
Infection possible – Aide à la suppression des virus, chevaux de Troie, logiciels espions et programmes malveillants – Bien choisir son serveur d impression
Résultat de l'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 19-04-2020
Ran par Daniele (administrateur) sur DANIELE-PC (Acer Aspire 5750G) (19-04-2020 14:37:26)
Exécution à partir de C: Users Daniele Downloads
Profils chargés: Daniele (Profils disponibles: Daniele & Ree)
Plateforme: Windows 7 Home Premium Service Pack 1 (X64) Langue: Italiano (Italia)
Internet Explorer version 11 (navigateur par défaut: FF)
Mode de démarrage: Normal
==================== Processus (sur liste blanche) =================
(Si une entrée est incluse dans la liste de correctifs, le processus sera fermé. Le fichier ne sera pas déplacé.)
(Adobe Inc. -> Adobe Systems) C: Program Files (x86) Common Files Adobe ARM 1.0 armsvc.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Antivirus avgnt.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Antivirus avguard.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Antivirus avscan.exe <2>
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Antivirus avshadow.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Antivirus sched.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Launcher Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Launcher Avira.Systray.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira Optimizer Host Avira.OptimizerHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira SoftwareUpdater Avira.SoftwareUpdater.ServiceHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C: Program Files (x86) Avira VPN Avira.VpnService.exe
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C: Program Files (x86) Battle.net Battle.net.exe <3>
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C: ProgramData Battle.net Agent Agent.7022 Agent.exe
(CyberLink -> CyberLink Corp.) C: Program Files (x86) Acer clear.fi MVP clear.fiAgent.exe
(CyberLink -> CyberLink) C: Program Files (x86) Acer clear.fi MVP Kernel DMR DMREngine.exe
(Discord Inc. -> Discord Inc.) C: Users Daniele AppData Local Discord app-0.0.306 Discord.exe <6>
(Even Balance, Inc. ->) C: Windows SysWOW64 PnkBstrA.exe
(Google LLC -> Google LLC) C: Program Files (x86) Google Chrome Application chrome.exe <28>
(HearthSim, LLC -> HearthSim) C: Users Daniele AppData Local HearthstoneDeckTracker app-1.10.7 HearthstoneDeckTracker.exe
(Intel Corporation -> Intel Corporation) C: Windows System32 igfxpers.exe
(Intel Corporation -> Intel Corporation) C: Windows System32 igfxtray.exe
(McAfee, LLC -> McAfee, LLC) C: Program Files McAfee WebAdvisor servicehost.exe
(McAfee, LLC -> McAfee, LLC) C: Program Files McAfee WebAdvisor uihost.exe
(Microsoft Corporation -> Microsoft Corporation) C: Program Files (x86) Fichiers communs microsoft shared Virtualization Handler CVHSVC.EXE
(Microsoft Corporation -> Microsoft Corporation) C: Program Files (x86) Microsoft Application Virtualization Client sftlist.exe
(Microsoft Corporation -> Microsoft Corporation) C: Program Files (x86) Microsoft Application Virtualization Client sftvsa.exe
(Microsoft Corporation -> Microsoft Corporation) C: Program Files Microsoft Security Client MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C: Program Files Microsoft Security Client msseces.exe
(Microsoft Corporation -> Microsoft Corporation) C: Program Files Microsoft Security Client NisSrv.exe
(Microsoft Windows -> Microsoft Corporation) C: Windows System32 dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C: Windows System32 rundll32.exe
(Mozilla Corporation -> Mozilla Corporation) C: Program Files (x86) Mozilla Firefox firefox.exe <5>
(NVIDIA Corporation -> NVIDIA Corporation) C: Program Files (x86) NVIDIA Corporation NvTelemetry NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C: Program Files NVIDIA Corporation Display.NvContainer NVDisplay.Container.exe <2>
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C: Program Files Fichiers communs EPSON EPW! 3 SSRP E_S60RPB.EXE
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C: Windows System32 spool drivers x64 3 E_IATILFE.EXE
(Shanghai Changzhi Network Technology Co., Ltd. ->) D: XuanZhi LDPlayer ldnews.exe
(Synaptics Incorporated -> Synaptics Incorporated) C: Program Files Synaptics SynTP SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C: Program Files Synaptics SynTP SynTPHelper.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C: Program Files (x86) TeamViewer TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C: Program Files (x86) TeamViewer TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C: Program Files (x86) TeamViewer tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C: Program Files (x86) TeamViewer tv_x64.exe
==================== Registre (liste blanche) ===================
(Si une entrée est incluse dans la liste de correctifs, l'élément de registre sera restauré par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM … Run: [MSC] => C: Program Files Microsoft Security Client msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM … Run: [SynTPEnh] => C: Program Files Synaptics SynTP SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM … Run: [] => [X]
HKLM-x32 … Exécuter: [KeePass 2 PreLoad] => C: Program Files (x86) KeePass Password Safe 2 KeePass.exe [3331264 2020-01-20] (Développeur Open Source, Dominik Reichl -> Dominik Reichl)
HKLM-x32 … Exécuter: [Avira SystrayStartTrigger] => C: Program Files (x86) Avira Launcher Avira.SystrayStartTrigger.exe [239520 2020-04-02] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKLM-x32 … Exécuter: [Avira System Speedup User Starter] => C: Program Files (x86) Avira System Speedup Avira.SystemSpeedup.Core.Common.Starter.exe [331368 2020-01-30] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKLM-x32 … Exécuter: [] => [X]
HKU S-1-5-19 … RunOnce: [IsMyWinLockerReboot] => msiexec.exe / qn / x voidguid
HKU S-1-5-20 … RunOnce: [IsMyWinLockerReboot] => msiexec.exe / qn / x voidguid
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … Run: [EPLTargetP0000000000000001] => C: Windows system32 spool DRIVERS x64 3 E_IATILFE.EXE [297024 2013-01-24] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … Run: [Discord] => C: Users Daniele AppData Local Discord app-0.0.306 Discord.exe [90950968 2020-02-24] (Discord Inc. -> Discord Inc.)
