OTL logfile created on: 19/02/2013 08:17:03 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\Download Remoto
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000410 | Country: Italia | Language: ITA | Date Format: dd/MM/yyyy
1,99 Gb Total Physical Memory | 0,74 Gb Available Physical Memory | 37,17% Memory free
3,98 Gb Paging File | 2,16 Gb Available in Paging File | 54,39% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297,99 Gb Total Space | 236,49 Gb Free Space | 79,36% Space Free | Partition Type: NTFS
Drive D: | 3,29 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 111,76 Gb Total Space | 47,54 Gb Free Space | 42,53% Space Free | Partition Type: FAT32
Drive G: | 7,46 Gb Total Space | 6,57 Gb Free Space | 88,00% Space Free | Partition Type: FAT32
Drive J: | 30,07 Gb Total Space | 23,96 Gb Free Space | 79,70% Space Free | Partition Type: FAT32
Computer Name: UTENTE-PC | User Name: Utente | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ========== PRC - E:\Download Remoto\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
PRC - C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Emsisoft GmbH)
PRC - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe (Emsisoft GmbH)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Macrium\Reflect\ReflectService.exe ()
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Users\Utente\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.DesktopHelper.exe (Research In Motion)
PRC - C:\Program Files\Cobian Backup 11\cbVSCService11.exe (CobianSoft, Luis Cobian)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
PRC - C:\ProgramData\Chiavetta Internet E353 21.6\OnlineUpdate\ouc.exe ()
PRC - C:\Program Files\Qlock\qlock.exe ()
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\ProgramData\DatacardService\HWDeviceService.exe ()
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe (Software602 a.s.)
PRC - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
========== Modules (No Company Name) ========== MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\78967b28f748b8807eaa97c1cb454adc\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\9266d6e1f8057b5b62b460cbf33cda21\System.WorkflowServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1e04a5319c58010e945220af2751d34e\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\77dfcfed5fd5f67d0d3edc545935bb21\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\3e79256ce40faa9682f9e3511ca115ea\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ad51da1b752b19c992fcefd56eb7c01\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\219c68f83fa608b496b163fd6782e696\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb33bf977e97e97b12e82c18e36fbaee\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\USBDetector.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\ticket.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\readerAppHelper.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskTimeHardware.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskNetInterface.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskPower.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskMediaPlayers.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskMobileMediaDevice.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\Fskin.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskinLocalize.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskDocumentViewer.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\ebookUsb.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\ebookDeviceNotifier.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\fsk.dll ()
MOD - C:\Program Files\Sony\ReaderDesktop\appHelper\FskSecurity.dll ()
MOD - C:\Program Files\Qlock\qlock.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll ()
========== Services (SafeList) ========== SRV - (vToolbarUpdater14.2.0) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (a2AntiMalware) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Emsisoft GmbH)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (ReflectService.exe) -- C:\Program Files\Macrium\Reflect\ReflectService.exe ()
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (cbVSCService11) -- C:\Program Files\Cobian Backup 11\cbVSCService11.exe (CobianSoft, Luis Cobian)
SRV - (AdvancedSystemCareService6) -- C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
SRV - (Sony SCSI Helper Service) -- C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe (Sony Corporation)
SRV - (Chiavetta Internet E353 21.6. RunOuc) -- C:\Program Files\Chiavetta Internet E353 21.6\UpdateDog\ouc.exe ()
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (IMFservice) -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (Guard Agent) -- C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (EaseUS Agent) -- C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (HWDeviceService.exe) -- C:\ProgramData\DatacardService\HWDeviceService.exe ()
SRV - (602XML Updater) -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe (Software602 a.s.)
