Aiuto PC

(RISOLTO) rimuovere pop up adultcameras.info e adultyum.info

« Older   Newer »
 
  Share  
.
  1. daniele1357
     
    .

    User deleted


    Ciao a tutti.
    A me succede una cosa alquanto strana, cerco di spiegarvi.

    Mia moglie usa un portatile per accedere a siti di cucina. Ad un certo punto hanno cominciato a vedersi degli avvisi in basso a destra pubblicizzanti siti porno.
    Poi è apparsa la famosa pagina della polizia che blocca il browser.
    Successivamente apparivano delle finestrelle all'interno della pagina visitata con filmati porno, al posto delle immagini dei piatti.

    Dopo vari tentativi di pulizia, cclean, advanced system care, spybot, pulizia a mano del registro, cancellazione di programmi vari ecc.ecc. ho optato per una soluzione drastica: ho formattato l'HD e reinstallato windows 8.1.
    Appena finita l'installazione installo chrome... e come prima cosa mi riappaiono i banner in basso a destra, successivamente le finestrelle con i filmati porno, poi anche la polizia.

    Dopo vari tentativi e prove decido di non usare la rete adsl di casa ma la penna internet, ovvero ADSL di casa è Wind la penna internet è fastweb.
    Usando la rete fastweb non vedo più i banner degli appuntamenti con fanciulle dell'est in basso a destra, ma continuo a vedere il popup, anche se disabilitato, di adultyum.info.
    Incuriosito stamattina ho portato il portatile in ufficio, rete meravigliosa, e anche qua non appaiono più i banner in basso a destra, mentre continua ad apparire il popup di aldultyium.info (che comunque ho bloccato nel file hosts).

    Sembra che i banner siano inviati dal provider di casa, wind, avete mai avuto sospetti di questo tipo???
     
    .
  2.  
    .

    Master Malware Expert

    Group
    Administrator
    Posts
    4,517
    Location
    Poggio Mirteto(RI)

    Status
    Anonymous
    È infetto il router.Lo devi resettare e mettere in sicurezza.
    Leggi i post precedenti, se non capisci qualcosa chiedi pure
     
    .
  3. Pneppe
     
    .

    User deleted


    Ho avuto lo stesso problema su Huawei EchoLife HG520c. Credo e spero di aver risolto il problema (dopo reset e tentativi vari) aggiornando il firmware del mio router e impostando 8.8.8.8 e 8.8.4.4 come DNS. Ovviamente ho modificato la password della pagina di configurazone
     
    .
  4.  
    .

    Master Malware Expert

    Group
    Administrator
    Posts
    4,517
    Location
    Poggio Mirteto(RI)

    Status
    Anonymous
    E' la soluzione per eliminare l'infezione al router,anche se a volta aggiornando il router la vulnerabilità rimane.
    I dns vanno impostati sulla scheda di rete,altrimenti se il router è ancora vulnerabile e lo puoi vedere dalla guida in basso verranno nuovamnete cambiati.
    Dai un'ochiata alla seconda parte di quetsa guida https://aiuto-pc.forumfree.it/?t=65967390
     
    .
  5. tiz81
     
    .

    User deleted


    Ciao,

    anche io lo stesso problema da qualche settimana. Uso esclusivamente il browser firefox e puntualmente mi si apre il popup di adultcamera.info. Succede anche quando navigo con iphone collegato alla rete wifi di casa (ma non con rete 3G), il che mi fa pensare che sia un problema di modem. L'ho resettato più volte, ma ogni volta il problema si ripresenta. Sono stata da mediaworld per comprarne uno nuovo, ma lì mi hanno detto che è il pc ad essere infettato e non il modem.
    Ho cercato di seguire le istruzioni nelle pagine precedenti, ma non mi intendo assolutamente di pc&C., quindi....HELPPPP! :wacko:
    Per ora ho fatto la scansione con farbar, allego il log sperando possiate aiutarmi...(dovrete spiegarmi come a una bambina dell'asilo eh... :P )
    File Allegato
    FRST.txt
    (Number of downloads: 60)

     
    .
  6.  
    .

    Master Malware Expert

    Group
    Administrator
    Posts
    4,517
    Location
    Poggio Mirteto(RI)

    Status
    Anonymous
    Lascia perdere quelli di mediaword.
    Il router è infetto
    Tcpip\Parameters: [DhcpNameServer] 91.194.254.105 8.8.8.8

    Il dns in grassetto è quello che dirotta la tua connessione sul server infetto

    Adesso ti spiego la situazione:
    Il tuo router è un router vulnerabile all'infezione.
    Per infettarlo viene attaccato tramite il tuo IP.Quindi anche dopo averlo resettato è possibile che si reinfetti di nuovo.

    Prima di acquistarne uno nuovo e comunque devi prenderne uno non vulnerabile agli attacchi esterni possiamo provare a metterlo in sicurezza.In questo modo puoi risparmiare un po' di soldi.

    L'infezione infetta anche i browser quindi adesso segui questa procedura:

    1)Resetta nuovamente il router.Devi resettarlo in hard reset premendo il pulsantino per tot secondi.C'è una funzione su alcuni router che te lo resetta in soft reset(dipende dai secondoi che lo tieni premuto,quindi controlla le istr. del tuo router).Te devi resettarlo in hard reset.
    2)Senza collegarti nella barra di ricerca scrivi CMD.Apri CMD e scrivi ipconfig /flushdns e dai invio
    3)Prima di collegarti nuovamente alla rete apri centro di rete e condivisione-modifica impostazioni scheda-fai tasto dx sulla scheda di rete wi-fi quindi clicca su proprietà.Portati dove c'è scritto protocollo internet versione 4 e metti la spunta a "utilizza i seguenti indirizzi server dns"
    In primario inserisci 8.8.8.8
    In secondario 8.8.4.4
    Salva e chiudi
    4)Resetta o meglio disinstalla firefox seguendo questa guida https://aiuto-pc.forumfree.it/?t=69695968
    5))Scaricare ed eseguire TFC BY OLD TIMER.(le istruzioni sono qui https://aiuto-pc.forumfree.it/?t=66300938).
    6)Metti in sicurezza il router come spiegato qui #entry570969517

    Dopo queste operazioni ricollegati alla rete e fammi sapere se le pagine si aprono ancora.

    Edited by vicky67 - 9/3/2015, 08:58
     
    .
  7. tiz81
     
    .

    User deleted


    Innanzitutto grazie per avermi risposto così rapidamente!
    Allora, ho seguito (spero correttamente) tutte le indicazioni che mi hai dato.
    Ti allego il log di FRST e ho fatto una prova con ROM-0-TEST. Adesso mi dice "Address is probably not vulnerable".

    Ho solo due dubbi:
    - Al momento sto navigando con il mio iphone utilizzando la connessione 3G...cosa devo fare prima di ricollegarmi alla rete wifi? E' sufficiente cancellare i dati siti web e la cronologia di safari del cell? Reistallare facebook? (visto che mi si apriva adulcamera ogni volta che aprivo link esterni all'applicazione)
    - Altra domanda...se vado in centro di rete e condivisioni, sotto "visualizza reti attive" c'è il nome della mia rete con indicato "rete pubblica"...mi devo preoccupare?

