Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-10-2017 Ran by [removed] (administrator) on CLAUDIA-PC (02-10-2017 16:22:11) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 10 Home Version 1511 (X64) Language: Italiano (Italia) Internet Explorer Version 11 (Default browser: Edge) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Dritek System INC.) C:\Windows\RfBtnSvc64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Microsoft Corporation) C:\Windows\splwow64.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE (Spotify Ltd) C:\Users\Claudia\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Claudia\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Claudia\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Claudia\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Claudia\AppData\Roaming\Spotify\Spotify.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-09-04] (CANON INC.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [239856 2017-09-07] (AVAST Software) HKLM-x32\...\Run: [BakupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [533568 2012-08-22] (NTI Corporation) HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-15] (Apple Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-04-02] (cyberlink) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3481912 2017-09-20] (Dropbox, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-06-23] (Google Inc.) HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\Run: [McAfeeSafeConnect] => C:\Program Files (x86)\McAfee Safe Connect\McAfee Safe Connect.exe [1003008 2017-08-30] (McAfee Inc.) HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\Run: [Spotify] => C:\Users\Claudia\AppData\Roaming\Spotify\Spotify.exe [20803184 2017-10-02] (Spotify Ltd) HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\Run: [Spotify Web Helper] => C:\Users\Claudia\AppData\Roaming\Spotify\SpotifyWebHelper.exe [777840 2017-10-02] (Spotify Ltd) HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\RunOnce: [Uninstall C:\Users\Claudia\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Claudia\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\RunOnce: [Uninstall C:\Users\Claudia\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Claudia\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" HKU\S-1-5-21-3763233370-3072659706-313367089-1001\...\MountPoints2: {427b47fd-dcf7-11e2-be71-b888e3a149d0} - "D:\autorun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk [2012-09-05] ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] [removed] Tcpip\..\Interfaces\{53145975-9706-4003-9ac7-0c0238d12885}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{53145975-9706-4003-9ac7-0c0238d12885}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{cf84d83d-6236-4173-81aa-dcfe8ef28e58}: [DhcpNameServer] [removed] Internet Explorer: ================== HKU\S-1-5-21-3763233370-3072659706-313367089-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKLM-x32 -> DefaultScope value is missing SearchScopes: HKU\S-1-5-21-3763233370-3072659706-313367089-1001 -> {3D598A7F-C402-4BAD-9B0C-8D4F03D5F166} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-02-09] (Microsoft Corporation) BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll [2014-01-24] (CANON INC.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-10-11] (Google Inc.) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-12] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-02-09] (Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-01-24] (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-27] (Oracle Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-10-11] (Google Inc.) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-12] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-27] (Oracle Corporation) Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll [2014-01-24] (CANON INC.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-10-11] (Google Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-01-24] (CANON INC.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-10-11] (Google Inc.) Toolbar: HKU\S-1-5-21-3763233370-3072659706-313367089-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-10-11] (Google Inc.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\4exgezs1.default [2016-03-17] FF SelectedSearchEngine: Mozilla\Firefox\Profiles\4exgezs1.default -> Wikipedia (it) FF Homepage: Mozilla\Firefox\Profiles\4exgezs1.default -> hxxps://www.google.it/ FF Session Restore: Mozilla\Firefox\Profiles\4exgezs1.default -> is enabled. FF NetworkProxy: Mozilla\Firefox\Profiles\4exgezs1.default -> type", 0 FF Extension: (Adblock Plus) - C:\Users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\4exgezs1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-20] FF HKLM-x32\...