SRV - (HP LaserJet Service) -- C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (VGPU) -- System32\drivers\rdvgkmd.sys File not found
DRV - (tsusbhub) -- system32\drivers\tsusbhub.sys File not found
DRV - (Synth3dVsc) -- System32\drivers\synth3dvsc.sys File not found
DRV - (MpKsl82bba66e) -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{82DD7113-64F8-4701-BCEF-13FFB6774E70}\MpKsl82bba66e.sys (Microsoft Corporation)
DRV - (avgtp) -- C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (pssnap) -- C:\Windows\System32\drivers\pssnap.sys (Macrium Software)
DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (UrlFilter) -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\UrlFilter.sys (IObit.com)
DRV - (a2acc) -- C:\Program Files\Emsisoft Anti-Malware\a2accx86.sys (Emsisoft GmbH)
DRV - (a2injectiondriver) -- C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys (Emsisoft GmbH)
DRV - (huawei_wwanecm) -- C:\Windows\System32\drivers\ew_juwwanecm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) -- C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_cdcacm) -- C:\Windows\System32\drivers\ew_jucdcacm.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) -- C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_ext_ctrl) -- C:\Windows\System32\drivers\ew_juextctrl.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) -- C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (FileMonitor) -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys (IObit)
DRV - (EUFDDISK) -- C:\Windows\System32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) -- C:\Windows\System32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) -- C:\Windows\System32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) -- C:\Windows\System32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (A2DDA) -- C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys (Emsi Software GmbH)
DRV - (speedfan) -- C:\Windows\System32\speedfan.sys (Almico Software)
DRV - (SmartDefragDriver) -- C:\Windows\System32\drivers\SmartDefragDriver.sys ()
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (UnlockerDriver5) -- C:\Program Files\Unlocker\UnlockerDriver5.sys ()
DRV - (HPFXBULKLEDM) -- C:\Windows\System32\drivers\hppcbulkio.sys (Hewlett Packard)
DRV - (a2util) -- C:\Program Files\Emsisoft Anti-Malware\a2util32.sys (Emsi Software GmbH)
DRV - (netw5v32) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (snpstd) -- C:\Windows\System32\drivers\snpstd.sys ()
DRV - (giveio) -- C:\Windows\System32\giveio.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\.DEFAULT\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://it.msn.com/?ocid=iehpIE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5C 66 5D 4B 0E 09 CD 01 [binary data]
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..\URLSearchHook: {4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1} - No CLSID value found
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..\SearchScopes\{0493ED0E-2F44-487E-9479-1F25E06AEA9D}: "URL" =
http://it.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=685749&p={searchTerms}
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://search.babylon.com/?q={searchTerms}&affID=111304&babsrc=SP_ss&mntrId=6046cb260000000000000011e2fcf485
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..\SearchScopes\{EFFEAADF-532F-4F9E-9EAA-571080AB8A8D}: "URL" =
http://www.bing.com/search?FORM=UP30DF&PC=UP30&q={searchTerms}&src=IE-SearchBox
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Bing "
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_IT Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851640&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.3: "Bing "
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=685749"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=2&CUI=SB_CUI&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@sony.com/ReaderDesktop: C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Utente\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Utente\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2013/01/11 15:14:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ [2012/12/04 03:02:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.2.0.1 [2013/02/18 22:34:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/02/05 07:36:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013/01/09 15:37:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.15.2\extensions\\Components: C:\Program Files\SeaMonkey\components [2013/02/06 07:56:06 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013/01/09 15:37:51 | 000,000,000 | ---D | M]
[2012/04/02 15:08:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Utente\AppData\Roaming\mozilla\Extensions
[2012/04/02 15:08:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Utente\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2013/01/11 04:29:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Utente\AppData\Roaming\mozilla\Firefox\Profiles\pw4lsdkf.default\extensions
[2013/01/11 04:26:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Utente\AppData\Roaming\mozilla\SeaMonkey\Profiles\9tihczen.default\extensions
[2012/10/11 02:52:11 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Utente\AppData\Roaming\mozilla\SeaMonkey\Profiles\9tihczen.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2012/10/13 08:04:14 | 000,000,000 | ---D | M] (Dizionario italiano) -- C:\Users\Utente\AppData\Roaming\mozilla\SeaMonkey\Profiles\9tihczen.default\extensions\it-IT@dictionaries.addons.mozilla.org
[2012/12/21 08:48:36 | 000,002,402 | ---- | M] () -- C:\Users\Utente\AppData\Roaming\mozilla\firefox\profiles\pw4lsdkf.default\searchplugins\bingp.xml
[2012/06/08 14:35:20 | 000,005,310 | ---- | M] () -- C:\Users\Utente\AppData\Roaming\mozilla\firefox\profiles\pw4lsdkf.default\searchplugins\footiefox.xml
[2013/01/11 04:16:03 | 000,001,050 | ---- | M] () -- C:\Users\Utente\AppData\Roaming\mozilla\firefox\profiles\pw4lsdkf.default\searchplugins\myashampoo-customized-web-search.xml
[2013/02/13 21:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/02/13 21:25:05 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/02/01 13:21:57 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/02/01 16:59:36 | 000,001,606 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-it.xml
[2013/02/18 22:34:59 | 000,003,688 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2013/02/01 16:59:36 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/01 16:59:36 | 000,000,957 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-it.xml
[2013/02/01 16:59:36 | 000,001,030 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\hoepli.xml
[2013/02/01 16:59:36 | 000,001,395 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-it.xml
[2013/02/01 16:59:36 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-it.xml
========== Chrome ========== CHR - Extension: No name found = C:\Users\Utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgchmkmjfjloickkmkdgibpmboaphdei\10.13.20.29_0\
CHR - Extension: No name found = C:\Users\Utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.6.0.11664_0\
CHR - Extension: No name found = C:\Users\Utente\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdghcmanhfigpijjllopocpcnjffkhl\2.3.11.0_0\
O1 HOSTS File: ([2012/03/24 18:28:54 | 000,441,409 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 15170 more lines...