    C'è altro che posso allegare per capire se mi sono liberata di sto maledetto?

    Grazie ancora per la pazienza e la disponibilità! :D
    File Allegato
    FRST.txt
    (Number of downloads: 69)

     
    .
  8.  
    .

    Master Malware Expert

    Group
    Administrator
    Posts
    4,517
    Location
    Poggio Mirteto(RI)

    Status
    Anonymous
    Brava.
    Si devi cancellare tutti i dati di navigazione su iphone.
    Facebook non è necessario disinstallarlo.
    Rete pubblica o privata non è importante nel tuo caso.

    Adesso ricollegati alla rete e naviga anche con il pc.Non dovresti avere più problemi del popup.
    Fammi sapere, poi facciamo un ulteriore controllo se è tutto ok.
     
    .
  9. tiz81
     
    .

    User deleted


    Ciaooo!
    E' dai ieri che navigo e di adultcamera nemmeno l'ombra!!!
    Grazie mille per l'aiuto preziosissimo, Vicky67! :D
     
    .
  10.  
    .

    Master Malware Expert

    Group
    Administrator
    Posts
    4,517
    Location
    Poggio Mirteto(RI)

    Status
    Anonymous
    Perfetto.
    Ciao
     
    .
  11. Caesar95
     
    .

    User deleted


    Ciao!

    Ieri sera ho visto un film in streaming su altadefinizione.tv, e da stamattina parecchie volte, aprendo siti vari, vengo indirizzato su adultyum.

    Uso esclusivamente Safari per MacBook. Utilizzando iOS X, non saprei come verificare cosa sta accadendo (la guida di Vicky è solo per Windows?)

    Ho dato un'occhiata ai vari posts su questo thread: a quanto pare dovrebbe essere un problema di modem. Ma aprendo su Iphone gli stessi siti che sul Mac mi indirizzano ad adultyum, non ho riscontrato lo stesso problema. Che sia il mac ad essere infetto?

    E' la prima volta che mi capita qualcosa del genere, e sono abbastanza imbarazzato! Potrei avere qualche suggerimento? Non sono molto pratico di computer, che uso solo per funzioni basilari (e.g. Word etc.), e davvero non so da dove iniziare.

    Grazie mille!
     
    .
  12.  
    .

    Master Malware Expert

    Group
    Administrator
    Posts
    4,517
    Location
    Poggio Mirteto(RI)

    Status
    Anonymous
    Sai entrare nel router?
    Per verificare che il router sia infetto vale sempre la mia guida linkata nella prima pagina.
    Dovresti resettare il router ,bloccarne l'accesso e inserire i dns di google e opends
    Resettare safari..
    Purtroppo con il mac non posso guidarti passo passo.

    Comunque prima entra nel router e verifica i dns
     
    .
  13. dissident
     
    .

    User deleted


    Buonasera a tutti!
    Vedo che non sono l'unica con questo irritante problema dopo la visione di serie tv in streaming. Che dire, è da una settimana che non riesco a navigare decentemente. Ho portato anche il pc (solo quello) dal tecnico ma niente, si ripresenta regolarmente il reindirizzamento a 'ste pagine schifose. Poi ho trovato questa discussione. Peccato che io sia abbastanza a livello base e che quindi mi trovi comunque in difficoltà a fare operazioni come quelle sopra. :)
    Detto questo, ho verificato se il router era infetto. Apparentemente non lo è, mi rende il risultato della prima immagine (della guida per l'infezione al router). Allora visto che il pc è stato controllato comunque più volte, ho scaricato e fatto la scansione con farbar, dando per scontata l'infezione al router. Questo forse spiegherebbe (da niubba, dico io) perchè se navigo con la chiavetta telecom il problema non si presenta. Allego i log (li incollo direttamente sotto lo spoiler, mi pare si possa fare ho letto nella guida...se sbaglio qualcosa ditemelo eh, scusate!), sperando che qualche anima buona mi possa guidare ed aiutare. Non ne posso più.