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … Run: [LDNews] => D: XuanZhi LDPlayer ldnews.exe [1309368 2020-03-25] (Shanghai Changzhi Network Technology Co., Ltd. ->)
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … Run: [] => [X]
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … RunOnce: [FlashPlayerUpdate] => C: Windows SysWOW64 Macromed Flash FlashUtil32_32_0_0_303_Plugin.exe [1457720 2019-12-18] (Adobe Inc. -> Adobe)
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: 050c8d1e-37e4-11ea-9ee4-1c7508f37aca – H: RTK_NIC_DRIVER_INSTALLER.sfx.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: 5e68e840-be54-11e2-b434-806e6f6e6963 – G: Setup.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: 839489ac-58a7-11e5-ac80-1c7508ead495 – C: Windows system32 RunDLL32.EXE Shell32.DLL, ShellExec_RunDLL H: Start.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: 84650df6-67d9-11ea-9c89-1c7508f37aca – H: HiSuiteDownLoader.exe} – H: HiSuiteDownLoader.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: aab47bad-b4df-11e2-b1df-1c7508ead495 – F: LANLauncher.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: b7603e81-b1e8-11e7-9500-1c7508ead495 – G: HiSuiteDownLoader.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 … MountPoints2: fb958786-5f36-11e3-8f8a-1c7508ead495 – F: autorun.exe
HKU S-1-5-21-1536202438-368462837-3654654372-1001 Control Panel Desktop \ SCRNSAVE.EXE -> C: Windows system32 scrnsave.scr [11264 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
HKU S-1-5-18 … RunOnce: [IsMyWinLockerReboot] => msiexec.exe / qn / x voidguid
HKLM Software Microsoft Active Setup Installed Components: [2D46B6DC-2207-486B-B523-A557E6D54B47] -> C: Windows system32 cmd.exe / D / C démarrer C: Windows system32 ie4uinit.exe -ClearIconCache
HKLM Software Microsoft Active Setup Installed Components: [8A69D345-D564-463c-AFF1-A69D9E530F96] -> C: Program Files (x86) Google Chrome Application 81.0.4044.113 Installer chrmstp.exe [2020-04-15] (Google LLC -> Google LLC)
HKLM Software Wow6432Node Microsoft Active Setup Installed Components: [2D46B6DC-2207-486B-B523-A557E6D54B47] -> C: Windows system32 cmd.exe / D / C démarrer C: Windows system32 ie4uinit.exe -ClearIconCache
HKLM Software Wow6432Node Microsoft Active Setup Installed Components: [8A69D345-D564-463c-AFF1-A69D9E530F96] -> "C: Program Files (x86) Google Chrome Application 57.0.2987.133 Installer chrmstp.exe" –configure-user-settings –verbose-logging –system-level
HKLM Software Wow6432Node Microsoft Active Setup Installed Components: [A6EADE66-0000-0000-484E-7E8A45000000] -> C: Program Files (x86) Adobe Acrobat Reader DC Esl AiodLite.dll [2019-05-03] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM Software … Authentication Credential Providers: [F8A0B131-5F68-486c-8040-7E8FC3C85BB6] -> C: Program Files Fichiers communs Microsoft Shared Windows Live WLIDCREDPROV.DLL [2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
Fournisseurs HKLM Software … Authentication PLAP: [60442b50-aac2-4db7-b9b0-813d2107287d] -> c: windows system32 dsNcSmartCardProv.dll [2014-04-16] (Juniper Networks, Inc. -> Juniper Networks)
Fournisseurs HKLM Software … Authentication PLAP: [9f4a51de-92b1-483a-b717-dd7d3bb7d3db] -> c: windows system32 dsNcCredProv.dll [2014-04-16] (Juniper Networks, Inc. -> Juniper Networks)
AppInit_DLLs: C: Windows system32 nvinitx.dll => C: Windows system32 nvinitx.dll [182784 2018-03-25] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs-x32: C: Windows SysWOW64 nvinit.dll => C: Windows SysWOW64 nvinit.dll [159704 2018-03-25] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
==================== Tâches planifiées (liste blanche) ============
(Si une entrée est incluse dans la liste de correctifs, elle sera supprimée du registre. Le fichier ne sera pas déplacé sauf s'il est répertorié séparément.)
Tâche: 0587C257-D7C6-4C78-8F21-1D7F3939B9B9 – System32 Tasks Recovery Management Burn Notification => C: Program Files Acer Acer eRecovery Management NotificationCenter Notification.exe [816520 2011-08-09] (Acer Incorporated -> Acer)
Tâche: 0698585B-BA25-4335-9278-3BC3C18BE8B5 – System32 Tasks Adobe Flash Player NPAPI Notifier => C: Windows SysWOW64 Macromed Flash FlashUtil32_32_0_0_303_Plugin.exe [1457720 2019-12-18] (Adobe Inc. -> Adobe)
Tâche: 0D073FB3-7592-4AD3-ACD5-261412DDD7DF – System32 Tasks EPSON XP-312 313 315 Series Invitation 6AFC5C38-E427-4C18-A613-15CA4120664F => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Tâche: 0D415B8D-D7FD-477F-97FB-381B18EBA498 – Tâche de mise à jour System32 Tasks Adobe Acrobat => C: Program Files (x86) Common Files Adobe ARM 1.0 AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Tâche: 16CBEF8D-2362-4ADC-9C8E-7F143609615F – System32 Tasks clear.fiAgent => C: Program Files (x86) Acer clear.fi MVP clear.fiAgent.exe [120104 2011-08-24] (CyberLink -> CyberLink Corp.)
Tâche: 19BE36DC-19D0-4AE2-B932-4E92E841E50E – System32 Tasks NvTmMon_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files (x86) NVIDIA Corporation Update Core NvTmMon.exe [510912 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: 28017D3E-92AD-4139-B233-772380FCF796 – System32 Tasks 898F6CA2-2FC0-4969-9594-F4670EF81EBA => C: Program Files (x86) Activision Rome – Total War RomeTW.exe
Tâche: 28FFE953-0A42-4552-8E34-DC5CE2F4000A – System32 Tasks F3E47E76-9709-4A21-BB71-1B0C6C9B8223 => C: Windows system32 pcalua.exe -a E: Setup.exe – d E:
Tâche: 2AFD2942-0BC9-4D3A-A82D-AD1D5CCE73FD – System32 Tasks E3F8847E-F1BC-4BFB-8A19-8DF64248AAFE => C: Program Files (x86) Activision Rome – Total War RomeTW.exe
Tâche: 34FFA4CE-EA47-418C-BE0E-1EA34C5DCC7B – System32 Tasks AviraSystemSpeedupUpdate => C: ProgramData Avira SystemSpeedup Update avira_speedup_setup_update.exe [27848432 2020-04-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Tâche: 461EE1FB-988C-4A90-BB13-D665D42A365A – System32 Tasks NvProfileUpdaterDaily_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files NVIDIA Corporation Update Core NvProfileUpdater64 [662464 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: 4802D53D-7317-4F6D-96B0-025C0D18E41B – System32 Tasks 5B715CDF-6EE8-460D-A988-FA5FE01124D1 => E: baldur.exe
Tâche: 53F97095-C1E8-4C4E-8E7E-D640EAC6E922 – System32 Tasks NVIDIA GeForce Experience SelfUpdate_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files (x86) NVIDIA Corporation NVIDIA GeForce Experience NVIDIA GeForce Experience.exe [2069952 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: 576D0D33-BE9A-4724-A555-8F4E9B90573B – System32 Tasks EPSON XP-312 313 315 Series Update E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Tâche: 58DE433B-64F3-4832-A901-30F96F3625BA – System32 Tasks NvProfileUpdaterOnLogon_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files NVIDIA Corporation Update Core NvProfileUpdater64 [662464 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: 5CED6FD0-67EC-4881-BEBA-77F9D42F4209 – System32 Tasks Adobe Flash Player Updater => C: Windows SysWOW64 Macromed Flash FlashPlayerUpdateService.exe [335416 2019-12-18] (Adobe Inc. -> Adobe)
Tâche: 6DA9947E-16BB-412B-9076-BAB7FB4730DC – System32 Tasks NvTmRep_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files (x86) NVIDIA Corporation Update Core NvTmRep.exe [757184 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: 6E86E2AF-4A75-49B5-B12F-E52842CDEB92 – System32 Tasks E4841482-3364-44D1-9773-1AA169AD4679 => C: Program Files (x86) Activision Rome – Total War RomeTW.exe
Tâche: 6E924764-AF68-4394-8DE7-E26688CAA88F – System32 Tasks E6B67C06-3DA8-48D9-8061-CC54EDA7A03D => C: Users Daniele Desktop Tor Browser Browser firefox.exe.exe
Tâche: 82643A6B-7C76-4DDE-9EFC-EAA23691FC3F – System32 Tasks 7D643D1C-0931-495D-8883-8D8B85E39BAB => C: Windows system32 pcalua.exe -a C: Users Daniele Bureau hpflash1.exe -d C: Users Daniele Desktop
Tâche: 89BBD1F3-AD18-4295-9C8F-408713D375EF – System32 Tasks DMREngine => C: Program Files (x86) Acer clear.fi MVP . Kernel DMR DMREngine.exe [169352 2011-08-24] (CyberLink -> CyberLink)
Tâche: 8DA7805F-DA82-44FD-8C16-3DB36A78306A – System32 Tasks UALU notificatin => C: Program Files Acer Acer Updater UALU.exe [22392 2012-04-05] (Acer Incorporated -> Acer Incorporated)
Tâche: 906AA2A6-A3F5-419E-AD07-0DC22E0C18E7 – System32 Tasks clear.fi => C: Program Files (x86) Acer clear.fi MVP clear.fi.exe [264760 2011-08-24] (CyberLink -> Acer Incorporated)
Tâche: 91BE0F27-0BB1-4F2D-AA59-B164367ED37B – System32 Tasks GoogleUpdateTaskMachineCore => C: Program Files (x86) Google Update GoogleUpdate.exe [144200 2015-08-28] (Google Inc -> Google Inc.)