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - No CLSID value found.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (no name) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [emsisoft anti-malware] c:\program files\emsisoft anti-malware\a2guard.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation)
O4 - HKLM..\Run: [snpstd] C:\Windows\vsnpstd.exe ()
O4 - HKU\S-1-5-21-2290898824-930106310-2662002411-1000..\Run: [Rim.DesktopHelper.exe] C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.DesktopHelper.exe (Research In Motion)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Utente\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qlock.lnk = C:\Program Files\Qlock\qlock.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Free YouTube Download - C:\Users\Utente\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Utente\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2290898824-930106310-2662002411-1000\..Trusted Domains: maris.com ([www.redshift] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 10.13.2)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 10.13.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{26D58F30-9F47-411B-8A1A-E92D920863BE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5CAA1C05-7314-4804-A8A6-0C1A2CC41F0D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BFF2772-B973-42E8-96AD-0627B6F96425}: NameServer = 62.13.173.92 62.13.173.93
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBA7AA67-1238-429D-B2D0-DC15B899E155}: NameServer = 62.13.173.92 62.13.173.93
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/02/21 10:20:56 | 000,000,048 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{465ad38c-8941-11e1-8800-001636bedc91}\Shell - "" = AutoRun
O33 - MountPoints2\{465ad38c-8941-11e1-8800-001636bedc91}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{59666379-74d6-11e1-ad53-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{59666379-74d6-11e1-ad53-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Go.exe -- [2007/02/15 05:18:10 | 000,372,736 | R--- | M] (Maris Technologies, Ltd.)
O33 - MountPoints2\{6f7fc570-8945-11e1-8d12-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{6f7fc570-8945-11e1-8d12-0011e2fcf485}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{850d9bfb-8980-11e1-a7f7-001636bedc91}\Shell - "" = AutoRun
O33 - MountPoints2\{850d9bfb-8980-11e1-a7f7-001636bedc91}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{999daa0a-871c-11e1-b45e-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{999daa0a-871c-11e1-b45e-0011e2fcf485}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{999daa2b-871c-11e1-b45e-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{999daa2b-871c-11e1-b45e-0011e2fcf485}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{b6e5fcfd-86af-11e1-9f25-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{b6e5fd08-86af-11e1-9f25-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{d171329f-887f-11e1-88f6-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{d171329f-887f-11e1-88f6-0011e2fcf485}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{d17132b0-887f-11e1-88f6-0011e2fcf485}\Shell - "" = AutoRun
O33 - MountPoints2\{d17132b0-887f-11e1-88f6-0011e2fcf485}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{fbc7fc0d-8922-11e1-8c00-001636bedc91}\Shell - "" = AutoRun
O33 - MountPoints2\{fbc7fc0d-8922-11e1-8c00-001636bedc91}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{fbc7fc3b-8922-11e1-8c00-001636bedc91}\Shell - "" = AutoRun
O33 - MountPoints2\{fbc7fc3b-8922-11e1-8c00-001636bedc91}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{fbc7fc54-8922-11e1-8c00-001636bedc91}\Shell - "" = AutoRun
O33 - MountPoints2\{fbc7fc6d-8922-11e1-8c00-001636bedc91}\Shell - "" = AutoRun
O33 - MountPoints2\{fbc7fc6d-8922-11e1-8c00-001636bedc91}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 60 Days ========== [2013/02/18 22:33:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2013/02/17 09:00:40 | 000,000,000 | ---D | C] -- C:\Program Files\Veetle
[2013/02/13 09:11:51 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/02/13 09:11:48 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/02/13 09:11:47 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/02/13 09:11:46 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/02/13 09:11:45 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/02/13 09:11:43 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/02/13 09:11:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/02/13 09:11:38 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/02/13 07:50:03 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/02/13 07:49:42 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013/02/13 07:49:41 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013/02/13 07:49:37 | 000,187,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/02/13 07:49:30 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013/02/10 22:09:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2013/02/08 08:49:12 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\{843D6C1A-5D96-429A-B03D-5668B1ECDD40}
[2013/02/08 08:03:00 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
[2013/02/07 08:34:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2013/02/06 07:59:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
