (HKLM-x32\...\reFX Nexus_is1) (Version: - ) reFX Vanguard 1.7.2 (HKLM-x32\...\reFX Vanguard 1.7.2_is1) (Version: - ) SampleTank (HKLM-x32\...\{6559654F-2F38-491F-8411-211517C3E635}) (Version: 2.5.5 - IK Multimedia) SampleTank 3 version 3.0.1 (HKLM\...\{4A5CE684-33A5-4EE6-AB22-4B92D92D37D8}_is1) (Version: 3.0.1 - IK Multimedia) Sandboxie 5.06 (64-bit) (HKLM\...\Sandboxie) (Version: 5.06 - Sandboxie Holdings, LLC) Steinberg Cubase 5 (HKLM-x32\...\{4A19D6AC-ADE0-4A07-80FF-9C9812C45557}) (Version: 5.1.2 - Steinberg Media Technologies GmbH) Steinberg Drum Loop Expansion 01 (HKLM-x32\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 1.0.0.1 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Content (HKLM-x32\...\{BD86F1AC-B594-46E4-85DC-1258AC9E2232}) (Version: 1.0.0.003 - Steinberg Media Technologies GmbH) Steinberg HALionOne (HKLM-x32\...\{E70E7159-93B1-470D-9FBD-D8E9EF34B538}) (Version: 1.1.0.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Additional Content Set 01 (HKLM-x32\...\{F3AFD063-8BAD-485E-B641-E7F5A2C5AE71}) (Version: 1.0.0.001 - Steinberg Media Technologies GmbH) Steinberg HALionOne Expression Set (HKLM-x32\...\{E22AD5D3-EB60-4A8F-835C-6C10E369DCE2}) (Version: 1.0.1.0 - Steinberg Media Technologies GmbH) Steinberg HALionOne GM Drum Set (HKLM-x32\...\{AC997F93-0757-4ED4-A701-F40C2D654D09}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne GM Set (HKLM-x32\...\{F057965A-D974-4C64-ADB1-4381CD4B8956}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Pro Set (HKLM-x32\...\{D82CDA0D-C182-42C8-8FF2-5649C98D6003}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Studio Drum Set (HKLM-x32\...\{865D9ED1-EAC2-436D-AFA7-0B750EB5AAAB}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Studio Set (HKLM-x32\...\{D23CBFDA-C46B-4920-BA70-FC7878A3F05A}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg LoopMash Content (HKLM-x32\...\{4D454CF8-12FD-464D-B57B-B46FE27B78BB}) (Version: 1.0.0.005 - Steinberg Media Technologies GmbH) Steinberg REVerence Content 01 (HKLM-x32\...\{532B917B-8235-4FA5-BE36-643A8BB053A5}) (Version: 1.0.0.006 - Steinberg Media Technologies GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1210 - SUPERAntiSpyware.com) TC Native Bundle v3.1 (HKLM-x32\...\TC Native Bundle v3.1) (Version: - ) UltraISO Premium V9.53 (HKLM-x32\...\UltraISO_is1) (Version: - ) WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1461667933-2917687346-235261616-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) ==================== Restore Points ========================= ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2015-11-27 11:46 - 00000861 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 activation.acronis.com ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {065FEFD8-D82D-4D0E-ADC9-4AEA09E49792} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-12-06] (AVAST Software) Task: {5925502A-A4E9-4AE5-A5B4-2EA2C93DC1AD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd) Task: {CB2CDA11-9EE6-4E2B-89C6-2F9BA3B5EFA9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-12-06] (AVAST Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2013-10-01 10:48 - 2013-10-01 10:48 - 02815536 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll 2015-11-16 17:55 - 2015-11-16 17:55 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1040.dll 2015-12-06 15:37 - 2015-12-06 15:37 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-12-06 15:37 - 2015-12-06 15:37 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-12-06 15:39 - 2015-12-06 15:39 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15120600\algo.dll 2015-12-06 15:37 - 2015-12-06 15:37 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-12-06 15:37 - 2015-12-06 15:37 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-11-14 22:22 - 2013-11-14 22:22 - 00028992 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll 2013-11-14 22:25 - 2013-11-14 22:25 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll 2013-10-01 11:00 - 2013-10-01 11:00 - 00022336 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\62325471.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\76543075.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\62325471.