    Questo è il log per il primo utilizzo di farbar:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
    Ran by USER at 2015-03-24 17:22:16
    Running from C:\Users\USER\Downloads
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.00.631.5823 - ABBYY)
    ABBYY FineReader 9.0 Sprint (x32 Version: 9.00.631.5823 - ABBYY) Hidden
    Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
    Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.10) - Italiano (HKLM-x32\...\{AC76BA86-7AD7-1040-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
    Aggiornamenti NVIDIA 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden
    Alice MOBILE (HKLM-x32\...\{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}) (Version: 1.0.0.0 - ONDA)
    Angry Birds (HKLM-x32\...\{07A6B206-3F11-4D92-92A1-90E116ADD660}) (Version: 2.0.2 - Rovio)
    Angry Birds Rio (HKLM-x32\...\{4D521C80-181E-4AE2-9253-6EFB8ED27100}) (Version: 2.2.0 - Rovio Entertainment Ltd.)
    Angry Birds Seasons (HKLM-x32\...\{F84FF19C-E18B-43C4-9366-D3056CEF74A0}) (Version: 1.0.0 - Rovio)
    aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.5187 - DsNET Corp)
    Avast Free Antivirus (HKLM-x32\...\avast) (Version: 10.2.2214 - AVAST Software)
    AVS Video Editor 6 (HKLM-x32\...\AVS Video Editor_is1) (Version: 6.4.2.241 - Online Media Technologies Ltd.)
    Bejeweled® 3 (HKLM-x32\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
    CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
    CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.1.3341 - CDBurnerXP)
    Cool & Quiet (HKLM-x32\...\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}) (Version: - )
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dead Island Game of The Years (HKLM-x32\...\Dead Island Game of The Years_is1) (Version: 1.3.0 - )
    Download Navigator (HKLM-x32\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
    Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
    Epson Easy Photo Print 2 (HKLM-x32\...\{02A312B5-1542-47B6-BFE9-F51358C39E86}) (Version: 2.4.0.0 - SEIKO EPSON CORPORATION)
    Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
    Epson Event Manager (HKLM-x32\...\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}) (Version: 3.01.0000 - Seiko Epson Corporation)
    EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
    EPSON XP-205 207 Series Printer Uninstall (HKLM\...\EPSON XP-205 207 Series) (Version: - SEIKO EPSON Corporation)
    EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
    FILEminimizer Pictures (HKLM-x32\...\FILEminimizer Pictures_is1) (Version: - balesio AG)
    Football Manager 2015 (HKLM-x32\...\Steam App 295270) (Version: - Sports Interactive)
    Fotosizer 2.09 (HKLM-x32\...\Fotosizer) (Version: 2.09.0.548 - Fotosizer.com)
    Free Mp3 Wma Converter V 2.2 (HKLM-x32\...\Free Mp3 Wma Converter_is1) (Version: 2.2.0.0 - Koyote Lab Inc.)
    GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
    GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
    GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
    Guida di rete EPSON XP-205 207 Series (HKLM-x32\...\EPSON XP-205 207 Series Netg) (Version: - )
    Guida utente EPSON XP-205 207 Series (HKLM-x32\...\EPSON XP-205 207 Series Useg) (Version: - )
    Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
    JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
    London 2012: The Official Video Game of the Olympic Games (HKLM-x32\...\London 2012: The Official Video Game of the Olympic Games_is1) (Version: - )
    Malwarebytes Anti-Malware versione 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
    Media Go (HKLM-x32\...\{DBF1AE39-DA30-4B89-A7EB-3BDA675C5D9E}) (Version: 2.1.392 - Sony)
    Media Go Video Playback Engine 1.116.105.02020 (HKLM-x32\...\{54215B8A-6212-8DB8-39B4-98EE2BB98BD1}) (Version: 1.116.105.02020 - Sony)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
    Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
    Mozilla Firefox 36.0.4 (x86 it) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 it)) (Version: 36.0.4 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
    Mp3tag v2.66 (HKLM-x32\...\Mp3tag) (Version: v2.66 - Florian Heidenreich)
    NVIDIA Driver 3D Vision 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.52 - NVIDIA Corporation)
    NVIDIA Driver audio HD 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
    NVIDIA Driver del controller 3D Vision 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation)
    NVIDIA Driver grafico 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation)
    NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
    NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation)
    NWZ-E470 E570 WALKMAN Guide (HKLM-x32\...\{F3448416-D3D7-4DBA-B982-4AEB064D9473}) (Version: 1.0.00 - Sony Corporation)
    OpenOffice 4.0.1 (HKLM-x32\...\{03F15CFC-BA7D-48B8-AA16-7F152BA27547}) (Version: 4.01.9714 - Apache Software Foundation)
    Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
    Pannello di controllo NVIDIA 347.52 (Version: 347.52 - NVIDIA Corporation) Hidden
    PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
    PlayStation(R)Network Downloader (HKLM-x32\...\{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}) (Version: 2.07.00849 - Sony Computer Entertainment Inc.)
    PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.14.6.15183 - Sony Computer Entertainment Inc.)
    Raccolta foto (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
    Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.17.304.2010 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
    Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group)
    Room Arranger (HKLM-x32\...\Room Arranger) (Version: 7.5.9 - Jan Adamec)
    SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden
    Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
    Spotify (HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1170 - SUPERAntiSpyware.com)
    System Requirements Lab CYRI (HKLM-x32\...\{E5F05232-96B6-4552-A480-785A60A94B21}) (Version: 5.0.6.0 - Husdawg, LLC)
    The Saboteur™ (HKLM-x32\...\{5C9A7E65-5B71-4C7F-876A-8C6AF9E9E23D}) (Version: 1.0.0.0 - Electronic Arts)
    The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
    The Sims™ 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.10.1 - Electronic Arts)
    The Sims™ 3 Animali & Co. (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
    The Sims™ 3 Generations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
    The Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.5.1 - Electronic Arts)
    The Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
    The Sims™ 3 Stagioni (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
    The Sims™ 3 Travel Adventures (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.17.2 - Electronic Arts)
    The Sims™ 3 Vita Universitaria (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
    The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.4.114.1010 - Electronic Arts Inc.)
    The Sims™ 4 Demo di Crea un Sim (HKLM-x32\...\{6908ED99-F02B-4E99-A202-3FAC99C510ED}) (Version: 1.0.237.100 - Electronic Arts Inc.)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
    Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 5.4.0.0 - Azureus Software, Inc.)
    Wargame European Escalation (HKLM-x32\...\Wargame European Escalation_is1) (Version: Wargame European Escalation - )
    Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
    Winamp Detector Plug-in (HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
    WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
    XMedia Recode versione 3.1.7.6 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.7.6 - XMedia Recode)
    Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


    ==================== Restore Points =========================

    30-12-2014 10:29:27 Windows Update
    06-01-2015 10:52:01 Windows Update
    09-01-2015 11:27:30 Windows Update
    14-01-2015 10:42:43 Windows Update
    14-01-2015 13:03:42 Windows Update
    15-01-2015 18:08:10 Removed Nero Kwik Media.
    20-01-2015 09:38:30 Windows Update
    23-01-2015 11:32:13 Windows Update
    27-01-2015 18:51:05 Windows Update
    03-02-2015 15:48:53 Windows Update
    10-02-2015 17:32:09 Windows Update
    11-02-2015 13:03:46 Windows Update
    12-02-2015 11:11:37 Windows Update
    17-02-2015 10:14:23 Windows Update
    20-02-2015 10:30:34 Windows Update
    24-02-2015 11:28:53 Windows Update
    25-02-2015 19:57:43 Windows Update
    03-03-2015 12:11:52 Windows Update
    04-03-2015 16:46:15 Windows Update
    11-03-2015 10:01:44 Windows Update
    11-03-2015 13:03:52 Windows Update
    16-03-2015 10:05:32 avast! antivirus system restore point
    18-03-2015 16:49:54 Windows Update
    22-03-2015 11:16:21 Windows Update
    22-03-2015 15:59:08 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
    22-03-2015 15:59:53 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {192DC72C-D886-4F37-BEE0-AF7FE9BC8CC9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-03-16] (Avast Software s.r.o.)
    Task: {38F08FB5-EA99-422E-8931-45DC11AE6A42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
    Task: {5503A788-D78E-4C62-B77E-298751793B64} - System32\Tasks\{ADA662FA-019B-4FAE-BE7D-D003C0C84787} => pcalua.exe -a C:\Users\USER\Downloads\Sims3_1.36.45.017002_from_1.34.27.016002.exe -d C:\Users\USER\Downloads
    Task: {7822C8A1-C15D-4BF6-B5FB-2CD395C7F05A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
    Task: {AB4B9FB0-9A04-44A7-B95E-D0280449391C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
    Task: {CB186031-BA9F-4A32-8266-B5A923987656} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)
    Task: {E382E391-6DF9-42FE-987C-EF026C5CB775} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-23] (Adobe Systems Incorporated)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
    Task: C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe

    ==================== Loaded Modules (whitelisted) ==============

    2012-07-27 10:05 - 2015-02-05 20:07 - 00117576 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2014-02-12 17:44 - 2008-09-16 17:38 - 00086016 _____ () C:\Windows\SysWOW64\SupportAppXL\onda_mon.exe
    2015-02-19 22:40 - 2015-02-19 22:40 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1040.dll
    2015-03-16 10:13 - 2015-03-16 10:13 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
    2015-03-16 10:13 - 2015-03-16 10:13 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
    2015-03-23 10:42 - 2015-03-23 10:42 - 02922496 _____ () C:\Program Files\AVAST Software\Avast\defs\15032300\algo.dll
    2015-03-24 16:50 - 2015-03-24 16:50 - 02923008 _____ () C:\Program Files\AVAST Software\Avast\defs\15032400\algo.dll
    2015-03-18 15:39 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2015-03-18 15:39 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    2015-03-18 15:39 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    2015-03-18 15:39 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    2015-03-18 15:39 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
    2015-03-16 10:13 - 2015-03-16 10:13 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2015-03-16 10:13 - 2015-03-16 10:13 - 01359872 _____ () C:\Program Files\AVAST Software\Avast\libglesv2.dll
    2015-03-16 10:13 - 2015-03-16 10:13 - 00212992 _____ () C:\Program Files\AVAST Software\Avast\libegl.dll
    2015-03-22 11:59 - 2015-03-14 11:12 - 01174856 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libglesv2.dll
    2015-03-22 11:59 - 2015-03-14 11:12 - 00080200 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libegl.dll
    2015-03-22 11:59 - 2015-03-14 11:12 - 09278792 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\pdf.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (whitelisted) ===============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 91.194.254.105 - 8.8.8.8