[2013/02/06 07:59:16 | 000,000,000 | ---D | C] -- C:\Program Files\Macrium
[2013/02/03 20:54:18 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013/02/03 20:53:54 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013/02/03 20:53:53 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013/02/03 20:53:53 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013/01/31 12:55:12 | 000,013,432 | ---- | C] (Paramount Software UK Ltd) -- C:\Windows\System32\drivers\PSVolAcc.sys
[2013/01/31 12:54:48 | 000,016,504 | ---- | C] (Macrium Software) -- C:\Windows\System32\drivers\pssnap.sys
[2013/01/29 06:20:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc
[2013/01/29 06:20:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Sony Shared
[2013/01/23 03:59:12 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\{4C568CB1-8B9A-4317-AC55-0D1F605D7F16}
[2013/01/21 03:07:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2013/01/21 03:07:22 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2013/01/20 03:21:35 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/01/15 08:58:16 | 000,000,000 | ---D | C] -- C:\boot
[2013/01/11 11:51:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/01/11 11:51:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013/01/09 15:37:50 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013/01/09 00:39:19 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2013/01/09 00:39:16 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/01/09 00:39:16 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/09 00:39:16 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/09 00:39:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/09 00:39:15 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/01/09 00:39:14 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/09 00:39:14 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/01/09 00:39:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/09 00:39:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/09 00:39:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/01/09 00:39:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/01/09 00:39:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/01/09 00:39:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/09 00:39:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/09 00:39:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/09 00:39:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/01/09 00:39:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/01/09 00:39:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/01/09 00:39:12 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/01/09 00:39:12 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/09 00:39:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/01/09 00:39:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/09 00:39:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/01/09 00:39:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/09 00:39:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/09 00:39:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/09 00:39:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/01/09 00:39:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/01/09 00:38:39 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2013/01/09 00:38:39 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\System32\fpb.rs
[2013/01/09 00:38:39 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc-nz.rs
[2013/01/09 00:38:39 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\System32\pegibbfc.rs
[2013/01/09 00:38:39 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\System32\csrr.rs
[2013/01/09 00:38:39 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\System32\cob-au.rs
[2013/01/09 00:38:39 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\System32\usk.rs
[2013/01/09 00:38:39 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\System32\grb.rs
[2013/01/09 00:38:39 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-pt.rs
[2013/01/09 00:38:39 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi.rs
[2013/01/09 00:38:39 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\System32\djctq.rs
[2013/01/09 00:38:38 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll
[2013/01/09 00:38:36 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\System32\cero.rs
[2013/01/09 00:38:36 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\System32\esrb.rs
[2013/01/09 00:38:36 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc.rs
[2013/01/09 00:38:36 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-fi.rs
[2013/01/09 00:38:26 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2013/01/09 00:38:25 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
[2013/01/05 15:36:59 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Roaming\Stellarium
[2013/01/01 15:17:23 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\{2B7760FD-AD05-4739-BB48-A1E0A75019C2}
[2012/12/30 03:44:22 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\{AC808C12-8BA5-4564-8D95-9370919C95D5}
[2012/12/28 13:45:27 | 000,000,000 | ---D | C] -- C:\Users\Utente\AppData\Local\AVG Secure Search