Tâche: 944C8AC3-46F0-49EA-BCE6-BD5F2ABF1E25 – System32 Tasks NvBatteryBoostCheckOnLogon_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files (x86) NVontia Corporation NvC [469952 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: 947B3B5A-7121-4AA4-A132-B3723F145F31 – System32 Tasks EPSON XP-312 313 315 Series Update 6AFC5C38-E427-4C18-A613-15CA4120664F => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Tâche: 96EC6761-5AF9-498C-A923-CBEB073F3C48 – System32 Tasks Microsoft Microsoft Antimalware Microsoft Antimalware Scheduled Scan => C: Program Files Microsoft Security Client \ MpCmdRun.exe [410784 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
Tâche: 971CBDDC-AE71-4383-BF3E-55684DC6BE1F – Tâche System32 Tasks Overwolf Updater => C: Program Files (x86) Overwolf OverwolfUpdater.exe [2463064 2020-03-14] (Overwolf Ltd -> Overwolf LTD)
Tâche: 9C563B9F-8477-4F74-9683-3D0C349598DD – System32 Tasks EPSON XP-312 313 315 Series Invitation E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Tâche: A2AF1F20-FAF1-44EB-A8EE-F9E61B94538B – System32 Tasks CEF4E478-F540-44FA-8A0A-B04F0C79ED38 => C: Windows system32 pcalua.exe -a C: Users Daniele Téléchargements HijackThis.exe -d C: Users Daniele Downloads
Tâche: A4CA37D7-063A-4E31-BD80-149FDBF10BE1 – System32 Tasks 5D586F1C-A007-495B-A683-84471FF9182E => C: Windows system32 pcalua.exe -a C: Users Daniele Desktop BaldursGate2 Setup.exe -d C: Users Daniele Desktop BaldursGate2
Tâche: A5D1C74C-C335-4965-A36A-010CC81124C7 – System32 Tasks E1FD0496-34FB-4E32-BE56-1638E11B44F0 => C: Program Files (x86) Activision Rome – Total War RomeTW.exe
Tâche: AA9292C3-4A04-427B-83C6-1D8EA215F4AC – System32 Tasks A07D0381-8480-48E5-93B1-1CD22638FA0B => C: Windows system32 pcalua.exe -a E: Launch.exe – d E:
Tâche: AF175631-4055-4EDD-B91E-ADC2D47EC4D7 – System32 Tasks NvNodeLauncher_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files (x86) NVIDIA Corporation NvNode nvnodejsla [976832 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: D7C41E02-A0BF-4278-A071-55694952ACDC – System32 Tasks GoogleUpdateTaskMachineUA => C: Program Files (x86) Google Update GoogleUpdate.exe [144200 2015-08-28] (Google Inc -> Google Inc.)
Tâche: D7F35FFC-47BF-4DC2-97D2-9C611F8EC20B – System32 Tasks Microsoft Windows Live SOXE Extractor Definitions Update Task => 3519154C-227E-47F3-9CC9-12C3F05817F1
Tâche: DD604AC5-C11F-4371-84FE-2AC34CF0D167 – System32 Tasks NvDriverUpdateCheckDaily_ B2FE1952-0186-46C3-BAEC-A80AA35AC5B8 => C: Program Files NVIDIA Corporation NvContainer nvcontain.exe [522688 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
Tâche: E002599A-08C1-4C42-883F-191BB591BB0F – System32 Tasks 6E01CB89-B997-4F11-A30C-C7CE8A9C91A1 => C: Windows system32 pcalua.exe -a C: Users Daniele Téléchargements win32_152824.exe -d C: Users Daniele Downloads
Tâche: F75AEAE1-46D4-4AE2-B52C-212BD3348EFE – System32 Tasks Avira_Antivirus_Systray => C: Program Files (x86) Avira Antivirus avgnt.exe [2759304 2020-04-01] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
(Si une entrée est incluse dans la liste de correctifs, le fichier de tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
Tâche: C: Windows Tasks EPSON XP-312 313 315 Series Invitation 6AFC5C38-E427-4C18-A613-15CA4120664F .job => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE
Tâche: C: Windows Tasks EPSON XP-312 313 315 Series Invitation E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF .job => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE
Tâche: C: Windows Tasks EPSON XP-312 313 315 Series Update 6AFC5C38-E427-4C18-A613-15CA4120664F .job => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE : / EXE: 6AFC5C38-E427-4C18-A613-15CA4120664F / F: UpdateSYSTEMĊ Recherche les mises à jour du logiciel EPSON et vous avertit lorsque des mises à jour sont disponibles.Si cette tâche est désactivée ou arrêtée, votre logiciel EPSON ne sera pas automatiquement mis à jour date.Thi
Tâche: C: Windows Tasks EPSON XP-312 313 315 Series Update E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF .job => C: Windows system32 spool DRIVERS x64 3 E_ITSLFE.EXE : / EXE: E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF / F: UpdateSYSTEMĊ Recherche les mises à jour du logiciel EPSON et vous avertit lorsque des mises à jour sont disponibles. Si cette tâche est désactivée ou arrêtée, votre logiciel EPSON ne sera pas automatiquement tenu à jour. date.Thi
==================== Internet (liste blanche) ====================
(Si un élément est inclus dans la liste de correctifs, s'il s'agit d'un élément du registre, il sera supprimé ou restauré par défaut.)