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
    MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\USER\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    ==================== Accounts: =============================

    Administrator (S-1-5-21-2021544046-4129450843-1710890237-500 - Administrator - Disabled)
    Guest (S-1-5-21-2021544046-4129450843-1710890237-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-2021544046-4129450843-1710890237-1003 - Limited - Enabled)
    USER (S-1-5-21-2021544046-4129450843-1710890237-1000 - Administrator - Enabled) => C:\Users\USER

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (03/24/2015 04:49:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (03/24/2015 04:48:57 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
    Description: NvStreamSvcNvVAD initialization failed [6]

    Error: (03/24/2015 04:48:57 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
    Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]

    Error: (03/24/2015 04:48:57 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
    Description: NvStreamSvcNvVAD endpoint registration failed [0]

    Error: (03/23/2015 01:58:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (03/23/2015 10:43:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (03/22/2015 07:51:35 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY)
    Description: Il valore della stringa del nome del contatore delle prestazioni nel Registro di sistema non è formattato correttamente. La stringa non valida è . Il primo valore DWORD nella sezione Data contiene il valore di indice della stringa non valida, mentre il secondo e il terzo valore DWORD contengono gli ultimi valori di indice validi.

    Error: (03/22/2015 07:44:45 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Nome dell'applicazione che ha generato l'errore: TS4.exe, versione: 1.4.114.1010, timestamp: 0x54f644a4
    Nome del modulo che ha generato l'errore: nvd3dum.dll, versione: 9.18.13.4752, timestamp: 0x54d3ae4d
    Codice eccezione: 0xc0000005
    Offset errore 0x0062abbe
    ID processo che ha generato l'errore: 0x1518
    Ora di avvio dell'applicazione che ha generato l'errore: 0xTS4.exe0
    Percorso dell'applicazione che ha generato l'errore: TS4.exe1
    Percorso del modulo che ha generato l'errore: TS4.exe2
    ID segnalazione: TS4.exe3

    Error: (03/22/2015 02:48:26 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Nome dell'applicazione che ha generato l'errore: Origin.exe, versione: 9.5.6.731, timestamp: 0x54e662d2
    Nome del modulo che ha generato l'errore: Origin.exe, versione: 9.5.6.731, timestamp: 0x54e662d2
    Codice eccezione: 0xc0000005
    Offset errore 0x0002ea56
    ID processo che ha generato l'errore: 0x4fc
    Ora di avvio dell'applicazione che ha generato l'errore: 0xOrigin.exe0
    Percorso dell'applicazione che ha generato l'errore: Origin.exe1
    Percorso del modulo che ha generato l'errore: Origin.exe2
    ID segnalazione: Origin.exe3

    Error: (03/22/2015 02:39:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    System errors:
    =============
    Error: (03/24/2015 04:51:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Gruppi reti peer dipende dal servizio Protocollo PNRP che non è stato avviato per il seguente errore:
    %%-2140993535

    Error: (03/24/2015 04:51:05 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: Servizio Protocollo PNRP terminato con l'errore:
    %%-2140993535

    Error: (03/24/2015 04:51:05 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: Servizio Protocollo PNRP terminato con l'errore:
    %%-2140993535

    Error: (03/24/2015 04:51:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Gruppi reti peer dipende dal servizio Protocollo PNRP che non è stato avviato per il seguente errore:
    %%-2140993535

    Error: (03/24/2015 04:51:05 PM) (Source: PNRPSvc) (EventID: 102) (User: )
    Description: 0x80630801

    Error: (03/24/2015 04:51:05 PM) (Source: PNRPSvc) (EventID: 102) (User: )
    Description: 0x80630801

    Error: (03/24/2015 04:50:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio Gruppi reti peer dipende dal servizio Protocollo PNRP che non è stato avviato per il seguente errore:
    %%-2140993535

    Error: (03/24/2015 04:50:55 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: Servizio Protocollo PNRP terminato con l'errore:
    %%-2140993535

    Error: (03/24/2015 04:50:55 PM) (Source: PNRPSvc) (EventID: 102) (User: )
    Description: 0x80630801

    Error: (03/24/2015 04:49:25 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Il servizio BlueStacks Android Service dipende dal servizio BlueStacks Hypervisor che non è stato avviato per il seguente errore:
    %%­3


    Microsoft Office Sessions:
    =========================
    Error: (03/24/2015 04:49:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (03/24/2015 04:48:57 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
    Description: NvStreamSvcNvVAD initialization failed [6]

    Error: (03/24/2015 04:48:57 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
    Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]

    Error: (03/24/2015 04:48:57 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
    Description: NvStreamSvcNvVAD endpoint registration failed [0]

    Error: (03/23/2015 01:58:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (03/23/2015 10:43:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (03/22/2015 07:51:35 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY)
    Description: 1600000000122F0000132F0000600B0000

    Error: (03/22/2015 07:44:45 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: TS4.exe1.4.114.101054f644a4nvd3dum.dll9.18.13.475254d3ae4dc00000050062abbe151801d064c401b5f76bC:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exeC:\Windows\system32\nvd3dum.dll81fb6ec0-d0c3-11e4-aa1c-bcaec5428b79

    Error: (03/22/2015 02:48:26 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Origin.exe9.5.6.73154e662d2Origin.exe9.5.6.73154e662d2c00000050002ea564fc01d064a6ddc568c9C:\Program Files (x86)\Origin\Origin.exeC:\Program Files (x86)\Origin\Origin.exe1cb34d6e-d09a-11e4-aa1c-bcaec5428b79

    Error: (03/22/2015 02:39:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3 CPU 550 @ 3.20GHz
    Percentage of memory in use: 44%
    Total physical RAM: 3958.99 MB
    Available physical RAM: 2206.42 MB
    Total Pagefile: 7916.17 MB
    Available Pagefile: 5649.54 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.83 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:465.66 GB) (Free:127.93 GB) NTFS
    Drive f: (Volume) (Fixed) (Total:465.76 GB) (Free:431.97 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: BB17B621)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 8AE0EA35)
    Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

    ==================== End Of Log ============================


    Questo è l'altro log:

