Results 1 to 9 of 9

Thread: slowdowns and browser CTDs, malwarebytes and avast show nothing

  1. #1
    Junior Member
    Join Date
    Jun 2008
    Posts
    11

    Default slowdowns and browser CTDs, malwarebytes and avast show nothing

    Issue as per subject, ASWMBR CTDs during scan as well, farbar logs below:

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
    Ran by Elisa (administrator) on ELISA-PC on 30-12-2014 10:41:18
    Running from C:\Users\Elisa\Downloads
    Loaded Profile: Elisa (Available profiles: Elisa)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Italiano (Italia)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Microsoft Corporation) C:\Windows\System32\StikyNot.exe
    (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
    (Microsoft Corporation) C:\Windows\System32\alg.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    (Raxco Software, Inc.) C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\perfhost.exe
    (Microsoft Corporation) C:\Windows\System32\snmptrap.exe
    (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
    (Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
    (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2014-12-15] (AVAST Software)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
    HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\RunOnce: [Adobe Speed Launcher] => 1419327379
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\MountPoints2: {0025884f-2023-11e2-8207-b888e3020023} - E:\autorun.exe
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\MountPoints2: {22d678de-67a2-11e2-9090-e4d53dd20221} - D:\Autorun.exe
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\MountPoints2: {a3841f49-8493-11e2-9e4c-b888e3020023} - D:\Setup.exe
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\MountPoints2: {d4e2e537-66b7-11e2-90d9-b888e3020023} - D:\Autorun.exe
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\MountPoints2: {d4e2e548-66b7-11e2-90d9-b888e3020023} - D:\Autorun.exe
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\MountPoints2: {fb8e5712-8bf8-11e2-b2c4-b888e3020023} - D:\Autorun.exe
    HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
    Startup: C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
    ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
    BootExecute: PDBoot.exeautocheck autochk *

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-368298906-4009226880-499156854-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
    HKU\S-1-5-21-368298906-4009226880-499156854-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
    BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 62.101.93.101 83.103.25.250

    FireFox:
    ========
    FF ProfilePath: C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\81aqx0ep.default
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-368298906-4009226880-499156854-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Elisa\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
    FF Plugin ProgramFiles/Appdata: C:\Users\Elisa\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
    FF Extension: NoScript - C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\81aqx0ep.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-08-15]
    FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-22]

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://www.google.com/
    CHR Profile: C:\Users\Elisa\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Drive) - C:\Users\Elisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-08]
    CHR Extension: (YouTube) - C:\Users\Elisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-08]
    CHR Extension: (Ricerca Google) - C:\Users\Elisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-08]
    CHR Extension: (Google Wallet) - C:\Users\Elisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
    CHR Extension: (Gmail) - C:\Users\Elisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-08]
    CHR HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\Chrome\Extension: [ncdghcmanhfigpijjllopocpcnjffkhl] - C:\Users\Elisa\AppData\Local\CRE\ncdghcmanhfigpijjllopocpcnjffkhl.crx [2012-08-26]
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-23]
    CHR HKLM-x32\...\Chrome\Extension: [ncdghcmanhfigpijjllopocpcnjffkhl] - C:\Users\Elisa\AppData\Local\CRE\ncdghcmanhfigpijjllopocpcnjffkhl.crx [2012-08-26]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-23] (AVAST Software)
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
    R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
    R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
    S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
    S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93696 2013-04-23] (LG Electronics Inc.)
    R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-23] ()
    R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-23] (AVAST Software)
    R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-23] (AVAST Software)
    R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-23] ()
    R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-23] (AVAST Software)
    R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-23] (AVAST Software)
    R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-23] (AVAST Software)
    R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-23] ()
    S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-08-30] (Broadcom Corporation.)
    R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-27] (DT Soft Ltd)
    S3 HSPADataCardusbmdm; C:\Windows\System32\DRIVERS\HSPADataCardusbmdm.sys [122752 2009-12-14] (HSPADataCard Incorporated) [File not signed]
    S3 HSPADataCardusbnmea; C:\Windows\System32\DRIVERS\HSPADataCardusbnmea.sys [122752 2009-12-14] (HSPADataCard Incorporated) [File not signed]
    S3 HSPADataCardusbser; C:\Windows\System32\DRIVERS\HSPADataCardusbser.sys [122752 2009-12-14] (HSPADataCard Incorporated) [File not signed]
    S3 HSPADataCardusbvoice; C:\Windows\System32\DRIVERS\HSPADataCardusbvoice.sys [122752 2009-12-14] (HSPADataCard Incorporated) [File not signed]
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
    R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
    S3 onda_cdc_acm; C:\Windows\System32\DRIVERS\onda_cdc_acm.sys [79872 2011-05-09] (ONDA)
    S3 onda_cdc_ecm; C:\Windows\System32\DRIVERS\onda_cdc_ecm.sys [58880 2011-05-09] (ONDA)
    R3 onda_dc_enum; C:\Windows\System32\DRIVERS\onda_dc_enum.sys [59392 2010-08-10] (ONDA)
    S3 onda_ecm_enum; C:\Windows\System32\DRIVERS\onda_ecm_enum.sys [56320 2011-05-09] (ONDA)
    S3 onda_ecm_enum_filter; C:\Windows\System32\DRIVERS\onda_ecm_enum_filter.sys [56320 2011-05-09] (ONDA)
    S3 onda_wcpo; C:\Windows\System32\DRIVERS\onda_wcpo.sys [10240 2011-05-09] (ONDA)