Winsock: Catalog5 07 C: Program Files (x86) Fichiers communs Microsoft Shared Windows Live WLIDNSP.DLL [145280 2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 08 C: Program Files (x86) Fichiers communs Microsoft Shared Windows Live WLIDNSP.DLL [145280 2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 07 C: Program Files Fichiers communs Microsoft Shared Windows Live WLIDNSP.DLL [171392 2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 08 C: Program Files Fichiers communs Microsoft Shared Windows Live WLIDNSP.DLL [171392 2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
Tcpip Paramètres: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip .. Interfaces 0EF91A76-19E2-4548-BB51-E60CD7106D02: [DhcpNameServer] 192.168.0.1
Tcpip .. Interfaces 3EFC82CC-B91A-4C1E-B521-C2B94DC80088: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip .. Interfaces 49233639-7CE3-4A19-9C9C-58E97178E1DA: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip .. Interfaces C05787A9-9258-4705-B63A-09E187B553B7: [DhcpNameServer] 192.168.42.129
Tcpip .. Interfaces E302DF92-CA2E-4BE6-BBDF-9847BF0E7A4F: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKU S-1-5-21-1536202438-368462837-3654654372-1001 Software Microsoft Internet Explorer Main, page de démarrage = hxxp: //uk.search.yahoo.com/? Type = 714647 & fr = spigot-yhp -c'est à dire
SearchScopes: HKLM -> DefaultScope 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxp: //www.bing.com/search? Q = searchTerms & form = AARTDF & pc = MAAR & src = IE-SearchBox
SearchScopes: HKLM -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxp: //www.bing.com/search? Q = searchTerms & form = AARTDF & pc = MAAR & src = IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxp: //www.bing.com/search? Q = searchTerms & form = AARTDF & pc = MAAR & src = IE-SearchBox
SearchScopes: HKLM-x32 -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxp: //www.bing.com/search? Q = searchTerms & form = AARTDF & pc = MAAR & src = IE-SearchBox
SearchScopes: HKU .DEFAULT -> DefaultScope 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL =
SearchScopes: HKU .DEFAULT -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL =
SearchScopes: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> DefaultScope 6F10B82E-F8E1-488B-AFF0-66E6D7950E71 URL = hxxps: //uk.search.yahoo.com/search? Fr = chr-greentree_ie & ei = utf-8 & ilc = 12 & type = 714647 & p = searchTerms
SearchScopes: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL =
SearchScopes: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> 0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9 URL = hxxp: //www1.delta-search.com/? Q = searchTerms & affID = 119776 & tt = gc_ & babsrc = SP_ss & mntrId = 0A75EC55F940E88A
SearchScopes: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> 6F10B82E-F8E1-488B-AFF0-66E6D7950E71 URL = hxxps: //uk.search.yahoo.com/search? Fr = chr-greentree_ie & ei = utf-8 & ilc = 12 & type = 714647 & p = searchTerms
SearchScopes: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> 7405AE7F-13A6-4266-A4B2-512B544AACDB URL = hxxp: //uk.search.yahoo.com/search? Fr = chr-greentree_ie & ei = utf-8 & ilc = 12 & type = 714647 & p = searchTerms
SearchScopes: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> 99209B94-587D-42C2-A3CA-F72D0A76A2F6 URL = hxxp: //www.bing.com/search? Q = searchTerms & r = 503
BHO: Aide à la connexion Windows Live ID -> 9030D464-4C02-4ABF-8ECC-5164760863C6 -> C: Program Files Fichiers communs Microsoft Shared Windows Live WindowsLiveLogin.dll [2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
BHO: McAfee WebAdvisor -> B164E929-A1B6-4A06-B104-2CD0E90A88FF -> C: Program Files McAfee WebAdvisor x64 IEPlugin.dll [2020-04-08] (McAfee, LLC -> McAfee, LLC)
BHO-x32: Java ™ Plug-In SSV Helper -> 761497BB-D6F0-462C-B6EB-D4DAF1D92D43 -> C: Program Files (x86) Java jre1.8.0_171 bin ssv.dll [2018-04-24] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Aide à la connexion Windows Live ID -> 9030D464-4C02-4ABF-8ECC-5164760863C6 -> C: Program Files (x86) Common Files Microsoft Shared Windows Live WindowsLiveLogin.dll [2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: McAfee WebAdvisor -> B164E929-A1B6-4A06-B104-2CD0E90A88FF -> C: Program Files McAfee WebAdvisor win32 IEPlugin.dll [2020-04-08] (McAfee, LLC -> McAfee, LLC)
BHO-x32: Java ™ Plug-In 2 SSV Helper -> DBC80044-A445-435b-BC74-9C25C1C588A9 -> C: Program Files (x86) Java jre1.8.0_171 bin jp2ssv.dll [2018-04-24] (Oracle America, Inc. -> Oracle Corporation)
Restauration de session IE: HKU S-1-5-21-1536202438-368462837-3654654372-1001 -> est activé.
DPF: HKLM AA570693-00E2-4907-B6F1-60A1199B030C hxxps: //juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 E5F5D008-DD2C-4D32-977D-1A0ADF03058B hxxps: //juniper.net/dana-cached/setup/JuniperSetupSP1.cab
DPF: HKLM-x32 F27237D7-93C8-44C2-AC6E-D6057B9A918F hxxps: //juniper.net/dana-cached/sc/JuniperSetupClient.cab
Gestionnaire: skype4com – FFC8B962-9B40-4DFF-9458-1830C7DD7F5D – Aucun fichier
Filter-x32: application / x-ica – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = euc-jp – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = ISO-8859-1 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = MS936 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = MS949 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = MS950 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = UTF-8 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = UTF8 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = euc-jp – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = ISO-8859-1 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = MS936 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = MS949 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = MS950 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = UTF-8 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application / x-ica; charset = UTF8 – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: ica – CFB6322E-CC85-4d1b-82C7-893888A236BC – C: Program Files (x86) Citrix ICA Client IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
FireFox:
========
FF DefaultProfile: xlbk4m4f.default-1485720396432
FF ProfilePath: C: Users Daniele AppData Roaming Mozilla Firefox Profiles xlbk4m4f.default-1485720396432 [2020-04-19]
Restauration de session FF: Mozilla Firefox Profiles xlbk4m4f.default-1485720396432 -> est activé.