\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\StartWeb.xml [2014-03-26] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] () FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-27] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-08-18] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-08-18] (Adobe Systems Inc.) FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\all-iminent.js [2014-03-29] Chrome: ======= CHR DefaultProfile: Default CHR StartupUrls: Default -> "hxxp://start.iminent.com/?appId=A05064EF-B60E-4D2A-AE3B-517533AA09F0","hxxps://www.google.com/" CHR Profile: C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default [2017-10-02] CHR Extension: (Adblock Plus) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-27] CHR Extension: (AdBlock) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-09-26] CHR Extension: (Skype) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-08-25] CHR Extension: (Pagamenti Chrome Web Store) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-25] CHR Extension: (Chrome Media Router) - C:\Users\Claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-02] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7452288 2017-09-07] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [275208 2017-09-07] (AVAST Software) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated) R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft) [File not signed] S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-06-16] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-06-16] (Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-09-20] (Dropbox, Inc.) S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-22] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corp.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) S3 McAfee Vpn Service; C:\Program Files (x86)\McAfee Safe Connect\service\VpnService.exe [314368 2017-08-30] () [File not signed] R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-22] (NTI Corporation) R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-09-05] (Dritek System INC.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 andnetadb; C:\WINDOWS\System32\Drivers\lgandnetadb.sys [31744 2011-03-24] (Google Inc) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [320528 2017-09-07] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-09-07] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343296 2017-09-07] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-09-07] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47016 2017-09-07] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41832 2017-09-07] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147784 2017-09-07] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-09-07] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-09-07] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1016384 2017-09-07] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [590880 2017-09-07] (AVAST Software) S2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [199312 2017-09-21] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [361784 2017-10-02] (AVAST Software) R3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [7585280 2015-10-30] (Broadcom Corporation) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R3 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2013-06-27] (DT Soft Ltd) S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Hewlett-Packard.) S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Hewlett-Packard.) R3 LgBttPort; C:\WINDOWS\system32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.) R3 lgbusenum; C:\WINDOWS\System32\drivers\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.) R3 LGVMODEM; C:\WINDOWS\system32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.) S3 netr28ux; C:\WINDOWS\System32\drivers\netr28ux.sys [2196480 2015-10-30] (MediaTek Inc.) R3 Ps2Kb2Hid; C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys [26736 2012-09-05] (Dritek System Inc.) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed] S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [146928 2010-06-28] (CyberLink Corp.) S3 dbx; system32\DRIVERS\dbx.