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\76543075.sys => ""="Driver" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1461667933-2917687346-235261616-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{8DD8236C-708A-4141-BB60-9A3DADE17131}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D94B15C4-8B73-4769-BD6A-703A99C88550}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{0A22DE97-A28E-466F-ABD2-58314CA01567}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{488A88FC-322B-4CCF-B027-BAF1AA9046FC}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{C84333CE-C2DE-4D13-8405-D2C88C01173B}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [{C84D5C38-D8B7-418A-9F8E-B599E8D327E7}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/06/2015 04:30:39 PM) (Source: Application Error) (EventID: 1005) (User: ) Description: Impossibile accedere al file per uno dei motivi seguenti: Si è verificato un problema relativo alla connessione di rete, al disco in cui è archiviato il file o ai driver di archiviazione installati nel computer oppure il disco è assente. Il programma Processo host per servizi di Windows è stato chiuso a causa dell'errore. Programma: Processo host per servizi di Windows File: Il valore dell'errore è indicato nella sezione Dati aggiuntivi. Azione utente 1. Aprire nuovamente il file. Potrebbe trattarsi di un problema temporaneo che si risolverà automaticamente rieseguendo il programma. 2. Se il file risulta comunque non accessibile e: - Si trova in rete, è necessario che l'amministratore della rete verifichi la presenza di eventuali problemi di rete e che sia possibile contattare il server. - Si trova in un disco rimovibile, ad esempio un disco floppy o un CD, verificare che il disco sia inserito correttamente nel computer. 3. Controllare e ripristinare il file system eseguendo CHKDSK. Per eseguire CHKDSK, fare clic sul pulsante Start, scegliere Esegui, digitare CMD, quindi scegliere OK. Al prompt dei comandi, digitare CHKDSK /F, quindi premere INVIO. 4. Se il problema persiste, ripristinare il file da una copia di backup. 5. Determinare se è possibile aprire altri file nello stesso disco. Se non è possibile, il disco potrebbe essere danneggiato. Se si tratta di un disco rigido, contattare l'amministratore o il fornitore dell'hardware del computer per ottenere assistenza. Dati aggiuntivi Valore errore: C000003F Tipo disco: 0 Error: (12/06/2015 04:30:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome dell'applicazione che ha generato l'errore: svchost.exe_SysMain, versione: 6.3.9600.16384, timestamp: 0x5215dfe3 Nome del modulo che ha generato l'errore: ntdll.dll, versione: 6.3.9600.17031, timestamp: 0x530895af Codice eccezione: 0xc0000006 Offset errore 0x000000000003f14b ID processo che ha generato l'errore: 0x13c Ora di avvio dell'applicazione che ha generato l'errore: 0xsvchost.exe_SysMain0 Percorso dell'applicazione che ha generato l'errore: svchost.exe_SysMain1 Percorso del modulo che ha generato l'errore: svchost.exe_SysMain2 ID segnalazione: svchost.exe_SysMain3 Nome completo pacchetto che ha generato l'errore: svchost.exe_SysMain4 ID applicazione relativo al pacchetto che ha generato l'errore: svchost.exe_SysMain5 Error: (12/06/2015 02:58:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: ) Description: Servizi di crittografia: impossibile inizializzare il database del catalogo. Errore ESENT: -501. Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 454) (User: ) Description: Catalog Database (1224) Catalog Database: Ripristino database non riuscito. Errore imprevisto -501. Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 465) (User: ) Description: Catalog Database (1224) Catalog Database: Sono stati rilevati dati danneggiati durante il ripristino software del file di registro C:\Windows\system32\CatRoot2\edb.log. Il record che origina l'errore nel checksum si trova nella seguente posizione: END. I primi dati non corrispondenti al criterio di riempimento del file di registro sono comparsi nel settore 285 (0x0000011D). Il file di registro è danneggiato. Impossibile utilizzarlo. Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 477) (User: ) Description: Catalog Database (1224) Catalog Database: Impossibile leggere l'intervallo di registro dal file "C:\Windows\system32\CatRoot2\edb.log" all'offset 1167360 (0x000000000011d000) per 4096 (0x00001000) byte a causa di una mancata corrispondenza del checksum dell'intervallo. Checksum previsto: 47007039726499975 (0xa700a750d73887). Checksum effettivo: 47007039726499975 (0xa700a750d73887). L'operazione di lettura non verrà effettuata con errore -501 (0xfffffe0b). Se tale condizione persiste, ripristinare il file di registro da un backup precedente. Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 465) (User: ) Description: Catalog Database (1224) Catalog Database: Sono stati rilevati dati danneggiati durante il ripristino software del file di registro C:\Windows\system32\CatRoot2\edb.log. Il record che origina l'errore nel checksum si trova nella seguente posizione: END. I primi dati non corrispondenti al criterio di riempimento del file di registro sono comparsi nel settore 285 (0x0000011D). Il file di registro è danneggiato. Impossibile utilizzarlo. Error: (12/06/2015 02:58:10 PM) (Source: ESENT) (EventID: 477) (User: ) Description: Catalog Database (1224) Catalog Database: Impossibile leggere l'intervallo di registro dal file "C:\Windows\system32\CatRoot2\edb.log" all'offset 1167360 (0x000000000011d000) per 4096 (0x00001000) byte a causa di una mancata corrispondenza del checksum dell'intervallo. Checksum previsto: 47007039726499975 (0xa700a750d73887). Checksum effettivo: 47007039726499975 (0xa700a750d73887). L'operazione di lettura non verrà effettuata con errore -501 (0xfffffe0b). Se tale condizione persiste, ripristinare il file di registro da un backup precedente. Error: (12/06/2015 02:57:30 PM) (Source: Windows Search Service) (EventID: 1006) (User: ) Description: Servizio Windows Search: impossibile creare il nuovo indice di ricerca. Errore interno <4, 0x80070020, Impossibile aggiungere il progetto: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>. Error: (12/06/2015 02:56:54 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Impossibile inizializzare l'indice. Dettagli: Impossibile trovare l'oggetto specificato. Specificare il nome di un oggetto esistente. (HRESULT : 0x80040d06) (0x80040d06) System errors: ============= Error: (12/07/2015 10:18:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Timeout (30000 millisecondi) durante l'attesa della connessione del servizio Servizio Segnalazione errori Windows. Error: (12/07/2015 10:15:31 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Il servizio MBAMService dipende dal servizio MBAMProtector che non è stato avviato per il seguente errore: %%193 Error: (12/07/2015 10:15:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Il servizio MBAMProtector non è stato avviato per il seguente errore: %%193 Error: (12/07/2015 10:15:10 AM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY) Description: C:\Device\HarddiskVolume23 Error: (12/06/2015 10:04:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Il servizio MBAMService dipende dal servizio MBAMProtector che non è stato avviato per il seguente errore: %%193 Error: (12/06/2015 10:04:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Il servizio MBAMProtector non è stato avviato per il seguente errore: %%193 Error: (12/06/2015 10:04:19 PM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY) Description: C:\Device\HarddiskVolume23 Error: (12/06/2015 04:32:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Servizio Generatore endpoint audio Windows terminato con l'errore: %%1115 Error: (12/06/2015 04:32:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Il servizio Client di Criteri di gruppo non è stato avviato per il seguente errore: %%1053 Error: (12/06/2015 04:32:16 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Timeout (30000 millisecondi) durante l'attesa della risposta alla transazione dal servizio gpsvc. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz Percentage of memory in use: 10% Total physical RAM: 16069.32 MB Available physical RAM: 14377.74 MB Total Virtual: 32453.32 MB Available Virtual: 30773.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:777.48 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DD5CACA0) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ==================== End of Addition.txt |
|
|
|
|
|
#6 |
|
Member
Iscritto dal: Dec 2015
Messaggi: 54
|
vorrei vedere anche i log di tdskiller e aswmbr, allegali non copiarli per cortesia
con tds killer per caso hai cliccato su ''delete'' ? |
|
|
|
|
|
#7 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
NOn mi sembra proprio di aver cliccate delete su tds killer ma lo posso dire al 99 % ....magari per errore ho cliccato qualcosa ha fatto una scansione lui e se ha cancellato qualcosa era in automatico... Ok allrgo solo i LINK va bene.
