Need fixlist.txt for Farbar Recovery Scan Tool

Matteocat

New Member
Thread author
Mar 21, 2014
1
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by SYSTEM on MININT-P9UNJMF on 21-03-2014 13:15:01
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Italian Standard
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.


The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6469736 2012-03-06] (Realtek Semiconductor)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.)
HKLM-x32\...\Run: [UX Launcher] - C:\Program Files (x86)\UX Pack\uxlaunch.exe [224999 2013-11-30] (Windows X)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-25] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\Giacomo\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
HKU\Giacomo\...\Run: [LiveSupport] - "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
HKU\Giacomo\...\Run: [RocketDock] - C:\Program Files (x86)\UX Pack\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\Giacomo\...\Run: [XLaunchpad] - C:\Program Files (x86)\UX Pack\XLaunchpad\XLaunchPad.exe [2372608 2013-05-17] (xwidget.com)
HKU\Giacomo\...\Policies\system: [DisableLockWorkstation] 0

==================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-25] (AVAST Software)
S2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [508016 2014-01-14] (Cherished Technololgy LIMITED)
S2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC)
S2 Update AdvanceMark; C:\Program Files (x86)\AdvanceMark\updateAdvanceMark.exe [348960 2014-03-15] ()
S2 USBMIDIAudioDevMon; C:\Program Files (x86)\M-Audio\USB MIDI Series\AudioDevMon.exe [1636872 2010-04-13] (M-Audio)
S2 Util AdvanceMark; C:\Program Files (x86)\AdvanceMark\bin\utilAdvanceMark.exe [348960 2014-03-15] ()
S2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [425104 2014-02-26] (Taiwan Shui Mu Chih Ching Technology Limited.)
S2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [501904 2014-02-26] (Cherished Technololgy LIMITED)

==================== Drivers (Whitelisted) ====================

S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-25] (AVAST Software)
S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-02-25] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-02-25] ()
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-25] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-25] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-25] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2014-01-22] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-02-25] ()
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-07-14] (DT Soft Ltd)
S3 MAUSBMIDI; C:\Windows\System32\DRIVERS\MAudioUSBMIDI.sys [200200 2010-04-13] (M-Audio)
S3 MFWAMIDI64; C:\Windows\System32\drivers\MFWAMIDI64.sys [32368 2012-04-26] (Mark of the Unicorn)
S3 MFWAWAVE64; C:\Windows\System32\drivers\MFWAWAVE64.sys [82544 2012-04-26] (Mark of the Unicorn)
S3 motubus; C:\Windows\System32\drivers\MotuBus64.sys [29808 2012-04-26] (Mark of the Unicorn)
S3 MotuFWA64; C:\Windows\System32\drivers\Motufwa64.sys [608368 2012-04-26] (Mark of the Unicorn)
S2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] ()
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]