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-12-30 10:41 - 2014-12-30 10:42 - 00014891 _____ () C:\Users\Elisa\Downloads\FRST.txt
    2014-12-30 10:40 - 2014-12-30 10:41 - 00000000 ____D () C:\FRST
    2014-12-30 10:40 - 2014-12-30 10:40 - 02123264 _____ (Farbar) C:\Users\Elisa\Downloads\FRST64.exe
    2014-12-30 10:40 - 2014-12-30 10:40 - 02123264 _____ (Farbar) C:\Users\Elisa\Downloads\FRST64 (1).exe
    2014-12-23 10:44 - 2014-12-23 10:49 - 00004237 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_71-b14.log
    2014-12-23 10:12 - 2014-12-23 10:34 - 00000000 ____D () C:\AdwCleaner
    2014-12-23 10:11 - 2014-12-23 10:11 - 02173952 _____ () C:\Users\Elisa\Downloads\AdwCleaner.exe
    2014-12-23 09:29 - 2014-12-23 10:07 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2014-12-23 09:27 - 2014-12-23 10:07 - 00000000 ____D () C:\Users\Elisa\Desktop\mbar
    2014-12-23 09:27 - 2014-12-23 09:27 - 16448208 _____ (Malwarebytes Corp.) C:\Users\Elisa\Downloads\mbar-1.08.2.1001.exe
    2014-12-20 18:25 - 2014-12-20 18:25 - 00699648 _____ () C:\Users\Elisa\Downloads\Outlook.com.zip
    2014-12-20 18:25 - 2014-12-20 18:25 - 00699648 _____ () C:\Users\Elisa\Downloads\Outlook.com (1).zip
    2014-12-18 07:23 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-12-18 07:23 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-12-17 21:27 - 2014-12-17 21:27 - 00000000 __SHD () C:\found.001
    2014-12-16 13:25 - 2014-12-16 13:25 - 00000000 ____D () C:\Users\Elisa\AppData\Local\{46C7B644-4C6B-4296-ACF1-0C48810653F0}
    2014-12-12 08:07 - 2014-12-12 08:07 - 00000000 ____D () C:\Windows\system32\appraiser
    2014-12-11 14:36 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2014-12-11 14:36 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
    2014-12-10 07:32 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2014-12-10 07:32 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2014-12-10 07:32 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2014-12-10 07:32 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2014-12-10 07:32 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-12-10 07:32 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2014-12-10 07:32 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-12-10 07:32 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
    2014-12-10 07:31 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-12-10 07:31 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-12-10 07:31 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-12-10 07:31 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-12-10 07:31 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-12-10 07:31 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-12-10 07:31 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-12-10 07:31 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-12-10 07:31 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-12-10 07:31 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-12-10 07:31 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-12-10 07:31 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-12-10 07:31 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-12-10 07:31 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-12-10 07:31 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-12-10 07:31 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-12-10 07:31 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-12-10 07:31 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-12-10 07:31 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2014-12-10 07:31 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-12-10 07:31 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-12-10 07:31 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-12-10 07:31 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-12-10 07:31 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-12-10 07:31 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-12-10 07:31 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-12-10 07:31 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-12-10 07:31 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2014-12-10 07:31 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-12-10 07:31 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-12-10 07:31 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2014-12-10 07:31 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-12-10 07:31 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-12-10 07:31 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-12-10 07:31 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-12-10 07:31 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2014-12-10 07:31 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-12-10 07:31 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-12-10 07:31 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-12-10 07:31 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-12-10 07:31 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-12-10 07:31 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-12-10 07:31 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2014-12-10 07:31 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2014-12-10 07:31 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2014-12-10 07:30 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-12-10 07:30 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-12-10 07:30 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2014-12-10 07:30 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-12-10 07:30 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-12-10 07:30 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-12-10 07:30 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2014-12-10 07:30 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-12-10 07:30 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2014-12-10 07:30 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2014-12-10 07:30 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-12-10 07:30 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-12-10 07:30 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
    2014-12-10 07:30 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
    2014-12-10 07:30 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
    2014-12-10 07:30 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
    2014-12-10 07:30 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
    2014-12-10 07:30 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
    2014-12-10 07:30 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
    2014-12-10 07:30 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
    2014-12-10 07:30 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
    2014-12-10 07:30 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
    2014-12-10 07:30 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
    2014-12-10 07:30 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
    2014-12-10 07:29 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2014-12-10 07:29 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2014-12-09 10:47 - 2014-12-09 10:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-12-30 10:40 - 2012-04-06 09:49 - 00741652 _____ () C:\Windows\system32\perfh010.dat
    2014-12-30 10:40 - 2012-04-06 09:49 - 00147674 _____ () C:\Windows\system32\perfc010.dat
    2014-12-30 10:40 - 2009-07-14 06:13 - 01661252 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-12-30 10:38 - 2012-11-08 13:11 - 00001150 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-12-30 10:37 - 2014-04-22 06:46 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
    2014-12-30 10:37 - 2012-10-14 17:24 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-12-30 10:37 - 2012-04-06 00:02 - 01486732 _____ () C:\Windows\WindowsUpdate.log
    2014-12-29 19:27 - 2014-05-08 07:57 - 00000000 ____D () C:\Users\Elisa\Desktop\matrimonio 2015
    2014-12-29 18:47 - 2012-11-08 13:11 - 00001146 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-12-25 09:23 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-12-25 09:23 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-12-23 10:44 - 2013-06-25 06:29 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-12-23 10:40 - 2014-09-07 12:29 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Adobe
    2014-12-23 10:40 - 2012-10-14 17:24 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-12-23 10:40 - 2012-10-14 17:24 - 00003916 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2014-12-23 10:40 - 2011-10-19 18:05 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-12-23 10:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Registration
    2014-12-23 10:36 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-12-23 10:36 - 2009-07-14 05:51 - 00115779 _____ () C:\Windows\setupact.log
    2014-12-23 10:35 - 2010-11-21 04:47 - 00156800 _____ () C:\Windows\PFRO.log
    2014-12-23 09:29 - 2014-09-21 21:19 - 00135384 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-12-23 09:28 - 2014-09-21 21:18 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-12-22 17:01 - 2014-10-02 18:43 - 00000000 ____D () C:\Users\Elisa\Desktop\unicusano scienze dell'educazione
    2014-12-22 14:12 - 2014-05-23 18:44 - 00000000 ____D () C:\Users\Elisa\.digiSigner
    2014-12-20 18:26 - 2014-10-20 19:12 - 00000000 ____D () C:\Users\Elisa\Documents\curriculum e dati
    2014-12-20 18:26 - 2012-10-14 16:52 - 00000000 ____D () C:\Users\Elisa\Documents\io e amorino
    2014-12-12 08:16 - 2013-11-18 08:43 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
    2014-12-12 08:14 - 2013-07-13 08:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2014-12-12 08:07 - 2014-04-23 09:27 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2014-12-12 08:07 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
    2014-12-12 08:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
    2014-12-11 14:58 - 2012-10-14 19:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2014-12-11 14:53 - 2013-07-24 15:38 - 00000000 ____D () C:\Windows\system32\MRT
    2014-12-11 14:42 - 2012-08-28 16:47 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