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
    Ran by USER (administrator) on USER-PC on 24-03-2015 17:21:15
    Running from C:\Users\USER\Downloads
    Loaded Profiles: USER (Available profiles: USER)
    Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Italiano (Italia)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: www.geekstogo.com/forum/topic/33508...very-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    () C:\Windows\SysWOW64\SupportAppXL\onda_mon.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIILE.EXE
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
    (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
    (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2011-10-31] (SEIKO EPSON CORPORATION)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-18] (Avast Software s.r.o.)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIILE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2015-01-22] (SUPERAntiSpyware)
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\MountPoints2: H - H:\Windows\AutoRun.exe
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\MountPoints2: {318d4692-d15c-11e4-9440-bcaec5428b79} - H:\Autorun.exe
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\MountPoints2: {8bbc75d3-d7d4-11e1-9f9b-806e6f6e6963} - D:\Install.exe
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\MountPoints2: {97d8996d-ec37-11e1-b584-bcaec5428b79} - G:\Autorun.exe
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\...\MountPoints2: {c32e394c-b3f2-11e2-9ed6-bcaec5428b79} - H:\Windows\AutoRun.exe
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (Avast Software s.r.o.)
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\Software\Microsoft\Internet Explorer\Main,Search Page = www.bing.com/search?q={searchTerms}...Box&FORM=IE10SR
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://it.msn.com/?ocid=iehp
    HKU\S-1-5-21-2021544046-4129450843-1710890237-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = www.bing.com
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-16] (Avast Software s.r.o.)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation)
    BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-16] (Avast Software s.r.o.)
    BHO-x32: Guida per l'accesso all'account Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation)
    Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
    Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
    Tcpip\Parameters: [DhcpNameServer] 91.194.254.105 8.8.8.8

    FireFox:
    ========
    FF ProfilePath: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\ybv16fx6.default
    FF SearchEngineOrder.1: Google
    FF NetworkProxy: "http", "proxy-auth.unifi.it"
    FF NetworkProxy: "http_port", 8888
    FF NetworkProxy: "type", 4
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-23] ()
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-23] ()
    FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation)
    FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
    FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 -> C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll [2011-08-03] (Sony Computer Entertainment Inc.)
    FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll [2012-02-03] (Sony Network Entertainment International LLC)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2012-06-28] (Nullsoft, Inc.)
    FF Extension: 20-20 3D Viewer - IKEA - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\ybv16fx6.default\Extensions\[email protected] [2015-01-15]
    FF Extension: Adblock Plus - C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\ybv16fx6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-28]
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-27]

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://www.google.com
    CHR DefaultSearchURL: Default -> www.google.com
    CHR DefaultSuggestURL: Default -> www.google.com/complete/search?q={searchTerms}
    CHR Profile: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (YouTube) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-27]
    CHR Extension: (Google Search) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-27]
    CHR Extension: (AdBlock) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-12-15]
    CHR Extension: (Avast Online Security) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-12-15]
    CHR Extension: (Google Wallet) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
    CHR Extension: (Gmail) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-27]
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-16]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
    R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-16] (Avast Software s.r.o.)
    R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4030800 2015-03-16] (Avast Software)
    R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
    R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation)
    R2 ONDA Autorun CDROM Monitor; C:\Windows\SysWOW64\SupportAppXL\onda_mon.exe [86016 2008-09-16] () [File not signed]
    S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-03-22] (Electronic Arts)
    R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S2 BstHdAndroidSvc; "C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android [X]
    S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [X]