Extension FF: (Sécurité du navigateur Avira) – C: Users Daniele AppData Roaming Mozilla Firefox Profiles xlbk4m4f.default-1485720396432 Extensions abs@avira.com.xpi [2020-03-23]
Extension FF: (Recherche et nouvel onglet par Yahoo) – C: Users Daniele AppData Roaming Mozilla Firefox Profiles xlbk4m4f.default-1485720396432 Extensions jid1-16aeif9OQIRKxA@jetpack.xpi [2019-05-16]
Plugin FF: @ adobe.com / FlashPlayer -> C: Windows system32 Macromed Flash NPSWF64_32_0_0_303.dll [2019-12-18] (Adobe Inc. ->)
Plugin FF: @ microsoft.com / GENUINE -> désactivé [No File]
Plugin FF: @ Microsoft.com / NpCtrl, version = 1.0 -> C: Program Files Microsoft Silverlight 5.1.50918.0 npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @ adobe.com / FlashPlayer -> C: Windows SysWOW64 Macromed Flash NPSWF32_32_0_0_303.dll [2019-12-18] (Adobe Inc. ->)
FF Plugin-x32: @ Citrix.com / npican -> C: Program Files (x86) Citrix ICA Client npicaN.dll [2013-10-01] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
FF Plugin-x32: @ java.com / DTPlugin, version = 11.171.2 -> C: Program Files (x86) Java jre1.8.0_171 bin dtplugin npDeployJava1.dll [2018-04-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @ java.com / JavaPlugin, version = 11.171.2 -> C: Program Files (x86) Java jre1.8.0_171 bin plugin2 npjp2.dll [2018-04-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @ microsoft.com / GENUINE -> désactivé [No File]
FF Plugin-x32: @ Microsoft.com / NpCtrl, version = 1.0 -> C: Program Files (x86) Microsoft Silverlight 5.1.50918.0 npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @ microsoft.com / SharePoint, version = 14.0 -> C: PROGRA ~ 2 MICROS ~ 4 Office14 NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @ microsoft.com / WLPG, version = 15.4.3502.0922 -> C: Program Files (x86) Windows Live Photo Gallery NPWLPG.dll [2011-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @ microsoft.com / WLPG, version = 15.4.3538.0513 -> C: Program Files (x86) Windows Live Photo Gallery NPWLPG.dll [2011-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @ videolan.org / vlc, version = 2.0.6 -> C: Program Files (x86) VideoLAN VLC npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @ videolan.org / vlc, version = 2.1.2 -> C: Program Files (x86) VideoLAN VLC npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @ videolan.org / vlc, version = 2.2.1 -> C: Program Files (x86) VideoLAN VLC npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @ videolan.org / vlc, version = 2.2.6 -> C: Program Files (x86) VideoLAN VLC npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @ videolan.org / vlc, version = 3.0.8 -> C: Program Files (x86) VideoLAN VLC npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @ WildTangent.com / GamesAppPresenceDetector, Version = 1.0 -> C: Program Files (x86) WildTangent Games App BrowserIntegration Registered 0 NP_wtapp.dll [2013-08-06] (WildTangent Inc ->)
FF Plugin-x32: Adobe Reader -> C: Program Files (x86) Adobe Acrobat Reader DC Reader AIR nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
Plugin FF HKU S-1-5-21-1536202438-368462837-3654654372-1001: @ asperasoft.com / AsperaConnect -> C: Users Daniele AppData Local Programs Aspera Aspera Connect lib 3.6. 1 npasperaweb_3.6.1.111228.dll [2015-09-11] (Aspera, Inc. -> Aspera, Inc.)
Plugin FF HKU S-1-5-21-1536202438-368462837-3654654372-1001: @ Unity3d.com / UnityPlayer, version = 1.0 -> C: Users Daniele AppData LocalLow Unity WebPlayer Loader npUnity3D32 .dll [2015-03-27] (Unity Technologies SF -> Unity Technologies ApS)
Plugin FF HKU S-1-5-21-1536202438-368462837-3654654372-1001: SkypeForBusinessPlugin-15.8 -> C: Users Daniele AppData Local Microsoft SkypeForBusinessPlugin 15.8.20020.400 npGatewayNpapi.dll [2015-06-15] (Microsoft Corporation -> Microsoft Corporation)
Plugin FF HKU S-1-5-21-1536202438-368462837-3654654372-1001: SkypeForBusinessPlugin64-15.8 -> C: Users Daniele AppData Local Microsoft SkypeForBusinessPlugin 15.8.20020.400 npGatewayNpapi-x64.dll [2015-06-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKUS-1-5-21-1536202438-368462837-3654654372-1001: SkypePlugin -> C:UsersDanieleAppDataLocalSkypePlugin7.26.0.48npGatewayNpapi.dll [2016-09-22] (Microsoft Corporation -> Skype Technologies S.A.)
FF Plugin HKUS-1-5-21-1536202438-368462837-3654654372-1001: SkypePlugin64 -> C:UsersDanieleAppDataLocalSkypePlugin7.26.0.48npGatewayNpapi-x64.dll [2016-09-22] (Microsoft Corporation -> Skype Technologies S.A.)
Chrome:
=======
CHR Profile: C:UsersDanieleAppDataLocalGoogleChromeUser DataDefault [2020-04-19]
CHR Notifications: Default -> hxxps://uk-mg42.mail.yahoo.com; hxxps://web.skype.com; hxxps://web.whatsapp.com; hxxps://www.hotukdeals.com; hxxps://www.reddit.com
CHR HomePage: Default -> hxxp://uk.search.yahoo.com/?type=714647&fr=spigot-yhp-ch
CHR StartupUrls: Default -> "hxxps://www.google.co.uk/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Presentazioni) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsaapocclcgogkmnckokdopfmhonfmgoek [2017-10-16]
CHR Extension: (Documenti) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsaohghmighlieiainnegkcijnfilokake [2017-10-16]
CHR Extension: (Google Drive) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsapdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Avira Password Manager) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionscaljgklbbfbcjjanaijlacgncafpegll [2020-04-14]
CHR Extension: (Google Search) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Fogli) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsfelcaaldnbdncclmgdcncolpebgiejap [2017-10-16]
CHR Extension: (Documenti Google offline) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-17]
CHR Extension: (AdBlock: il miglior ad-blocker di sempre) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsgighmmpiobklfepjocnamgkkbiglidom [2020-04-17]
CHR Extension: (Lightshot (strumento per screenshot)) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsmbniclmhobmnbdlbpiphghaielnnpgdp [2020-01-31]
CHR Extension: (Pagamenti Chrome Web Store) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionsnmmhkkegccagdldgiimedpiccmgmieda [2019-10-05]
CHR Extension: (Gmail) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia [2019-05-16]
CHR Extension: (Chrome Media Router) – C:UsersDanieleAppDataLocalGoogleChromeUser DataDefaultExtensionspkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-14]
CHR HKLM…ChromeExtension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM…ChromeExtension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32…ChromeExtension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32…ChromeExtension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32…ChromeExtension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32…ChromeExtension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32…ChromeExtension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32…ChromeExtension: [ibbfklbaljofpaanmpaeadejijfdddco]
CHR HKLM-x32…ChromeExtension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
CHR HKLM-x32…ChromeExtension: [nbmafkdmkkckhggblphicnnhlgljnoje] –
CHR HKLM-x32…ChromeExtension: [njpedbdniajflhgfoipnjkednnlkngbj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:Program Files (x86)AviraAntivirusavmailc7.exe [1209856 2020-04-01] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:Program Files (x86)AviraAntivirussched.exe [485960 2020-04-01] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:Program Files (x86)AviraAntivirusavguard.exe [485960 2020-04-01] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:Program Files (x86)AviraAntivirusavwebg7.exe [573760 2020-03-22] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:Program Files (x86)AviraLauncherAvira.ServiceHost.exe [634896 2020-04-02] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraOptimizerHost; C:Program Files (x86)AviraOptimizer HostAvira.OptimizerHost.exe [2989888 2020-01-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:Program Files (x86)AviraVPNAvira.VpnService.exe [382992 2020-03-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraUpdaterService; C:Program Files (x86)AviraSoftwareUpdaterAvira.SoftwareUpdater.ServiceHost.exe [161216 2020-04-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S4 EpsonScanSvc; C:Windowssystem32EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:Program FilesCommon FilesEPSONEPW!3 SSRPE_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
S3 fussvc; C:Program Files (x86)Windows Kits8.1App Certification Kitfussvc.exe [143872 2014-10-24] (Microsoft Corporation) [File not signed]
S4 GamesAppIntegrationService; C:Program Files (x86)WildTangent GamesAppGamesAppIntegrationService.exe [240736 2013-10-07] (WildTangent Inc -> WildTangent)
R2 McAfee WebAdvisor; C:Program FilesMcAfeeWebAdvisorServiceHost.exe [913640 2020-04-08] (McAfee, LLC -> McAfee, LLC)
R2 MsMpSvc; C:Program FilesMicrosoft Security ClientMsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S4 MyEpson Portal Service; C:Program Files (x86)EPSONMyEpson PortalmepService.exe [714712 2017-06-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R3 NisSrv; C:Program FilesMicrosoft Security ClientNisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S4 NTI IScheduleSvc; C:Program Files (x86)NTIAcer Backup ManagerIScheduleSvc.exe [256832 2011-04-24] (NTI Corporation -> NTI Corporation)
S3 NvContainerLocalSystem; C:Program FilesNVIDIA CorporationNvContainernvcontainer.exe [522688 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:Program FilesNVIDIA CorporationNvContainernvcontainer.exe [522688 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
S4 Origin Client Service; C:Program Files (x86)OriginOriginClientService.exe [2098528 2017-08-23] (Electronic Arts, Inc. -> Electronic Arts)
S4 Origin Web Helper Service; C:Program Files (x86)OriginOriginWebHelperService.exe [2977640 2017-08-23] (Electronic Arts, Inc. -> Electronic Arts)
S4 OverwolfUpdater; C:Program Files (x86)OverwolfOverwolfUpdater.exe [2463064 2020-03-14] (Overwolf Ltd -> Overwolf LTD)
R2 PnkBstrA; C:WindowsSysWOW64PnkBstrA.exe [75136 2013-05-17] (Even Balance, Inc. -> )
S3 Te.Service; C:Program Files (x86)Windows Kits8.1TestingRuntimesTAEFWex.Services.exe [122368 2015-02-26] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:Program Files (x86)TeamViewerTeamViewer_Service.exe [13216272 2020-03-20] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WinDefend; C:Program FilesWindows Defendermpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S3 wlidsvc; C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE [2292096 2011-03-29] (Microsoft Corporation -> Microsoft Corp.)