    Some content of TEMP:
    ====================
    C:\Users\Elisa\AppData\Local\Temp\fb1vbl4n.aiz.exe
    C:\Users\Elisa\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
    C:\Users\Elisa\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
    C:\Users\Elisa\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
    C:\Users\Elisa\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
    C:\Users\Elisa\AppData\Local\Temp\jscrcap2_libNativeApi_x86.dll
    C:\Users\Elisa\AppData\Local\Temp\jscrcap_libNativeApi_x86.dll
    C:\Users\Elisa\AppData\Local\Temp\Quarantine.exe
    C:\Users\Elisa\AppData\Local\Temp\SkypeSetup.exe
    C:\Users\Elisa\AppData\Local\Temp\sqlite3.dll


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2014-12-25 19:08

    ==================== End Of Log ============================


    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2014
    Ran by Elisa at 2014-12-30 10:44:00
    Running from C:\Users\Elisa\Downloads
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
    AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKLM-x32\...\uTorrent) (Version: 3.2.0 - BitTorrent Inc.)
    Abe's Oddysee (HKLM-x32\...\Abe's Oddysee) (Version: - )
    Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
    Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
    Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
    Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Acer Incorporated)
    Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.04.3504 - Acer Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
    Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
    Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.10) - Italiano (HKLM-x32\...\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
    ATI Catalyst Install Manager (HKLM\...\{3605D89A-BD66-F5C5-779B-BE9110B41077}) (Version: 3.0.829.0 - ATI Technologies, Inc.)
    Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
    Bing Bar (HKLM-x32\...\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}) (Version: 7.0.765.0 - Microsoft Corporation)
    CCleaner (HKLM\...\CCleaner) (Version: 3.22 - Piriform)
    Cisco WebEx Meetings (HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
    Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.8.50 - Conexant)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0316 - DT Soft Ltd)
    Default (x32 Version: 1.0.0.1 - Default Company Name) Hidden
    DigiSigner (HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\DigiSigner) (Version: - )
    ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
    ETDWare PS/2-X64 8.0.6.0_WHQL (HKLM\...\Elantech) (Version: 8.0.6.0 - ELAN Microelectronic Corp.)
    FASTWEB 3G (HKLM-x32\...\{788769EA-3F2B-49E2-B3C1-CDC740EB4045}) (Version: 1.00.0000 - FASTWEB)
    Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotogrŕfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
    Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle)
    Jazz Jackrabbit 2 Christmas Chronicles 99 (HKLM-x32\...\Jazz Jackrabbit 2 Christmas Chronicles 99) (Version: - )
    Jazz Jackrabbit 2 Holiday Hare 98 (HKLM-x32\...\Jazz Jackrabbit 2 Holiday Hare 98) (Version: - )
    Jazz Jackrabbit 2 Secret Files (HKLM-x32\...\Jazz Jackrabbit 2 Secret Files) (Version: - )
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    LG United Mobile Driver (HKLM-x32\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics)
    Malwarebytes Anti-Malware versione 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
    OpenOffice.org 3.4.1 (HKLM-x32\...\{1ADB558F-1E50-43F2-8EAC-E7D75294C1D8}) (Version: 3.41.9593 - Apache Software Foundation)
    Pandemonium for Windows (HKLM-x32\...\Pandemonium) (Version: - )
    PerfectDisk Professional (HKLM\...\{682B22AB-EAAA-4B1C-83AF-B26E7D4ED01E}) (Version: 13.0.783 - Raxco Software Inc.)
    Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Rayman 3 (HKLM-x32\...\Rayman 3_is1) (Version: - GOG.com)
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
    Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
    Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
    Superfrog (HKLM-x32\...\Superfrog_is1) (Version: - GOG.com)
    The Great Battles Collector's Edition (HKLM-x32\...\GOGPACKGREATBATTLESCE_is1) (Version: 2.0.0.16 - GOG.com)
    Unity Web Player (HKU\S-1-5-21-368298906-4009226880-499156854-1001\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
    VLC media player 2.0.3 (HKLM-x32\...\VLC media player) (Version: 2.0.3 - VideoLAN)
    WIDCOMM Bluetooth Software (HKLM\...\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}) (Version: 6.5.0.2200 - Broadcom Corporation)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
    Windows Phone app for desktop (HKLM-x32\...\{CFF220E2-642C-4B41-87FA-9A634C6E01CF}) (Version: 1.1.2726.0 - Microsoft Corporation)
    WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
    Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
    Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