Nell'ordine: un link di una scansione fatta ieri con Rkill http://www.wikifortio.com/778640/Rkill.txt poi link con scansione di aswmbr (con cui nella precedente scansione non ho cancellato nulla): quick scan:http://www.wikifortio.com/800057/aswMBR%20quick.txt C scan: http://www.wikifortio.com/817504/aswMBR%20C.txt riguardo TDS KILLER: http://www.wikifortio.com/771063/TDS....15.18_log.txt fatto ora e un altro fatto ieri: http://www.wikifortio.com/700474/TDS....15.10_log.txt |
|
|
|
|
|
#8 |
|
Member
Iscritto dal: Dec 2015
Messaggi: 54
|
prova ad usare tds killer settato cosi'
scarica TDSSKiller sul desktop ed estrai il contenuto Clicca su "Change parameters" Metti la spunta sulle caselline: verify driver digital singatures e poi Detect TDLFS file system . Conferma cliccando OK. Poi clicca su "Start Scan" Se trova qualche infezione di default avrai l'opzione "Cure" per cui, clicca su "Continue". Se un file sospetto viene trovato,l'azione di default sarà "skip",clicca su "Continue". Se è richiesto il riavvio,(Reboot) acconsenti. (per eliminare l'infezione è necessario riavviare il pc) Se nessun riavvio è richiesto clicca su report e salva il contenuto in un file di testo. Fai anche questa scansione, oltre a cercare elementi nocivi dovrebbe ripristinare qualche filesystem che e' stato corrotto scarica combofix sul desktop alla richiesta se vuoi installare la recovery console clicca su NO esegui ComboFix.exe segui le instruzioni finita la scansione portati in C:\ e allega nella tua prossima risposta, il contenuto del file di testo Combofix.txt |
|
|
|
|
|
#9 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
OK ora eseguo ma combofix purtroppo non funziona con windows 8.1 , ma solo fino a win 8----!!! Almeno cosi' ho trovato sul sito... esiste un programma analogo alternativo o una nuova versione per win 8.1 ? Llo avrei usato per primo infatti...
|
|
|
|
|
|
#10 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
La scansione che mi hai indicato l'ho postata sopra come fatta 15 minuti fa E' la prima delle due...i settaggi erano proprio quelli infatti ci avevo pensato; per sicurezza la rifaccio (quella fatta ieri aveva altro settaggio non considerarla... ) e la riposto. Ma mi manca combo fix un casino
|
|
|
|
|
|
#11 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
COn TDSSkiller non ho avuto problemi non mi ha trovato alcuna infeizone di default ad ogni modo. Per ripristinare i file di sistema potrei usare tweaking windows repair ? O si fa peggio? O col disco originale di winb.1 (ma ho apura che mi rispoda impossibile ripristinare ) oppure dal prompt di wind scannow ripristino ?