R2 NVDisplay.ContainerLocalSystem; "C:Program FilesNVIDIA CorporationDisplay.NvContainerNVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:ProgramDataNVIDIANVDisplay.ContainerLocalSystem.log" -l 3 -d "C:Program FilesNVIDIA CorporationDisplay.NvContainerpluginsLocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:Program Files (x86)NVIDIA CorporationNvTelemetryNvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:ProgramDataNVIDIANvTelemetryContainer.log" -l 3 -d "C:Program Files (x86)NVIDIA CorporationNvTelemetryplugins" -r
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:WindowsSystem32DRIVERSathrx.sys [2755584 2011-07-19] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R0 avdevprot; C:WindowsSystem32DRIVERSavdevprot.sys [68152 2019-06-07] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 avgntflt; C:WindowsSystem32DRIVERSavgntflt.sys [223744 2020-03-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avipbb; C:WindowsSystem32DRIVERSavipbb.sys [177376 2020-04-06] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avkmgr; C:WindowsSystem32DRIVERSavkmgr.sys [36072 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 avnetflt; C:WindowsSystem32DRIVERSavnetflt.sys [78600 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R0 avusbflt; C:WindowsSystem32Driversavusbflt.sys [35376 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:WindowsSystem32DRIVERSdtsoftbus01.sys [283064 2013-12-07] (Disc Soft Ltd -> Disc Soft Ltd)
R2 LdBoxDrv; C:Program Filesdnplayerext2LdBoxDrv.sys [319376 2019-12-18] (Shanghai Changzhi Network Technology Co., Ltd. -> Oracle Corporation)
R2 LdVBoxDrv; C:Program FilesldplayerboxLdVBoxDrv.sys [319376 2020-03-25] (Shanghai Changzhi Network Technology Co., Ltd. -> Oracle Corporation)
R0 MpFilter; C:WindowsSystem32DRIVERSMpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
S3 MYFAULT; C:Windowssystem32driversmyfault.sys [25392 2018-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals)
R3 NisDrv; C:WindowsSystem32DRIVERSNisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 nusb3hub; C:Windowssystem32driversnusb3hub.sys [82432 2011-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 nusb3xhc; C:Windowssystem32driversnusb3xhc.sys [181760 2011-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
S3 NvStreamKms; C:Program FilesNVIDIA CorporationNvStreamSrvNvStreamKms.sys [31168 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:WindowsSystem32driversnvvad64v.sys [59240 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:WindowsSystem32DRIVERSnvvhci.sys [58816 2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
R3 phantomtap; C:WindowsSystem32DRIVERSphantomtap.sys [35664 2020-03-18] (Avira Operations GmbH & Co. KG -> The OpenVPN Project)
S3 rtux64w7; C:WindowsSystem32DRIVERSrtux64w7.sys [328448 2016-08-19] (Realtek Semiconductor Corp -> Realtek )
S4 secdrv; C:WindowsSysWow64Driverssecdrv.sys [11973 2017-06-06] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R0 sptd; C:WindowsSystem32Driverssptd.sys [381440 2013-12-07] (Disc Soft Ltd -> Duplex Secure Ltd.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-19 14:36 – 2020-04-19 14:36 – 000000000 ____D C:UsersDanieleDownloadsFRST-OlderVersion
2020-04-18 14:29 – 2020-04-18 14:29 – 000062792 _____ C:ProgramDataagent.uninstall.1587216527.bdinstall.v2.bin
2020-04-17 00:37 – 2020-04-17 00:46 – 000072692 _____ C:UsersDanieleDownloadsAddition.txt
2020-04-17 00:28 – 2020-04-19 14:41 – 000045553 _____ C:UsersDanieleDownloadsFRST.txt
2020-04-17 00:22 – 2020-04-19 14:40 – 000000000 ____D C:FRST
2020-04-17 00:21 – 2020-04-19 14:36 – 002281984 _____ (Farbar) C:UsersDanieleDownloadsFRST64.exe
2020-04-16 23:30 – 2020-04-16 23:30 – 000013738 _____ C:UsersDanieleDesktophijackthis2
2020-04-16 22:55 – 2020-04-18 14:29 – 000000000 ____D C:Program FilesBitdefender Agent
2020-04-16 22:55 – 2020-04-16 22:55 – 000102692 _____ C:ProgramDataagent.1587074131.bdinstall.v2.bin
2020-04-16 22:55 – 2020-04-16 22:55 – 000000000 ____D C:ProgramDataBitdefender Agent
2020-04-16 22:53 – 2020-04-16 22:53 – 010527368 _____ C:UsersDanieleDownloadsbitdefender_online.exe
2020-04-16 22:40 – 2020-04-16 22:40 – 000000000 ____D C:ProgramDataUbisoft
2020-04-16 22:11 – 2020-04-16 22:11 – 000388608 _____ (Trend Micro Inc.) C:UsersDanieleDownloadsHijackThis.exe
2020-04-15 17:17 – 2020-04-15 17:17 – 000000219 _____ C:UsersDanieleDesktopCounter-Strike Global Offensive.url
2020-04-10 00:18 – 2020-04-10 00:18 – 004342776 _____ (Avira Operations GmbH & Co. KG) C:UsersDanieleDownloadsavira_en_sptl1_1609235037-1586472637__phpws-spotlight-release (1).exe
2020-04-10 00:16 – 2020-04-10 00:16 – 000003292 _____ C:Windowssystem32TasksAvira_Antivirus_Systray
2020-04-10 00:15 – 2020-04-06 21:13 – 000177376 _____ (Avira Operations GmbH & Co. KG) C:Windowssystem32Driversavipbb.sys
2020-04-10 00:15 – 2020-03-27 12:48 – 000223744 _____ (Avira Operations GmbH & Co. KG) C:Windowssystem32Driversavgntflt.sys
2020-04-10 00:15 – 2019-06-07 15:09 – 000068152 _____ (Avira Operations GmbH & Co. KG) C:Windowssystem32Driversavdevprot.sys