[2012/12/28 13:44:00 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2012/12/28 13:42:53 | 000,033,112 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012/12/28 13:42:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2012/12/28 13:40:47 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/12/22 07:17:22 | 000,000,000 | ---D | C] -- C:\Users\Utente\Documents\ccsetup326
========== Files - Modified Within 60 Days ========== [2013/02/19 07:48:06 | 000,000,132 | ---- | M] () -- C:\Users\Utente\Documents\cc_20130219_074746.reg
[2013/02/19 07:47:33 | 000,701,426 | ---- | M] () -- C:\Windows\System32\perfh010.dat
[2013/02/19 07:47:33 | 000,618,912 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/02/19 07:47:33 | 000,128,740 | ---- | M] () -- C:\Windows\System32\perfc010.dat
[2013/02/19 07:47:33 | 000,107,232 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/02/19 07:43:00 | 000,000,978 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/19 07:36:51 | 000,020,576 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/19 07:36:51 | 000,020,576 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/19 07:36:03 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/19 07:29:13 | 000,001,164 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2290898824-930106310-2662002411-1000UA.job
[2013/02/19 07:28:47 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/19 07:28:39 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2013/02/19 07:28:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/19 07:27:54 | 1602,887,680 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/18 22:32:23 | 000,033,112 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/18 08:05:42 | 000,005,336 | ---- | M] () -- C:\Users\Utente\Documents\cc_20130218_080458.reg
[2013/02/17 21:49:44 | 000,031,999 | ---- | M] () -- C:\Users\Utente\Desktop\Fuori era -12.htm
[2013/02/17 21:39:35 | 004,739,072 | ---- | M] () -- C:\Users\Utente\Documents\Money 2011.mny
[2013/02/17 21:39:34 | 000,957,726 | R--- | M] () -- C:\Users\Utente\Documents\Money 2011 Backup_2013-02-17_213931.mbf
[2013/02/17 21:29:01 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2290898824-930106310-2662002411-1000Core.job
[2013/02/16 07:36:56 | 000,000,132 | ---- | M] () -- C:\Users\Utente\Documents\cc_20130216_073639.reg
[2013/02/13 21:39:16 | 002,347,059 | ---- | M] () -- C:\Users\Utente\Desktop\IMG_0401.JPG
[2013/02/13 09:31:27 | 000,455,888 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/12 22:06:31 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013/02/12 21:14:04 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/02/12 21:14:04 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/02/06 08:05:01 | 000,000,925 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/02/05 07:36:38 | 000,001,065 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/02/03 20:53:38 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013/02/03 20:53:31 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013/02/03 20:53:30 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013/02/03 20:53:29 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013/02/03 20:53:27 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2013/02/03 20:53:27 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013/01/31 12:55:12 | 000,013,432 | ---- | M] (Paramount Software UK Ltd) -- C:\Windows\System32\drivers\PSVolAcc.sys
[2013/01/31 12:54:48 | 000,016,504 | ---- | M] (Macrium Software) -- C:\Windows\System32\drivers\pssnap.sys
[2013/01/31 12:53:54 | 000,055,416 | ---- | M] () -- C:\Windows\System32\drivers\psmounterex.sys
[2013/01/30 05:53:21 | 000,232,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2013/01/27 06:22:09 | 000,032,256 | ---- | M] () -- C:\Users\Utente\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/26 08:07:29 | 000,299,893 | ---- | M] () -- C:\Users\Utente\Desktop\Telecom.pdf
[2013/01/26 07:16:07 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2013/01/26 07:16:07 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2013/01/24 08:36:49 | 000,001,051 | ---- | M] () -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/01/20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\NisDrvWFP.sys
[2013/01/11 11:51:13 | 000,002,503 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013/01/10 08:52:05 | 000,496,452 | ---- | M] () -- C:\Users\Utente\Desktop\Guida 730.pdf
[2013/01/10 08:51:00 | 000,316,887 | ---- | M] () -- C:\Users\Utente\Desktop\Modulo 730.pdf
[2013/01/08 17:11:21 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/01/08 17:03:12 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/01/08 17:01:48 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/01/08 17:00:14 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/01/08 16:59:02 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/01/08 16:57:49 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/01/08 16:56:23 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/01/08 16:53:13 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/01/05 00:00:15 | 003,967,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013/01/05 00:00:11 | 003,913,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013/01/03 23:50:52 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013/01/03 22:00:29 | 002,347,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/01/03 00:04:43 | 000,187,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2012/12/28 01:18:21 | 000,001,027 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/21 08:25:30 | 000,000,083 | ---- | M] () -- C:\Users\Utente\AppData\Roaming\default.pls