    ==================== Restore Points =========================

    04-12-2014 21:39:44 Windows Update
    08-12-2014 15:03:29 Windows Update
    11-12-2014 14:31:47 Windows Update
    14-12-2014 17:01:29 Windows Update
    18-12-2014 21:42:20 Windows Update
    19-12-2014 07:15:13 Windows Update
    22-12-2014 10:46:22 Windows Update
    23-12-2014 10:42:45 Installed Java 7 Update 71
    26-12-2014 10:04:05 Windows Update
    29-12-2014 18:22:12 Windows Update

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 03:34 - 2013-08-10 11:46 - 00450636 ____R C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 www.10sek.com
    127.0.0.1 10sek.com
    127.0.0.1 www.1-2005-search.com
    127.0.0.1 1-2005-search.com
    127.0.0.1 www.123fporn.info
    127.0.0.1 123fporn.info
    127.0.0.1 123haustiereundmehr.com
    127.0.0.1 www.123haustiereundmehr.com
    127.0.0.1 123moviedownload.com

    There are 1000 more lines.


    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {0F22D517-2801-4260-BD0A-622FA329777E} - System32\Tasks\{20C13FB8-C4C0-4822-BB26-E0FEBA0C0B5D} => C:\Users\Elisa\Desktop\cotw\CASTLE1.EXE
    Task: {199CF2F7-FDA8-4B0A-819F-20020C36CD8F} - System32\Tasks\{2B63E88E-50E8-4AE0-A5CA-92BB4A10050F} => pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
    Task: {1E417160-06C8-45D9-8C34-E185DA644F26} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-08] (Google Inc.)
    Task: {2BB49E96-2D57-4D4D-AA76-555448BE8356} - System32\Tasks\{65474D64-1F5D-4B09-BD47-016DBB7E9C85} => E:\SETUP.EXE
    Task: {351ADCE5-6FD5-4B2B-A2A7-7AFA6B7CAE35} - System32\Tasks\{A7A7F208-0BDD-48A4-814F-03E79FA9C5C9} => E:\JAZZ.EXE
    Task: {3BAE2E67-7BAE-4500-B2D8-0FC4C59E812B} - System32\Tasks\{7F9D21F5-E425-457E-AA3F-5C421DB32BAA} => E:\SETUP.EXE
    Task: {3C467383-8154-463C-ABA8-5E1AA10FAB91} - System32\Tasks\{C98CE9E9-3BBD-4495-B043-C09BE3E6EFCE} => C:\Games\World_of_Tanks\WorldOfTanks.exe
    Task: {4CCB5BBE-9EC1-4306-B9D4-56CDA3C678EC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-23] (Adobe Systems Incorporated)
    Task: {691FB0FA-8766-4DE7-87D4-447A02899D3E} - System32\Tasks\{375642A9-EACD-472C-A3DE-648C64BA8AEF} => E:\INSTALL.EXE
    Task: {735A146B-E159-439E-8924-8A88FA48CC42} - System32\Tasks\{E406B91C-139A-418A-8761-2E3D8F34278F} => pcalua.exe -a "C:\Users\Elisa\Desktop\giochi\Jazz Jackrabbit 3\System\Setup.exe" -d "C:\Users\Elisa\Desktop\giochi\Jazz Jackrabbit 3\System"
    Task: {764660BC-8D3C-4020-BCFB-B78CAC8D9B98} - System32\Tasks\{2E679CDB-FADE-40ED-A2B3-4342FDFF9047} => pcalua.exe -a D:\Setup.exe -d D:\
    Task: {869EBEF8-EF33-443D-AEBD-B7495959FEC8} - System32\Tasks\{9865D05A-1762-4C76-86D3-8CD2924F215D} => C:\Users\Elisa\Desktop\cotw\CASTLE1.EXE
    Task: {8B05D2DB-3237-49FE-AC21-FC9C46D2A3F9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-23] (AVAST Software)
    Task: {B2582B45-4A27-4B0A-902F-79473B46BE4F} - System32\Tasks\{A983E7FA-1A46-4D57-BD1F-98684C78711F} => C:\Games\World_of_Tanks\WorldOfTanks.exe
    Task: {C3C0ED44-A77F-4C7B-8CFF-1E1FB02F344A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-08] (Google Inc.)
    Task: {D21119A0-5CBE-4E38-9997-ADBC43A9BC2C} - System32\Tasks\{68B7B9E6-F5FA-40EB-9323-6859B3C17F51} => D:\Setup.exe
    Task: {D783E7AF-A187-4DFB-B6FA-5AE45E51B544} - System32\Tasks\{812C3A41-DD05-4E2E-814B-94765BC6C360} => E:\JAZZ.EXE
    Task: {D841189F-C8E1-4788-B3B5-345B916BFF89} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-08-22] (Piriform Ltd)
    Task: {DFA6269B-79ED-441B-A0C7-0825335CE79E} - System32\Tasks\{B9F38873-8CFD-4E3C-8FAE-0623F473B13F} => D:\Setup.exe
    Task: {E330414C-0283-44E0-AB45-C55B9428AA8A} - System32\Tasks\{78E6FFC0-1CE4-45C6-BD6E-1FA380B7BB94} => D:\Setup.exe
    Task: {E96F4E71-059E-4F41-A8F2-7018AECC1755} - System32\Tasks\{CBF4D81A-1108-4F67-BA0B-15BF7FB4A15B} => C:\Users\Elisa\Desktop\cotw\CASTLE1.EXE
    Task: {F6325ED5-6132-40A7-B529-C08AFAD98483} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Loaded Modules (whitelisted) =============