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-10-02 16:22 - 2017-10-02 16:23 - 000023505 _____ C:\Users\Claudia\Downloads\FRST.txt 2017-10-02 16:22 - 2017-10-02 16:22 - 000000000 ____D C:\FRST 2017-10-02 16:21 - 2017-10-02 16:21 - 002399744 _____ (Farbar) C:\Users\Claudia\Downloads\FRST64.exe 2017-10-02 15:26 - 2017-10-02 15:26 - 000045704 _____ () C:\WINDOWS\system32\Drivers\staport.sys.150695076696801 2017-09-26 17:55 - 2017-09-26 17:55 - 000298496 _____ C:\Users\Claudia\Downloads\iscrizione_corsi_singoli.pdf 2017-09-26 17:55 - 2017-09-26 17:55 - 000000806 _____ C:\Users\Claudia\Downloads\Desktop - collegamento.lnk 2017-09-25 21:09 - 2017-09-25 21:10 - 001028939 _____ C:\Users\Claudia\Downloads\Ladyman Understanding Philosophy of Science.pdf 2017-09-22 16:41 - 2017-09-22 16:54 - 165946589 _____ C:\Users\Claudia\Downloads\heroesofmightandmagic2_dos_win.7z 2017-09-21 15:35 - 2017-09-21 15:35 - 000164849 _____ C:\Users\Claudia\Downloads\Final_Fantasy_VII_PC_ITA_2013_By_Laguna___Giulia.rar 2017-09-21 15:13 - 2017-09-21 15:23 - 000000000 ____D C:\Program Files\rempl 2017-09-21 15:11 - 2017-09-21 15:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-09-20 18:48 - 2017-09-20 18:48 - 000049992 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2017-09-20 18:48 - 2017-09-20 18:48 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2017-09-20 18:48 - 2017-09-20 18:48 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2017-09-20 18:48 - 2017-09-20 18:48 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2017-09-19 21:16 - 2017-09-19 21:16 - 000001194 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Safe Connect.lnk 2017-09-19 21:16 - 2017-09-19 21:16 - 000001182 _____ C:\Users\Public\Desktop\McAfee Safe Connect.lnk 2017-09-19 21:16 - 2017-09-19 21:16 - 000000000 ____D C:\Users\Claudia\AppData\Roaming\McAfee Safe Connect 2017-09-19 21:16 - 2017-09-19 21:16 - 000000000 ____D C:\Users\Claudia\AppData\Local\McAfee_Inc 2017-09-19 21:14 - 2017-09-19 21:14 - 000000000 ____D C:\Program Files (x86)\McAfee Safe Connect 2017-09-19 21:11 - 2017-09-19 21:08 - 000000030 _____ C:\AVScanner.ini 2017-09-19 21:08 - 2017-09-19 21:08 - 000004732 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-09-19 21:08 - 2017-09-19 21:08 - 000000000 ____D C:\ProgramData\McAfee 2017-09-18 20:56 - 2017-09-18 20:56 - 000000000 ____D C:\Users\Claudia\AppData\Roaming\YoudaGames 2017-09-13 11:05 - 2017-09-13 11:05 - 000001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2017-09-13 11:01 - 2017-09-13 11:01 - 000091930 _____ C:\Users\Claudia\Desktop\logica_17-18-i-anno.pdf 2017-09-07 15:23 - 2017-09-07 15:20 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-10-02 16:08 - 2017-06-16 10:30 - 000000000 ____D C:\Users\Claudia\AppData\Roaming\Spotify 2017-10-02 15:43 - 2015-07-26 15:32 - 000001132 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2017-10-02 15:27 - 2014-06-22 11:45 - 000004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6049597C-64FF-472F-8A5B-3EAA566E9F60} 2017-10-02 15:26 - 2017-06-16 14:04 - 000004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2017-10-02 15:26 - 2017-06-16 10:31 - 000000000 ____D C:\Users\Claudia\AppData\Local\Spotify 2017-10-02 15:26 - 2013-06-23 22:06 - 000361784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys 2017-10-02 15:21 - 2015-07-26 15:32 - 000001128 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job 2017-10-01 10:48 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\system32\NDF 2017-09-27 19:48 - 2013-06-23 22:08 - 000002234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-09-27 19:48 - 2013-06-23 22:08 - 000002222 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-09-26 17:46 - 2016-01-05 22:35 - 001832886 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-09-26 17:46 - 2015-10-30 20:19 - 000813240 _____ C:\WINDOWS\system32\perfh010.dat 2017-09-26 17:46 - 2015-10-30 20:19 - 000152000 _____ C:\WINDOWS\system32\perfc010.dat 2017-09-26 17:46 - 2015-10-30 09:21 - 000000000 ____D C:\WINDOWS\INF 2017-09-22 15:07 - 2017-08-09 16:17 - 000003370 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3763233370-3072659706-313367089-1001 2017-09-22 15:07 - 2016-01-05 23:10 - 000002459 _____ C:\Users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-09-22 15:07 - 2016-01-05 23:10 - 000000000 ___RD C:\Users\Claudia\OneDrive 2017-09-21 15:33 - 2015-10-28 17:30 - 000000000 ____D C:\ProgramData\Skype 2017-09-21 15:33 - 2012-08-09 14:54 - 000000000 ____D C:\Program Files (x86)\WildGames 2017-09-21 15:32 - 2012-08-09 14:54 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-09-21 