========== Files Created - No Company Name ========== [2013/02/19 07:48:02 | 000,000,132 | ---- | C] () -- C:\Users\Utente\Documents\cc_20130219_074746.reg
[2013/02/18 08:05:35 | 000,005,336 | ---- | C] () -- C:\Users\Utente\Documents\cc_20130218_080458.reg
[2013/02/17 21:49:43 | 000,031,999 | ---- | C] () -- C:\Users\Utente\Desktop\Fuori era -12.htm
[2013/02/17 21:39:34 | 000,957,726 | R--- | C] () -- C:\Users\Utente\Documents\Money 2011 Backup_2013-02-17_213931.mbf
[2013/02/16 07:36:50 | 000,000,132 | ---- | C] () -- C:\Users\Utente\Documents\cc_20130216_073639.reg
[2013/02/13 21:39:05 | 002,347,059 | ---- | C] () -- C:\Users\Utente\Desktop\IMG_0401.JPG
[2013/01/31 12:53:54 | 000,055,416 | ---- | C] () -- C:\Windows\System32\drivers\psmounterex.sys
[2013/01/26 08:07:27 | 000,299,893 | ---- | C] () -- C:\Users\Utente\Desktop\Telecom.pdf
[2013/01/26 07:16:07 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2013/01/26 07:16:07 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2013/01/26 06:55:24 | 000,000,925 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/01/11 11:51:13 | 000,002,503 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2013/01/10 08:52:04 | 000,496,452 | ---- | C] () -- C:\Users\Utente\Desktop\Guida 730.pdf
[2013/01/10 08:51:00 | 000,316,887 | ---- | C] () -- C:\Users\Utente\Desktop\Modulo 730.pdf
[2012/12/29 01:28:06 | 000,001,051 | ---- | C] () -- C:\Users\Utente\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/12/20 16:56:21 | 000,001,091 | ---- | C] () -- C:\Users\Utente\Documenti - collegamento.lnk
[2012/12/18 01:12:35 | 000,015,672 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys
[2012/11/15 16:40:30 | 000,032,256 | ---- | C] () -- C:\Users\Utente\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/05 10:58:27 | 000,000,083 | ---- | C] () -- C:\Users\Utente\AppData\Roaming\default.pls
[2012/05/05 06:37:08 | 000,000,000 | ---- | C] () -- C:\Windows\Irremote.ini
[2012/03/27 01:53:37 | 000,043,656 | ---- | C] () -- C:\Windows\System32\drivers\EUBKMON.sys
[2012/03/26 14:53:12 | 000,178,688 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012/03/24 07:11:12 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2012/03/24 07:09:26 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/03/23 11:56:12 | 000,001,024 | ---- | C] () -- C:\Users\Utente\.rnd
========== ZeroAccess Check ========== [2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 20:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2012/06/07 16:48:03 | 000,000,000 | -HSD | M] -- C:\Users\Utente\AppData\Roaming\.#
[2012/08/12 05:36:18 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\602Installer
[2012/03/25 12:37:04 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\AbelCam
[2012/06/23 03:31:15 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\aignes
[2012/03/27 01:55:56 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Ashampoo
[2012/05/07 07:38:33 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Auslogics
[2012/04/12 08:01:59 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\BlueSprig
[2012/03/27 01:57:55 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Canneverbe Limited
[2012/03/25 06:50:34 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Canon
[2013/02/19 07:30:09 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Dropbox
[2012/12/04 03:06:53 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\DVDVideoSoft
[2012/12/04 03:06:55 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/03/25 02:19:22 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Easeware
[2012/04/04 05:29:21 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Foxit Software
[2012/11/29 11:19:15 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\GlarySoft
[2012/10/17 14:09:04 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\IObit
[2012/05/11 06:18:07 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\LibreOffice
[2012/03/28 06:26:52 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Opera
[2012/10/24 07:38:09 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\pdfforge
[2012/05/04 02:13:44 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\PhotoScape
[2012/07/30 17:22:16 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Qlock
[2012/11/15 16:32:42 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Research In Motion
[2012/03/27 01:49:59 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Softland
[2013/01/05 15:37:06 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Stellarium
[2012/04/26 01:57:14 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\SumatraPDF
[2012/04/12 15:35:22 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Thunderbird
[2012/04/02 15:08:51 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\TomTom
[2013/02/19 07:46:09 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\uTorrent
[2012/03/29 02:07:29 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\Windows Live Writer
[2012/04/23 13:42:31 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\WinFF
[2012/12/17 17:02:38 | 000,000,000 | ---D | M] -- C:\Users\Utente\AppData\Roaming\XnView
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:0CFF5F08
< End of report >