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] ()
    R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-03-16] ()
    R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-03-16] (Avast Software s.r.o.)
    R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-03-16] (Avast Software s.r.o.)
    R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-03-16] ()
    R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-03-16] (Avast Software s.r.o.)
    R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [441728 2015-03-16] (Avast Software s.r.o.)
    R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-03-16] (Avast Software s.r.o.)
    R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [268640 2015-03-16] ()
    S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32512 2014-04-14] ()
    R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
    R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation)
    S3 ONDAusbmdm6k; C:\Windows\System32\DRIVERS\ONDAusbmdm6k.sys [150656 2008-09-16] (ONDA Incorporated)
    S3 ONDAusbmdm6k; C:\Windows\SysWOW64\DRIVERS\ONDAusbmdm6k.sys [150656 2008-09-16] (ONDA Incorporated)
    S3 ONDAusbnet; C:\Windows\System32\DRIVERS\ONDAusbnet.sys [167424 2008-09-16] (ONDA Corporation)
    S3 ONDAusbnet; C:\Windows\SysWOW64\DRIVERS\ONDAusbnet.sys [167424 2008-09-16] (ONDA Corporation)
    S3 ONDAusbnmea; C:\Windows\System32\DRIVERS\ONDAusbnmea.sys [150656 2008-09-16] (ONDA Incorporated)
    S3 ONDAusbnmea; C:\Windows\SysWOW64\DRIVERS\ONDAusbnmea.sys [150656 2008-09-16] (ONDA Incorporated)
    S3 ONDAusbser6k; C:\Windows\System32\DRIVERS\ONDAusbser6k.sys [150656 2008-09-16] (ONDA Incorporated)
    S3 ONDAusbser6k; C:\Windows\SysWOW64\DRIVERS\ONDAusbser6k.sys [150656 2008-09-16] (ONDA Incorporated)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-07-26] () [File not signed]
    R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-03-16] (Avast Software)
    U3 aym8k6oo; C:\Windows\System32\Drivers\aym8k6oo.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
    S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-03-24 17:21 - 2015-03-24 17:21 - 00019687 _____ () C:\Users\USER\Downloads\FRST.txt
    2015-03-24 17:21 - 2015-03-24 17:21 - 00000000 ____D () C:\FRST
    2015-03-24 17:20 - 2015-03-24 17:20 - 02095616 _____ (Farbar) C:\Users\USER\Downloads\FRST64.exe
    2015-03-23 10:41 - 2015-03-24 16:53 - 00000628 _____ () C:\Windows\setupact.log
    2015-03-23 10:41 - 2015-03-23 10:41 - 00425528 _____ () C:\Windows\system32\FNTCACHE.DAT
    2015-03-23 10:41 - 2015-03-23 10:41 - 00000336 _____ () C:\Windows\PFRO.log
    2015-03-23 10:41 - 2015-03-23 10:41 - 00000000 _____ () C:\Windows\setuperr.log
    2015-03-22 11:35 - 2015-03-22 11:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2015-03-18 16:53 - 2015-02-05 18:57 - 00621384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
    2015-03-18 15:40 - 2015-03-18 15:40 - 00000656 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
    2015-03-18 15:40 - 2015-03-18 15:40 - 00000628 _____ () C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
    2015-03-18 15:40 - 2015-03-18 15:40 - 00000458 _____ () C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
    2015-03-18 15:39 - 2015-03-18 16:58 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
    2015-03-18 15:39 - 2015-03-18 15:41 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
    2015-03-18 15:39 - 2015-03-18 15:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2015-03-18 15:39 - 2015-03-18 15:39 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2015-03-18 15:39 - 2015-03-18 15:39 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2015-03-18 15:39 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
    2015-03-18 15:38 - 2015-03-18 15:38 - 00001768 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    2015-03-18 15:38 - 2015-03-18 15:38 - 00000000 ____D () C:\Users\USER\AppData\Roaming\SUPERAntiSpyware.com
    2015-03-18 15:38 - 2015-03-18 15:38 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
    2015-03-18 15:38 - 2015-03-18 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    2015-03-18 15:38 - 2015-03-18 15:38 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
    2015-03-18 15:36 - 2015-03-18 15:36 - 00305664 _____ (Secure By Design Inc.) C:\Users\USER\Downloads\Ninite Spybot 2 Super Installer.exe
    2015-03-16 10:13 - 2015-03-16 10:13 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
    2015-03-16 10:13 - 2015-03-16 10:13 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
    2015-03-16 10:01 - 2015-03-16 10:01 - 00000197 _____ () C:\Windows\system32\2015-03-16-09-01-02.059-AvastVBoxSVC.exe-3920.log
    2015-03-15 17:57 - 2015-03-15 17:57 - 00000197 _____ () C:\Windows\system32\2015-03-15-16-57-04.099-AvastVBoxSVC.exe-3228.log
    2015-03-15 17:51 - 2015-03-15 17:56 - 00008468 _____ () C:\Users\USER\Downloads\hijackthis.log
    2015-03-15 17:45 - 2015-03-15 17:45 - 00000197 _____ () C:\Windows\system32\2015-03-15-16-45-10.006-AvastVBoxSVC.exe-3540.log
    2015-03-15 17:31 - 2015-03-15 17:31 - 00388608 _____ (Trend Micro Inc.) C:\Users\USER\Downloads\HijackThis.exe
    2015-03-15 16:48 - 2015-03-15 16:48 - 00000197 _____ () C:\Windows\system32\2015-03-15-15-48-48.041-AvastVBoxSVC.exe-3640.log
    2015-03-15 11:23 - 2015-03-15 11:23 - 00000197 _____ () C:\Windows\system32\2015-03-15-10-23-25.049-AvastVBoxSVC.exe-3388.log
    2015-03-15 11:08 - 2015-03-15 11:08 - 00000197 _____ () C:\Windows\system32\2015-03-15-10-08-05.088-AvastVBoxSVC.exe-3752.log
    2015-03-14 10:05 - 2015-03-14 10:06 - 00000197 _____ () C:\Windows\system32\2015-03-14-09-05-47.078-AvastVBoxSVC.exe-3692.log
    2015-03-13 18:16 - 2015-03-13 18:16 - 00000197 _____ () C:\Windows\system32\2015-03-13-17-16-05.029-AvastVBoxSVC.exe-1548.log
    2015-03-13 09:26 - 2015-03-13 09:26 - 00000197 _____ () C:\Windows\system32\2015-03-13-08-26-11.003-AvastVBoxSVC.exe-3216.log
    2015-03-12 10:05 - 2015-03-12 10:06 - 00000197 _____ () C:\Windows\system32\2015-03-12-09-05-50.043-AvastVBoxSVC.exe-3940.log
    2015-03-11 19:30 - 2015-03-11 19:30 - 00000197 _____ () C:\Windows\system32\2015-03-11-18-30-16.012-AvastVBoxSVC.exe-2608.log
    2015-03-11 19:25 - 2015-03-11 19:25 - 00000197 _____ () C:\Windows\system32\2015-03-11-18-25-41.076-AvastVBoxSVC.exe-2568.log
    2015-03-11 10:12 - 2015-02-20 05:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2015-03-11 10:12 - 2015-02-20 05:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2015-03-11 10:12 - 2015-02-20 05:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
    2015-03-11 10:12 - 2015-02-20 05:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2015-03-11 10:12 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2015-03-11 10:12 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2015-03-11 10:12 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2015-03-11 10:12 - 2015-02-20 05:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2015-03-11 10:12 - 2015-02-20 04:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
    2015-03-11 10:12 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2015-03-11 10:12 - 2015-02-03 04:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-03-11 10:12 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
    2015-03-11 10:12 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
    2015-03-11 10:11 - 2015-02-03 04:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
    2015-03-11 10:11 - 2015-02-03 04:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
    2015-03-11 10:11 - 2015-02-03 04:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
    2015-03-11 10:11 - 2015-02-03 04:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
    2015-03-11 10:11 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
    2015-03-11 10:11 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
    2015-03-11 10:11 - 2015-02-03 04:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
    2015-03-11 10:11 - 2015-02-03 04:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
    2015-03-11 10:11 - 2015-02-03 04:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
    2015-03-11 10:11 - 2015-02-03 04:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
    2015-03-11 10:11 - 2015-02-03 04:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-03-11 10:11 - 2015-02-03 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
    2015-03-11 10:11 - 2015-02-03 04:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
    2015-03-11 10:11 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-03-11 10:11 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-03-11 10:11 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
    2015-03-11 10:11 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
    2015-03-11 10:11 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
    2015-03-11 10:11 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
    2015-03-11 10:11 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
    2015-03-11 10:11 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
    2015-03-11 10:11 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
    2015-03-11 10:11 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-03-11 10:11 - 2015-02-03 03:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2015-03-11 10:11 - 2014-10-31 23:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
    2015-03-11 10:10 - 2015-01-31 04:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
    2015-03-11 10:10 - 2015-01-31 04:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
    2015-03-11 10:10 - 2015-01-31 00:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
    2015-03-11 10:09 - 2015-03-06 06:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-03-11 10:09 - 2015-03-06 06:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-03-11 10:09 - 2015-03-06 06:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-03-11 10:09 - 2015-03-06 06:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-03-11 10:09 - 2015-03-06 06:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-03-11 10:09 - 2015-03-06 06:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-03-11 10:09 - 2015-03-06 06:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-03-11 10:09 - 2015-03-06 06:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-03-11 10:09 - 2015-03-06 06:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-03-11 10:09 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-03-11 10:09 - 2015-03-06 06:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-03-11 10:09 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-03-11 10:09 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-03-11 10:09 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-03-11 10:09 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-03-11 10:09 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2015-03-11 10:09 - 2015-02-13 06:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2015-03-11 10:09 - 2015-02-03 04:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2015-03-11 10:09 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
    2015-03-11 10:09 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2015-03-11 10:09 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
    2015-03-11 10:09 - 2015-01-31 00:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-03-11 10:09 - 2015-01-17 03:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2015-03-11 10:09 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
    2015-03-11 10:08 - 2015-02-26 04:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-03-11 10:08 - 2015-02-24 04:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-03-11 10:08 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-03-11 10:08 - 2015-02-21 02:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-03-11 10:08 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-03-11 10:08 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-03-11 10:08 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-03-11 10:08 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-03-11 10:08 - 2015-02-21 00:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-03-11 10:08 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-03-11 10:08 - 2015-02-20 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-03-11 10:08 - 2015-02-20 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-03-11 10:08 - 2015-02-20 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-03-11 10:08 - 2015-02-20 03:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-03-11 10:08 - 2015-02-20 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-03-11 10:08 - 2015-02-20 03:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-03-11 10:08 - 2015-02-20 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-03-11 10:08 - 2015-02-20 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-03-11 10:08 - 2015-02-20 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-03-11 10:08 - 2015-02-20 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-03-11 10:08 - 2015-02-20 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-03-11 10:08 - 2015-02-20 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-03-11 10:08 - 2015-02-20 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-03-11 10:08 - 2015-02-20 03:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-03-11 10:08 - 2015-02-20 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-03-11 10:08 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-03-11 10:08 - 2015-02-20 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-03-11 10:08 - 2015-02-20 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-03-11 10:08 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-03-11 10:08 - 2015-02-20 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-03-11 10:08 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-03-11 10:08 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-03-11 10:08 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-03-11 10:08 - 2015-02-20 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-03-11 10:08 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-03-11 10:08 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-03-11 10:08 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-03-11 10:08 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-03-11 10:08 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-03-11 10:08 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-03-11 10:08 - 2015-02-20 02:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-03-11 10:08 - 2015-02-20 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-03-11 10:08 - 2015-02-20 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-03-11 10:08 - 2015-02-20 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-03-11 10:08 - 2015-02-20 02:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-03-11 10:08 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-03-11 10:08 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-03-11 10:08 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-03-11 10:08 - 2015-02-20 02:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-03-11 10:08 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-03-11 10:08 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-03-11 10:08 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-03-11 10:08 - 2015-02-20 02:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-03-11 10:08 - 2015-02-20 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-03-11 10:08 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-03-11 10:08 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-03-11 10:08 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-03-11 10:07 - 2015-02-04 04:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
    2015-03-11 10:07 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
    2015-03-11 09:51 - 2015-03-11 09:51 - 00000197 _____ () C:\Windows\system32\2015-03-11-08-51-20.035-AvastVBoxSVC.exe-2240.log
    2015-03-09 18:52 - 2015-03-09 18:52 - 00000197 _____ () C:\Windows\system32\2015-03-09-17-52-43.043-AvastVBoxSVC.exe-3852.log
    2015-03-09 12:36 - 2015-03-09 12:37 - 00000197 _____ () C:\Windows\system32\2015-03-09-11-36-58.033-AvastVBoxSVC.exe-3632.log
    2015-03-09 12:20 - 2015-03-09 12:20 - 00000197 _____ () C:\Windows\system32\2015-03-09-11-20-04.089-AvastVBoxSVC.exe-2704.log
    2015-03-08 18:36 - 2015-03-08 18:36 - 00000197 _____ () C:\Windows\system32\2015-03-08-17-36-50.048-AvastVBoxSVC.exe-3012.log
    2015-03-08 10:47 - 2015-03-08 10:48 - 00000197 _____ () C:\Windows\system32\2015-03-08-09-47-54.099-AvastVBoxSVC.exe-3576.log
    2015-03-07 14:48 - 2015-03-07 14:48 - 00000197 _____ () C:\Windows\system32\2015-03-07-13-48-29.040-AvastVBoxSVC.exe-3928.log
    2015-03-07 12:40 - 2015-03-07 12:40 - 00000197 _____ () C:\Windows\system32\2015-03-07-11-40-02.008-AvastVBoxSVC.exe-2096.log
    2015-03-07 12:31 - 2015-03-07 12:31 - 00000197 _____ () C:\Windows\system32\2015-03-07-11-31-10.055-AvastVBoxSVC.exe-3944.log
    2015-03-07 12:19 - 2015-03-07 12:19 - 02126848 _____ () C:\Users\USER\Downloads\adwcleaner_4.111.exe
    2015-03-07 10:42 - 2015-03-07 10:42 - 00000197 _____ () C:\Windows\system32\2015-03-07-09-42-43.023-AvastVBoxSVC.exe-3148.log
    2015-03-04 16:30 - 2015-03-04 16:30 - 05325696 _____ (Piriform Ltd) C:\Users\USER\Downloads\ccsetup503.exe
    2015-03-04 16:18 - 2015-03-04 16:18 - 00000197 _____ () C:\Windows\system32\2015-03-04-15-18-05.001-AvastVBoxSVC.exe-2564.log
    2015-03-04 12:05 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
    2015-03-04 12:05 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
    2015-03-04 12:05 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
    2015-03-04 12:05 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
    2015-03-04 11:59 - 2015-03-04 12:00 - 00000197 _____ () C:\Windows\system32\2015-03-04-10-59-43.052-AvastVBoxSVC.exe-2856.log
    2015-03-03 19:07 - 2015-03-03 19:07 - 00000197 _____ () C:\Windows\system32\2015-03-03-18-07-08.089-AvastVBoxSVC.exe-1988.log
    2015-03-03 13:48 - 2015-03-03 13:48 - 00000197 _____ () C:\Windows\system32\2015-03-03-12-48-46.003-AvastVBoxSVC.exe-3084.log
    2015-03-03 11:46 - 2015-03-03 11:46 - 00000197 _____ () C:\Windows\system32\2015-03-03-10-46-12.090-AvastVBoxSVC.exe-2960.log
    2015-03-02 17:06 - 2015-03-02 17:06 - 00000197 _____ () C:\Windows\system32\2015-03-02-16-06-22.093-AvastVBoxSVC.exe-3008.log
    2015-03-02 10:20 - 2015-03-02 10:20 - 00000197 _____ () C:\Windows\system32\2015-03-02-09-20-04.077-AvastVBoxSVC.exe-3908.log
    2015-03-01 18:07 - 2015-03-01 18:08 - 00000197 _____ () C:\Windows\system32\2015-03-01-17-07-50.076-AvastVBoxSVC.exe-3388.log
    2015-03-01 10:57 - 2015-03-01 10:58 - 00000197 _____ () C:\Windows\system32\2015-03-01-09-57-55.047-AvastVBoxSVC.exe-2588.log
    2015-02-28 10:35 - 2015-02-28 10:36 - 00000197 _____ () C:\Windows\system32\2015-02-28-09-35-56.014-AvastVBoxSVC.exe-2596.log
    2015-02-27 16:16 - 2015-02-27 16:16 - 00000197 _____ () C:\Windows\system32\2015-02-27-15-16-03.044-AvastVBoxSVC.exe-3336.log
    2015-02-26 14:58 - 2015-02-26 14:58 - 00000197 _____ () C:\Windows\system32\2015-02-26-13-58-01.052-AvastVBoxSVC.exe-2284.log
    2015-02-25 19:58 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
    2015-02-25 19:58 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
    2015-02-25 19:17 - 2015-02-25 19:18 - 00000197 _____ () C:\Windows\system32\2015-02-25-18-17-33.044-AvastVBoxSVC.exe-3768.log
    2015-02-24 11:22 - 2015-02-24 11:23 - 00000197 _____ () C:\Windows\system32\2015-02-24-10-22-46.080-AvastVBoxSVC.exe-3152.log
    2015-02-23 17:40 - 2015-02-23 17:41 - 00000197 _____ () C:\Windows\system32\2015-02-23-16-40-53.067-AvastVBoxSVC.exe-2224.log
    2015-02-23 10:18 - 2015-02-23 10:19 - 00000197 _____ () C:\Windows\system32\2015-02-23-09-18-42.040-AvastVBoxSVC.exe-3116.log
    2015-02-22 18:28 - 2015-02-22 18:29 - 00000197 _____ () C:\Windows\system32\2015-02-22-17-28-35.049-AvastVBoxSVC.exe-2236.log
    2015-02-22 11:18 - 2015-02-22 11:18 - 00000197 _____ () C:\Windows\system32\2015-02-22-10-18-15.067-AvastVBoxSVC.exe-748.log