    2014-12-23 10:15 - 2014-12-23 10:15 - 02908160 _____ () C:\Program Files\AVAST Software\Avast\defs\14122300\algo.dll
    2014-12-30 10:38 - 2014-12-30 10:38 - 02908160 _____ () C:\Program Files\AVAST Software\Avast\defs\14123000\algo.dll
    2012-08-10 15:51 - 2012-08-10 15:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
    2014-11-23 09:25 - 2014-11-23 09:25 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2014-12-09 10:47 - 2014-12-09 10:47 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    2014-12-13 09:18 - 2014-12-06 02:50 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
    2014-12-13 09:18 - 2014-12-06 02:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll
    2014-12-13 09:18 - 2014-12-06 02:50 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll
    2014-12-13 09:18 - 2014-12-06 02:50 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (whitelisted) =============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== MSCONFIG/TASK MANAGER disabled items =========

    (Currently there is no automatic fix for this section.)

    MSCONFIG\Services: AdobeARMservice => 2
    MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
    MSCONFIG\Services: AeLookupSvc => 3
    MSCONFIG\Services: ALG => 3
    MSCONFIG\Services: AppIDSvc => 3
    MSCONFIG\Services: AudioEndpointBuilder => 2
    MSCONFIG\Services: AudioSrv => 2
    MSCONFIG\Services: avast! Antivirus => 2
    MSCONFIG\Services: AxInstSV => 3
    MSCONFIG\Services: BBSvc => 3
    MSCONFIG\Services: BDESVC => 3
    MSCONFIG\Services: BFE => 2
    MSCONFIG\Services: BITS => 2
    MSCONFIG\Services: Browser => 3
    MSCONFIG\Services: bthserv => 3
    MSCONFIG\Services: btwdins => 2
    MSCONFIG\Services: CertPropSvc => 3
    MSCONFIG\Services: clr_optimization_v4.0.30319_32 => 2
    MSCONFIG\Services: clr_optimization_v4.0.30319_64 => 2
    MSCONFIG\Services: COMSysApp => 3
    MSCONFIG\Services: CryptSvc => 2
    MSCONFIG\Services: CxAudMsg => 2
    MSCONFIG\Services: defragsvc => 3
    MSCONFIG\Services: Dhcp => 2
    MSCONFIG\Services: Dnscache => 2
    MSCONFIG\Services: dot3svc => 3
    MSCONFIG\Services: DPS => 2
    MSCONFIG\Services: EapHost => 3
    MSCONFIG\Services: EFS => 3
    MSCONFIG\Services: ehRecvr => 3
    MSCONFIG\Services: ehSched => 3
    MSCONFIG\Services: eventlog => 2
    MSCONFIG\Services: EventSystem => 2
    MSCONFIG\Services: Fax => 3
    MSCONFIG\Services: fdPHost => 3
    MSCONFIG\Services: FDResPub => 2
    MSCONFIG\Services: FontCache => 2
    MSCONFIG\Services: FontCache3.0.0.0 => 3
    MSCONFIG\Services: hidserv => 3
    MSCONFIG\Services: hkmsvc => 3
    MSCONFIG\Services: HomeGroupListener => 3
    MSCONFIG\Services: HomeGroupProvider => 3
    MSCONFIG\Services: idsvc => 3
    MSCONFIG\Services: IKEEXT => 2
    MSCONFIG\Services: IPBusEnum => 3
    MSCONFIG\Services: iphlpsvc => 2
    MSCONFIG\Services: KeyIso => 3
    MSCONFIG\Services: KtmRm => 3
    MSCONFIG\Services: LanmanWorkstation => 2
    MSCONFIG\Services: lltdsvc => 3
    MSCONFIG\Services: lmhosts => 2
    MSCONFIG\Services: MBAMScheduler => 2
    MSCONFIG\Services: MBAMService => 2
    MSCONFIG\Services: Microsoft SharePoint Workspace Audit Service => 3
    MSCONFIG\Services: MMCSS => 2
    MSCONFIG\Services: MozillaMaintenance => 3
    MSCONFIG\Services: MpsSvc => 2
    MSCONFIG\Services: MSDTC => 3
    MSCONFIG\Services: MSiSCSI => 3
    MSCONFIG\Services: msiserver => 3
    MSCONFIG\Services: napagent => 3
    MSCONFIG\Services: Netlogon => 3
    MSCONFIG\Services: Netman => 3
    MSCONFIG\Services: netprofm => 3
    MSCONFIG\Services: NlaSvc => 2