2020-04-10 00:15 – 2019-03-20 19:50 – 000078600 _____ (Avira Operations GmbH & Co. KG) C:Windowssystem32Driversavnetflt.sys
2020-04-10 00:15 – 2019-03-20 19:50 – 000036072 _____ (Avira Operations GmbH & Co. KG) C:Windowssystem32Driversavkmgr.sys
2020-04-10 00:15 – 2019-03-20 19:50 – 000035376 _____ (Avira Operations GmbH & Co. KG) C:Windowssystem32Driversavusbflt.sys
2020-04-09 23:54 – 2020-04-09 23:55 – 000000000 ____D C:UsersPublicSpeedup Sessions
2020-04-09 23:54 – 2020-04-09 23:54 – 000003668 _____ C:Windowssystem32TasksAviraSystemSpeedupUpdate
2020-04-09 23:53 – 2020-04-15 08:51 – 000000000 ____D C:ProgramDataMicrosoftWindowsStart MenuProgramsAvira
2020-04-09 23:53 – 2020-04-09 23:53 – 000001192 _____ C:UsersPublicDesktopAvira.lnk
2020-04-09 23:53 – 2020-04-09 23:53 – 000001192 _____ C:ProgramDataDesktopAvira.lnk
2020-04-09 23:50 – 2020-04-09 23:50 – 004342776 _____ (Avira Operations GmbH & Co. KG) C:UsersDanieleDownloadsavira_en_sptl1_1609235037-1586472637__phpws-spotlight-release.exe
2020-04-09 23:08 – 2020-04-09 23:08 – 003318440 _____ (Dominik Reichl ) C:UsersDanieleDownloadsKeePass-2.44-Setup.exe
2020-04-03 01:24 – 2020-04-03 01:24 – 000000000 ____D C:UsersDanieleAppDataLocalLowObsidian Entertainment
2020-04-02 22:10 – 2020-04-02 22:10 – 000000222 _____ C:UsersDanieleDesktopPillars of Eternity.url
2020-03-30 19:29 – 2020-03-30 19:29 – 000076137 _____ C:UsersDanieleDownloadseContract.pdf
2020-03-26 17:50 – 2020-03-26 18:04 – 000000000 ____D C:UsersDanieleDesktopRee Accident Claim
2020-03-25 23:46 – 2020-04-04 11:49 – 000000000 ____D C:UsersDaniele.Ld2VirtualBox
2020-03-25 23:45 – 2020-03-25 23:45 – 000000671 _____ C:UsersDanieleDesktopLDMultiPlayer4.lnk
2020-03-25 23:45 – 2020-03-25 23:45 – 000000671 _____ C:UsersDanieleAppDataRoamingMicrosoftWindowsStart MenuLDMultiPlayer4.lnk
2020-03-25 23:45 – 2020-03-25 23:45 – 000000656 _____ C:UsersDanieleDesktopLDPlayer4.lnk
2020-03-25 23:45 – 2020-03-25 23:45 – 000000656 _____ C:UsersDanieleAppDataRoamingMicrosoftWindowsStart MenuLDPlayer4.lnk
2020-03-25 23:45 – 2020-03-25 23:45 – 000000000 ____D C:UsersDanieleAppDataRoamingMicrosoftWindowsStart MenuProgramsLDPlayer4
2020-03-25 23:44 – 2020-03-25 23:45 – 000000000 ____D C:Program Filesldplayerbox
2020-03-25 23:44 – 2020-03-25 23:44 – 000000000 ____D C:UsersDanieleDocumentsXuanZhi
2020-03-25 23:43 – 2020-03-25 23:43 – 000000000 ____D C:Program FilesMcAfee
2020-03-25 23:42 – 2020-03-25 23:42 – 000284010 _____ C:UsersDanieleAppDataRoamingm47_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
2020-03-25 23:42 – 2020-03-25 23:42 – 000000000 ____D C:UsersDanieleDownloads2cep
2020-03-25 23:41 – 2020-03-25 23:46 – 000000000 ____D C:UsersDanieleAppDataRoamingXuanZhi
2020-03-25 23:41 – 2020-03-25 23:41 – 002931392 _____ (XUANZHI INTERNATIONAL CO., LIMITED) C:UsersDanieleDownloadsLDPlayer_ens_3020_ld.exe
2020-03-25 23:41 – 2020-03-25 23:41 – 002931392 _____ (XUANZHI INTERNATIONAL CO., LIMITED) C:UsersDanieleDownloadsLDPlayer_ens_3020_ld (1).exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-19 14:47 – 2014-02-28 19:48 – 000000000 ____D C:UsersDanieleAppDataLocalBattle.net
2020-04-19 14:28 – 2017-01-29 20:15 – 000000000 ____D C:UsersDanieleAppDataLocalLowMozilla
2020-04-19 14:27 – 2019-01-30 14:34 – 000000000 ____D C:UsersDanieleAppDataRoamingDiscord
2020-04-19 13:50 – 2018-10-22 17:50 – 000000911 _____ C:WindowsTasksEPSON XP-312 313 315 Series Update E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF.job
2020-04-19 13:50 – 2018-10-22 17:50 – 000000911 _____ C:WindowsTasksEPSON XP-312 313 315 Series Update 6AFC5C38-E427-4C18-A613-15CA4120664F.job
2020-04-19 13:50 – 2018-10-22 17:50 – 000000725 _____ C:WindowsTasksEPSON XP-312 313 315 Series Invitation E25A4D64-F87D-4249-99D5-CFF2F8F8E6DF.job
2020-04-19 13:50 – 2018-10-22 17:50 – 000000725 _____ C:WindowsTasksEPSON XP-312 313 315 Series Invitation 6AFC5C38-E427-4C18-A613-15CA4120664F.job
2020-04-19 12:25 – 2018-07-01 20:59 – 000000000 ____D C:ProgramDataNVIDIA
2020-04-19 03:56 – 2009-07-14 05:45 – 000016976 ____H C:Windowssystem327B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-04-19 03:56 – 2009-07-14 05:45 – 000016976 ____H C:Windowssystem327B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-04-19 03:19 – 2018-03-26 22:41 – 000000000 ____D C:UsersDanieleAppDataRoamingHearthstoneDeckTracker
2020-04-18 20:55 – 2018-03-26 22:41 – 000002512 _____ C:UsersDanieleDesktopHearthstone Deck Tracker.lnk
2020-04-18 20:55 – 2018-03-26 22:41 – 000000000 ____D C:UsersDanieleAppDataLocalHearthstoneDeckTracker
2020-04-18 20:54 – 2018-03-26 22:41 – 000000000 ____D C:UsersDanieleAppDataLocalSquirrelTemp
2020-04-18 15:26 – 2014-02-28 19:47 – 000000000 ____D C:Program Files (x86)Battle.net
2020-04-18 14:22 – 2014-06-18 09:34 – 000000000 ____D C:Program Files (x86)TeamViewer
2020-04-18 14:21 – 2009-07-14 06:08 – 000000006 ____H C:WindowsTasksSA.DAT
2020-04-17 19:37 – 2017-05-31 22:40 – 000000000 ____D C:UsersRee
2020-04-17 13:30 – 2019-12-20 00:37 – 000000000 ____D C:WindowsSysWOW64NV
2020-04-17 13:30 – 2019-12-20 00:37 – 000000000 ____D C:Windowssystem32NV
2020-04-17 13:29 – 2017-09-12 00:30 – 000000000 ____D C:Program Files (x86)Mozilla Firefox