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-03-24 16:57 - 2012-07-27 11:29 - 00001150 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-03-24 16:56 - 2009-07-14 05:45 - 00031504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-03-24 16:56 - 2009-07-14 05:45 - 00031504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-03-24 16:55 - 2012-07-26 09:35 - 01515129 _____ () C:\Windows\WindowsUpdate.log
    2015-03-24 16:50 - 2012-07-27 11:38 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
    2015-03-24 16:50 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
    2015-03-24 16:49 - 2012-07-27 11:29 - 00001146 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-03-24 16:48 - 2012-07-27 10:06 - 00000000 ____D () C:\ProgramData\NVIDIA
    2015-03-24 16:48 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-03-23 14:30 - 2012-07-27 08:51 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-03-23 14:13 - 2012-07-27 10:46 - 00000000 ____D () C:\Users\USER\AppData\Local\Adobe
    2015-03-23 14:10 - 2012-07-27 08:51 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-03-23 14:10 - 2012-07-27 08:51 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-03-23 14:10 - 2012-07-27 08:51 - 00003916 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-03-23 11:46 - 2012-07-30 14:35 - 00000000 ____D () C:\ProgramData\Origin
    2015-03-23 10:42 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
    2015-03-22 19:51 - 2013-03-15 19:08 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Mp3tag
    2015-03-22 17:41 - 2012-11-12 16:49 - 00000000 ____D () C:\Program Files (x86)\Steam
    2015-03-22 17:40 - 2012-09-09 13:58 - 00000000 ____D () C:\Windows\Minidump
    2015-03-22 17:37 - 2015-01-13 19:15 - 00000000 ____D () C:\Users\USER\AppData\Local\Room Arranger
    2015-03-22 16:00 - 2014-08-17 11:50 - 00000000 ____D () C:\ProgramData\Package Cache
    2015-03-22 14:48 - 2012-07-30 18:08 - 00000000 ____D () C:\Program Files (x86)\Origin
    2015-03-22 14:38 - 2012-07-27 08:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2015-03-22 11:59 - 2012-07-27 11:31 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2015-03-20 09:58 - 2009-07-14 06:08 - 00032548 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
    2015-03-18 16:53 - 2014-02-18 19:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    2015-03-18 15:36 - 2014-04-14 18:39 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-03-17 16:35 - 2013-03-31 11:10 - 00000000 ____D () C:\Users\USER\Documents\Lettera
    2015-03-17 11:35 - 2014-02-12 17:44 - 00000000 ____D () C:\Program Files (x86)\Alice MOBILE
    2015-03-16 10:13 - 2014-05-04 13:18 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys
    2015-03-16 10:13 - 2014-02-18 14:59 - 00136752 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
    2015-03-16 10:13 - 2013-07-13 11:16 - 00268640 _____ () C:\Windows\system32\Drivers\aswVmm.sys
    2015-03-16 10:13 - 2013-07-13 11:16 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
    2015-03-16 10:13 - 2012-07-27 11:29 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
    2015-03-16 10:13 - 2012-07-27 11:29 - 00441728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
    2015-03-16 10:13 - 2012-07-27 11:29 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
    2015-03-16 10:13 - 2012-07-27 11:29 - 00088408 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
    2015-03-15 18:03 - 2012-11-14 15:04 - 00000000 ____D () C:\Users\USER\AppData\Roaming\PhotoScape
    2015-03-15 17:56 - 2012-07-26 09:38 - 00000000 ____D () C:\Users\USER\AppData\Local\VirtualStore
    2015-03-15 17:40 - 2014-04-14 18:21 - 00000000 ____D () C:\AdwCleaner
    2015-03-15 16:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
    2015-03-11 19:22 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
    2015-03-11 19:22 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
    2015-03-11 12:32 - 2014-04-26 15:37 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Spotify
    2015-03-11 11:46 - 2014-04-26 15:39 - 00000000 ____D () C:\Users\USER\AppData\Local\Spotify
    2015-03-07 15:10 - 2012-10-19 16:09 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Skype
    2015-03-07 15:09 - 2014-10-11 14:00 - 00000000 ___RD () C:\Program Files (x86)\Skype
    2015-03-07 15:09 - 2012-10-19 16:09 - 00000000 ____D () C:\ProgramData\Skype
    2015-03-07 10:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
    2015-03-04 16:37 - 2012-08-01 10:58 - 00000000 ____D () C:\Users\USER\Desktop\Giochi
    2015-03-04 16:37 - 2012-07-28 14:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TunnelBear
    2015-03-04 16:37 - 2012-07-26 10:30 - 00000000 ____D () C:\Windows\Panther
    2015-03-04 16:35 - 2014-02-07 17:44 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
    2015-03-04 16:35 - 2012-07-28 14:14 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Azureus
    2015-03-04 16:35 - 2012-07-26 17:00 - 00000000 ____D () C:\Users\USER\AppData\Roaming\DAEMON Tools Lite
    2015-03-04 16:30 - 2014-01-09 16:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    2015-03-04 16:30 - 2014-01-09 16:04 - 00000000 ____D () C:\Program Files\CCleaner
    2015-03-04 12:40 - 2014-08-16 14:07 - 00000000 ____D () C:\Program Files (x86)\Free mp3 Wma Converter
    2015-03-04 12:24 - 2014-04-14 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-03-04 12:24 - 2014-04-14 18:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-02-26 16:49 - 2012-07-27 08:47 - 00000000 ____D () C:\Users\USER\AppData\Roaming\vlc
    2015-02-24 04:17 - 2010-11-21 04:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