    MSCONFIG\Services: nsi => 2
    MSCONFIG\Services: ose => 3
    MSCONFIG\Services: osppsvc => 3
    MSCONFIG\Services: p2pimsvc => 3
    MSCONFIG\Services: p2psvc => 3
    MSCONFIG\Services: PcaSvc => 2
    MSCONFIG\Services: PerfHost => 3
    MSCONFIG\Services: pla => 3
    MSCONFIG\Services: PNRPAutoReg => 3
    MSCONFIG\Services: PNRPsvc => 3
    MSCONFIG\Services: PolicyAgent => 3
    MSCONFIG\Services: Power => 2
    MSCONFIG\Services: ProtectedStorage => 3
    MSCONFIG\Services: QWAVE => 3
    MSCONFIG\Services: RasAuto => 3
    MSCONFIG\Services: RasMan => 3
    MSCONFIG\Services: RemoteRegistry => 3
    MSCONFIG\Services: RpcLocator => 3
    MSCONFIG\Services: SamSs => 2
    MSCONFIG\Services: SBSDWSCService => 2
    MSCONFIG\Services: SCardSvr => 3
    MSCONFIG\Services: SCPolicySvc => 3
    MSCONFIG\Services: SDRSVC => 3
    MSCONFIG\Services: seclogon => 3
    MSCONFIG\Services: SENS => 2
    MSCONFIG\Services: SensrSvc => 3
    MSCONFIG\Services: SessionEnv => 3
    MSCONFIG\Services: ShellHWDetection => 2
    MSCONFIG\Services: SkypeUpdate => 2
    MSCONFIG\Services: SNMPTRAP => 3
    MSCONFIG\Services: Spooler => 2
    MSCONFIG\Services: sppuinotify => 3
    MSCONFIG\Services: SSDPSRV => 3
    MSCONFIG\Services: SstpSvc => 3
    MSCONFIG\Services: stisvc => 3
    MSCONFIG\Services: SysMain => 2
    MSCONFIG\Services: TabletInputService => 3
    MSCONFIG\Services: TapiSrv => 3
    MSCONFIG\Services: TBS => 3
    MSCONFIG\Services: TermService => 3
    MSCONFIG\Services: Themes => 2
    MSCONFIG\Services: THREADORDER => 3
    MSCONFIG\Services: TrkWks => 2
    MSCONFIG\Services: TrustedInstaller => 3
    MSCONFIG\Services: UI0Detect => 3
    MSCONFIG\Services: upnphost => 3
    MSCONFIG\Services: UxSms => 2
    MSCONFIG\Services: VaultSvc => 3
    MSCONFIG\Services: vds => 3
    MSCONFIG\Services: W32Time => 3
    MSCONFIG\Services: WatAdminSvc => 3
    MSCONFIG\Services: wbengine => 3
    MSCONFIG\Services: WbioSrvc => 3
    MSCONFIG\Services: wcncsvc => 3
    MSCONFIG\Services: WcsPlugInService => 3
    MSCONFIG\Services: WdiServiceHost => 3
    MSCONFIG\Services: WdiSystemHost => 3
    MSCONFIG\Services: WebClient => 3
    MSCONFIG\Services: Wecsvc => 3
    MSCONFIG\Services: wercplsupport => 3
    MSCONFIG\Services: WerSvc => 3
    MSCONFIG\Services: WinDefend => 2
    MSCONFIG\Services: WinHttpAutoProxySvc => 3
    MSCONFIG\Services: Winmgmt => 2
    MSCONFIG\Services: WinRM => 3
    MSCONFIG\Services: Wlansvc => 2
    MSCONFIG\Services: wlidsvc => 3
    MSCONFIG\Services: wmiApSrv => 3
    MSCONFIG\Services: WMZuneComm => 3
    MSCONFIG\Services: WPCSvc => 3
    MSCONFIG\Services: WPDBusEnum => 3
    MSCONFIG\Services: wscsvc => 2
    MSCONFIG\Services: wuauserv => 2
    MSCONFIG\Services: wudfsvc => 2
    MSCONFIG\Services: WwanSvc => 3
    MSCONFIG\Services: ZuneNetworkSvc => 3
    MSCONFIG\Services: ZuneWlanCfgSvc => 3
    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk.disabled => C:\Windows\pss\Bluetooth.lnk.disabled.CommonStartup
    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: avast => "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe
    MSCONFIG\startupreg: InstallShieldSetup => C:\PROGRA~2\INSTAL~1\{047F7~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{047F7~1\reboot.ini
    MSCONFIG\startupreg: MCtlSuc => C:\Program Files (x86)\FASTWEB\FastWeb 3G\Resource\MCtlSuc.exe
    MSCONFIG\startupreg: Power Management => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
    MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    MSCONFIG\startupreg: Zune Launcher => "C:\Program Files\Zune\ZuneLauncher.exe"