========================== Drivers MD5 =======================

C:\Windows\System32\DRIVERS\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 79059559E89D06E8B80CE2944BE20228
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\system32\drivers\aswMonFlt.sys 0ACC3F49015E628590CA4372322EB46B
C:\Windows\system32\drivers\aswRdr2.sys 679712B7A353EE665B9301592164A172
C:\Windows\System32\Drivers\aswRvrt.sys C04F7B373881009D7994D9BF55D24AB4
C:\Windows\system32\drivers\aswSnx.sys 43599E630DFC30AD4E6A2B4B269EB1C0
C:\Windows\system32\drivers\aswSP.sys F22DE5F5BA8ADA0A861441B624B51EB5
C:\Windows\system32\drivers\aswStm.sys FD3EA14ADF6216BDF4030DB2EFD43D96
C:\Windows\System32\Drivers\aswTdi.sys 367CF04C38DFF33368FCDBBF71C96297
C:\Windows\System32\Drivers\aswVmm.sys 90399625F341AB76BA4B85A5E860EB1F
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys ==> MD5 is legit
C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys EBF28856F69CF094A902F884CF989706
C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys ==> MD5 is legit
C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\dtsoftbus01.sys 46571ED73AE84469DCA53081D33CF3C8
C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52
C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\GEARAspiWDM.sys 8E98D21EE06192492A5671A6144D092F
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\System32\DRIVERS\igdkmd64.sys 371D7F91C0D2314EB984A4A6CBEABC92
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\drivers\RTKVHD64.sys 059DDDEDBE5701DC3B779D32798108AC
C:\Windows\System32\DRIVERS\IntcDAud.sys FC727061C0F47C8059E88E05D5C8E381
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\system32\drivers\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys 8F489706472F7E9A06BAAA198703FA64
C:\Windows\System32\Drivers\ksecpkg.sys 868A2CAAB12EFC7A021682BCA0EEC54C
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\MAudioUSBMIDI.sys 6EA9AA4A432871225938CC6869E59213
C:\Windows\System32\drivers\MBfilt64.sys 8FF2D95CBA49B405C5DE27039FF0BF35
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\drivers\MFWAMIDI64.sys B992A0D38B61D257171AC4078DC409AE
C:\Windows\System32\drivers\MFWAWAVE64.sys 5D74D2F72587A0DBC3FCA1E51C83E8B0
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\drivers\MotuBus64.sys B530BC8DE36AA7416D2B9321893AEE3F
C:\Windows\System32\drivers\Motufwa64.sys 4E150AFC2B936FEC445EA46C27EE4DAF
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404
C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC
C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163
C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C
C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nusb3hub.sys 0EBC9D13CD96C15B1B18D8678A609E4B
C:\Windows\System32\DRIVERS\nusb3xhc.sys 7BDEC000D56D485021D9C1E63C2F81CA
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Rt64win7.sys 6CF9DB101A75360E98659F823852E540
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Tpkd.sys 7CACE8801848966B7541E664000E4EE4
C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09
C:\Windows\System32\drivers\tsusbflt.sys ==> MD5 is legit
C:\Windows\system32\drivers\TsUsbGD.sys 9CC2CCAE8A84820EAECB886D477CBCB8
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit
C:\Windows\System32\Drivers\usbaapl64.sys C9E9D59C0099A9FF51697E9306A44240
C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2
C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965
C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA
C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC
C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6
C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3
C:\Windows\system32\drivers\uxpatch.sys 297EE9C666FC8BB96A232DB0DDBA1E49
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-21 13:13 - 2014-03-21 13:15 - 00000000 ____D () C:\FRST
2014-03-21 12:59 - 2014-03-21 12:59 - 00003720 ____N () C:\bootsqm.dat
2014-03-21 12:01 - 2014-03-21 12:01 - 00000000 ___HD () C:\.fseventsd
2014-03-21 10:48 - 2011-02-05 18:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\System32\winload.exe
2014-03-21 10:47 - 2014-03-21 10:47 - 00004096 ____H () C:\._.Trashes
2014-03-21 10:47 - 2014-03-21 10:47 - 00000000 ___HD () C:\.Trashes
2014-03-16 00:58 - 2014-02-23 08:12 - 17847808 _____ () C:\Windows\System32\mshtml.dll
2014-03-16 00:58 - 2014-02-23 07:54 - 02334720 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-03-16 00:58 - 2014-02-23 07:52 - 10926592 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-03-16 00:58 - 2014-02-23 07:48 - 01392128 _____ () C:\Windows\System32\wininet.dll
2014-03-16 00:58 - 2014-02-23 07:48 - 01347072 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-03-16 00:58 - 2014-02-23 07:46 - 01494528 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-03-16 00:58 - 2014-02-23 07:46 - 00237056 _____ () C:\Windows\System32\url.dll
2014-03-16 00:58 - 2014-02-23 07:46 - 00086016 _____ () C:\Windows\System32\jsproxy.dll
2014-03-16 00:58 - 2014-02-23 07:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2014-03-16 00:58 - 2014-02-23 07:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2014-03-16 00:58 - 2014-02-23 07:45 - 00173056 _____ () C:\Windows\System32\ieUnatt.exe
2014-03-16 00:58 - 2014-02-23 07:44 - 02382848 _____ () C:\Windows\System32\mshtml.tlb
2014-03-16 00:58 - 2014-02-23 07:44 - 02147840 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-03-16 00:58 - 2014-02-23 07:44 - 00729088 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-03-16 00:58 - 2014-02-23 07:44 - 00096768 _____ () C:\Windows\System32\mshtmled.dll
2014-03-16 00:58 - 2014-02-23 07:43 - 00248320 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-03-16 00:58 - 2014-02-23 06:50 - 12347904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-16 00:58 - 2014-02-23 06:47 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-16 00:58 - 2014-02-23 06:43 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-16 00:58 - 2014-02-23 06:41 - 01105408 _____ () C:\Windows\SysWOW64\urlmon.dll
2014-03-16 00:58 - 2014-02-23 06:40 - 01129472 _____ () C:\Windows\SysWOW64\wininet.dll
2014-03-16 00:58 - 2014-02-23 06:39 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-16 00:58 - 2014-02-23 06:38 - 00231936 _____ () C:\Windows\SysWOW64\url.dll
2014-03-16 00:58 - 2014-02-23 06:38 - 00142848 _____ () C:\Windows\SysWOW64\ieUnatt.exe
2014-03-16 00:58 - 2014-02-23 06:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-16 00:58 - 2014-02-23 06:37 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-16 00:58 - 2014-02-23 06:37 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-03-16 00:58 - 2014-02-23 06:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-16 00:58 - 2014-02-23 06:37 - 00421376 _____ () C:\Windows\SysWOW64\vbscript.dll
2014-03-16 00:58 - 2014-02-23 06:36 - 02382848 _____ () C:\Windows\SysWOW64\mshtml.tlb
2014-03-16 00:58 - 2014-02-23 06:36 - 00073216 _____ () C:\Windows\SysWOW64\mshtmled.dll
2014-03-16 00:58 - 2014-02-23 06:35 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-14 08:41 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2014-03-14 08:41 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\System32\wer.dll
2014-03-14 08:41 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-14 08:41 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2014-03-13 22:19 - 2014-03-13 22:19 - 00471030 _____ () C:\Windows\System32\PerfStringBackup.TMP
2014-03-13 08:56 - 2014-03-13 08:56 - 00782712 _____ ( ) C:\Users\Giacomo\Downloads\SkypeSetup (1).exe
2014-03-13 08:51 - 2014-03-13 08:51 - 00003158 _____ () C:\Windows\System32\Tasks\{28D0BF10-2908-4FD6-8CCF-E40B0AB489B2}
2014-03-13 08:49 - 2014-03-13 08:49 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Giacomo\Downloads\SkypeSetup.exe
2014-03-13 08:38 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\System32\qedit.dll
2014-03-13 08:38 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-12 19:58 - 2014-03-12 19:58 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\Media Player Classic
2014-03-12 17:53 - 2014-03-12 17:53 - 00000000 ____D () C:\Users\Giacomo\AppData\Local\Lollipop
2014-03-12 17:53 - 2014-03-12 17:53 - 00000000 _____ () C:\END
2014-03-12 17:51 - 2014-03-12 17:51 - 00381320 _____ () C:\Users\Giacomo\Downloads\Java.exe
2014-03-11 18:05 - 2014-03-11 18:08 - 00000000 ____D () C:\Users\Giacomo\Desktop\Originals
2014-03-11 18:04 - 2014-03-11 18:09 - 00003072 ____H () C:\Users\Giacomo\Desktop\photothumb.db
2014-03-11 10:25 - 2014-03-11 10:26 - 00000000 ____D () C:\Users\Giacomo\Desktop\Aladdin
2014-03-03 20:54 - 2014-03-03 20:54 - 06899248 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 003.wav
2014-03-03 20:54 - 2014-03-03 20:54 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 006.wav
2014-03-03 20:54 - 2014-03-03 20:54 - 00067010 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 003.wav.reapeaks
2014-03-03 20:54 - 2014-03-03 20:54 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 006.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 03242086 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 001.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 03043636 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 002.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 00563014 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 005.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 00463786 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 004.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 00031498 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 001.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 00029570 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 002.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 00005514 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 005.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 00004530 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 004.wav.reapeaks
2014-03-03 20:52 - 2014-03-03 20:52 - 03449992 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 002.wav
2014-03-03 20:52 - 2014-03-03 20:52 - 00033526 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 002.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 06899248 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 001.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 003.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 002.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 001.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 00067010 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 001.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 003.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 002.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 001.wav.reapeaks
2014-03-03 20:49 - 2014-03-03 20:49 - 06615736 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI glued render 001.wav
2014-03-03 20:49 - 2014-03-03 20:49 - 00064242 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI glued render 001.wav.reapeaks
2014-03-03 19:54 - 2014-03-03 19:54 - 00000460 _____ () C:\Users\Giacomo\Desktop\1000gb (D) - collegamento.lnk
2014-03-03 13:37 - 2014-03-03 13:40 - 00000000 ____D () C:\Users\Giacomo\Desktop\zio
2014-03-02 13:36 - 2014-03-11 18:10 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\PhotoScape
2014-03-02 13:36 - 2014-03-02 13:36 - 00001036 _____ () C:\Users\Giacomo\Desktop\PhotoScape.lnk
2014-03-02 13:36 - 2014-03-02 13:36 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-03-02 13:35 - 2014-03-02 13:36 - 21331096 _____ (Mooii) C:\Users\Giacomo\Desktop\PhotoScape_V3-6-5.exe
2014-03-01 23:38 - 2014-03-01 23:39 - 00016384 _____ () C:\Users\Giacomo\Desktop\06-01-pan-140301_2338.wav.reapeaks
2014-03-01 23:38 - 2014-03-01 23:39 - 00004096 _____ () C:\Users\Giacomo\Desktop\07-01-pan-140301_2338.wav.reapeaks
2014-03-01 23:38 - 2014-03-01 23:38 - 00000000 _____ () C:\Users\Giacomo\Desktop\07-01-pan-140301_2338.wav
2014-03-01 23:38 - 2014-03-01 23:38 - 00000000 _____ () C:\Users\Giacomo\Desktop\06-01-pan-140301_2338.wav
2014-03-01 23:21 - 2014-03-01 23:26 - 07405568 _____ () C:\Users\Giacomo\Desktop\05-01-pan-140301_2321.wav
2014-03-01 23:21 - 2014-03-01 23:26 - 07405568 _____ () C:\Users\Giacomo\Desktop\04-01-pan-140301_2321.wav
2014-03-01 23:21 - 2014-03-01 23:26 - 00077824 _____ () C:\Users\Giacomo\Desktop\05-01-pan-140301_2321.wav.reapeaks
2014-03-01 23:21 - 2014-03-01 23:26 - 00077824 _____ () C:\Users\Giacomo\Desktop\04-01-pan-140301_2321.wav.reapeaks
2014-02-26 19:42 - 2014-03-15 10:06 - 00000000 ____D () C:\Program Files (x86)\WinZipper
2014-02-26 19:42 - 2014-02-27 20:12 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\WinZipper
2014-02-26 19:42 - 2014-02-26 19:42 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\SupTab
2014-02-26 08:30 - 2014-02-26 08:30 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\AVAST Software
2014-02-25 08:47 - 2014-03-02 12:02 - 00002015 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-02-25 08:47 - 2014-02-25 08:47 - 00080184 _____ (AVAST Software) C:\Windows\System32\Drivers\aswStm.sys
2014-02-25 08:46 - 2014-02-25 08:46 - 00000000 ____D () C:\Users\Giacomo\Desktop\Jack
2014-02-25 08:45 - 2014-02-25 08:47 - 00207904 _____ () C:\Windows\System32\Drivers\aswVmm.sys
2014-02-25 08:45 - 2014-02-25 08:47 - 00065776 _____ () C:\Windows\System32\Drivers\aswRvrt.sys
2014-02-24 23:46 - 2014-02-26 00:34 - 01633058 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-19 18:41 - 2014-02-19 18:41 - 05166532 _____ () C:\Users\Giacomo\Downloads\Claudio.zip

==================== One Month Modified Files and Folders =======

2014-03-21 13:15 - 2014-03-21 13:13 - 00000000 ____D () C:\FRST
2014-03-21 12:59 - 2014-03-21 12:59 - 00003720 ____N () C:\bootsqm.dat
2014-03-21 12:01 - 2014-03-21 12:01 - 00000000 ___HD () C:\.fseventsd
2014-03-21 10:47 - 2014-03-21 10:47 - 00004096 ____H () C:\._.Trashes
2014-03-21 10:47 - 2014-03-21 10:47 - 00000000 ___HD () C:\.Trashes
2014-03-16 00:58 - 2012-07-15 15:07 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\vlc
2014-03-16 00:58 - 2012-07-13 17:43 - 01743860 _____ () C:\Windows\WindowsUpdate.log
2014-03-16 00:40 - 2012-07-13 16:41 - 00000978 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-16 00:29 - 2014-02-10 18:18 - 00001152 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-15 17:29 - 2014-02-10 18:18 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-15 10:10 - 2009-07-14 05:45 - 00024688 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-15 10:10 - 2009-07-14 05:45 - 00024688 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-15 10:06 - 2014-02-26 19:42 - 00000000 ____D () C:\Program Files (x86)\WinZipper
2014-03-15 10:03 - 2012-07-18 13:15 - 00072650 _____ () C:\Windows\setupact.log
2014-03-15 10:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-14 18:56 - 2012-07-13 17:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-14 09:40 - 2014-02-10 22:15 - 00000000 ____D () C:\Users\Giacomo\AppData\Local\Songr
2014-03-14 08:44 - 2012-07-18 13:15 - 00311808 _____ () C:\Windows\System32\FNTCACHE.DAT
2014-03-13 22:19 - 2014-03-13 22:19 - 00471030 _____ () C:\Windows\System32\PerfStringBackup.TMP
2014-03-13 22:19 - 2010-11-21 16:30 - 00727388 _____ () C:\Windows\System32\perfh010.dat
2014-03-13 22:19 - 2010-11-21 16:30 - 00142444 _____ () C:\Windows\System32\perfc010.dat
2014-03-13 21:43 - 2009-07-14 06:13 - 00200702 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-03-13 08:56 - 2014-03-13 08:56 - 00782712 _____ ( ) C:\Users\Giacomo\Downloads\SkypeSetup (1).exe
2014-03-13 08:51 - 2014-03-13 08:51 - 00003158 _____ () C:\Windows\System32\Tasks\{28D0BF10-2908-4FD6-8CCF-E40B0AB489B2}
2014-03-13 08:49 - 2014-03-13 08:49 - 01678496 _____ (Skype Technologies S.A.) C:\Users\Giacomo\Downloads\SkypeSetup.exe
2014-03-12 19:58 - 2014-03-12 19:58 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\Media Player Classic
2014-03-12 17:53 - 2014-03-12 17:53 - 00000000 ____D () C:\Users\Giacomo\AppData\Local\Lollipop
2014-03-12 17:53 - 2014-03-12 17:53 - 00000000 _____ () C:\END
2014-03-12 17:51 - 2014-03-12 17:51 - 00381320 _____ () C:\Users\Giacomo\Downloads\Java.exe
2014-03-12 16:47 - 2014-02-11 09:03 - 00259452 _____ () C:\Windows\PFRO.log
2014-03-11 18:10 - 2014-03-02 13:36 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\PhotoScape
2014-03-11 18:09 - 2014-03-11 18:04 - 00003072 ____H () C:\Users\Giacomo\Desktop\photothumb.db
2014-03-11 18:08 - 2014-03-11 18:05 - 00000000 ____D () C:\Users\Giacomo\Desktop\Originals
2014-03-11 10:26 - 2014-03-11 10:25 - 00000000 ____D () C:\Users\Giacomo\Desktop\Aladdin
2014-03-11 10:00 - 2014-02-10 16:45 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-03-03 20:54 - 2014-03-03 20:54 - 06899248 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 003.wav
2014-03-03 20:54 - 2014-03-03 20:54 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 006.wav
2014-03-03 20:54 - 2014-03-03 20:54 - 00067010 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 003.wav.reapeaks
2014-03-03 20:54 - 2014-03-03 20:54 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 006.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 03242086 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 001.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 03043636 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 002.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 00563014 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 005.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 00463786 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 004.wav
2014-03-03 20:53 - 2014-03-03 20:53 - 00031498 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 001.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 00029570 _____ () C:\Users\Giacomo\Desktop\01-Dfh Sampler-Recorded MIDI glued render 002.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 00005514 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 005.wav.reapeaks
2014-03-03 20:53 - 2014-03-03 20:53 - 00004530 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 004.wav.reapeaks
2014-03-03 20:52 - 2014-03-03 20:52 - 03449992 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 002.wav
2014-03-03 20:52 - 2014-03-03 20:52 - 00033526 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 002.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 06899248 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 001.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 003.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 002.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 06830206 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 001.wav
2014-03-03 20:51 - 2014-03-03 20:51 - 00067010 _____ () C:\Users\Giacomo\Desktop\03-Dfh Sampler-Recorded MIDI render 001.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 003.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 002.wav.reapeaks
2014-03-03 20:51 - 2014-03-03 20:51 - 00066338 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI render 001.wav.reapeaks
2014-03-03 20:49 - 2014-03-03 20:49 - 06615736 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI glued render 001.wav
2014-03-03 20:49 - 2014-03-03 20:49 - 00064242 _____ () C:\Users\Giacomo\Desktop\02-Dfh Sampler-Recorded MIDI glued render 001.wav.reapeaks
2014-03-03 19:54 - 2014-03-03 19:54 - 00000460 _____ () C:\Users\Giacomo\Desktop\1000gb (D) - collegamento.lnk
2014-03-03 15:22 - 2009-07-14 06:08 - 00032512 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-03 13:40 - 2014-03-03 13:37 - 00000000 ____D () C:\Users\Giacomo\Desktop\zio
2014-03-02 13:36 - 2014-03-02 13:36 - 00001036 _____ () C:\Users\Giacomo\Desktop\PhotoScape.lnk
2014-03-02 13:36 - 2014-03-02 13:36 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-03-02 13:36 - 2014-03-02 13:35 - 21331096 _____ (Mooii) C:\Users\Giacomo\Desktop\PhotoScape_V3-6-5.exe
2014-03-02 12:02 - 2014-02-25 08:47 - 00002015 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-03-01 23:39 - 2014-03-01 23:38 - 00016384 _____ () C:\Users\Giacomo\Desktop\06-01-pan-140301_2338.wav.reapeaks
2014-03-01 23:39 - 2014-03-01 23:38 - 00004096 _____ () C:\Users\Giacomo\Desktop\07-01-pan-140301_2338.wav.reapeaks
2014-03-01 23:38 - 2014-03-01 23:38 - 00000000 _____ () C:\Users\Giacomo\Desktop\07-01-pan-140301_2338.wav
2014-03-01 23:38 - 2014-03-01 23:38 - 00000000 _____ () C:\Users\Giacomo\Desktop\06-01-pan-140301_2338.wav
2014-03-01 23:26 - 2014-03-01 23:21 - 07405568 _____ () C:\Users\Giacomo\Desktop\05-01-pan-140301_2321.wav
2014-03-01 23:26 - 2014-03-01 23:21 - 07405568 _____ () C:\Users\Giacomo\Desktop\04-01-pan-140301_2321.wav
2014-03-01 23:26 - 2014-03-01 23:21 - 00077824 _____ () C:\Users\Giacomo\Desktop\05-01-pan-140301_2321.wav.reapeaks
2014-03-01 23:26 - 2014-03-01 23:21 - 00077824 _____ () C:\Users\Giacomo\Desktop\04-01-pan-140301_2321.wav.reapeaks
2014-02-27 20:12 - 2014-02-26 19:42 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\WinZipper
2014-02-27 14:56 - 2012-07-15 02:44 - 00000256 _____ () C:\Windows\SysWOW64\w3data.vss
2014-02-27 14:56 - 2012-07-15 02:44 - 00000256 _____ () C:\Windows\SysWOW64\msvcsv60.dll
2014-02-27 14:56 - 2012-07-15 02:44 - 00000256 _____ () C:\Windows\msocreg32.dat
2014-02-27 13:11 - 2014-02-10 22:20 - 00000000 ____D () C:\Program Files (x86)\AdvanceMark
2014-02-26 19:46 - 2012-07-14 20:15 - 00000000 ____D () C:\Program Files\REAPER (x64)
2014-02-26 19:42 - 2014-02-26 19:42 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\SupTab
2014-02-26 19:41 - 2014-02-10 22:16 - 00000000 ____D () C:\ProgramData\WPM
2014-02-26 08:30 - 2014-02-26 08:30 - 00000000 ____D () C:\Users\Giacomo\AppData\Roaming\AVAST Software
2014-02-26 00:34 - 2014-02-24 23:46 - 01633058 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-25 08:47 - 2014-02-25 08:47 - 00080184 _____ (AVAST Software) C:\Windows\System32\Drivers\aswStm.sys
2014-02-25 08:47 - 2014-02-25 08:45 - 00207904 _____ () C:\Windows\System32\Drivers\aswVmm.sys
2014-02-25 08:47 - 2014-02-25 08:45 - 00065776 _____ () C:\Windows\System32\Drivers\aswRvrt.sys
2014-02-25 08:47 - 2012-07-13 17:00 - 01038072 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2014-02-25 08:47 - 2012-07-13 17:00 - 00421704 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2014-02-25 08:47 - 2012-07-13 17:00 - 00334136 _____ (AVAST Software) C:\Windows\System32\aswBoot.exe
2014-02-25 08:47 - 2012-07-13 17:00 - 00092544 _____ (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2014-02-25 08:47 - 2012-07-13 17:00 - 00078648 _____ (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2014-02-25 08:47 - 2012-07-13 17:00 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-25 08:46 - 2014-02-25 08:46 - 00000000 ____D () C:\Users\Giacomo\Desktop\Jack
2014-02-25 08:45 - 2012-07-13 17:00 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-02-25 08:45 - 2012-07-13 17:00 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
2014-02-23 08:12 - 2014-03-16 00:58 - 17847808 _____ () C:\Windows\System32\mshtml.dll
2014-02-23 07:54 - 2014-03-16 00:58 - 02334720 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-02-23 07:52 - 2014-03-16 00:58 - 10926592 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-02-23 07:48 - 2014-03-16 00:58 - 01392128 _____ () C:\Windows\System32\wininet.dll
2014-02-23 07:48 - 2014-03-16 00:58 - 01347072 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-02-23 07:46 - 2014-03-16 00:58 - 01494528 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-02-23 07:46 - 2014-03-16 00:58 - 00237056 _____ () C:\Windows\System32\url.dll
2014-02-23 07:46 - 2014-03-16 00:58 - 00086016 _____ () C:\Windows\System32\jsproxy.dll
2014-02-23 07:45 - 2014-03-16 00:58 - 00816640 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2014-02-23 07:45 - 2014-03-16 00:58 - 00599040 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2014-02-23 07:45 - 2014-03-16 00:58 - 00173056 _____ () C:\Windows\System32\ieUnatt.exe
2014-02-23 07:44 - 2014-03-16 00:58 - 02382848 _____ () C:\Windows\System32\mshtml.tlb
2014-02-23 07:44 - 2014-03-16 00:58 - 02147840 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-02-23 07:44 - 2014-03-16 00:58 - 00729088 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-02-23 07:44 - 2014-03-16 00:58 - 00096768 _____ () C:\Windows\System32\mshtmled.dll
2014-02-23 07:43 - 2014-03-16 00:58 - 00248320 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-02-23 06:50 - 2014-03-16 00:58 - 12347904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-23 06:47 - 2014-03-16 00:58 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-23 06:43 - 2014-03-16 00:58 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-23 06:41 - 2014-03-16 00:58 - 01105408 _____ () C:\Windows\SysWOW64\urlmon.dll
2014-02-23 06:40 - 2014-03-16 00:58 - 01129472 _____ () C:\Windows\SysWOW64\wininet.dll
2014-02-23 06:39 - 2014-03-16 00:58 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-23 06:38 - 2014-03-16 00:58 - 00231936 _____ () C:\Windows\SysWOW64\url.dll
2014-02-23 06:38 - 2014-03-16 00:58 - 00142848 _____ () C:\Windows\SysWOW64\ieUnatt.exe
2014-02-23 06:38 - 2014-03-16 00:58 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-23 06:37 - 2014-03-16 00:58 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-23 06:37 - 2014-03-16 00:58 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-02-23 06:37 - 2014-03-16 00:58 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-23 06:37 - 2014-03-16 00:58 - 00421376 _____ () C:\Windows\SysWOW64\vbscript.dll
2014-02-23 06:36 - 2014-03-16 00:58 - 02382848 _____ () C:\Windows\SysWOW64\mshtml.tlb
2014-02-23 06:36 - 2014-03-16 00:58 - 00073216 _____ () C:\Windows\SysWOW64\mshtmled.dll
2014-02-23 06:35 - 2014-03-16 00:58 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-21 17:24 - 2014-02-10 18:18 - 00004148 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-21 17:24 - 2014-02-10 18:18 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-21 10:07 - 2014-02-11 09:23 - 00000000 ____D () C:\Users\Giacomo\Desktop\CV
2014-02-19 18:41 - 2014-02-19 18:41 - 05166532 _____ () C:\Users\Giacomo\Downloads\Claudio.zip

Some content of TEMP:
====================
C:\Users\Giacomo\AppData\Local\Temp\BackupSetup.exe
C:\Users\Giacomo\AppData\Local\Temp\bitool.dll
C:\Users\Giacomo\AppData\Local\Temp\dlLogic.exe
C:\Users\Giacomo\AppData\Local\Temp\Install_BubbleDock.exe
C:\Users\Giacomo\AppData\Local\Temp\Install_BubbleDock_new.exe
C:\Users\Giacomo\AppData\Local\Temp\LiveSupport_setup.exe
C:\Users\Giacomo\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Giacomo\AppData\Local\Temp\ShoppinHelper2.exe
C:\Users\Giacomo\AppData\Local\Temp\smt_awesomehp_new.exe
C:\Users\Giacomo\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Giacomo\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Giacomo\AppData\Local\Temp\{4DA6F867-78B2-4017-82D0-DB0E2BCECE63}-33.0.1750.154_33.0.1750.146_chrome_updater.exe


==================== Known DLLs (Whitelisted) ================

[2014-03-16 00:58] - [2014-02-23 06:41] - 1105408 ____A () C:\Windows\SysWOW64\URLMON.dll
[2014-03-16 00:58] - [2014-02-23 07:48] - 1392128 ____A () C:\Windows\System32\WININET.dll
[2014-03-16 00:58] - [2014-02-23 06:40] - 1129472 ____A () C:\Windows\SysWOW64\WININET.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2014-02-11 14:44] - [2011-02-25 07:19] - 2760192 ____A (Microsoft Corporation) 79FE952905C8B5E49333C2DEC807C4A3

C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================


==================== BCD ================================

Windows Boot Manager
--------------------
identificatore {bootmgr}
device partition=Y:
path \bootmgr
description Windows Boot Manager
locale it-IT
inherit {globalsettings}
default {default}
resumeobject {141bbe51-3be4-11e1-849a-9a431b405934}
displayorder {default}
toolsdisplayorder {memdiag}
timeout 30

Caricatore di avvio di Windows
-------------------
identificatore {default}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale it-IT
inherit {bootloadersettings}
recoverysequence {current}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {141bbe51-3be4-11e1-849a-9a431b405934}
nx OptIn

Caricatore di avvio di Windows
-------------------
identificatore {current}
device ramdisk=[C:]\Recovery\141bbe53-3be4-11e1-849a-9a431b405934\Winre.wim,{141bbe54-3be4-11e1-849a-9a431b405934}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {bootloadersettings}
osdevice ramdisk=[C:]\Recovery\141bbe53-3be4-11e1-849a-9a431b405934\Winre.wim,{141bbe54-3be4-11e1-849a-9a431b405934}
systemroot \windows
nx OptIn
winpe Yes

Ripresa da modalit… di ibernazione
---------------------
identificatore {141bbe51-3be4-11e1-849a-9a431b405934}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale it-IT
inherit {resumeloadersettings}
filedevice partition=C:
filepath \hiberfil.sys
debugoptionenabled No

Tester memoria di Windows
---------------------
identificatore {memdiag}
device partition=Y:
path \boot\memtest.exe
description Diagnostica memoria Windows
locale it-IT
inherit {globalsettings}
badmemoryaccess Yes

Impostazioni Servizi di gestione emergenze
------------
identificatore {emssettings}
bootems Yes

Impostazioni debugger
-----------------
identificatore {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200

Problemi RAM
-----------
identificatore {badmemory}

Impostazioni globali
---------------
identificatore {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}

Impostazioni caricatore di avvio
-------------------
identificatore {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}

Impostazioni hypervisor
-------------------
identificatore {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

Impostazioni Resume Loader
----------------------
identificatore {resumeloadersettings}
inherit {globalsettings}

Opzioni dispositivo
--------------
identificatore {141bbe54-3be4-11e1-849a-9a431b405934}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\141bbe53-3be4-11e1-849a-9a431b405934\boot.sdi


==================== Memory info ===========================

Percentage of memory in use: 9%
Total physical RAM: 8086.04 MB
Available physical RAM: 7287.75 MB
Total Pagefile: 8084.24 MB
Available Pagefile: 7281.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: (Win 7) (Fixed) (Total:59.53 GB) (Free:1.71 GB) NTFS
Drive d: (1000gb) (Fixed) (Total:931.51 GB) (Free:902.05 GB) NTFS
Drive g: (USB DISK) (Removable) (Total:3.73 GB) (Free:3.72 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (Riservato per il sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 60 GB) (Disk ID: 681143A5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=60 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3CE90C74)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)

Partition: GPT Partition Type.


LastRegBack: 2014-03-11 09:53

==================== End Of Log ============================


Thanks
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Good day, sir.

This is not automated service that fixes your problem automatically. We need to start some kind of communication. What is your problem?
 
  • Like
Reactions: Ink

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top