    ==================== Files in the root of some directories =======

    2013-10-18 09:09 - 2013-10-18 09:09 - 50053120 _____ () C:\Program Files (x86)\GUT1AF1.tmp
    2014-08-16 16:20 - 2014-08-16 16:20 - 0030321 _____ () C:\Users\USER\AppData\Local\recently-used.xbel

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-02-20 12:43

    ==================== End Of Log ============================


    Visto che non ci capisco nulla, attendo numi a chi gentilmente me li potrà dare! Grazie infinite!
    Ciao! Alessia
     
    .
  14. dissident
     
    .

    User deleted


    Scusate per il doppio post ma...ripensandoci, volevo aggiungere che ho provato a navigare con lo stesso modem nei giorni scorsi su un portatile e non mi ha mai dato il problema dei pop-up fastidiosi. Giusto per aggiungere ulteriori misteri alla cosa. :D
     
    .
  15. Caesar95
     
    .

    User deleted


    CITAZIONE (vicky67 @ 22/3/2015, 14:01) 
    Sai entrare nel router?
    Per verificare che il router sia infetto vale sempre la mia guida linkata nella prima pagina.
    Dovresti resettare il router ,bloccarne l'accesso e inserire i dns di google e opends
    Resettare safari..
    Purtroppo con il mac non posso guidarti passo passo.

    Comunque prima entra nel router e verifica i dns

    Intanto grazie mille per la tua risposta! Perdonami se non ho a mia volta risposto, ma sono appena tornato da un viaggio di lavoro, e non ho avuto un istante libero.

    Ho resettato Safari un paio di volte in più, e sono stato a posto per un po'. Da poco sono ripresi i links to Adultyum purtroppo.

    Come si entra nel router? :huh:
     
    .
51 replies since 30/1/2015, 11:52   12909 views
  Share  
.