    ========================= Accounts: ==========================

    Administrator (S-1-5-21-368298906-4009226880-499156854-500 - Administrator - Disabled)
    Elisa (S-1-5-21-368298906-4009226880-499156854-1001 - Administrator - Enabled) => C:\Users\Elisa
    Guest (S-1-5-21-368298906-4009226880-499156854-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-368298906-4009226880-499156854-1002 - Limited - Enabled)

    ==================== Faulty Device Manager Devices =============

    Name: Iniziatore iSCSI Microsoft
    Description: Iniziatore iSCSI Microsoft
    Class Guid: {4d36e97b-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: iScsiPrt
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/23/2014 10:36:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/23/2014 07:26:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/17/2014 11:19:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/17/2014 09:11:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/17/2014 09:05:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/12/2014 08:14:47 AM) (Source: MsiInstaller) (EventID: 1024) (User: Elisa-PC)
    Description: Prodotto Adobe Reader XI (11.0.09) - Italiano: impossibile installare aggiornamento "{AC76BA86-7AD7-0000-2550-7A8C40011010}". Codice errore 1625. Č possibile impostare Windows Installer per la creazione di log, che possono facilitare la risoluzione di problemi di installazione dei pacchetti software. Istruzioni per l'attivazione del supporto della registrazione sono disponibili tramite il seguente collegamento: http://go.microsoft.com/fwlink/?LinkId=23127

    Error: (12/12/2014 08:10:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/11/2014 02:55:48 PM) (Source: PerfNet) (EventID: 2006) (User: )
    Description:

    Error: (12/11/2014 02:53:36 PM) (Source: PerfNet) (EventID: 2005) (User: )
    Description:

    Error: (12/08/2014 02:53:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    System errors:
    =============
    Error: (12/30/2014 10:43:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:43:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:43:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:42:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:42:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:42:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:42:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:42:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:42:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058

    Error: (12/30/2014 10:40:22 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Browser di computer dipende dal servizio Server che non č stato avviato per il seguente errore:
    %%1058


    Microsoft Office Sessions:
    =========================
    Error: (12/23/2014 10:36:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/23/2014 07:26:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/17/2014 11:19:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/17/2014 09:11:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/17/2014 09:05:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/12/2014 08:14:47 AM) (Source: MsiInstaller) (EventID: 1024) (User: Elisa-PC)
    Description: Adobe Reader XI (11.0.09) - Italiano{AC76BA86-7AD7-0000-2550-7A8C40011010}1625(NULL)(NULL)(NULL)

    Error: (12/12/2014 08:10:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (12/11/2014 02:55:48 PM) (Source: PerfNet) (EventID: 2006) (User: )
    Description:

    Error: (12/11/2014 02:53:36 PM) (Source: PerfNet) (EventID: 2005) (User: )
    Description:

    Error: (12/08/2014 02:53:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    ==================== Memory info ===========================

    Processor: AMD C-60 APU with Radeon(tm) HD Graphics
    Percentage of memory in use: 57%
    Total physical RAM: 3818.9 MB
    Available physical RAM: 1634.14 MB
    Total Pagefile: 7635.98 MB
    Available Pagefile: 4757.09 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.82 MB

    ==================== Drives ================================

    Drive c: (Acer) (Fixed) (Total:283.99 GB) (Free:207.36 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 5B7D26B5)
    Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=284 GB) - (Type=07 NTFS)

    ==================== End Of Log ============================


    Thanks for any help!

  2. #2
    Security Expert Satchfan's Avatar
    Join Date
    Feb 2009
    Location
    Exeter, UK
    Posts
    259

    Default

    Hello Zarax and welcome to the forum.

    My name is Satchfan and I would be glad to help you with your computer problem.

    Please read the following guidelines which will help to make cleaning your machine easier:

    • please follow all instructions in the order posted
    • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
    • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
    • if you don't understand something, please don't hesitate to ask for clarification before proceeding
    • the fixes are specific to your problem and should only be used for this issue on this machine.
    • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

    IMPORTANT:

    Please DO NOT install/uninstall any programs unless asked to.
    Please DO NOT run any scans other than those requested


    I see you have run some scans and your computer is pretty clean. There are, however some issues.

    ===================================================

    P2P - I see you have P2P software, (uTorrent ), installed on your machine.

    We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

    If your computer is infected, it almost certainly contributed to your current situation.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

    Please see this topic for more information:

    P2P File Sharing Risks.

    I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

    Should you decide to keep it, please don’t use it until we have finished up here.

    ===================================================

    Multiple antiviruses

    You have Avast and Microsoft Security Essential (MSE) antivirus programs installed.

    You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them all ineffective.

    I would suggest you uninstall MSE but it is your choice.

    • click Start, Control Panel, Programs and Features
    • scroll down the list click on either Avast or MSE and then on Remove.


    ==================================================

    Run Malwarebytes’ Anti-Malware

    I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:

    • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
    • once it is updated, click on “Scan” tab, select Threat Scan, then click Scan.
    • when the scan is complete, if no malicious items are found you can close the program
    • if malicious items are found be sure that everything is checked and click Quarantine
    • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
    • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • copy and paste the contents of that report in your next reply and exit MBAM.


    NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

    ==================================================

    Run Security Check

    Download Security Check by screen317 from here or here.