15:31 - 2013-10-26 17:03 - 000000000 ____D C:\Users\Claudia\AppData\Roaming\WildTangent 2017-09-21 15:31 - 2012-08-09 14:54 - 000000000 ____D C:\ProgramData\WildTangent 2017-09-21 15:24 - 2014-03-10 21:54 - 000199312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys 2017-09-21 15:13 - 2015-10-30 09:11 - 000000000 ____D C:\WINDOWS\CbsTemp 2017-09-21 15:12 - 2015-07-26 15:32 - 000000000 ____D C:\Program Files (x86)\Dropbox 2017-09-21 15:04 - 2015-10-28 17:30 - 000000000 ____D C:\Users\Claudia\AppData\Roaming\Skype 2017-09-21 15:01 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\AppReadiness 2017-09-19 21:10 - 2013-06-27 14:42 - 000000000 ____D C:\Users\Claudia\AppData\Local\Adobe 2017-09-19 21:08 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-09-19 21:08 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\system32\Macromed 2017-09-19 19:46 - 2015-10-30 09:24 - 000000000 ___HD C:\Program Files\WindowsApps 2017-09-18 22:04 - 2016-01-06 10:22 - 000000000 ____D C:\Users\Claudia\AppData\Local\Deployment 2017-09-18 20:55 - 2016-01-05 22:10 - 000000000 ____D C:\Users\Claudia 2017-09-18 20:52 - 2014-09-04 16:01 - 000000000 ____D C:\Users\Claudia\AppData\Roaming\Origin 2017-09-18 20:52 - 2014-09-04 15:57 - 000000000 ____D C:\ProgramData\Origin 2017-09-13 11:06 - 2016-10-08 11:02 - 000004018 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1475917315 2017-09-13 11:04 - 2016-01-05 22:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-09-13 11:03 - 2015-10-30 08:28 - 000524288 ___SH C:\WINDOWS\system32\config\BBI 2017-09-07 15:23 - 2017-06-16 14:05 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-09-07 15:20 - 2014-08-15 13:35 - 000047016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2017-09-07 15:20 - 2014-03-10 21:54 - 000199312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys.150600024823401 2017-09-07 15:20 - 2013-06-23 22:06 - 000590880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2017-09-07 15:20 - 2013-06-23 22:06 - 000361336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys.150695076726502 2017-09-07 15:20 - 2013-06-23 22:06 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2017-09-07 15:20 - 2013-06-23 22:06 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2017-09-07 15:20 - 2013-06-23 22:05 - 000147784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2017-09-07 15:19 - 2016-10-06 22:11 - 000041832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2017-09-07 15:19 - 2013-06-23 22:06 - 001016384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2017-09-07 15:18 - 2017-06-16 14:04 - 000343296 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys 2017-09-07 15:18 - 2017-06-16 14:04 - 000320528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys 2017-09-07 15:18 - 2017-06-16 14:04 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys 2017-09-07 15:18 - 2017-06-16 14:04 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys ==================== Files in the root of some directories ======= 2014-03-29 21:59 - 2014-03-29 22:07 - 000001299 _____ () C:\Users\Claudia\AppData\Roaming\Bubble Dock.boostrap.log 2014-03-29 21:59 - 2014-03-29 22:01 - 000012300 _____ () C:\Users\Claudia\AppData\Roaming\Bubble Dock.installation.log 2017-06-21 10:51 - 2017-06-21 10:51 - 000000000 _____ () C:\Users\Claudia\AppData\Local\{1D890D83-742D-42C3-A57B-50C4F6B88063} 2017-06-24 14:00 - 2017-06-24 14:00 - 000000000 _____ () C:\Users\Claudia\AppData\Local\{3484CCD7-DD17-49D4-BFBE-324AFDDE8F7D} 2017-06-23 09:46 - 2017-06-23 09:46 - 000000000 _____ () C:\Users\Claudia\AppData\Local\{88754023-C05A-4E5B-B99D-3B339F6F9D35} Some files in TEMP: ==================== 2017-09-19 21:15 - 2017-09-19 21:15 - 000290304 _____ (Microsoft Corporation) C:\Users\Claudia\AppData\Local\Temp\CakeTubeSdk.Windows.Service.subinacl.exe 2017-08-25 19:15 - 2017-08-25 19:15 - 000740416 _____ (Oracle Corporation) C:\Users\Claudia\AppData\Local\Temp\jre-8u144-windows-au.exe 2017-06-17 18:33 - 2017-06-17 18:33 - 000175416 ____T (Symantec Corporation) C:\Users\Claudia\AppData\Local\Temp\SCC.dll 2016-09-26 16:58 - 2016-09-26 16:58 - 000000000 _____ () C:\Users\Claudia\AppData\Local\Temp\{2038C7D7-0A87-43E8-86CB-57445E83C122}-GoogleUpdateSetup.exe 2016-07-06 14:56 - 2016-07-06 14:56 - 000000000 _____ () C:\Users\Claudia\AppData\Local\Temp\{9181AB9E-9B09-425C-85D5-4CFA14562134}-GoogleUpdateSetup.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-09-21 15:20 ==================== End of FRST.txt ============================