|
|
|
|
|
|
#12 |
|
Member
Iscritto dal: Dec 2015
Messaggi: 54
|
|
|
|
|
|
|
#13 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Ok la faccio dal DVD riavviando il tutto poi ti faccio sapere
|
|
|
|
|
|
#14 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Ecco di nuovo una stranezza.... ho fatto un primo tentativo dal sistema in ambiente windows da ricerca ho digitato cmd ... dal prompt previa disabilitazione di avast e dei programi in esecuzione: .- ho utlizzato i privilegi di amministrtore (tasto destro esegio come amministratore) - e mi è uscito C: Windows/system32
e poi sfc /scannow Lui ha controllato scrivendo " avvio in corso dell'analisi di sistema " ecc... a fine controllo dei file di C mi ha risposto: protezione risorse di windows impossibile eseguire l'operazione richiesta ????? |
|
|
|
|
|
#15 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Lo stesso aviene se utilizzo il disco di windows 8.1 seguendo la procedura dal boot settato con dvd come prima opzione... la risposta è a stessa: proteizone di risorse di windows impossibile eseguire l'operazione richiesta dopo sfc scannow (ma anche con l'altro comando). Niente da fare l'intrusione avvenuta deve aver bloccato qualcosa nei servizi di windows forse....Sto cercando di farmi venire qualche idea
|
|
|
|
|
|
#16 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
nel frattempo posto di nuovo il log di TDSS KILLER con le modifiche settate per un ulteriore controllo
http://www.wikifortio.com/771063/TDS....15.18_log.txt |
|
|
|
|
|
#17 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Allora a beneficio pure di altri utenti in caso uguale ho trovato come utile suggerimento nel mio caso di risposta di scannow impossibile da effettaure, essendo risultati file di sistema mancanti o danneggaiti da tutte le scansioni, quello di utilizzare i comandi DISM dal prompt come amministratore per correggere l'immagine di sistema:
dism.exe /online /cleanup-image /scanhealth alla fine del procesos mi è uscita la risposta : l'archivio dei componenti è ripristinabile al che ho provato dism.exe /online /cleanup-image /restorehealth tuttavia questa seconda operazione mi ha dato esito negativo in quanto non riusciva a tovare la cartella o al directory source per correggere Infine ho riprovato a usare il comando scannow e questa volta il risultato finale è stato positivo Proteione di windows: nessuna violazione di integrità trovata Probabilmente i file mancanti sono stati ripristinati con la prima delle due operazioni!!! Adesso che scansione faccio per far eun ultimo controllo di integrita' del sistema???? Di nuovo con FARBAR????? |
|
|
|
|
|
#18 |
|
Member
Iscritto dal: Dec 2015
Messaggi: 54
|
ora che hai eseguito Sfc /scannow controlla i risultato nella cartella C:\WINDOWS\logs\cbs\CBS.log
Allegalo qui una domanda: il pc e' lento o instabile dopo queste operazioni? facciamo anche un controllo sui servizi Scarica Farbar Service metti la spunta a tutte le caselle e clicca su ''scan'' Allega il log di fine scansione |
|
|
|
|
|
#19 |
|
Junior Member
Iscritto dal: Dec 2015
Messaggi: 22
|
Piu' che altro il pc tende a bloccarsi nei cambi di link su internet o nei comandi di apertura icone o programmi ad esempio ho scaricato faber e come ho aperto la cartella download si è bloccata quest'utima lasciando in esecuzione il comando del mouse per un po' poi si sblocca ; specie quando si sovrappongono i comandi ;
ora posto i link a) link di scannow : http://www.wikifortio.com/712234/CBS.log b) link di FFS farbar servizi tutte le caselle spuntate : http://www.wikifortio.com/844720/FSS.txt |
|
|
|
|
|
#20 |
|
Member
Iscritto dal: Dec 2015
Messaggi: 54
|
hai Windows Update e Windows Defender disattivati, ti consiglio di attivarli quanto prima
dimmi il problema principale qual'e' o se il pc e' migliorato, rootkit nemmeno l'ombra |
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 15:00.



