2020-04-17 13:29 – 2013-05-04 17:46 – 000000000 ____D C:Program Files (x86)Mozilla Maintenance Service
2020-04-17 13:22 – 2014-01-15 19:16 – 000000000 ____D C:Program Files (x86)Steam
2020-04-17 13:10 – 2017-12-17 16:51 – 000000000 ____D C:UsersDanieleAppDataLocalUbisoft Game Launcher
2020-04-16 22:37 – 2012-06-21 20:37 – 000000000 ___HD C:Program Files (x86)InstallShield Installation Information
2020-04-16 22:37 – 2009-07-14 06:32 – 000000000 ___RD C:ProgramDataMicrosoftWindowsStart MenuProgramsGames
2020-04-16 22:36 – 2013-05-04 20:18 – 000000000 ____D C:UsersDanieleAppDataRoaminguTorrent
2020-04-15 20:36 – 2013-05-04 18:11 – 000002226 _____ C:ProgramDataMicrosoftWindowsStart MenuProgramsGoogle Chrome.lnk
2020-04-10 00:17 – 2009-07-14 04:20 – 000000000 ____D C:Windowsinf
2020-04-10 00:15 – 2013-05-06 00:19 – 000000000 ____D C:ProgramDataAvira
2020-04-10 00:15 – 2013-05-06 00:19 – 000000000 ____D C:Program Files (x86)Avira
2020-04-10 00:13 – 2013-04-13 02:40 – 000743878 _____ C:Windowssystem32perfh010.dat
2020-04-10 00:13 – 2013-04-13 02:40 – 000148496 _____ C:Windowssystem32perfc010.dat
2020-04-10 00:13 – 2009-07-14 06:13 – 001662796 _____ C:Windowssystem32PerfStringBackup.INI
2020-04-10 00:04 – 2013-04-16 13:43 – 000000000 ____D C:UsersDaniele
2020-04-09 23:52 – 2014-08-20 13:02 – 000000000 ____D C:ProgramDataPackage Cache
2020-04-09 23:28 – 2018-01-28 01:56 – 000000000 ____D C:UsersDanieleAppDataRoamingKeePass
2020-04-09 23:10 – 2018-01-28 01:00 – 000001121 _____ C:ProgramDataMicrosoftWindowsStart MenuProgramsKeePass 2.lnk
2020-04-09 23:10 – 2018-01-28 01:00 – 000001109 _____ C:UsersDanieleDesktopKeePass 2.lnk
2020-04-09 23:10 – 2018-01-28 01:00 – 000000000 ____D C:Program Files (x86)KeePass Password Safe 2
2020-04-02 06:28 – 2018-03-29 14:27 – 000000000 ____D C:Program Files (x86)Overwolf
2020-04-02 00:49 – 2010-11-21 04:27 – 000744808 ____N (Microsoft Corporation) C:Windowssystem32MpSigStub.exe
2020-03-26 18:43 – 2019-12-18 20:22 – 000000000 ____D C:UsersDanieleAppDataRoamingChangZhi2
2020-03-26 17:50 – 2013-05-12 22:25 – 000000000 ____D C:UsersDanieleDesktopCompleanno Ree 2013
2020-03-26 17:49 – 2020-02-04 14:31 – 000000000 ____D C:UsersDanieleDesktopCittadinanza
2020-03-25 23:42 – 2013-05-06 19:11 – 000000000 ____D C:ProgramDataMcAfee
2020-03-25 23:34 – 2019-12-18 20:31 – 000000000 ____D C:UsersDaniele.LdVirtualBox
2020-03-25 13:00 – 2019-02-14 20:04 – 000000000 ____D C:UsersDanieleAppDataLocalBluestacks
2020-03-24 02:08 – 2013-05-15 17:30 – 000000000 ____D C:UsersDanieleAppDataRoamingSoftGrid Client
2020-03-21 02:29 – 2013-05-04 18:11 – 000003586 _____ C:Windowssystem32TasksGoogleUpdateTaskMachineUA
2020-03-21 02:29 – 2013-05-04 18:11 – 000003458 _____ C:Windowssystem32TasksGoogleUpdateTaskMachineCore
2020-03-20 08:46 – 2015-01-01 09:45 – 000004476 _____ C:Windowssystem32TasksAdobe Acrobat Update Task
2020-03-20 08:45 – 2015-12-16 22:13 – 000002441 _____ C:ProgramDataMicrosoftWindowsStart MenuProgramsAcrobat Reader DC.lnk
==================== Files in the root of some directories ========
2013-12-31 12:57 – 2013-12-31 12:58 – 000000093 _____ () C:UsersDanieleAppDataRoamingARCompanion.log
2019-12-18 20:31 – 2019-12-18 20:31 – 000000068 _____ () C:UsersDanieleAppDataRoamingchangzhi_leidian.data
2019-12-21 18:17 – 2019-12-21 18:17 – 000000068 _____ () C:UsersDanieleAppDataRoamingchangzhi_mplayer.data
2020-03-25 23:42 – 2020-03-25 23:42 – 000284010 _____ () C:UsersDanieleAppDataRoamingm47_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
2017-07-11 22:13 – 2017-07-11 22:13 – 000014139 _____ () C:UsersDanieleAppDataLocalHWVendorDetection.log
2013-05-05 00:55 – 2019-12-27 13:15 – 000007615 _____ () C:UsersDanieleAppDataLocalresmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2020-04-17 19:29
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-04-2020
Ran by Daniele (19-04-2020 14:50:00)
Running from C:UsersDanieleDownloads
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-16 12:43:25)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1536202438-368462837-3654654372-500 – Administrator – Disabled)
Daniele (S-1-5-21-1536202438-368462837-3654654372-1001 – Administrator – Enabled) => C:UsersDaniele
Guest (S-1-5-21-1536202438-368462837-3654654372-501 – Limited – Disabled)
HomeGroupUser$ (S-1-5-21-1536202438-368462837-3654654372-1003 – Limited – Enabled)
Ree (S-1-5-21-1536202438-368462837-3654654372-1005 – Limited – Enabled) => C:UsersRee
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled – Up to date) 8EAC8D5C-B3AA-95AA-3DF1-2845CDD09CBE
AV: Microsoft Security Essentials (Enabled – Up to date) 71A27EC9-3DA6-45FC-60A7-004F623C6189
AS: Microsoft Security Essentials (Enabled – Up to date) CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34
AS: Avira Antivirus (Enabled – Up to date) 35CD6CB8-9590-9A24-0741-1337B657D603
AS: Windows Defender (Disabled – Out of date) D68DDC3A-831F-4fae-9E44-DA132C1ACF46
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acer Backup Manager (HKLM-x32…InstallShield_0B61BBD5-DA3C-409A-8730-0C3DC3B0F270) (Version: 3.0.0.99 – NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32…