    • save it to your Desktop.
    • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • a Notepad document should open automatically called checkup.txt; please post the contents of that document.


    Logs to include with the next post:

    Mbam.txt
    checkup.txt


    Can you tell me if there is an improvement and if there are any outstanding problems, what specifically are they?

    Satchfan
    Last edited by Satchfan; 2014-12-31 at 12:34.

  3. #3
    Junior Member
    Join Date
    Jun 2008
    Posts
    11

    Default

    Here are the logs.
    After removing avast it seems a bit better but I still get unexplained usage spikes (from 4-5% it jumps to 30-40% on idle).

    Results of screen317's Security Check version 0.99.93
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Microsoft Security Essentials
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    MVPS Hosts File
    Spybot - Search & Destroy
    Java 7 Update 60
    Java version 32-bit out of Date!
    Adobe Flash Player 16.0.0.235
    Adobe Reader XI
    Mozilla Firefox (34.0.5)
    Google Chrome (39.0.2171.71)
    Google Chrome (39.0.2171.95)
    ````````Process Check: objlist.exe by Laurent````````
    Microsoft Security Essentials MSMpEng.exe
    Microsoft Security Essentials msseces.exe
    Spybot Teatimer.exe is disabled!
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 3%
    ````````````````````End of Log``````````````````````


    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Data scansione: 31/12/2014
    Ora scansione: 13:41:00
    File di log: mbam.txt
    Amministratore: Si

    Versione: 2.00.4.1028
    Database malware: v2014.12.31.03
    Database rootkit: v2014.12.30.01
    Licenza: Free
    Protezione da malware: Disattivata
    Protezione da siti web nocivi: Disattivata
    Autoprotezione: Disattivata

    SO: Windows 7 Service Pack 1
    CPU: x64
    File system: NTFS
    Utente: Elisa

    Tipo di scansione: Scansione elementi nocivi
    Risultati: Completata
    Elementi analizzati: 334492
    Tempo impiegato: 28 min, 35 sec

    Memoria: Attivata
    Esecuzioni automatiche: Attivata
    File system: Attivata
    Archivi compressi: Attivata
    Rootkit: Disattivata
    Euristica: Attivata
    PUP: Avviso
    PUM: Attivata

    Processi: 0
    (Nessun elemento malevolo rilevato)

    Moduli: 0
    (Nessun elemento malevolo rilevato)

    Chiavi di registro: 0
    (Nessun elemento malevolo rilevato)

    Valori di registro: 0
    (Nessun elemento malevolo rilevato)

    Dati di registro: 0
    (Nessun elemento malevolo rilevato)

    Cartelle: 0
    (Nessun elemento malevolo rilevato)

    File: 0
    (Nessun elemento malevolo rilevato)

    Settori fisici: 0
    (Nessun elemento malevolo rilevato)


    (end)

  4. #4
    Security Expert Satchfan's Avatar
    Join Date
    Feb 2009
    Location
    Exeter, UK
    Posts
    259

    Default

    I can’t see what could be causing that so let’s see if an online scan shows up anything that has been missed.

    Run ESET Online Scan


    IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

    Note: You can use Internet Explorer, FireFox or Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

    Hold down Control and click on the following link to open ESET OnlineScan in a new window.

    ESET OnlineScan

    • click the Eset online Scanner button
    • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o double click on the Eset installer icon on your desktop.

    • check Yes, I accept the Terms of Use
    • click the Start button
    • accept any security warnings from your browser
    • check Enable detection of potentially unwanted applications
    • click Advanced settings and select the following:


    o scan archives
    o scan for potentially unsafe applications
    o enable Anti-Stealth technology

    Note: Do not check Remove found threats

    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • when the scan completes, push List of found threats
    • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.

    • push the back button.
    • push Finish


    When the scan is complete:

    If no threats were found:

    o put a checkmark in "Uninstall application on close"
    o close program
    o report to me that nothing was found

    If threats were found:

    o click on "list of threats found"
    o click on "export to text file" and save it as ESET results and save to the desktop
    o Click on back
    o put a checkmark in "Uninstall application on close"
    o click on finish
    o close program
    o copy and paste the report here

    Thanks

    Satchfan

  5. #5
    Security Expert Satchfan's Avatar
    Join Date
    Feb 2009
    Location
    Exeter, UK
    Posts
    259

    Default

    Hi Zarax

    It has been several days since I asked you to run an Eset scan.

    Please let me know the result and we can then tidy up

    Thanks

    Satchfan

  6. #6
    Junior Member
    Join Date
    Jun 2008
    Posts
    11

    Default

    Hi, unfortunately I'll be unable to access the machine until january 8, sorry for the inconvenience.

  7. #7
    Security Expert Satchfan's Avatar
    Join Date
    Feb 2009
    Location
    Exeter, UK
    Posts
    259

    Default

    I'll keep the thread open until then but please let me know when you have run it.

    Satchfan

  8. #8
    Security Expert Satchfan's Avatar
    Join Date
    Feb 2009
    Location
    Exeter, UK
    Posts
    259

    Default

    Hello Zarax

    Are you able to continue yet?

  9. #9
    Security Expert Satchfan's Avatar
    Join Date
    Feb 2009
    Location
    Exeter, UK
    Posts
    259

    Default

    Due to inactivity, this thread will now be closed.

    If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a new DDS log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •