Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Peppe (administrator) on ADMINISTRATOR (01-04-2018 19:36:23)
Running from C:\Users\Peppe\Desktop
Loaded Profiles: Peppe (Available Profiles: Peppe & Administrator)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Italiano (Italia)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe
() C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Program Files\Mouse\Amoumain.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(SoundSwitch) C:\Program Files\SoundSwitch\SoundSwitch.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(ShareX Team) C:\Program Files\ShareX\ShareX.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.04.01\AsusFanControlService.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Grass Valley K.K.) C:\Program Files\Grass Valley\EDIUS 7\GV DownloadAgent\GVDownloadAgent.exe
() C:\Users\Peppe\Documents\LCDSirReal\LCDSirReal.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(M-Audio) C:\Program Files (x86)\M-Audio\M-Track 2X2M\AudioDevMon.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
() C:\Windows\System32\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome334.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [Cm108Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-22] (Adobe Systems Incorporated)
HKLM\...\Run: [WheelMouse] => C:\Program Files\Mouse\Amoumain.exe [196608 2000-01-01] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [245608 2018-04-01] (AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\Run: [SoundSwitch] => C:\Program Files\SoundSwitch\SoundSwitch.exe [1008832 2018-03-10] (SoundSwitch)
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [17074688 2018-03-06] (Piriform Ltd)
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: F - F:\setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: H - H:\Setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {0ab1aa23-1432-11e5-ac98-10c37b50a90d} - E:\Setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {0c848b72-d75e-11e7-98ea-00ac31a303cd} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {3ae279b5-f628-11e4-9c0a-10c37b50a90d} - E:\Setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {58ce6838-f2d4-11e7-8e9d-00ac31a303cd} - H:\setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {9c599feb-1b35-11e5-90f3-10c37b50a90d} - G:\stp-fifa18.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {beab5097-c1bc-11e7-8195-00ac31a303cd} - F:\setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {e1a26777-41b7-11e5-aca0-10c37b50a90d} - H:\Setup.exe
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\...\MountPoints2: {f8d5210f-cc95-11e7-aed9-00ac31a303cd} - G:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\Users\Peppe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2018-03-31]
ShortcutTarget: ShareX.lnk -> C:\Program Files\ShareX\ShareX.exe (ShareX Team)
GroupPolicy: Restriction - Chrome <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{5A7E9B46-9D4A-470E-868B-FAACC9D530F8}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{5CC126F7-0DC5-4908-B1C9-B26DD7136AFF}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{AFACDD1F-24EC-44B4-BA1D-2105A6B6490B}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{AFACDD1F-24EC-44B4-BA1D-2105A6B6490B}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{EEF4A8DF-F5DE-4E0F-BA02-D84A6A21B012}: [DhcpNameServer] 172.20.10.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.google.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.google.com/?bcutc=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://
www.google.com/search?bcutc=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
www.google.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://
www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://
www.google.com/search?bcutc=sp-006&q={searchTerms}
HKU\S-1-5-21-2921988991-613299845-3104574246-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.google.com/?bcutc=sp-006
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://
www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://
www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2921988991-613299845-3104574246-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://
www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2921988991-613299845-3104574246-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://
www.google.com/search?bcutc=sp-006&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-13] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-04-01] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-13] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-09-17] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Arc\Plugins\ArcPluginIE.dll [2017-12-14] (Perfect World Entertainment Inc)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-04-01] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-17] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: s1qci7f5.default
FF ProfilePath: C:\Users\Peppe\AppData\Roaming\Mozilla\Firefox\Profiles\s1qci7f5.default [2018-04-01]
FF user.js: detected! => C:\Users\Peppe\AppData\Roaming\Mozilla\Firefox\Profiles\s1qci7f5.default\user.js [2017-06-30]
FF Homepage: Mozilla\Firefox\Profiles\s1qci7f5.default -> hxxps://mail.ru/cnt/11956636?fr=ffhp1.0.3&gp=800000
FF NewTab: Mozilla\Firefox\Profiles\s1qci7f5.default -> about:newtab
FF Extension: (System Table) - C:\Users\Peppe\AppData\Roaming\Mozilla\Firefox\Profiles\s1qci7f5.default\Extensions\
622127@modext.tech.xpi [2018-02-27]
FF Extension: (Avast SafePrice) - C:\Users\Peppe\AppData\Roaming\Mozilla\Firefox\Profiles\s1qci7f5.default\Extensions\
sp@avast.com.xpi [2017-08-15]
FF Extension: (Avast Online Security) - C:\Users\Peppe\AppData\Roaming\Mozilla\Firefox\Profiles\s1qci7f5.default\Extensions\
wrc@avast.com.xpi [2018-02-07]
FF SearchPlugin: C:\Users\Peppe\AppData\Roaming\Mozilla\Firefox\Profiles\s1qci7f5.default\searchplugins\google-avast.xml [2016-09-17]
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-13] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-13] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-23] (Adobe Systems)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32:
@Intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32:
@Intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-17] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll [2014-12-22] (Nexon)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\Plugins\npArcPluginFF.dll [2017-12-14] (Perfect World Entertainment Inc)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2012-12-13] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-23] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2921988991-613299845-3104574246-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Peppe\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)
Chrome:
=======
CHR res: Infected resources.pak (Adware script). Reinstall Chrome. <==== ATTENTION
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://
www.google.com/
CHR StartupUrls: Default -> "hxxp://
www.google.com/"
CHR NewTab: Default -> Active:"chrome-extension://ibfhiehdjpogpbdcicjnphklppinghjj/index.html"
CHR Profile: C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default [2018-04-01]
CHR Extension: (Presentazioni) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2000-01-01]
CHR Extension: (Google Drive) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (uBlock Origin) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-03-22]
CHR Extension: (Google Search) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Fogli) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2000-01-01]
CHR Extension: (Google Documenti offline) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-03-13]
CHR Extension: (Speed Dial 3™(APP)) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfhiehdjpogpbdcicjnphklppinghjj [2015-06-11]
CHR Extension: (Pagamenti Chrome Web Store) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Speechnotes - Dettatura Notepad) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\opekipbefdbacebgkjjdgoiofdbhocok [2018-01-13]
CHR Extension: (Gmail) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-11]
CHR Extension: (Chrome Media Router) - C:\Users\Peppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-14]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
OPR Extension: (Teddy Protection Lite) - C:\Users\Peppe\AppData\Roaming\Opera Software\Opera Stable\Extensions\nojkagbjbhgnilkopgljfkhddmdjcjfn [2017-03-03]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2015-07-09] (Adobe Systems) [File not signed]
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112 2015-07-22] (Adobe Systems Incorporated)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [87064 2017-12-14] (Perfect World Entertainment Inc)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-07] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2013-08-01] (ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.04.01\AsusFanControlService.exe [1656464 2013-08-13] (ASUSTeK Computer Inc.) [File not signed]
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7556704 2018-04-01] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [303728 2018-04-01] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1530888 2017-07-15] ()
S3 Blackberry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) [File not signed]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291904 2017-08-14] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-03-18] (EasyAntiCheat Ltd)
R2 GVDownloadAgentService; C:\Program Files\Grass Valley\EDIUS 7\GV DownloadAgent\GVDownloadAgent.exe [68832 2015-03-30] (Grass Valley K.K.)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-20] (Hi-Rez Studios) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344184 2017-01-24] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2000-01-01] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
R2 MTrack2X2MAudioDevMon; C:\Program Files (x86)\M-Audio\M-Track 2X2M\AudioDevMon.exe [595032 2016-12-13] (M-Audio)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-12-02] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3685968 2015-07-22] (INCA Internet Co., Ltd.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123240 2017-03-25] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2184688 2017-03-25] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1326408 2017-05-14] (Overwolf LTD)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-07-31] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-07-31] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11294448 2018-03-09] (TeamViewer GmbH)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [838128 2016-12-15] (Tunngle.net GmbH) [File not signed]
S3 vncserver; C:\Program Files\RealVNC\VNC Server\vncserver.exe [5848656 2017-05-19] (RealVNC Ltd)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 wsaudio; C:\Windows\SysWOW64\wsaudio.dll [1072128 2015-07-22] () [File not signed]
S2 ihctrl32; %SystemRoot%\System32\ihctrl32.dll [X]
S2 Mobizen plugin; C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2012-09-14] ()
S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [196648 2018-04-01] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [227504 2018-04-01] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199440 2018-04-01] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343752 2018-04-01] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57680 2018-04-01] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [215320 2018-04-01] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-04-01] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146656 2018-04-01] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-04-01] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-04-01] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-04-01] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [460520 2018-04-01] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [205976 2018-04-01] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [380528 2018-04-01] (AVAST Software)
R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [34360 2008-05-30] (Canopus Co,. Ltd.)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-11-05] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-11-05] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
R4 IOMap; C:\Windows\system32\drivers\IOMap64.sys [23680 2013-01-25] (ASUSTeK Computer Inc.)
S3 maxjoypad; C:\Windows\System32\DRIVERS\maxjoypad.sys [18880 2016-08-05] (Windows (R) Win 7 DDK provider)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-04-01] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2000-01-01] (Intel Corporation)
S3 MTRACK2X2M; C:\Windows\System32\DRIVERS\MAudioMTrack2X2M.sys [569432 2016-12-13] (M-Audio)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0116.sys [38432 2017-07-24] (SoftEther Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [78336 2013-01-03] (Research In Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [39464 2016-04-26] (Tunngle.net GmbH)
S1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-10-02] (Oracle Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [125520 2015-10-02] (Oracle Corporation)
R1 VBoxUSBMon; C:\Windows\System32\DRIVERS\VBoxUSBMon.sys [144656 2017-08-22] (BigNox Corporation)
R3 XSplit_Dummy; C:\Windows\System32\drivers\xspltspk.sys [26200 2014-07-02] (SplitmediaLabs Limited)
R2 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\drivers\YSDrv\YSDrv.sys [270608 2018-01-24] (BigNox Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
S3 X6va020; \??\C:\Windows\SysWOW64\Drivers\X6va020 [X]
S3 X6va021; \??\C:\Windows\SysWOW64\Drivers\X6va021 [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
S3 X6va031; \??\C:\Windows\SysWOW64\Drivers\X6va031 [X]
S3 X6va063; \??\C:\Windows\SysWOW64\Drivers\X6va063 [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
========================== Drivers MD5 =======================
C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys FA886682CFC5D36718D3E436AACF10B9
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\atikmdag.sys AF0AA655323BB0E6288F47C56DBA9FD4
C:\Windows\System32\DRIVERS\atikmpag.sys DE729FB8DD5ED960430E5AC751215FAE
C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys A0711D119BA4B48A1470C768D301013E
C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit
C:\Windows\SysWow64\drivers\AsIO.sys 798DE15F187C1F013095BBBEB6FB6197
C:\Windows\SysWow64\drivers\AsUpIO.sys 1392B92179B07B672720763D9B1028A5
C:\Windows\SysWow64\drivers\ASUSFILTER.sys A5E4CDB420540095D1293C874B5F89AA
C:\Windows\System32\drivers\aswArPot.sys DCD966874B4C8C952662D2D16DDB4D7C
C:\Windows\System32\drivers\aswbidsdrivera.sys A2F689B3E2BEAF05DD6DBE6ED862F781
C:\Windows\System32\drivers\aswbidsha.sys 9CAF76B70650DBF39AD85E6CE885F5B7
C:\Windows\System32\drivers\aswbloga.sys A846D0306A72F8AF5515009D811F344B
C:\Windows\System32\drivers\aswbuniva.sys 6A4C9AEBDBB30D9DF0A6F03BC3B4007B
C:\Windows\System32\drivers\aswHdsKe.sys 385F63137F179F0ED040E3D7899AF149
C:\Windows\System32\drivers\aswHwid.sys 92F25DFDF0C1051B311A7BD980A0E9AE
C:\Windows\System32\drivers\aswMonFlt.sys 6B24EFD741C02480A7AFDD68A334EA4F
C:\Windows\System32\drivers\aswRdr2.sys B9C7752B3D482D8CAEE9848F414164A9
C:\Windows\System32\drivers\aswRvrt.sys 841177ED7A3F4A899E50736FBA7E9AB2
C:\Windows\System32\drivers\aswSnx.sys CC12B6E35CCC5282DEFE3E74A9C7D33D
C:\Windows\System32\drivers\aswSP.sys CD8387672DA9F706481EF9D3F7C32BB2
C:\Windows\System32\drivers\aswStm.sys 95B840B4BEDA5DBCC60D7A5FEF0DAE54
C:\Windows\System32\drivers\aswVmm.sys CA1FC21F1A2D55AE0BB5F6E8FBEA8ECF
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\drivers\AtihdW76.sys 22710CB9781EF2370610400E689D74B4
C:\Windows\system32\DRIVERS\bxvbda.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrblock.sys 5A6632F51F643E2EB47F647D82CB242D
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys 404B7DF9CA4D1CB675045AF220FF3285
C:\Windows\system32\DRIVERS\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys 27667A788130A7F7A5858DE27572E6D7
C:\Windows\system32\DRIVERS\compbatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit
C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\dtlitescsibus.sys 679FF716052109392D870F6A6C4A3535
C:\Windows\System32\DRIVERS\dtliteusbbus.sys E23FDD696839A4790682CA66C48D3F2F
C:\Windows\System32\drivers\dxgkrnl.sys 87CE5C8965E101CCCED1F4675557E868
C:\Windows\system32\DRIVERS\evbda.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\GEARAspiWDM.sys 8E98D21EE06192492A5671A6144D092F
C:\Windows\System32\DRIVERS\hamachi.sys 1E6438D4EA6E1174A3B3B1EDC4DE660B
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys F61634BEC53F73702A10DE69F6DCAF57
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\iaStorA.sys 25555186E4FBDF0E30A5DBFC9B9A73F9
C:\Windows\System32\DRIVERS\iaStorF.sys 10E79E366FA255318F5D1D0ED07F947D
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\System32\DRIVERS\igdkmd64.sys DB612DDA2E9643F8C759E68DAE07F2D4
C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit
C:\Windows\System32\drivers\RTKVHD64.sys 734E92848983F17822B4F71C5F912C6C
C:\Windows\System32\DRIVERS\IntcDAud.sys 9D01DDF5EA8494BBCBB73FF385E35D35
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\IOMap64.sys A01C412699B6F21645B2885C2BAE4454
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6
C:\Windows\System32\DRIVERS\iusb3hcs.sys A1EA5DFDE6C4C3A55C54B50B68BA1EF5
C:\Windows\System32\DRIVERS\iusb3hub.sys 61DB13A14A7F384D21DEADAEE3763BBC
C:\Windows\System32\DRIVERS\iusb3xhc.sys F3A9A90A8B6C5B9DF60D0EA957976E66
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys A405647429DE231CD954D93F792CFBA2
C:\Windows\System32\Drivers\ksecpkg.sys E4DC0909B5EACB5BF50F6252095BCFF2
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\drivers\LGBusEnum.sys FA529FB35694C24BF98A9EF67C1CD9D0
C:\Windows\System32\drivers\LGVirHid.sys 94B29CE153765E768F004FB3440BE2B0
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\maxjoypad.sys 8D57626FC4E8E6F7A3B5E9C8CF5F4099
C:\Windows\System32\Drivers\mbamswissarmy.sys 351BF8F77B0A15A7B5A2AE098C52A387
C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\TeeDriverx64.sys EB1D78140D6634C32A46AB1006105EDC
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys 67050452C0118BAF2883928E6FCCFE47
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys AE3334958D8F631FF14A0AEB3D7EFB3A
C:\Windows\System32\DRIVERS\mrxsmb.sys 43E1F4B0EFDC244D2A83995CCD7846F7
C:\Windows\System32\DRIVERS\mrxsmb10.sys 62CEA59FF56B66154E08BD51D87392C2
C:\Windows\System32\DRIVERS\mrxsmb20.sys 7D65B5E9573A26C204AA547457DBF544
C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\MAudioMTrack2X2M.sys 4ED04901579644D270C3CE58ACC3B5CA
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisrd.sys 2E7C9CC1DF7F878358C7292D036AFE63
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Neo_0116.sys 3351A92971670764F014A566D1106E2B
C:\Windows\System32\DRIVERS\netaapl64.sys EE00C544C025958AF50C7B199F3C8595
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys 1A29A59A4C5BA6F8C85062A613B7E2B2
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ED6E75158D28D33A2E2A020AC5B2B59D
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 065F79543D7999EC28B687F87E96B803
C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\Drivers\RimUsb_AMD64.sys 6D850FAD4CC9498D1F382B77BA4035CC
C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys 344604E6913BD6E4EAEC34AF2E0943D7
C:\Windows\System32\Drivers\RootMdm.sys 388D3DD1A6457280F3BADBA9F3ACD6B1
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\Rt64win7.sys 61A04C0C084D560BBEF1D09604608262
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\SysWOW64\speedfan.sys 0FFE35F0B0CD5A324BBE22F02569AE3B
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tap0901t.sys C2535200B274DEC508881F587B7B5F16
C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E
C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys 70988118145F5F10EF24720B97F35F65
C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tssecsrv.sys E232A3B43A894BB327FC161529BD9ED1
C:\Windows\System32\drivers\tsusbflt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit
C:\Windows\System32\Drivers\usbaapl64.sys F957092C63CD71D85903CA0D8370F473
C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2
C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965
C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA
C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC
C:\Windows\System32\drivers\CM10864.sys A3FD7E087957D765DF5575EF10AE0E96
C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit
C:\Windows\system32\drivers\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24
C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6
C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3
C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7
C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys E1915B4B40F5F36E2FC9E8EBD2696B14
C:\Windows\System32\Drivers\VBoxUSB.sys 62ACAECC82F16F604960BB627860F715
C:\Windows\System32\DRIVERS\VBoxUSBMon.sys FB10E94F07D3F3892779129FDAA8FBAD
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\System32\drivers\vmbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vncmirror.sys 93F279A2C172562050700A18FA84BE2E
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys DF8126BD41180351A093A3AD2FC8903B
C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659
C:\Windows\System32\DRIVERS\xnacc.sys 4A5CE13408945E525503B5F73D29B9C5
C:\Windows\System32\drivers\xspltspk.sys 377F3E3467A8BFA3CDC921AD6425D513
C:\Windows\System32\DRIVERS\xusb21.sys 2EE48CFCE7CA8E0DB4C44C7476C0943B
C:\Program Files (x86)\Bignox\BigNoxVM\RT\drivers\YSDrv\YSDrv.sys 27578F40FD3C5EFD43563A266476F466
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three Months Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-01 19:36 - 2018-04-01 19:37 - 000049354 _____ C:\Users\Peppe\Desktop\FRST.txt
2018-04-01 19:28 - 2018-04-01 19:28 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-04-01 19:27 - 2018-04-01 00:41 - 000137728 _____ C:\Users\Peppe\AppData\Local\Cadavers.exe
2018-04-01 19:16 - 2018-04-01 19:19 - 000007660 _____ C:\Users\Peppe\Desktop\Fixlog.txt
2018-04-01 19:13 - 2018-04-01 19:13 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\AMD
2018-04-01 19:10 - 2018-04-01 19:16 - 000000000 ____D C:\Users\Peppe\AppData\Local\AMD
2018-04-01 19:03 - 2018-04-01 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\##ID_STRING16##
2018-04-01 19:03 - 2018-04-01 19:03 - 000003146 _____ C:\Windows\System32\Tasks\StartCN
2018-04-01 19:03 - 2018-04-01 19:03 - 000003060 _____ C:\Windows\System32\Tasks\StartDVR
2018-04-01 19:03 - 2018-04-01 19:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2018-04-01 19:03 - 2018-04-01 19:03 - 000000000 ____D C:\Program Files (x86)\AMD
2018-04-01 19:01 - 2018-04-01 19:01 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
2018-04-01 19:00 - 2018-04-01 19:00 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-04-01 19:00 - 2017-11-02 22:15 - 000928568 _____ C:\Windows\system32\vulkan-1.dll
2018-04-01 19:00 - 2017-11-02 22:15 - 000798520 _____ C:\Windows\SysWOW64\vulkan-1.dll
2018-04-01 19:00 - 2017-11-02 22:15 - 000490808 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2018-04-01 19:00 - 2017-11-02 22:14 - 000591672 _____ C:\Windows\system32\vulkaninfo.exe
2018-04-01 18:59 - 2018-04-01 18:59 - 000000000 ____D C:\Users\Peppe\AppData\Local\RadeonInstaller
2018-04-01 18:58 - 2018-04-01 19:03 - 000000000 ____D C:\Program Files\AMD
2018-04-01 18:51 - 2018-04-01 18:52 - 000000000 ____D C:\Users\Peppe\Desktop\settings
2018-04-01 18:51 - 2018-04-01 18:52 - 000000000 ____D C:\Users\Peppe\Desktop\DDU Logs
2018-04-01 18:51 - 2018-04-01 18:51 - 000000000 ____D C:\Users\Peppe\Desktop\x64
2018-04-01 18:51 - 2018-02-27 20:36 - 000615936 _____ C:\Users\Peppe\Desktop\Display Driver Uninstaller.pdb
2018-04-01 18:51 - 2018-01-30 16:23 - 000000893 _____ C:\Users\Peppe\Desktop\Readme.txt
2018-04-01 18:51 - 2017-06-18 14:43 - 000000937 _____ C:\Users\Peppe\Desktop\Issues and solutions.txt
2018-04-01 18:51 - 2015-09-06 13:26 - 000000224 _____ C:\Users\Peppe\Desktop\Display Driver Uninstaller.exe.config
2018-04-01 18:49 - 2018-04-01 18:52 - 000309986 _____ C:\Windows\ntbtlog.txt
2018-04-01 18:46 - 2018-04-01 18:46 - 051965752 _____ (AMD Inc.) C:\Users\Peppe\Downloads\radeon-crimson-relive-17.7.2-minimalsetup-170727_web.exe
2018-04-01 18:36 - 2018-04-01 18:36 - 004179293 _____ (Lavalys, Inc. ) C:\Users\Peppe\Downloads\everesthome220.exe
2018-04-01 18:36 - 2018-04-01 18:36 - 000001102 _____ C:\Users\Administrator\Desktop\EVEREST Home Edition.lnk
2018-04-01 18:36 - 2018-04-01 18:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
2018-04-01 18:36 - 2018-04-01 18:36 - 000000000 ____D C:\Program Files (x86)\Lavalys
2018-04-01 18:34 - 2018-04-01 18:34 - 001100518 _____ C:\Users\Peppe\Downloads\[Guru3D.com]-DDU (1).zip
2018-04-01 17:23 - 2018-04-01 17:23 - 000069011 _____ C:\Users\Peppe\Downloads\Addition.txt
2018-04-01 17:22 - 2018-04-01 19:36 - 000000000 ____D C:\FRST
2018-04-01 17:22 - 2018-04-01 17:23 - 000055091 _____ C:\Users\Peppe\Downloads\FRST.txt
2018-04-01 17:22 - 2018-04-01 17:22 - 002403328 _____ (Farbar) C:\Users\Peppe\Desktop\FRST64.exe
2018-04-01 17:06 - 2018-04-01 17:06 - 008222496 _____ (Malwarebytes) C:\Users\Peppe\Downloads\adwcleaner_7.0.8.0.exe
2018-04-01 16:57 - 2018-04-01 16:59 - 000000000 ____D C:\Program Files (x86)\Startup Optimizer
2018-04-01 16:57 - 2018-04-01 16:57 - 001147120 _____ (Cyberlion Solutions Inc. ) C:\Users\Peppe\Downloads\StartOpt.exe
2018-04-01 16:57 - 2018-04-01 16:57 - 000000988 _____ C:\Users\Peppe\Desktop\Startup Optimizer.lnk
2018-04-01 16:57 - 2018-04-01 16:57 - 000000988 _____ C:\Users\Administrator\Desktop\Startup Optimizer.lnk
2018-04-01 16:57 - 2018-04-01 16:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Optimizer
2018-04-01 16:48 - 2018-04-01 16:48 - 000000000 ____D C:\Users\Peppe\AppData\Local\CrashReportClient
2018-04-01 05:59 - 2018-04-01 12:19 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-04-01 05:57 - 2018-04-01 14:35 - 000000000 ____D C:\ProgramData\RogueKiller
2018-04-01 05:56 - 2018-04-01 05:56 - 000000858 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-04-01 05:56 - 2018-04-01 05:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-04-01 05:56 - 2018-04-01 05:56 - 000000000 ____D C:\Program Files\RogueKiller
2018-04-01 05:52 - 2018-04-01 05:56 - 036513656 _____ (Adlice Software ) C:\Users\Peppe\Downloads\RogueKiller_setup (1).exe
2018-04-01 05:50 - 2018-04-01 12:26 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\36659E07.sys
2018-04-01 05:49 - 2018-04-01 13:48 - 000000000 ____D C:\Users\Peppe\Desktop\mbar
2018-04-01 05:49 - 2018-04-01 13:48 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-04-01 05:49 - 2018-04-01 12:26 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2018-04-01 05:49 - 2018-04-01 05:49 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Peppe\Downloads\mbar-1.10.3.1001.exe
2018-04-01 05:48 - 2018-04-01 05:48 - 008222496 _____ (Malwarebytes) C:\Users\Peppe\Downloads\AdwCleaner.exe
2018-04-01 05:36 - 2018-04-01 05:51 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-04-01 05:36 - 2018-04-01 05:36 - 000448512 _____ (OldTimer Tools) C:\Users\Peppe\Downloads\TFC.exe
2018-04-01 05:36 - 2018-04-01 05:36 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-04-01 05:36 - 2018-04-01 05:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-04-01 05:36 - 2018-04-01 05:36 - 000000000 ____D C:\Program Files\Malwarebytes
2018-04-01 05:36 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-04-01 05:35 - 2018-04-01 05:35 - 071942408 _____ (Malwarebytes ) C:\Users\Peppe\Downloads\mb3-setup-35891.35891-3.4.5.2467-1.0.342-1.0.4514.exe
2018-04-01 05:25 - 2018-04-01 05:25 - 000380768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-04-01 04:57 - 2018-04-01 04:57 - 000000000 ____D C:\ProgramData\SWCUTemp
2018-04-01 03:13 - 2018-04-01 03:13 - 000000909 ____R C:\Windows\system32\Drivers\etc\hosts.20180401-031326.backup
2018-04-01 02:27 - 2018-04-01 02:45 - 000000000 ____D C:\ProgramData\e1604ea055
2018-04-01 02:27 - 2018-04-01 02:43 - 000000000 ____D C:\Program Files (x86)\hennigan
2018-04-01 02:27 - 2018-04-01 02:27 - 000000012 _____ C:\Windows\b81125234
2018-04-01 02:27 - 2018-04-01 02:27 - 000000000 ___HD C:\Program Files (x86)\testimonial
2018-04-01 02:26 - 2018-04-01 02:26 - 000194048 _____ C:\Users\Peppe\AppData\Local\install.dll
2018-04-01 02:26 - 2018-04-01 02:26 - 000003072 _____ C:\Users\Peppe\AppData\Local\install_UEFIConfig.exe
2018-04-01 02:00 - 2018-04-01 02:00 - 058809515 _____ C:\Users\Peppe\Downloads\Microsoft Toolkit 2.6.3 Official Torrent.zip
2018-04-01 01:46 - 2018-04-01 01:46 - 000000134 _____ C:\Windows\wininit.ini
2018-04-01 01:44 - 2018-04-01 01:45 - 001797188 _____ C:\Users\Peppe\Downloads\Removewat 2.2.7 pass 123456 (1).rar
2018-04-01 01:10 - 2018-04-01 01:10 - 000000000 __SHD C:\82ace7d6-0197-474d-bf4b-a2043e72329b
2018-04-01 00:41 - 2018-04-01 00:41 - 000137728 _____ C:\Windows\inventors.exe
2018-03-31 23:23 - 2018-03-31 23:23 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-03-31 23:20 - 2018-03-31 23:20 - 015333512 _____ (Piriform Ltd) C:\Users\Peppe\Downloads\ccsetup541 (1).exe
2018-03-31 22:47 - 2018-03-31 22:52 - 001204720 _____ (Adobe Systems Incorporated) C:\Users\Peppe\Downloads\flashplayer29ppau_ha_install.exe
2018-03-31 22:43 - 2018-03-31 22:43 - 000017916 _____ C:\Windows\system32\results.xml
2018-03-31 17:59 - 2018-03-31 17:59 - 037780649 _____ C:\Users\Peppe\Downloads\phoenix-reveal-by-LMD.rar
2018-03-31 17:59 - 2018-03-31 17:59 - 037780649 _____ C:\Users\Peppe\Downloads\phoenix-reveal-by-LMD (1).rar
2018-03-30 16:05 - 2018-03-31 18:00 - 000000000 ____D C:\Users\Peppe\Desktop\VOD
2018-03-27 03:30 - 2018-03-27 03:30 - 006648319 ____R C:\Users\Peppe\Downloads\Stephen Covey - Le sette abitudini per avere successo.pdf
2018-03-27 03:27 - 2018-03-27 03:28 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\uTorrent
2018-03-27 03:27 - 2018-03-27 03:27 - 000001010 _____ C:\Users\Peppe\Downloads\Stephen R Covey - Le sette regole per avere successo.torrent
2018-03-23 12:28 - 2018-03-23 12:28 - 010269280 _____ C:\Users\Peppe\Desktop\3-Proteine_noanim.pdf
2018-03-18 16:07 - 2018-03-17 21:05 - 000000230 ___SH C:\Users\Public\Libraries.ini
2018-03-18 15:28 - 2018-03-18 15:28 - 032260096 _____ C:\Users\Peppe\Downloads\EpicInstaller-7.5.0-fortnite-c4899f16b6934760a534fe7ec70ae9b2.msi
2018-03-16 20:22 - 2018-03-16 20:22 - 044398486 _____ C:\Users\Peppe\Downloads\V3-Signed_ONE.PIECE.TREASURE.CRUISE_v.8.0.0o.apk
2018-03-16 19:38 - 2018-03-16 19:39 - 085022931 _____ C:\Users\Peppe\Downloads\Monster Legends RPG v6.2.2 FRsigned.apk
2018-03-16 19:32 - 2018-03-16 19:34 - 092931480 _____ C:\Users\Peppe\Downloads\m_l_v.5.0.2_mod_(1).apk
2018-03-15 20:30 - 2018-03-15 20:30 - 000001043 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
2018-03-15 20:30 - 2018-03-15 20:30 - 000001031 _____ C:\Users\Public\Desktop\TeamViewer 13.lnk
2018-03-15 20:29 - 2018-03-15 20:29 - 020361728 _____ (TeamViewer GmbH) C:\Users\Peppe\Downloads\TeamViewer_Setup.exe
2018-03-15 20:23 - 2018-03-15 20:24 - 020545618 _____ C:\Users\Peppe\Downloads\Summoners War v3.8.0 Mod v3 iHackedit.com.apk
2018-03-15 20:12 - 2018-03-15 20:12 - 000353023 _____ C:\Users\Peppe\Downloads\Office365RoadMap_Features_03-15-2018.xlsx
2018-03-13 03:23 - 2018-03-13 03:23 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\Bad Seed SRL
2018-03-07 17:26 - 2018-03-07 17:26 - 000064523 _____ C:\Users\Peppe\Downloads\pratica.ricevuta.pagamento (3).pdf
2018-03-07 17:25 - 2018-03-07 17:25 - 000064523 _____ C:\Users\Peppe\Downloads\pratica.ricevuta.pagamento (2).pdf
2018-03-07 17:24 - 2018-03-07 17:24 - 000066208 _____ C:\Users\Peppe\Downloads\stampa.bollettino.pagamento (1).pdf
2018-03-07 15:55 - 2018-03-07 15:56 - 016093512 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.9 Mod iHackedit.com.apk
2018-03-06 22:04 - 2018-03-06 22:04 - 000154837 _____ C:\Users\Peppe\Downloads\ORDINAMENTO VVF.pptx
2018-03-04 17:06 - 2018-03-04 17:06 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\Blizzard Entertainment
2018-03-04 17:06 - 2018-03-04 17:06 - 000000000 ____D C:\ProgramData\.mono
2018-02-24 02:06 - 2018-02-24 02:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YoloMouse
2018-02-24 02:05 - 2018-02-24 02:06 - 000000000 ____D C:\Program Files\YoloMouse
2018-02-23 12:57 - 2018-02-23 12:56 - 000064521 _____ C:\Users\Peppe\Documents\pratica.ricevuta.pagamento (1).pdf
2018-02-23 12:56 - 2018-02-23 12:56 - 000064521 _____ C:\Users\Peppe\Downloads\pratica.ricevuta.pagamento (1).pdf
2018-02-23 12:54 - 2018-02-23 12:54 - 000064521 _____ C:\Users\Peppe\Downloads\pratica.ricevuta.pagamento.pdf
2018-02-23 12:26 - 2018-02-23 12:26 - 000066197 _____ C:\Users\Peppe\Downloads\stampa.bollettino.pagamento.pdf
2018-02-21 03:52 - 2018-02-21 04:07 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\Battlerite
2018-02-21 03:47 - 2018-02-21 03:47 - 000000222 _____ C:\Users\Peppe\Desktop\Battlerite.url
2018-02-19 15:00 - 2018-02-19 15:00 - 025910000 _____ (AMD Inc.) C:\Users\Peppe\Downloads\radeon-adrenalin-18.2.1-minimalsetup-180206_64bit.exe
2018-02-19 03:34 - 2018-02-19 03:34 - 004182688 _____ (Husdawg, LLC) C:\Users\Peppe\Downloads\Detection.exe
2018-02-15 13:41 - 2018-02-15 13:41 - 001010694 _____ C:\Users\Peppe\Downloads\cnvvf per corsi.pdf
2018-02-15 13:40 - 2018-02-15 13:41 - 024742912 _____ C:\Users\Peppe\Downloads\la protezione civile in Italia.ppt
2018-02-13 18:56 - 2018-02-13 21:47 - 000000000 ____D C:\Users\Peppe\Downloads\Kingdom.Come.Deliverance-CODEX
2018-02-13 18:54 - 2018-02-13 18:54 - 000083269 _____ C:\Users\Peppe\Downloads\Kingdom.Come.Deliverance-CODEX.torrent
2018-02-13 13:40 - 2018-02-13 13:40 - 015604789 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.8 Mod v4 iHackedit.com.apk
2018-02-13 13:29 - 2018-02-13 13:29 - 015604794 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.8 Mod v3 iHackedit.com.apk
2018-02-07 21:08 - 2018-04-01 05:25 - 000196648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-02-07 21:08 - 2018-04-01 05:24 - 000215320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-02-07 21:05 - 2018-02-07 21:05 - 003312000 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Peppe\Downloads\Non confermato 507735.crdownload
2018-02-07 20:17 - 2018-02-07 20:18 - 000000000 ____D C:\Users\Peppe\Downloads\Windows 10 AIO 6in1 x86-x64
2018-02-07 20:16 - 2018-02-07 20:16 - 000969974 _____ C:\Users\Peppe\Downloads\Windows 10 ISO (1).zip
2018-02-07 20:16 - 2018-02-07 20:16 - 000000000 ____D C:\Users\Peppe\Desktop\Windows 10 ISO
2018-02-07 20:11 - 2018-02-21 21:59 - 000000000 ____D C:\Windows\System32\Tasks\Leader Technologies
2018-02-07 20:11 - 2018-02-07 20:11 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\Leadertech
2018-02-05 23:11 - 2018-02-05 23:11 - 002379532 _____ C:\Users\Peppe\Downloads\contratto (1).pdf
2018-02-05 23:11 - 2018-02-05 23:11 - 000528500 _____ C:\Users\Peppe\Downloads\certificato.pdf
2018-02-04 01:47 - 2018-02-04 01:50 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2018-02-04 01:47 - 2018-02-04 01:47 - 000001622 _____ C:\Users\Peppe\Desktop\Ironsight.lnk
2018-02-04 01:47 - 2018-02-04 01:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ironsight
2018-02-04 00:33 - 2018-02-04 00:33 - 000000000 ____D C:\AeriaGames
2018-02-04 00:30 - 2018-02-04 00:30 - 000577056 _____ (gamigo AG) C:\Users\Peppe\Downloads\Ironsight_US_downloader.exe
2018-02-01 15:22 - 2018-02-01 15:22 - 002796344 _____ C:\Users\Peppe\Downloads\brick_wall_painted_yellow_01_specular.dds
2018-02-01 14:58 - 2018-02-01 14:58 - 001422106 _____ C:\Users\Peppe\Downloads\PREVENTIVO_PRP0000030874687.pdf
2018-02-01 02:12 - 2018-02-01 02:12 - 011770544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 009574032 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 000196400 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 000173216 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 000161344 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 000143864 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 000009936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\detoured.dll
2018-02-01 02:12 - 2018-02-01 02:12 - 000009936 _____ (Microsoft Corporation) C:\Windows\system32\detoured.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 016040912 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 015728520 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 014318984 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 013242384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 012359728 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 011825664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 001961272 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 001555488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000700296 _____ (AMD) C:\Windows\system32\atieclxx.exe
2018-02-01 02:11 - 2018-02-01 02:11 - 000536968 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2018-02-01 02:11 - 2018-02-01 02:11 - 000475016 _____ (AMD) C:\Windows\system32\atitmm64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000472456 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2018-02-01 02:11 - 2018-02-01 02:11 - 000470920 _____ C:\Windows\system32\dgtrayicon.exe
2018-02-01 02:11 - 2018-02-01 02:11 - 000458632 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000449416 _____ C:\Windows\system32\GameManager64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000405384 _____ C:\Windows\system32\atieah64.exe
2018-02-01 02:11 - 2018-02-01 02:11 - 000357256 _____ C:\Windows\SysWOW64\GameManager32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000342920 _____ C:\Windows\system32\clinfo.exe
2018-02-01 02:11 - 2018-02-01 02:11 - 000325512 _____ C:\Windows\SysWOW64\atieah32.exe
2018-02-01 02:11 - 2018-02-01 02:11 - 000224136 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000197000 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000175288 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000163720 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000153640 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000144776 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000139656 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000124808 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000124808 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000120680 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000115592 _____ (AMD) C:\Windows\system32\atimuixx.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000111440 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000111440 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000105736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000092328 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000092328 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000078728 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2018-02-01 02:11 - 2018-02-01 02:11 - 000068488 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 065594248 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 041570184 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2018-02-01 02:10 - 2018-02-01 02:10 - 031553416 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 025145224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 016034696 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdvlk64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 015434120 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 012924808 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 002933128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amfrt64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 002541448 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amfrt32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 001462664 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 001237896 _____ (AMD) C:\Windows\system32\coinst_17.50.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 001055624 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 001055624 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000866184 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdlvr64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000694152 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdlvr32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000547208 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Rapidfire64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000461192 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\Rapidfire.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000436616 _____ C:\Windows\system32\amdgfxinfo64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000352136 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000349064 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe
2018-02-01 02:10 - 2018-02-01 02:10 - 000305544 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2018-02-01 02:10 - 2018-02-01 02:10 - 000170888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000149896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000148360 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000141704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000126344 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000124296 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000072072 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000067464 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe
2018-02-01 02:10 - 2018-02-01 02:10 - 000065416 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000060296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000036232 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\RapidFireServer64.dll
2018-02-01 02:10 - 2018-02-01 02:10 - 000033160 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\RapidFireServer.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 051029384 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 029519240 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 013607304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdvlk32.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 000543624 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmcl64.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 000373640 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmcl32.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 000157064 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amduve64.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 000139144 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 000135048 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amduve32.dll
2018-02-01 02:09 - 2018-02-01 02:09 - 000117128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2018-02-01 02:08 - 2018-02-01 02:08 - 035689864 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2018-02-01 01:24 - 2018-02-01 01:24 - 000858720 _____ C:\Windows\SysWOW64\atiapfxx.blb
2018-02-01 01:24 - 2018-02-01 01:24 - 000858720 _____ C:\Windows\system32\atiapfxx.blb
2018-02-01 01:18 - 2018-02-01 01:18 - 003437632 _____ C:\Windows\system32\atiumd6a.cap
2018-02-01 01:17 - 2018-02-01 01:17 - 000204952 _____ C:\Windows\SysWOW64\ativvsvl.dat
2018-02-01 01:17 - 2018-02-01 01:17 - 000204952 _____ C:\Windows\system32\ativvsvl.dat
2018-02-01 01:17 - 2018-02-01 01:17 - 000157144 _____ C:\Windows\SysWOW64\ativvsva.dat
2018-02-01 01:17 - 2018-02-01 01:17 - 000157144 _____ C:\Windows\system32\ativvsva.dat
2018-02-01 01:12 - 2018-02-01 01:12 - 003471376 _____ C:\Windows\SysWOW64\atiumdva.cap
2018-01-31 19:11 - 2018-01-31 19:11 - 000155688 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdihk64.dll
2018-01-31 19:11 - 2018-01-31 19:11 - 000126848 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdihk32.dll
2018-01-30 21:49 - 2018-01-30 21:50 - 015278630 _____ C:\Users\Peppe\Downloads\Fixed-Summoners War v3.7.7 Mod v3 iHackedit.com.apk
2018-01-30 21:49 - 2018-01-30 21:50 - 015278618 _____ C:\Users\Peppe\Downloads\Fixed-Summoners War v3.7.7 Mod v4 iHackedit.com.apk
2018-01-28 17:20 - 2018-01-28 17:44 - 000001908 _____ C:\Windows\diagwrn.xml
2018-01-28 17:20 - 2018-01-28 17:44 - 000001908 _____ C:\Windows\diagerr.xml
2018-01-28 17:20 - 2018-01-28 17:44 - 000000000 ___HD C:\$WINDOWS.~BT
2018-01-28 17:04 - 2018-01-28 17:20 - 000000000 ____D C:\ESD
2018-01-28 17:04 - 2018-01-28 17:04 - 000969974 _____ C:\Users\Peppe\Downloads\Windows 10 ISO.zip
2018-01-28 17:02 - 2018-01-28 17:02 - 000000000 ___HD C:\$Windows.~WS
2018-01-28 17:01 - 2018-01-28 17:01 - 018617536 _____ (Microsoft Corporation) C:\Users\Peppe\Downloads\MediaCreationTool.exe
2018-01-24 19:27 - 2018-01-24 19:27 - 005878801 _____ C:\Users\Peppe\Downloads\k-click_rc4.zip
2018-01-23 15:34 - 2018-01-23 15:35 - 007211520 _____ C:\Users\Peppe\Desktop\ECDL_mod_1 - Copia.ppt
2018-01-18 21:21 - 2018-01-18 21:21 - 000075791 _____ C:\Users\Peppe\Downloads\4_5983572648070742670.pdf
2018-01-18 20:49 - 2018-01-18 20:49 - 015477209 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.6 Mod v3 iHackedit.com.apk
2018-01-18 20:49 - 2018-01-18 20:49 - 015477202 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.6 Mod v4 iHackedit.com.apk
2018-01-18 09:17 - 2018-01-18 09:18 - 015908041 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.5 Mod v3 iHackedit.com.apk
2018-01-18 09:17 - 2018-01-18 09:18 - 015908029 _____ C:\Users\Peppe\Downloads\Summoners War v3.7.5 Mod v4 iHackedit.com.apk
2018-01-16 21:43 - 2018-01-16 21:43 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\CDProjektRED
2018-01-14 23:54 - 2018-01-14 23:55 - 000000221 _____ C:\Users\Peppe\Desktop\Trine 2.url
2018-01-14 23:39 - 2018-04-01 00:41 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2018-01-14 23:39 - 2018-01-14 23:39 - 000000000 ____D C:\Users\Peppe\AppData\Local\GOG.com
2018-01-14 23:38 - 2018-01-14 23:38 - 165087840 _____ (GOG.com ) C:\Users\Peppe\Downloads\setup_gwent_1.2.32.20_it-IT.exe
2018-01-14 23:38 - 2018-01-14 23:38 - 000000064 _____ C:\Users\Peppe\Downloads\gogGalaxy.auth
2018-01-13 16:08 - 2018-01-13 16:08 - 005235316 _____ (ShareX Team ) C:\Users\Peppe\Downloads\ShareX-12.0.0-setup.exe
2018-01-11 13:56 - 2018-01-11 13:56 - 000107628 _____ C:\Users\Peppe\Documents\sintesi_conto_per_isee.pdf
2018-01-11 13:52 - 2018-01-11 13:52 - 000107628 _____ C:\Users\Peppe\Downloads\sintesi_conto_per_isee.pdf
2018-01-08 21:33 - 2018-04-01 19:18 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\Temp
2018-01-08 19:12 - 2018-01-08 19:12 - 000133800 _____ C:\Users\Peppe\Downloads\4_5900101199918531232 (2).pdf
2018-01-07 00:55 - 2018-01-07 00:55 - 000001164 _____ C:\Users\Peppe\Desktop\Nier Automata.lnk
2018-01-07 00:54 - 2018-01-07 00:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nier Automata
2018-01-07 00:22 - 2018-01-07 01:00 - 000000000 ____D C:\Program Files (x86)\Nier Automata
2018-01-07 00:22 - 2018-01-07 00:22 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\Terrible Toybox
2018-01-07 00:21 - 2018-01-07 00:21 - 000001729 _____ C:\Users\Public\Desktop\Thimbleweed Park.lnk
2018-01-06 21:51 - 2018-01-06 21:51 - 000000000 ____D C:\Users\Peppe\AppData\Local\FinchGame
2018-01-06 20:56 - 2018-01-06 21:05 - 000000000 ____D C:\Users\Peppe\Downloads\What.Remains.of.Edith.Finch-HI2U
2018-01-06 20:55 - 2018-01-06 20:55 - 000052110 _____ C:\Users\Peppe\Downloads\What.Remains.of.Edith.Finch-HI2U-[rarbg.to].torrent
2018-01-06 20:54 - 2018-01-06 21:11 - 990340556 _____ C:\Users\Peppe\Downloads\thimbleweedpark10955gog.rar
2018-01-06 20:31 - 2018-01-06 23:09 - 131373056 _____ C:\Users\Peppe\Downloads\cpy-nra.iso
2018-01-06 20:15 - 2018-01-08 17:52 - 000000000 ____D C:\Users\Peppe\Documents\MEGAsync Downloads
2018-01-06 20:14 - 2018-01-28 17:10 - 000000000 ____D C:\Windows\System32\Tasks\MEGA
2018-01-06 20:14 - 2018-01-06 20:14 - 000000000 ____D C:\Users\Peppe\AppData\Local\Mega Limited
2018-01-06 20:13 - 2018-01-06 20:13 - 014975800 _____ (MEGA Limited) C:\Users\Peppe\Downloads\MEGAsyncSetup.exe
2018-01-06 20:05 - 2018-01-06 20:05 - 000268383 _____ C:\Users\Peppe\Downloads\Quantum.Break.COMPLETE-CODEX.torrent
2018-01-06 19:17 - 2018-01-06 19:17 - 001949447 _____ C:\Users\Peppe\Downloads\The Last of US PC Installer.rar
2018-01-06 19:17 - 2018-01-06 19:17 - 001949447 _____ C:\Users\Peppe\Downloads\The Last of US PC Installer (1).rar
2018-01-03 15:10 - 2018-01-03 15:10 - 000988781 _____ C:\Windows\system32\amdicdxx.dat
==================== Three Months Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2064-01-01 16:45 - 2017-11-16 16:39 - 000000000 ____D C:\ProgramData\eLicenser
2018-04-01 19:33 - 2009-07-14 06:45 - 000025120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-01 19:33 - 2009-07-14 06:45 - 000025120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-01 19:26 - 2015-04-09 23:40 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-04-01 19:26 - 2014-10-17 19:36 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-04-01 19:25 - 2017-07-11 22:19 - 000000318 _____ C:\Windows\Tasks\iToolsDaemon.job
2018-04-01 19:25 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-01 19:20 - 2016-08-05 17:28 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-04-01 19:09 - 2009-07-14 06:45 - 005075184 _____ C:\Windows\system32\FNTCACHE.DAT
2018-04-01 19:05 - 2014-09-30 15:09 - 000114824 _____ C:\Users\Peppe\AppData\Local\GDIPFONTCACHEV1.DAT
2018-04-01 19:01 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-04-01 18:59 - 2014-09-30 15:38 - 000000000 ____D C:\AMD
2018-04-01 17:21 - 2015-10-01 13:31 - 000000000 ____D C:\Windows\pss
2018-04-01 17:08 - 2015-06-16 16:04 - 000000000 ____D C:\AdwCleaner
2018-04-01 16:23 - 2014-09-30 15:40 - 000000000 ____D C:\ProgramData\Package Cache
2018-04-01 14:54 - 2016-03-22 22:21 - 000000000 ____D C:\Users\Peppe\Documents\ShareX
2018-04-01 14:40 - 2014-09-30 15:57 - 000000000 ____D C:\Users\Peppe\AppData\Local\Adobe
2018-04-01 13:59 - 2017-07-12 00:32 - 000000000 ____D C:\Users\Peppe\AppData\Local\Nox
2018-04-01 12:28 - 2015-01-03 17:22 - 000000000 ____D C:\Users\Peppe\.android
2018-04-01 12:27 - 2017-08-22 13:07 - 000000000 ____D C:\Users\Peppe\.BigNox
2018-04-01 12:27 - 2017-07-12 00:34 - 000000000 ____D C:\Users\Peppe\vmlogs
2018-04-01 06:26 - 2017-08-12 06:38 - 000000000 ____D C:\Program Files (x86)\Removewat 2.2.7
2018-04-01 06:25 - 2016-09-16 19:12 - 000000000 ____D C:\Program Files (x86)\Ghostery Storage Server
2018-04-01 06:25 - 2014-11-30 21:39 - 000000000 ____D C:\Program Files (x86)\2eb628ee-7327-4304-bd33-0abb95505b88
2018-04-01 06:25 - 2014-10-01 20:46 - 000000000 ____D C:\Program Files (x86)\Adobe Media Player
2018-04-01 06:06 - 2015-10-23 15:19 - 000000000 ____D C:\Users\Peppe\AppData\Local\TeamViewer
2018-04-01 05:31 - 2014-09-30 15:31 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-04-01 05:31 - 2014-09-30 15:31 - 000000000 ____D C:\Windows\system32\Macromed
2018-04-01 05:26 - 2017-08-15 08:12 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2018-04-01 05:25 - 2014-09-30 16:21 - 000460520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-04-01 05:25 - 2014-09-30 16:21 - 000380528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-04-01 05:25 - 2014-09-30 16:21 - 000205976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-04-01 05:25 - 2014-09-30 16:21 - 000146656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-04-01 05:25 - 2014-09-30 16:21 - 000110328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-04-01 05:25 - 2014-09-30 16:21 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-04-01 05:25 - 2014-09-30 16:21 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-04-01 05:24 - 2017-08-15 08:12 - 000343752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2018-04-01 05:24 - 2017-08-15 08:12 - 000227504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2018-04-01 05:24 - 2017-08-15 08:12 - 000199440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2018-04-01 05:24 - 2017-08-15 08:12 - 000057680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2018-04-01 05:24 - 2014-09-30 16:21 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-04-01 04:56 - 2016-10-04 18:23 - 000472328 _____ C:\Windows\SysWOW64\win32_hlp
2018-04-01 04:52 - 2009-07-14 12:53 - 000744956 _____ C:\Windows\system32\perfh010.dat
2018-04-01 04:52 - 2009-07-14 12:53 - 000148628 _____ C:\Windows\system32\perfc010.dat
2018-04-01 04:52 - 2009-07-14 07:13 - 001671250 _____ C:\Windows\system32\PerfStringBackup.INI
2018-04-01 04:15 - 2015-08-09 05:50 - 000707595 _____ (Intel Corporation) C:\Windows\system32\igfxDH.dll
2018-04-01 03:47 - 2014-10-01 13:51 - 000000000 ____D C:\Program Files (x86)\Steam
2018-04-01 03:29 - 2014-10-01 13:50 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\DAEMON Tools Lite
2018-04-01 03:29 - 2014-09-30 16:05 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2018-04-01 03:28 - 2015-10-16 20:39 - 000000000 ____D C:\Users\Peppe\AppData\Local\CrashDumps
2018-04-01 02:49 - 2015-10-13 02:02 - 000000000 ____D C:\Program Files (x86)\BDO - English Please
2018-04-01 02:42 - 2017-11-15 00:54 - 000000000 _____ C:\Windows\SysWOW64\last.dump
2018-04-01 02:27 - 2017-07-10 12:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-04-01 02:26 - 2014-09-30 15:26 - 000000000 ____D C:\Program Files (x86)\Google
2018-04-01 02:18 - 2014-09-30 16:04 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-04-01 02:16 - 2014-09-30 16:04 - 000000000 ____D C:\Program Files\Microsoft Office
2018-04-01 02:16 - 2009-07-14 04:34 - 000000408 _____ C:\Windows\win.ini
2018-04-01 02:15 - 2009-07-14 13:19 - 000000000 ____D C:\Windows\ShellNew
2018-04-01 02:15 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-04-01 01:21 - 2016-02-19 20:10 - 000000000 ____D C:\Program Files\Epic Games
2018-04-01 00:55 - 2014-10-01 13:59 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-04-01 00:53 - 2016-05-30 00:16 - 000000000 ____D C:\Users\Peppe\Desktop\SoundBoard
2018-04-01 00:53 - 2014-10-02 15:03 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\vlc
2018-04-01 00:52 - 2017-09-07 14:50 - 000001001 _____ C:\Users\Public\Desktop\SoundSwitch.lnk
2018-04-01 00:52 - 2014-10-01 13:32 - 000000866 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-04-01 00:41 - 2017-12-08 15:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2018-04-01 00:41 - 2017-09-16 14:22 - 000000000 ____D C:\ProgramData\GOG.com
2018-04-01 00:21 - 2014-10-17 19:37 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\TeamViewer
2018-04-01 00:21 - 2014-10-01 13:57 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\TS3Client
2018-04-01 00:21 - 2014-10-01 13:32 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\uTorrent
2018-04-01 00:05 - 2015-05-03 13:48 - 000000000 ____D C:\Windows\Minidump
2018-03-31 23:23 - 2014-10-01 13:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-03-31 23:23 - 2014-10-01 13:32 - 000000000 ____D C:\Program Files\CCleaner
2018-03-31 22:46 - 2016-03-22 22:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShareX
2018-03-31 22:46 - 2016-03-22 22:20 - 000000000 ____D C:\Program Files\ShareX
2018-03-31 22:43 - 2015-12-14 13:29 - 000000000 __SHD C:\Users\Peppe\IntelGraphicsProfiles
2018-03-31 22:36 - 2014-09-30 15:12 - 000000000 ____D C:\Intel
2018-03-30 22:42 - 2015-07-14 15:11 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\Spotify
2018-03-30 18:27 - 2015-07-14 15:11 - 000000000 ____D C:\Users\Peppe\AppData\Local\Spotify
2018-03-30 04:46 - 2017-07-11 22:19 - 000003302 _____ C:\Windows\System32\Tasks\iToolsDaemon
2018-03-30 04:46 - 2015-12-03 17:11 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2018-03-30 04:46 - 2014-12-25 13:56 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-03-30 04:46 - 2014-10-01 13:32 - 000002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-03-30 04:46 - 2014-09-30 15:26 - 000003582 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-03-30 04:46 - 2014-09-30 15:26 - 000003454 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-03-30 02:02 - 2017-06-15 22:26 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\discord
2018-03-21 20:44 - 2014-11-22 23:34 - 000000000 ____D C:\Users\Peppe\AppData\Local\ElevatedDiagnostics
2018-03-21 03:13 - 2014-09-30 15:27 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-18 16:02 - 2017-05-20 03:54 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\EasyAntiCheat
2018-03-18 16:02 - 2016-02-18 15:35 - 000000000 ____D C:\Users\Peppe\AppData\Local\UnrealEngine
2018-03-18 01:58 - 2016-07-16 04:19 - 000000000 ____D C:\Users\Peppe\AppData\Local\YoloMouse
2018-03-17 20:07 - 2017-05-14 15:18 - 000000000 ____D C:\Users\Peppe\AppData\LocalLow\Mozilla
2018-03-17 16:20 - 2017-09-07 14:50 - 000000000 ____D C:\Users\Peppe\AppData\Roaming\SoundSwitch
2018-03-17 16:19 - 2017-09-07 14:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundSwitch
2018-03-17 16:19 - 2017-09-07 14:50 - 000000000 ____D C:\Program Files\SoundSwitch
2018-03-17 01:42 - 2014-10-09 20:13 - 000000000 ____D C:\Users\Peppe\AppData\Local\Battle.net
2018-03-17 01:40 - 2014-10-09 20:13 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-03-14 19:13 - 2009-07-14 07:08 - 000032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-03-13 01:25 - 2015-07-18 22:11 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-03-13 01:06 - 2015-01-11 22:04 - 000000000 ____D C:\Program Files (x86)\Heroes of the Storm
2018-03-02 23:30 - 2015-08-04 18:26 - 000000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
==================== Files in the root of some directories =======
2009-04-03 13:09 - 2009-04-03 13:09 - 000142152 _____ (Microsoft Corporation) C:\Users\Peppe\oarpman.exe
2014-11-30 00:20 - 2014-11-30 00:20 - 000835843 _____ () C:\Users\Peppe\AppData\Roaming\b4gzzFlQsfcHnrWMIsZw6L3G5VuSbKU9ZH1gGxAzRaV44Qnxrw8c1umknivrERRqIRs6Eq11qVpoPeauHYiZDnrW2T6wGzgFLlf9eCLG.K8eIx
2015-07-09 00:35 - 2015-07-09 00:35 - 000000050 _____ () C:\Users\Peppe\AppData\Roaming\Camdata.ini
2015-07-09 00:35 - 2015-07-09 00:35 - 000000408 _____ () C:\Users\Peppe\AppData\Roaming\CamLayout.ini
2015-07-09 00:35 - 2015-07-09 00:35 - 000000408 _____ () C:\Users\Peppe\AppData\Roaming\CamShapes.ini
2015-07-09 00:35 - 2015-07-09 00:35 - 000004521 _____ () C:\Users\Peppe\AppData\Roaming\CamStudio.cfg
2015-08-07 19:28 - 2015-08-08 15:48 - 000099384 _____ () C:\Users\Peppe\AppData\Roaming\inst.exe
2015-08-07 19:28 - 2015-08-08 15:48 - 000007859 _____ () C:\Users\Peppe\AppData\Roaming\pcouffin.cat
2015-08-07 19:28 - 2015-08-08 15:48 - 000001167 _____ () C:\Users\Peppe\AppData\Roaming\pcouffin.inf
2015-08-07 19:28 - 2015-08-08 15:48 - 000000055 _____ () C:\Users\Peppe\AppData\Roaming\pcouffin.log
2015-08-07 19:28 - 2015-08-08 15:48 - 000082816 _____ (VSO Software) C:\Users\Peppe\AppData\Roaming\pcouffin.sys
2014-11-10 15:41 - 2014-11-10 15:43 - 000000077 _____ () C:\Users\Peppe\AppData\Roaming\Rim.Desktop.Exception.log
2014-11-10 15:41 - 2014-11-10 15:41 - 000001153 _____ () C:\Users\Peppe\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2014-11-10 15:41 - 2014-11-10 15:43 - 000000077 _____ () C:\Users\Peppe\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-11-30 03:36 - 2014-12-20 16:41 - 000000682 _____ () C:\Users\Peppe\AppData\Roaming\SpeedRunnersLog.txt
2015-08-07 19:27 - 2015-08-08 15:21 - 000001059 _____ () C:\Users\Peppe\AppData\Roaming\vso_ts_preview.xml
2014-11-30 22:27 - 2016-12-27 23:58 - 000000600 _____ () C:\Users\Peppe\AppData\Roaming\winscp.rnd
2018-04-01 19:27 - 2018-04-01 00:41 - 000137728 _____ () C:\Users\Peppe\AppData\Local\Cadavers.exe
2018-04-01 02:26 - 2018-04-01 02:26 - 000194048 _____ () C:\Users\Peppe\AppData\Local\install.dll
2018-04-01 02:26 - 2018-04-01 02:26 - 000003072 _____ () C:\Users\Peppe\AppData\Local\install_UEFIConfig.exe
2017-01-25 17:54 - 2017-01-25 22:20 - 000000072 _____ () C:\Users\Peppe\AppData\Local\MamaToGo.txt
2017-08-20 12:43 - 2017-08-20 12:43 - 000000882 _____ () C:\Users\Peppe\AppData\Local\Nox_crash.log
2017-01-25 17:38 - 2017-01-25 22:20 - 000000020 _____ () C:\Users\Peppe\AppData\Local\PapaToGo.txt
2015-04-18 13:35 - 2015-04-18 13:35 - 000000000 _____ () C:\Users\Peppe\AppData\Local\{45FD1050-0D15-4B13-8C02-0B27F8613971}
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
==================== BCD ================================
Windows Boot Manager
--------------------
identificatore {bootmgr}
device partition=\Device\HarddiskVolume1
description Windows Boot Manager
locale it-IT
inherit {globalsettings}
default {current}
resumeobject {3d59d639-489f-11e4-a9d9-d8ff8242313e}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 3
Caricatore di avvio di Windows
-------------------
identificatore {current}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale it-IT
inherit {bootloadersettings}
recoverysequence {3d59d63b-489f-11e4-a9d9-d8ff8242313e}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {3d59d639-489f-11e4-a9d9-d8ff8242313e}
nx OptIn
numproc 4
usefirmwarepcisettings No
Caricatore di avvio di Windows
-------------------
identificatore {3d59d63b-489f-11e4-a9d9-d8ff8242313e}
device ramdisk=[C:]\Recovery\3d59d63b-489f-11e4-a9d9-d8ff8242313e\Winre.wim,{3d59d63c-489f-11e4-a9d9-d8ff8242313e}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {bootloadersettings}
osdevice ramdisk=[C:]\Recovery\3d59d63b-489f-11e4-a9d9-d8ff8242313e\Winre.wim,{3d59d63c-489f-11e4-a9d9-d8ff8242313e}
systemroot \windows
nx OptIn
winpe Yes
Ripresa da modalit� di ibernazione
---------------------
identificatore {3d59d639-489f-11e4-a9d9-d8ff8242313e}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale it-IT
inherit {resumeloadersettings}
filedevice partition=C:
filepath \hiberfil.sys
debugoptionenabled No
Tester memoria di Windows
---------------------
identificatore {memdiag}
device partition=\Device\HarddiskVolume1
path \boot\memtest.exe
description Diagnostica memoria Windows
locale it-IT
inherit {globalsettings}
badmemoryaccess Yes
Impostazioni Servizi di gestione emergenze
------------
identificatore {emssettings}
bootems Yes
Impostazioni debugger
-----------------
identificatore {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
Problemi RAM
-----------
identificatore {badmemory}
Impostazioni globali
---------------
identificatore {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Impostazioni caricatore di avvio
-------------------
identificatore {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Impostazioni hypervisor
-------------------
identificatore {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Impostazioni Resume Loader
----------------------
identificatore {resumeloadersettings}
inherit {globalsettings}
Opzioni dispositivo
--------------
identificatore {3d59d63c-489f-11e4-a9d9-d8ff8242313e}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\3d59d63b-489f-11e4-a9d9-d8ff8242313e\boot.sdi
LastRegBack: 2018-03-30 17:10
==================== End of FRST.txt ============================